Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ianal but I find the idea of this approach being legal to be astounding.

If nothing else, many firm have attempted to sue security researchers for computer intrusion - if nothing else, based on the EULA not allowing that kind of thing. I used to think of that kind of lawsuit as really sleazy but with this, everything seems fair game.

Plus it seems possible that libel or insider-trader laws could be leveraged here given that they too are pretty flexible.

Anyway, pure speculation, I'd be curious what lawyers thought.



Characterizing flaws in a publicly available product is not anywhere near insider trading. It's obviously research, not proprietary information.

It's also likely to be quite easy to avoid libel/slander. Just specify when you obtained the product and demonstrate the flaw in the product you obtained.

edit edit: reading fail.


Except that demonstrating a flaw _by predatory profit-driven entities that have a direct stake in said flaw_ leaves plenty of room for spin and hype. This is already obvious if you read the MW report, some of the "vulnerabilities" are so contrived that the real-world impact is miniscule if not entirely absent, yet they present them (whilst omitting key facts and occulting others) in such a way as to elicit a certain response from the readers.

Given that security is not a solved problem, by far, if you allow this sort of behavior you're opening up the gates of Hell.

There needs to be an objective overseer, that is not profit-driven, for proper evaluation.

This Muddy Waters-MedSec fiasco is evoking memories of the Wild West and is surely not where we want to end up.


> There needs to be an objective overseer, that is not profit-driven, for proper evaluation. This Muddy Waters-MedSec fiasco is evoking memories of the Wild West and is surely not where we want to end up.

So, another Federal bureaucracy? Or what? And how could you guarantee that such a body would remain objective, and avoid regulatory capture?

I think the solution you propose could easily be worse than the problem.


It doesn't have to be a Federal Bureaucracy.

Consumer Reports is one example. Mudge _already doing_ it in the cybersecurity domain is another.


But nobody is required to go though organizations like these when they demonstrate flaws. Why would they start doing that?


All I said was It's also likely to be quite easy to avoid libel/slander.

I didn't evaluate this case or claim that all researchers/shorts would succeed in doing so.

In the end think I'm more concerned about devices that crash/fail due to unauthenticated radio traffic (claimed in the report) than I am about some dude accidentally libeling a company.


> Except that demonstrating a flaw _by predatory profit-driven entities that have a direct stake in said flaw_ leaves plenty of room for spin and hype.

I think we're at a point where getting some money behind spinning and hyping the seriousness of security vulnerabilities is probably a Good Thing™.


In my view, this is the naive outsider perspective.

Security vulnerabilities are everywhere. The old adage 'seek and ye shall find' is king and it doesn't take particular expertise or resources to enter this arena. Moreover, you have hidden cascade/network effects that are growing stronger every day.

With that in mind, one needs to think longer and harder in order to begin to realize what a Good Thing would even be.

When you open the gates of Hell, you have no control over what comes out of it. I'm fully in favor of holding corporations liable when it comes to security vulnerabilities, but making deals with the devil is certainly not the best way of doing that. If this case sets a strong precedent you can expect to see similar speculatory attacks in widely disparate domains, not just medical. I do not share Thomas Ptacek's pessimism re: limited domain applicability of such attacks.

In order to at a minimum avoid chilling effects, you need clear evaluation protocols.

We do not have that in this case, it seems rather that the downside for MW is minimal (and also heavily hedged against).


The objective overseer is the market. If the flaw described is not noteworthy or material (i.e. just hype), then no profit can be made, as there won't be a market impact.


the market is not objective.


Arstechnica also runs a story on this and cites a VW case where researchers were ordered by court not to disclose a flaw: http://arstechnica.com/security/2016/08/trading-in-stock-of-...

The real issue here is that stock effects have occurred because of both (i) a potential flaw in a product and (ii) short positions. Carson acts as a monetization platform for product flaws of publicly listed companies, creating value by executing (ii) for (i) and thus creating real pressure on companies to disclose and address (i). To what degree these accusations are true is another question and pulls this into the same reign as the currently ongoing public feud between Ackman and Icahn over Herbalife.


Hmm... I'm not sure I see this the same way. The impact on the price by a single investor shorting the stock (even a leveraged hedge fund) will be minimal. Furthermore, the only way for said investor to actually make a profit is to make other investors agree (i.e. to essentially anticipate their actions), so they do need to publicise the vulnerability. Still, they're taking a risk because other investors might not see the vulnerability as critical or otherwise worthy of a lower valuation.


I would say that anyone expecting a collaborative approach to market efficiency was raised on an inefficient set of rules.

You would do yourself a greater service by analyzing why you are surprised that this is a legal form of risk.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: