|
|
Log in / Subscribe / Register

KRACK, ROCA, and device insecurity

KRACK, ROCA, and device insecurity

Posted Oct 28, 2017 10:05 UTC (Sat) by ras (subscriber, #33059)
In reply to: KRACK, ROCA, and device insecurity by pabs
Parent article: KRACK, ROCA, and device insecurity

Interestingly, we have a law in Australia that says - well I'm not sure what it says, but it boils down to manufactures can't sell you a defective product. Warranty doesn't come into it - if it is defective, the manufacturer has to repair or replace it, no matter how old.

There are obviously blurry lines, but to give an example if a battery stop holding charge outside of it warranty period that's your problem. But if it swells and looks like it might explode, it's the manufacturers problem - even if it's outside of the warranty period. You don't have to sue a supplier to enforce this - the government does it for you.

I've never heard of it being applied to software, but I imagine it's just a question of time.


to post comments

KRACK, ROCA, and device insecurity

Posted Oct 28, 2017 22:55 UTC (Sat) by mathstuf (subscriber, #69389) [Link] (4 responses)

How's that work with things that are licensed, not sold? Or is that practice illegal down there too?

KRACK, ROCA, and device insecurity

Posted Oct 29, 2017 12:02 UTC (Sun) by ras (subscriber, #33059) [Link]

I don't know for certain.

My guess is if you talking about a yearly licence for software like say Microsoft Office, it doesn't apply. If you are talking free software it doesn't apply because the expectation of quantity is determined by the price (a $2000 monitor is expected to last longer than a $200 one) [0] . But f you talking about manufacturer selling you a router, then claiming the router isn't covered by this provision because you don't own the software or the software inside is open source - I'd say they don't have a hope.

This isn't as radical as it sounds. For example, Dell just contacted me to say they are replacing the battery in my laptop because it may have a manufacturing defect. Car manufacturers regularly do out of warranty recalls. Yubico is replacing the broken Yubikey 4's. In other words: companies that care about their reputation do this without prodding. The difference in Australian is all companies have to behave like they plan to be in business in 10 years time.

It does change your perspective. It obviously doesn't apply when say you purchase on ebay from an overseas seller who is beyond the reach of Australian law. Back in the day, it used to be fashionable to brag about the great deals you got that way. (Australians can get things cheaply doing that because Asia is on our doorstep). But the wheel has turned - most people who buy online regularly have been bitten by overseas sellers and now "Australian Seller, with an Australian Business Number" can now can happily command a price premium. You know it will do what it says on the box, and if it is at the upper end of the price range it will be at the upper and of the quality spectrum too. Simple assurances like this really does help in making commerce frictionless.

[0] http://www.news.com.au/finance/e806700959101b117f16d7c265...

KRACK, ROCA, and device insecurity

Posted Nov 15, 2017 4:09 UTC (Wed) by ras (subscriber, #33059) [Link] (2 responses)

It's a bit late now for anyone to notice, but this is an example of Australia's consumer protection laws and government agencies in action. This is a home page of a computer retailer (like newegg I guess). It will have the government mandated notice you can see there displayed for a few months:

http://www.msy.com.au/

It doesn't stop people from shopping there as obviously they aren't going to make the same mistake again in a hurry. A long while ago HP made the same mistake of not honouring their warranties in Australia. Seeing that notice on HP's main page is something I will never forget.

KRACK, ROCA, and device insecurity

Posted Nov 18, 2017 3:48 UTC (Sat) by mathstuf (subscriber, #69389) [Link] (1 responses)

Interesting. The list of claims isn't loading here, but that is an interesting notice (especially with it loading sans JS). That's still hardware though. Has anyone been able to get it for software that was prematurely EOL'd? Android manufacturers? IoT crap (or is it still too early for that)?

KRACK, ROCA, and device insecurity

Posted Nov 18, 2017 7:52 UTC (Sat) by ras (subscriber, #33059) [Link]

> Has anyone been able to get it for software that was prematurely EOL'd? Android manufacturers? IoT crap (or is it still too early for that)?

Not that I know of. But we haven't have the equivalent of Samsung bricking all their new TV's here, yet alone that followed by someone making that mistake and then refusing to fix it.

In reality it will have to be something expensive before the ACCC steps in, a $100 router it unlikely to trigger their interest. My guess is IoT is safe until they are actually become dangerous.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds