|
|
Log in / Subscribe / Register

KRACK, ROCA, and device insecurity

KRACK, ROCA, and device insecurity

Posted Oct 19, 2017 0:34 UTC (Thu) by bojan (subscriber, #14302)
Parent article: KRACK, ROCA, and device insecurity

> Upgrading other WiFi devices may not be as easy—or even possible—for millions of devices.

In the age of the internet, selling network connected devices that cannot be easily updated (either automatically or manually) should be made illegal, IMHO. If major markets, such as USA, Europe and the rest of developed world enacted such regulation, the cowboys would either perish or would have to get their act together.

Where I live, you cannot buy a car without seat belts. If you don't use them, you get fined. Why should devices that can potentially cause people's money and private information to get stolen be any different?


to post comments

KRACK, ROCA, and device insecurity

Posted Oct 19, 2017 2:37 UTC (Thu) by jkingweb (subscriber, #113039) [Link]

I'm not sure seatbelts are the best analogy, though I certainly agree with the general sentiment. Certainly if devices must follow FCC guidelines not to cause harmful interference, it's reasonable that they should be hardened against recruitment into botnets used for DDoS attacks---surely a form of harmful interference.

Have security updates been demonstrated to save lives more or less directly like seatbelts have? In medical devices, I suppose?

KRACK, ROCA, and device insecurity

Posted Oct 19, 2017 6:57 UTC (Thu) by eru (subscriber, #2753) [Link]

Your proposed law would also have the positive effect it would make manufacturers think twice before adding network connectivity to devices that do not really need it: Making the device upgradeable, and providing upgrades has a cost.

KRACK, ROCA, and device insecurity

Posted Oct 19, 2017 7:04 UTC (Thu) by pabs (subscriber, #43278) [Link] (17 responses)

That isn't going to help for companies that went out of business or have short security support cycles, their devices will still be out there on people's networks, participating in the latest botnets etc.

KRACK, ROCA, and device insecurity

Posted Oct 19, 2017 7:35 UTC (Thu) by marcH (subscriber, #57642) [Link]

Software is a service. Buying a service from an unstable company is and has always been a well-known risk. Nothing new here besides the ignorance by some people that they are buying a service and the illusion to perform a once-off, hardware purchase instead. This type of illusion will pass; stories like this one and unmainted smartphones are making sure of that.

Insurance

Posted Oct 19, 2017 13:54 UTC (Thu) by tialaramex (subscriber, #21167) [Link] (9 responses)

_If_ that became a problem (and maybe it wouldn't) we have seen this solved for services that routinely go out of business leaving thousands of customers inconvenienced. The usual model is something along the lines of some form of mandatory insurance and the state steps in to actually administrate things using the money from that insurance. Good actors in an industry are neutralised, if they're really at no risk then they will surely obtain insurance very cheaply with no fuss, if they struggle to get insurance then it suggests they're a bad risk after all.

Two UK examples:

1. When a small bank fails, the government gives all its personal customers their money back (in theory up to a limit per customer, but in practice it has always been everything) and the remaining industry has to pay them back. This creates a "Last Man Standing" insurance without actually paying premiums etcetera, and it creates an incentive for big banks to tattle on small banks with risky practices to the regulator, because if they wait and let it fail they'll eat all the costs.

2. Package holiday companies have to join an industry scheme with insurance. No membership? It's illegal to sell holidays that include separate elements like flights and hotel booking bundled together and of course members have a powerful incentive to ensure this is enforced. So, when inevitably lots of these companies go broke each year the insurance pays out and makes sure nobody is left abandoned on some Greek island or arrives to find there's no hotel.

In the case of networked devices I'd imagine that some sort of code escrow would be involved, so when a business fails and can't/ won't ship security fixes the escrow gets unlocked, the insurance pays out and some fleet of maintenance programmers are paid to airdrop in and fix things. Deciding how much we, as a society, are willing to pay for that is just a numbers game. If we want it, we can have it.

Insurance

Posted Oct 19, 2017 15:47 UTC (Thu) by NAR (subscriber, #1313) [Link] (2 responses)

There are two small problems with your example:

1. These are (local) services. The (local) government could (more) easily regulate theme and you can't "buy" these services after they go out of business. So for example if I put my money into a foreign bank, the insurance in my home country will not cover me. I actually did have an account at a bank which was registered in a foreign country and they mentioned in all of their communication that my money is not covered by the local insurance (it was covered by the insurance of the foreign country). Also I can't go into a bank office after the bank shut down. On the other hand IoT devices are usually made in a different country and it is very much possible to find a device on the shelf of a local store where the maker is already out of business and thus no longer paying insurance.

2, These insurances increase the hurdle to enter the market. In the case of banks, it's probably not a bad idea. For holiday companies - I don't know. Here they don't have insurance (as far as I know), so from time to time there are news of some poor souls who are stranded somewhere. On the other hand the clients can (and maybe should) insure themselves. My wife is starting a (very) small business where an insurance is compulsory - and it's a real hurdle because initially it takes about 10% of the income (not from profit, from income).

Insurance

Posted Oct 20, 2017 16:32 UTC (Fri) by tialaramex (subscriber, #21167) [Link]

The use of insurance is appropriate when businesses keep failing. If your wife's business is in a sector where new businesses routinely fail and leave personal clients out of pocket, well, I appreciate that it's tough finding the money but wider society has to prioritise ensuring nobody gets screwed over the inconvenience for your wife. In fact arguably the insurance, though expensive, is helping her because without it clients would have to assume her new untested business is likely to fail and stay away.

The idea that clients should insure themselves is inefficient. It can work when clients are all or mostly corporations, though it will usually be inefficient even then. But for ordinary consumers it's ludicrously inefficient. The acquisition costs per customer may be slightly lower, but the insurance has many more customers, so overall a lot more resource is wasted. Where possible laws should put insurance requirements onto the larger entity which will usually be the supplier.

We _could_ say that everybody living in my building needs to take out an insurance policy in case the building burns down. If it happens, the insurers all pay out, together we buy a new building, everything is fine. But that's very inefficient. What actually happens is much better, the building's owner (maybe all the residents jointly, in my case a brass plate company in a tax haven) has to buy insurance and post proof to all residents, and they bill everybody for a share of the insurance along with the other costs of running the building, like elevator maintenance and painting the corridors.

The US has a lot of deliberately anti-competitive policies which can give the idea of regulation a bad name, rather than compete by offering a better service it turns out it's cheaper to "persuade" politicians to pass a law saying nobody is to compete with you, or indeed not to pass a law which would render you obsolete (title insurance, tax filing, and dozens of other things that needn't exist but still do because the campaign donations roll in from those selling them). So I'm not suggesting that every type of business ought to have insurance against the consequences of failing, just that it's a sensible remedy if an industry has this persistent problem the way that banks, and package holiday companies do, and the other poster suggested IoT manufacturers might.

Insurance

Posted Oct 22, 2017 1:25 UTC (Sun) by ssmith32 (subscriber, #72404) [Link]

But a hurdle to enter the market isn't a bad thing - especially if you're not ready or willing to cover the long-term effects you might have on society. If you're not willing to pay a price to help protect society against the damages you may cause if you fail, I see a hurdle as a good thing, not a bad.

Externalities are a real thing.

Not Insurance, Liability

Posted Oct 19, 2017 16:09 UTC (Thu) by kh (guest, #19413) [Link] (5 responses)

Product Liability law is the real fix. If you sell hardware that cannot get security updates, you should be held liable.

https://blog.valbonne-consulting.com/2015/07/24/cybersecu...

Dan Greer's talk on software liability - excerpt, quoted text below:

-----------------[Quoting]--------------

"[Software vendors]... must live with normal product liability, just like manufactures of cars, blenders, chain-saws and hot coffee.

How dire the consequences, and what constitutes "used normally" is for your legislature and courts to decide, but let us put up a strawman example:

A sales-person from one of your long time vendors visits and delivers new product documentation on a USB key, you plug the USB key into your computer and copy the files onto the computer.

This is "used normally" and it should never cause your computer to become part of a botnet, transmit your credit card number to Elbonia, or copy all your design documents to the vendor. If it does, your computer's operating system is defective."

------------------
3. Source code liability -- CHOICE

Nat Howard said that "Security will always be exactly as bad as it can possibly be while allowing everything to still function," but with each passing day, that "and still function" clause requires a higher standard. As Ken Thompson told us in his Turing Award lecture, there is no technical escape; in strict mathematical terms you neither trust a program nor a house unless you created it 100% yourself, but in reality most of us will trust a house built by a suitably skilled professional, usually we will trust it more than one we had built ourselves, and this even if we have never met the builder, or even if he is long since dead.

The reason for this trust is that shoddy building work has had that crucial "or else ..." clause for more than 3700 years:

If a builder builds a house for someone, and does not construct it properly, and the house which he built falls in and kills its owner, then the builder shall be put to death.
-- Code of Hammurabi, approx 1750 B.C.

Today the relevant legal concept is "product liability" and the fundamental formula is "If you make money selling something, then you better do it well, or you will be held responsible for the trouble it causes." For better or poorer, the only two products not covered by product liability today are religion and software, and software should not escape for much longer. Poul-Henning Kamp and I have a strawman proposal for how software liability regulation could be structured....

Not Insurance, Liability

Posted Oct 20, 2017 13:45 UTC (Fri) by jospoortvliet (guest, #33164) [Link] (4 responses)

Liability is useless if the company goes bankrupt. And bankruptcy is an often used way to get out of liability that even bigger companies use - put the liability on a small subsidiary, and done.

So it would help, a bit, against Microsoft and other large companies, though THEY of course can extend court cases far beyond what a small business or home user could sustain - again leaving those without recourse.

Last but not least, it is becoming common practice to put enforced arbitrage in contracts and unless the courts step up against that (most don't) this kills any serious liability risks.

I don't disagree that adding liability to software is a good idea. I just don't think it solves all problems ;-)

Not Insurance, Liability

Posted Oct 22, 2017 1:29 UTC (Sun) by ssmith32 (subscriber, #72404) [Link] (2 responses)

Yeah, but that's just because the way the law is structured, you can avoid all kinds of personal responsibility by incorporating. The solution would be personal liability, not corporate liability.

Not Insurance, Liability

Posted Dec 14, 2017 0:46 UTC (Thu) by immibis (subscriber, #105511) [Link] (1 responses)

That's dangerous territory too.

Personal liability means that, if the damages work out to many hundreds of thousands of dollars, the government can take away my house to pay them. Under those conditions you'll find a lot less people willing to release software. Or the price will massively increase to cover the required insurance. Free software would not be a thing either.

Not Insurance, Liability

Posted Dec 14, 2017 15:51 UTC (Thu) by raven667 (subscriber, #5198) [Link]

> Personal liability means that ... you'll find a lot less people willing to release software ... Free software would not be a thing

There would have to be standards and licencing, so that there would be clear expectations on _both_ sides of what is acceptable practice, but if you are responsible for causing someone harm is it really a bad thing to have liability for your actions. The devils are in the details though because nothing is without boundaries, you can't have infinite liability and the user has some responsibility to use the tools properly, just like in Civil Engineering practice. Free software may not be impossible in that environment but it depends on the exact rules and policies which make that environment happen.

Not Insurance, Liability

Posted Oct 26, 2017 8:35 UTC (Thu) by Wol (subscriber, #4433) [Link]

> Last but not least, it is becoming common practice to put enforced arbitrage in contracts and unless the courts step up against that (most don't) this kills any serious liability risks.

In the UK (and Europe) this is one-sided :-) The company *must* abide by the arbitrage, unless the customer decides to sue instead. (And we've also got "unfair terms and conditions" so if the arbitrager or Judge thinks the arbitrage is loaded in favour of the company they can just ignore the contract ... :-)

Cheers,
Wol

KRACK, ROCA, and device insecurity

Posted Oct 28, 2017 10:05 UTC (Sat) by ras (subscriber, #33059) [Link] (5 responses)

Interestingly, we have a law in Australia that says - well I'm not sure what it says, but it boils down to manufactures can't sell you a defective product. Warranty doesn't come into it - if it is defective, the manufacturer has to repair or replace it, no matter how old.

There are obviously blurry lines, but to give an example if a battery stop holding charge outside of it warranty period that's your problem. But if it swells and looks like it might explode, it's the manufacturers problem - even if it's outside of the warranty period. You don't have to sue a supplier to enforce this - the government does it for you.

I've never heard of it being applied to software, but I imagine it's just a question of time.

KRACK, ROCA, and device insecurity

Posted Oct 28, 2017 22:55 UTC (Sat) by mathstuf (subscriber, #69389) [Link] (4 responses)

How's that work with things that are licensed, not sold? Or is that practice illegal down there too?

KRACK, ROCA, and device insecurity

Posted Oct 29, 2017 12:02 UTC (Sun) by ras (subscriber, #33059) [Link]

I don't know for certain.

My guess is if you talking about a yearly licence for software like say Microsoft Office, it doesn't apply. If you are talking free software it doesn't apply because the expectation of quantity is determined by the price (a $2000 monitor is expected to last longer than a $200 one) [0] . But f you talking about manufacturer selling you a router, then claiming the router isn't covered by this provision because you don't own the software or the software inside is open source - I'd say they don't have a hope.

This isn't as radical as it sounds. For example, Dell just contacted me to say they are replacing the battery in my laptop because it may have a manufacturing defect. Car manufacturers regularly do out of warranty recalls. Yubico is replacing the broken Yubikey 4's. In other words: companies that care about their reputation do this without prodding. The difference in Australian is all companies have to behave like they plan to be in business in 10 years time.

It does change your perspective. It obviously doesn't apply when say you purchase on ebay from an overseas seller who is beyond the reach of Australian law. Back in the day, it used to be fashionable to brag about the great deals you got that way. (Australians can get things cheaply doing that because Asia is on our doorstep). But the wheel has turned - most people who buy online regularly have been bitten by overseas sellers and now "Australian Seller, with an Australian Business Number" can now can happily command a price premium. You know it will do what it says on the box, and if it is at the upper end of the price range it will be at the upper and of the quality spectrum too. Simple assurances like this really does help in making commerce frictionless.

[0] http://www.news.com.au/finance/e806700959101b117f16d7c265...

KRACK, ROCA, and device insecurity

Posted Nov 15, 2017 4:09 UTC (Wed) by ras (subscriber, #33059) [Link] (2 responses)

It's a bit late now for anyone to notice, but this is an example of Australia's consumer protection laws and government agencies in action. This is a home page of a computer retailer (like newegg I guess). It will have the government mandated notice you can see there displayed for a few months:

http://www.msy.com.au/

It doesn't stop people from shopping there as obviously they aren't going to make the same mistake again in a hurry. A long while ago HP made the same mistake of not honouring their warranties in Australia. Seeing that notice on HP's main page is something I will never forget.

KRACK, ROCA, and device insecurity

Posted Nov 18, 2017 3:48 UTC (Sat) by mathstuf (subscriber, #69389) [Link] (1 responses)

Interesting. The list of claims isn't loading here, but that is an interesting notice (especially with it loading sans JS). That's still hardware though. Has anyone been able to get it for software that was prematurely EOL'd? Android manufacturers? IoT crap (or is it still too early for that)?

KRACK, ROCA, and device insecurity

Posted Nov 18, 2017 7:52 UTC (Sat) by ras (subscriber, #33059) [Link]

> Has anyone been able to get it for software that was prematurely EOL'd? Android manufacturers? IoT crap (or is it still too early for that)?

Not that I know of. But we haven't have the equivalent of Samsung bricking all their new TV's here, yet alone that followed by someone making that mistake and then refusing to fix it.

In reality it will have to be something expensive before the ACCC steps in, a $100 router it unlikely to trigger their interest. My guess is IoT is safe until they are actually become dangerous.

KRACK, ROCA, and device insecurity

Posted Oct 22, 2017 15:32 UTC (Sun) by NAR (subscriber, #1313) [Link]

"selling network connected devices that cannot be easily updated (either automatically or manually)"

I see one problem here: do I want to care about upgrading the software in my WiFi-enabled "smart" light bulb? Although I don't actually have one, but my guess is most users would absolutely not want to care about this. I think they want to install it, then forget that there's WiFi in that gadget, just enjoy the "magic". Even I don't want to care about the software in my WiFi router. So I don't think manual upgrade would solve this. Automatic upgrades (i.e. devices "calling home") on the other hand would cause outrage in the privacy-conscious population - and these can have their own security problems. A smart bulb can't even notify the user with a popup that "hey, upgrade me!" - maybe should morse-code this message after each time it's turned on?


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds