Sunday, August 10, 2008

A question of policy


I would like to pose a question to those who read this blog, and ask that they discuss this question with those in their circle of influence. I hope that you will bear with me as I describe the issue, as there is an involved back story before I get to the question[s] at hand.

In the computer security world, there is a term that represents how the majority of corporations regard all things security related. The phrase is "security through obscurity." The mentality is, if we don't tell anyone anything, then there is no way for them to break in [both in a physical and digital sense]. Skipping the discussion on why this is the first line of defense, let us get further in. Additionally, we will skip the "open source" arguments in favor of transparency in all things so that the world can analyze the details, and supposedly reveal weak points that need addressing.

Here is a scenario, sans any specifics...choose your own adventure style:
A group/individual discovers a flaw that is more or less critical to the intent of the system, yet does not threaten national security. The group/individual has four main options. 1. Say nothing 2. Tell the public exactly how to do it 3. Tell the public the nature of the issue, but not the details on exact execution [like Mythbusters] and 4. Tell the company quietly.

Reasoning behind each option:
1. Malicious 2. Malicious 3. Public awareness that there is an issue that need to be resolved and to prompt companies to use resources to address the issue. 4. Prompt companies to use resources to address the issue.

Historical responses from the companies:
1. Unaware 2. NOOOOOOOOOO! Send out the spin doctors and lie!... and get it fixed 3. NOOOOOOOOOO! Send out the spin doctors and lie!... and get it fixed 4. Tell the discover[s] that the flaw can not be replicated, say it is a FEATURE, or get the issue fixed.

Here is the dilemma, what should the discover[s] do if the company responds with either "the flaw can not be replicated" or say it is a feature?

Should they 1. give up 2. plead with the company more [to my knowledge this alone has never prompted a fix] 3. disclose publicly that there is a flaw, but not the details or 4. disclose the flaw and the methods for exploiting the flaw?

My opinion is that the discover[s] should use option 3 and tell the public that there is an issue. It should be noted that the flaw finder[s] typically wait a minimum of one month, though some have waited for a year.

What do you think should be done?

7 comments:

TheFeltShoppe said...

You should stop being so smart. It hurts my brain!
Deidre

TJ said...

This is the simple version.
I appreciate that you commented on the post, I really was ecstatic to see the little number 1 there, but now you and Levi need to answer the question.

<3
TJ

Unknown said...

Within the private sector, I don't think people who discover the flaw have a responsibility to make it publicly known. Companies do not have a responsibility to disclose all of their flaws or insecurities, as long as the safety and confidentiality of their employees is not compromised. Likewise, I don't think the finders of flaw within the private sector are obliged to report it publicly. In fact, I think there would be grounds to sue if they did and it resulted in major losses of profit.

However, everything changes in the public sector. Government transparency is vital in most situations outside of national security. The public has great interest in the security, efficiency, and functionality of their publicly funded programs. In that case, I would agree that an announcement of a problem would be acceptable, without the full disclosure of details.

The question remains: In the private sector, what interest does the public have in knowing that there are problems in a private system, as long as it doesn't compromise safety or confidentiality?

TJ said...

I have had a hard time identifying who the private sector is. In my mind, I have seen it as being private companies.... but then most private companies offer a product to the public. Do they then have a public side to a private company?

A lead in example:
I car seat is known to have defects that keeps the seat from preforming one of its intended tasks, protecting a child from injury. We all know that there is some oversight in this market, as I think there should be. I think that the public needs to know that there are hazerdous consequences to using the product.

Here are some real world examples from the nerd side of things:
1. You can get access to the Boston subway system for free and even get into "secure" areas that control the system critical aspects of the transit system. Should this be reported?

2. Pace makers are vulernable to people reverse engineering them and then having complete control over the signals, changing them to be faster, slower, or even stop. Should the customers who have them be warned?

3. Certian routers suffer from a flaw that will render them as useful as a brick [the term is actually called "bricking"], thus rendering the routers useless and stopping all internet access that uses them. Should the companies who use them be told that they might come to work on Monday, only to find the life blood of information convayence to be dead?

Unknown said...

I think all you are saying is true and valid. I do want to say, however, that to me there is, in fact, a distinct difference between the private and public sector. That line definitely gets blurred, but a private company, etitiy, family, or organization is one that is NOT owned or operated by the government (Nike, Elks club, LDS Church, the Kartchner family, etc). I think it is important to make this distinction because there are certain rights that are guaranteed to the private sector. For example, the government can not force a church to not discriminate when hiring pastors. Otherwise, a Lutheran minister could sue a Baptist congregation for religious discrimination if he is not hired. A less extreme example is that the government can't tell a family how to raise their children (Yoder v. Wisconsin is the court case, I think). The same thing applies to companies; they are given certain rights to run their companies how they want, with certain guidelines...I'll get into that in a bit...

Conversely, of course, a public entity, agency, or organization is one that is owned, commissioned, or operated by the government. Such organizations are held to a higher standard and follow more rules and regulations.

Now back to the private sector. You rightly stated that there is a public side to private companies. Companies, after all, offer their services to the public. This, however, does NOT make them a PUBLIC company. It DOES, however, make them accountable to the public, in my opinion. The question is, and I think this is what you're getting at, to what exent are they accountable to the public and is that accountability taken through government action or through the marketplace?

Here's my opinion: If the issue concerns safety or confidentiality, then transparency and publicity are important. After all, we have the right to know if a product or service will seriously harm us or put our sensitive personal information at risk. In these cases (like the pace makers, traffic lights, car seats, and subway systems you mentioned), I think that the poeple have the right to know. I would then choose the same option that you did, that it should be announced that there is a flaw, but not the details, so to deter hackers and troublemakers from putting people in harm's way.

However, I do not think that a company has the obligation to fully disclose ANY flaw or disadvantage that their product or service may pose. Surely no product is perfect, and I think it is the consumer's responsibility to research the pro's and con's of a particular company/product/service. There are several instances where I think companies are accountable to make their flaws public:

1. When the flaw compromises safety of confidentiality.

2. When the product or service is one of great complication or specialty (such as legal or medical advice).

Otherwise, it is the the customer's job to find out which product, service, or company to patronize. A car company, for example, should not have to tell each customer "Every once in a while the window won't roll down in these types of cars." That is the customer's responsibility to research. A pharmacuetical company SHOULD have to disclose serious risks or side affects, or if a medicine is found to be defective or harmful.

I hope I'm not just rambling. I hope I'm making a bit of sense.

T3 said...

I agree with the limitations that you mentioned.

I looked up the Yoder v Wisconsin case and it seems to only have a thin thread connected to raising children, though I agree with the main points in your responce.

Here is what I read:
http://en.wikipedia.org/wiki/Wisconsin_v._Yoder

Unknown said...

Yes, the Yoder case centered mainly on the Free Exercise Clause of the 1st amendment (freedom of religion), but if you read the actual decision you see that they make specific mention of the right of parents to raise their children (admittedly that right is specifically applied in this case to the parents religious interest). As far as I've studied constitutional law, this case is generally accepted as extending rearing rights to parents even past their religious interests.

Here is the full text of the decision:

http://supreme.justia.com/us/406/205/case.html

The main points of the holding are detailed in bullet points in the beginning, so you don't have to read all 40 some-odd pages.

Always nice to find some common ground, eh? =)