|
|
Log in / Subscribe / Register

Insurance

Insurance

Posted Oct 19, 2017 13:54 UTC (Thu) by tialaramex (subscriber, #21167)
In reply to: KRACK, ROCA, and device insecurity by pabs
Parent article: KRACK, ROCA, and device insecurity

_If_ that became a problem (and maybe it wouldn't) we have seen this solved for services that routinely go out of business leaving thousands of customers inconvenienced. The usual model is something along the lines of some form of mandatory insurance and the state steps in to actually administrate things using the money from that insurance. Good actors in an industry are neutralised, if they're really at no risk then they will surely obtain insurance very cheaply with no fuss, if they struggle to get insurance then it suggests they're a bad risk after all.

Two UK examples:

1. When a small bank fails, the government gives all its personal customers their money back (in theory up to a limit per customer, but in practice it has always been everything) and the remaining industry has to pay them back. This creates a "Last Man Standing" insurance without actually paying premiums etcetera, and it creates an incentive for big banks to tattle on small banks with risky practices to the regulator, because if they wait and let it fail they'll eat all the costs.

2. Package holiday companies have to join an industry scheme with insurance. No membership? It's illegal to sell holidays that include separate elements like flights and hotel booking bundled together and of course members have a powerful incentive to ensure this is enforced. So, when inevitably lots of these companies go broke each year the insurance pays out and makes sure nobody is left abandoned on some Greek island or arrives to find there's no hotel.

In the case of networked devices I'd imagine that some sort of code escrow would be involved, so when a business fails and can't/ won't ship security fixes the escrow gets unlocked, the insurance pays out and some fleet of maintenance programmers are paid to airdrop in and fix things. Deciding how much we, as a society, are willing to pay for that is just a numbers game. If we want it, we can have it.


to post comments

Insurance

Posted Oct 19, 2017 15:47 UTC (Thu) by NAR (subscriber, #1313) [Link] (2 responses)

There are two small problems with your example:

1. These are (local) services. The (local) government could (more) easily regulate theme and you can't "buy" these services after they go out of business. So for example if I put my money into a foreign bank, the insurance in my home country will not cover me. I actually did have an account at a bank which was registered in a foreign country and they mentioned in all of their communication that my money is not covered by the local insurance (it was covered by the insurance of the foreign country). Also I can't go into a bank office after the bank shut down. On the other hand IoT devices are usually made in a different country and it is very much possible to find a device on the shelf of a local store where the maker is already out of business and thus no longer paying insurance.

2, These insurances increase the hurdle to enter the market. In the case of banks, it's probably not a bad idea. For holiday companies - I don't know. Here they don't have insurance (as far as I know), so from time to time there are news of some poor souls who are stranded somewhere. On the other hand the clients can (and maybe should) insure themselves. My wife is starting a (very) small business where an insurance is compulsory - and it's a real hurdle because initially it takes about 10% of the income (not from profit, from income).

Insurance

Posted Oct 20, 2017 16:32 UTC (Fri) by tialaramex (subscriber, #21167) [Link]

The use of insurance is appropriate when businesses keep failing. If your wife's business is in a sector where new businesses routinely fail and leave personal clients out of pocket, well, I appreciate that it's tough finding the money but wider society has to prioritise ensuring nobody gets screwed over the inconvenience for your wife. In fact arguably the insurance, though expensive, is helping her because without it clients would have to assume her new untested business is likely to fail and stay away.

The idea that clients should insure themselves is inefficient. It can work when clients are all or mostly corporations, though it will usually be inefficient even then. But for ordinary consumers it's ludicrously inefficient. The acquisition costs per customer may be slightly lower, but the insurance has many more customers, so overall a lot more resource is wasted. Where possible laws should put insurance requirements onto the larger entity which will usually be the supplier.

We _could_ say that everybody living in my building needs to take out an insurance policy in case the building burns down. If it happens, the insurers all pay out, together we buy a new building, everything is fine. But that's very inefficient. What actually happens is much better, the building's owner (maybe all the residents jointly, in my case a brass plate company in a tax haven) has to buy insurance and post proof to all residents, and they bill everybody for a share of the insurance along with the other costs of running the building, like elevator maintenance and painting the corridors.

The US has a lot of deliberately anti-competitive policies which can give the idea of regulation a bad name, rather than compete by offering a better service it turns out it's cheaper to "persuade" politicians to pass a law saying nobody is to compete with you, or indeed not to pass a law which would render you obsolete (title insurance, tax filing, and dozens of other things that needn't exist but still do because the campaign donations roll in from those selling them). So I'm not suggesting that every type of business ought to have insurance against the consequences of failing, just that it's a sensible remedy if an industry has this persistent problem the way that banks, and package holiday companies do, and the other poster suggested IoT manufacturers might.

Insurance

Posted Oct 22, 2017 1:25 UTC (Sun) by ssmith32 (subscriber, #72404) [Link]

But a hurdle to enter the market isn't a bad thing - especially if you're not ready or willing to cover the long-term effects you might have on society. If you're not willing to pay a price to help protect society against the damages you may cause if you fail, I see a hurdle as a good thing, not a bad.

Externalities are a real thing.

Not Insurance, Liability

Posted Oct 19, 2017 16:09 UTC (Thu) by kh (guest, #19413) [Link] (5 responses)

Product Liability law is the real fix. If you sell hardware that cannot get security updates, you should be held liable.

https://blog.valbonne-consulting.com/2015/07/24/cybersecu...

Dan Greer's talk on software liability - excerpt, quoted text below:

-----------------[Quoting]--------------

"[Software vendors]... must live with normal product liability, just like manufactures of cars, blenders, chain-saws and hot coffee.

How dire the consequences, and what constitutes "used normally" is for your legislature and courts to decide, but let us put up a strawman example:

A sales-person from one of your long time vendors visits and delivers new product documentation on a USB key, you plug the USB key into your computer and copy the files onto the computer.

This is "used normally" and it should never cause your computer to become part of a botnet, transmit your credit card number to Elbonia, or copy all your design documents to the vendor. If it does, your computer's operating system is defective."

------------------
3. Source code liability -- CHOICE

Nat Howard said that "Security will always be exactly as bad as it can possibly be while allowing everything to still function," but with each passing day, that "and still function" clause requires a higher standard. As Ken Thompson told us in his Turing Award lecture, there is no technical escape; in strict mathematical terms you neither trust a program nor a house unless you created it 100% yourself, but in reality most of us will trust a house built by a suitably skilled professional, usually we will trust it more than one we had built ourselves, and this even if we have never met the builder, or even if he is long since dead.

The reason for this trust is that shoddy building work has had that crucial "or else ..." clause for more than 3700 years:

If a builder builds a house for someone, and does not construct it properly, and the house which he built falls in and kills its owner, then the builder shall be put to death.
-- Code of Hammurabi, approx 1750 B.C.

Today the relevant legal concept is "product liability" and the fundamental formula is "If you make money selling something, then you better do it well, or you will be held responsible for the trouble it causes." For better or poorer, the only two products not covered by product liability today are religion and software, and software should not escape for much longer. Poul-Henning Kamp and I have a strawman proposal for how software liability regulation could be structured....

Not Insurance, Liability

Posted Oct 20, 2017 13:45 UTC (Fri) by jospoortvliet (guest, #33164) [Link] (4 responses)

Liability is useless if the company goes bankrupt. And bankruptcy is an often used way to get out of liability that even bigger companies use - put the liability on a small subsidiary, and done.

So it would help, a bit, against Microsoft and other large companies, though THEY of course can extend court cases far beyond what a small business or home user could sustain - again leaving those without recourse.

Last but not least, it is becoming common practice to put enforced arbitrage in contracts and unless the courts step up against that (most don't) this kills any serious liability risks.

I don't disagree that adding liability to software is a good idea. I just don't think it solves all problems ;-)

Not Insurance, Liability

Posted Oct 22, 2017 1:29 UTC (Sun) by ssmith32 (subscriber, #72404) [Link] (2 responses)

Yeah, but that's just because the way the law is structured, you can avoid all kinds of personal responsibility by incorporating. The solution would be personal liability, not corporate liability.

Not Insurance, Liability

Posted Dec 14, 2017 0:46 UTC (Thu) by immibis (subscriber, #105511) [Link] (1 responses)

That's dangerous territory too.

Personal liability means that, if the damages work out to many hundreds of thousands of dollars, the government can take away my house to pay them. Under those conditions you'll find a lot less people willing to release software. Or the price will massively increase to cover the required insurance. Free software would not be a thing either.

Not Insurance, Liability

Posted Dec 14, 2017 15:51 UTC (Thu) by raven667 (subscriber, #5198) [Link]

> Personal liability means that ... you'll find a lot less people willing to release software ... Free software would not be a thing

There would have to be standards and licencing, so that there would be clear expectations on _both_ sides of what is acceptable practice, but if you are responsible for causing someone harm is it really a bad thing to have liability for your actions. The devils are in the details though because nothing is without boundaries, you can't have infinite liability and the user has some responsibility to use the tools properly, just like in Civil Engineering practice. Free software may not be impossible in that environment but it depends on the exact rules and policies which make that environment happen.

Not Insurance, Liability

Posted Oct 26, 2017 8:35 UTC (Thu) by Wol (subscriber, #4433) [Link]

> Last but not least, it is becoming common practice to put enforced arbitrage in contracts and unless the courts step up against that (most don't) this kills any serious liability risks.

In the UK (and Europe) this is one-sided :-) The company *must* abide by the arbitrage, unless the customer decides to sue instead. (And we've also got "unfair terms and conditions" so if the arbitrager or Judge thinks the arbitrage is loaded in favour of the company they can just ignore the contract ... :-)

Cheers,
Wol


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds