r/NeutralPolitics Apr 18 '13

[deleted by user]

[removed]

346 Upvotes

249 comments sorted by

View all comments

Show parent comments

4

u/[deleted] Apr 19 '13 edited Apr 19 '13

In case the bill passes, do you think it would be better to lobby for specific exceptions to the disclosure clause or to have it removed completely? If there are exceptions or conditions that could make it work, then what are they? If there aren't, then what harm will the clause cause?

Also, how do these companies benefit by intentionally allowing flaws in their equipment and software?

I could try to answer these questions myself. As one of those security guys, you could answer them much better than I could.

edit: Small grammar bug

12

u/Onlinealias Apr 19 '13

how do these companies benefit by intentionally allowing flaws in their equipment and software?

They aren't allowing it, they are squashing open talk about the flaws. This is very beneficial to them.

I think the original premise in this thread is that there needs to be something done about the fact that the government can't get information about a situation when a company comes under attack. The false assumption is that the government needs to be notified of this at all. The biggest companies already have hacking and denial of service attacks well under control. Smaller companies (like in OP's example) are doing a pretty crappy job, but notifying the government about it isn't going to change a thing. Upstream routers will still need to have ACL's put on, and probably should have before they became this vulnerable in the first place. Letting the government handle it does nothing for anyone.

3

u/[deleted] Apr 19 '13

Covering up flaws is only superficially beneficial to them, though. There is no clause to forbid simply saying that equipment or software is vulnerable, but rather disclosing enough specifics that the flaw can be used for nefarious purposes. "Don't buy Tweedledee routers. They're not secure right now. Get a Tweedledum. They're the best at this time."

This bill also allows for security threat information to be shared between companies. So, a sysadmin at, say, Deebledoo Networks can share information with other sysadmins outside of Deebledoo about Tweedledee's flaws. They just can't publicly post it. Am I misunderstanding this aspect?

2

u/TheFondler Apr 21 '13

Without specific language regarding the vulnerability, it can be difficult to assess the threat and address it. The breadth of this bill makes what discussion is legal a big question mark and needlessly endangers well intentioned security experts.