Slashdot Mirror


Why Companies Knowingly Ship Insecure Devices

wiredmikey writes "A recent survey which included responses from 800 engineers and developers that work on embedded devices revealed that 24% of respondents knew of security problems in their company's products that had not been disclosed to the public before the devices were shipped. But just what that means in terms of attitudes towards security may be more complex than it seems. Additionally, just 41% said their company has 'allocated sufficient time and money to secure' its device products against hacks and attacks. Despite this, 64 percent felt that when engineers call attention to potential security problems, 'those problems are addressed before the device is released.' So, what exactly does this illustrate about the state of security in the development process? The answer, some say, is a jumbled collage of business pressures, bug prioritization and varying attention to security."

123 comments

  1. Not important enough by Anrego · · Score: 4, Informative

    Security isn’t important enough or visible enough to the end user, and insecurity doesn’t cost companies enough money.

    If company A spends 100,020 extra on securing their product, whereas company B spends $1,020 extra .. and neither product “gets hacked” .. there is no perceived value increase. If company A has to sell their product at a higher cost .. most consumers will go with company B’s product.. _even if_ company A can somehow demonstrate that their product is more secure (and aside from a clean track record, this is hard).

    If Company B’s product gets hacked, 99% of users don’t know or don’t care.. and company A gets exactly 3 new customers (always 3.. regardless of scale) who are concerned with company B’s security track record and assume company A makes a more secure product.

    More importantly, if legislation went through saying that companies were liable for insecurity and the damage that is caused, everything would triple in cost and the masses with piss soup in rage

    1. Re:Not important enough by shadowfaxcrx · · Score: 2

      Done in 1. (I don't count the troll above you)

      Start fining the hell out of companies for knowingly exposing their customers to risk (any risk, whether security or e-coli) and companies will clean up their acts.

      Yes, regulating companies makes (sometimes) the end product cost more. That was true when airlines were regulated. We also didn't have incidents like Valujet when airlines were regulated. Safety/security costs more up front, but costs less in the long term.

      --
      "I disagree with you" does not equal "flamebait."
    2. Re:Not important enough by robthebloke · · Score: 1

      More importantly, if legislation went through saying that companies were liable for insecurity and the damage that is caused, everything would triple in cost and the masses with piss soup in rage

      No, it would simply force the hand of developers to release all security related code under a GNU license to avoid the liabilities of being the maintainers of the software. That or (very brave) specialsed hardware/software security companies would start providing middleware for that purpose.

    3. Re:Not important enough by mfh · · Score: 1

      When Playstation Network was hacked I laughed because I wasn't stupid enough to give them my personal info or a password used in multiple other places. I had a distinct password sent to them and they never saw a dime from me over a credit card.

      When it comes down to it, what other people call paranoia, I call standard practice.

      --
      The dangers of knowledge trigger emotional distress in human beings.
    4. Re:Not important enough by Anrego · · Score: 1

      When it comes down to it, what other people call paranoia, I call standard practice.

      In a world where a huge company like Sony can fuck up on such an epic scale and get little more than a wrist slap.. and will probably keep right on doing business they way that've been doing... yup!

      Unfortunately it's hard to "not participate". Everyone wants all your personal info for everything. There are ways around this (temporary credit card numbers) but it's pretty hard to avoid giving someone enough data to do damage while still living a relatively enjoyable life.

      Also.. two digit UID.. jebus!

    5. Re:Not important enough by 0123456 · · Score: 2

      Start fining the hell out of companies for knowingly exposing their customers to risk (any risk, whether security or e-coli) and companies will clean up their acts.

      No, they'll stop making stuff because unlimited liability for 'any risk' is simply insane. If they can't get insurance then there'd be no point being in business if you could be bankrupted at any time (e.g. Joe Loser sues Dell for selling a PC with Windows installed, which clearly exposes them to serious risks).

    6. Re:Not important enough by brainzach · · Score: 1

      The company that is focuses too much security is going to get fired for being behind schedule and making them lose money.

    7. Re:Not important enough by pnewhook · · Score: 1

      So clearly you must own a Blackberry if you are concerned about security since all other smartphones can be eavesdropped onto. You must also have timfoiled your house.

      --
      Tesla was a genius. Edison however was a overrated hack who liked to torture puppies.
    8. Re:Not important enough by jellomizer · · Score: 1

      Then expect no new devices to be released. And put the world into a worse recession..

      If you fine them too much then they will calculate that it isn't a profitable sector to be in... Then they won't be in the sector.
      There is only a limit on how prices will rise for a personal device. Airline travel can allow a high price variant as the value of getting there faster is very high. However for your Personal Device getting the newest and greatest if it is too expensive will not add any value to the customer. They won't buy them at a high price.

      Most security holes do not have a wide effect, and can be fixed before major problems occur. In the meantime they can have sold thousands or millions of units before then.

      And what about Open Source developers... You release some code to the public and you may know there is a security hole in it, perhaps because you don't know how to fix it, and looking for a better solution, perhaps someone uses your code and gets hacked who is responsible... Probably you so you get to pay a nice hefty fine.

      When the government needs to control and fine products to meet a particular standard they need to be careful about it, lets say a device cost the life of one person... However being able to ship the device 5 years earlier can save the lives of 50 people. Too tight regulation is just as bad as having no regulations.

      --
      If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    9. Re:Not important enough by Opportunist · · Score: 1

      Brave? You needn't be brave. Just start a subsidiary company that does the security baloney, cash in, transfer the money and when the shit hits the fan, the subsidiary goes bankrupt.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    10. Re:Not important enough by Anonymous Coward · · Score: 0

      Adding to the parent: When the skript-kiddiez come along and break into the system and make off with the keys to everyone's kingdom, the engineers and the company that sold the highly insecure gadget/operating system/whatever are usually let off the hook, and all the rage is pointed toward the kiddiez. The company might offer an extra 'security bundle', which somehow doesn't make people ask 'why didn't you ship it as a secure/reliable product in the first place?', but that rarely happens. For the odd occasional few who might ask those questions, the company will set up a second company which offers products to secure the insecure products offered by their parent company. I agree that even though most people know eating their vegetables is good for them, they will fight like hell about having veggies interspersed between their steak and beer. "Don't you dare tell me blah blah blah!" ...but, but your particular steak is 86% fat and carcinogens and you will die within 48 hours..... "I don't care, now get your damn veggies away from my steak! ...and gimmie another beer!"

    11. Re:Not important enough by jellomizer · · Score: 1

      Consultants, they will hire consultants to do the work. Then point their finger back at them when there is a problem and go BAD BAD consultants, then hire them for the next job. That is what the government does. If they need to do something that is politically risky they get a consultant to do it, if it succeeds they person get the credit, it it fails they blame the consultant, which privately the consultant happily takes because he knows that he will probably get the next job as well because why would the government authority get rid of a perfectly good skate-goat, for any mistakes (probably due to bad leadership).

      --
      If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    12. Re:Not important enough by rickb928 · · Score: 1

      So the solution is to use the GNU license to avoid liability.

      You must work in the industry. Maybe as a CEO?

      --
      deleting the extra space after periods so i can stay relevant, yeah.
    13. Re:Not important enough by Opportunist · · Score: 1

      What bothers me most, from a pure security point of view, is that this pretty much turned the PCI-DSS into a weak joke and a laughing stock of the IT-Security community. Sony pretty much had to be compliant, i.e. get the cert. They stored credit card info, they are most likely even a level 1 (highest possible level, more than 6 million transactions annually (or already had a breach, i.e. if they were not, they are now), highest possible security risk) merchant, in other words, they pretty much had to get audited at the very least every 3 months. And yet they dropped the ball badly.

      Ok, it's not like we thought that those certs mean jack anyway, but I guess it starts to become visible outside the business now...

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    14. Re:Not important enough by Anrego · · Score: 1

      but I guess it starts to become visible outside the business now...

      Problem is it really doesn't.

      Sure, people think about it a bit when it's in the news.. and maybe down the road someone will be looking into something and this incident will be used as a case study... but for the most part... people forget this shit as soon as it's out of the headlines.

    15. Re:Not important enough by dubl-u · · Score: 1

      Safety/security costs more up front, but costs less in the long term.

      Not necessarily true. If you blindly make producers liable for all risk, and pile on top of that a substantial regulatory framework, you could create costs well above benefits.

      I have a friend that makes jam. It's good jam. If she were to sell it at the farmer's market, people would happily buy it. And the sorts of people who buy jam at the farmer's market know what they're getting into. If by some fluke one of the jars doesn't seal properly, they'll deal with it. But in your world, she'd be exposing herself to substantial legal liability, plus the need to comply with a bureaucratic system that proves she has taken all possible steps to mitigate risk. Equipment, procedures, documentation, keeping up with regulations, filing reports. She wouldn't do that just to sell a few jars of jam.

      For software, it's even worse. Regulating software creation uniformly is like regulating the creation of things made out of atoms: the variety is too wide to talk about it sensibly. The whole point of writing software is to do new things, which guarantees many risks won't be well understood. And software processes are moving to very fast cycles, where the goal isn't to completely prevent errors, it's to keep any impact very small. Regulation-induced ritual can wreck that.

      Customers should generally be able to choose what level of risk they're accepting except where the risks are catastrophic and hard to understand (e.g., flying on a commercial airline). Without that freedom, we won't get small jam producers, we won't get companies that do bungee jumping or skydiving, and we won't get a great deal of the innovative software we now get.

    16. Re:Not important enough by Anonymous Coward · · Score: 0

      Done in 1. (I don't count the troll above you)

      Start fining the hell out of companies for knowingly exposing their customers to risk (any risk, whether security or e-coli) and companies will clean up their acts.

      Yes, regulating companies makes (sometimes) the end product cost more. That was true when airlines were regulated. We also didn't have incidents like Valujet when airlines were regulated. Safety/security costs more up front, but costs less in the long term.

      The above after going through the US far right filter:

      Blah blah blah stupid hippy nerd talk blah blah blah risk blah blah blah REGULATING COMPANIES MAKES blah THE END PRODUCT COST MORE blah blah blah blah blah SAFETY/SECURITY COSTS MORE blah blah blah.

      So, good luck with that.

    17. Re:Not important enough by Runaway1956 · · Score: 2

      Open source is distributed for free, as-is, with no warranty, and plenty of disclaimers that the product may not be suitable for your purposes, or any other purposes.

      Unlike the other side of the road, where the code is a closely held secret, you pay for the privilege of using it, and there are generally at least implied warranties that the product is fit for consumer use.

      In short - if the company is willing to rape the consumer for huge profits, while supplying shoddy products, then they DESERVE to be sued. Open source, not so much. "Yeah, you can mess with my code, if you like, but be warned, it's a mishmash of ideas that may or may not work, so you're on your own. Call me if you have problems, and MAYBE we can work things out!"

      --
      "Windows is like the faint smell of piss in a subway: it's there, and there's nothing you can do about it." - Charlie Br
    18. Re:Not important enough by maxume · · Score: 1

      If you start from the premise that the credit card companies are the ones that could go ahead and implement secure authentication (with card readers or token generators or whatever), the security of the whole industry is a joke.

      Of course, they are more worried about costs than security so it isn't a big surprise.

      --
      Nerd rage is the funniest rage.
    19. Re:Not important enough by Anonymous Coward · · Score: 0

      1. No. Companies will not pack up and leave (and you're either stupid or malicious to suggest this).

      2. Microsoft would have to clean up their act, not Dell.

    20. Re:Not important enough by swordgeek · · Score: 1

      Agreed, except for "any risk." Sooner or later, companies will just stop trying to produce anything. The small private airplane market was a perfect example of this: The government assigned essentially indefinite liability to the manufacturer of an airplane, and after a while Cessna et al just quit making small planes.

      --

      "People who do stupid things with hazardous materials often die." -- Jim Davidson on alt.folklore.urban
    21. Re:Not important enough by Opportunist · · Score: 1

      Forget security tokens or other security features that the customer would have to use. The customer doesn't give half a shit, if you "force" a security token on him, he'll use a different CC provider that doesn't. Especially since, hey, if someone abuses my card, the CC company will cover it, so why bother?

      That the merchant he bought at will most likely discontinue business with him (because he, eventually, gets to foot the bill) is another matter. And I guess a lot of people would be pissed if Amazon, EBay or Paypal would discontinue doing business with them because of it. But hey, as long as it doesn't happen, no damage done.

      The sad truth is that nobody really wants security. Aside of a small minority that just simply doesn't count.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    22. Re:Not important enough by Dog-Cow · · Score: 1

      skate-goat

      Ruminants on wheels?

    23. Re:Not important enough by danhaas · · Score: 1

      That "full responsibility" approach led the american health system to its present state.

      Sometimes you just have to learn to live with the risk, and try to manage it instead of eliminating it.

    24. Re:Not important enough by Obfuscant · · Score: 1

      No, they'll stop making stuff because unlimited liability for 'any risk' is simply insane.

      This. I wish I had mod points today.

      Everything anyone does has risk. The only secure computer is one that is turned off. The only secure cell phone is one that has the battery removed. The only secure ... well, you get the idea.

      Absolute security is an impossible dream, an unreachable goal, and a continuous drain on money and time. At some point, we all have to weigh the cost/benfit ratios of what we are doing and get on with our lives. E.g., the value of getting to work greatly outweighs the risks involved in driving there, so I do it. The value of cleaning oneself outweighs the risks involved in taking a shower.

      That's the equation that people seem to forget when talking about safety and hacking. There is a cost to safety and security, and sometimes the cost is more than the risks would cost. What would it cost to put a thermal/smoke detector in every toaster, connected to an internal fire extinguisher and cell phone that dials 911 in an emergency? Well, toasters sometimes start to burn, wouldn't the safety be worth it? That $20 toaster would now cost $200 and nobody would buy it. Or you could get the government to write a law saying you had to buy that kind of toaster, just like they have laws saying you must have smoke detectors in certainly residences. The former is economics at work; the latter a governmental distortion of those principles. And look out when one of those toaster safety features doesn't work, the company will be sued anyway.

    25. Re:Not important enough by cdrguru · · Score: 1

      ValuJet got a bunch of oxygen generators loaded on a plane in spite of a strict regulatory environment. They partly adhered to the regulations and partly did not. There were no inspectors on site to verify compliance, and they took some shortcuts. No amount of regulation would have changed that unless they had on-site inspectors. The cargo handlers had a box to move and they put it on a plane to move it. They were not supposed to, they knew they were not supposed to but did it anyway.

      Alaska Air did shoddy maintenance on planes, again in spite of a strict regulatory environment. One plane crashed and I believe a lot more were taken out of service because of maintenance issues relating to the elevator jackscrew.

      American Airlines did shoddy maintenance on DC-10 engines and this resulted in Flight 191 crashing in spite of a strict regulatory environment. Again, the only thing that would have stopped them would have been on-site inspectors, which there were none and are none today.

      Sorry, but regulation doesn't solve problems. Companies following regulations is generally a good thing, but the problem today is we have regulations like those in the wake of Prop 65 in California. Sure, putting up a sign that says "Enter here and risk your life, your children's lives and all of the rest of humanty" is really effective when it is required on nearly every business in the state. The problem is when there are too many silly regulations all regulations are going to be treated as silly and ignored - and there is no monitoring. Enforcement is great, but it is after the fact - after people have died.

      Oh, so you think the solution is more monitoring and enforcement? What do you think it would take to effectively monitor, say aircraft maintenance? Shouldn't be too hard because there are only around 600 airports and maybe 100 maintenance facilities in the US. To do the job in a weak and pathetic manner it only takes a few inspectors as we have today. To do the job in a way that would eliminate cargo handlers putting the wrong box on a plane would take 7000 or more inspectors with a cost likely over a billion dollars. Just a tiny drop in the bucket, but nobody is going to spend that on inspectors today when if everyone follows the rules these inspectors are completely unnecessary.

    26. Re:Not important enough by Hadlock · · Score: 2

      Yep. Your job as a product manager is to
       
      1. Ship the product
      2. Ship the product on time and
      3. Do it under budget
       
      Pick any two. #1 is not optional. As long as conditions 1 and 2 or 3 are met you get to keep your job, and possibly a project completion bonus (if you're lucky). As long as security flaws aren't getting in the way of two of those three objectives, you can ignore them and patch them in a later firmware/software update.
       
      Complaining to your manager that you need to delay the product and that you're going to have to exceed your budget to address security concerns that a junior engineer mentioned in a memo is probably not going to net you that fully paid team building exercise that involves playing golf in the Cayman Islands for a week next month. The fact that you blew your project over something like "security" isn't helping matters with the wife; that $3000 bonus you decided to eschew in favor of security isn't helping pay for the pair of diamond earrings, the new 47" plasma TV, new PS3 for junior who made a 3.8 last semester, or the 15th wedding anniversary trip to hawaii.

      --
      moox. for a new generation.
    27. Re:Not important enough by cdrguru · · Score: 1

      How many companies make vaccines today? What companies make the chemicals used for executions?

      The risk became too great and just about everyone got out of the business. The last round of vaccine production for flu required the government to provide immunity to the manufacturer before they would do it.

    28. Re:Not important enough by Anonymous Coward · · Score: 0

      I, for many devices and most software, would happily buy an insecure version which is cheaper than a secure one.
      I only need one secure PC for banking and ebuying. For the rest, I take the tradeoff thanks. It's not that my media center getting hacked gets me many trouble (beside, it's running without antivirus now to be more performant, if it dies, I restore the harddrive image I made in march and lose one or two house md episodes tops.

    29. Re:Not important enough by darth+dickinson · · Score: 1

      I was thinking of this just this morning. It seems we hear more and more about damn *stupid* security breaches. SQL Injection, etc... heck, didn't the CitiBank credit card cracker simply modify the URL to scrape thousands of card numbers? Given what we know about outsourcing (not necessarily offshoring, but simply farming out the latest "Web 2.0!!!" design to companies like Accenture) it's hard to believe that a lot of these faulty web sites were designed by one of a few companies.

      It left me wondering, "Why hire these people if they churn out insecure code like this?" I think it's partially the fact that no one will admit publicly what company provided the faulty code, but more the parent's post... "We here at MegaTelcoBank are secure, none of *our* employees would churn out crap code like that!!"

    30. Re:Not important enough by tepples · · Score: 1

      Open source is distributed for free, as-is, with no warranty

      Regulation of the industry would likely make such disclaimers null and void.

    31. Re:Not important enough by jellomizer · · Score: 1

      What you forgot is durring the process the Consulting company may really try to say you should do it this way it is more secure, but normally it will not go threw because consultants are not to be trusted.

      --
      If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    32. Re:Not important enough by shadowfaxcrx · · Score: 1

      There's a big difference between selling jelly at the farmers market and knowingly releasing devices that facilitate identity theft, or knowingly selling meat that was contaminated with feces when the guy working in the factory cut too deep.

      Note the key word "knowingly."

      --
      "I disagree with you" does not equal "flamebait."
    33. Re:Not important enough by Anonymous Coward · · Score: 0

      That's like saying we don't need cops because when people follow the rules cops are totally unnecessary. Another one of your statements I interpret as akin to, "the real problem is we have so many needless laws about speeding and jaywalking, so our rules about robbery and arson are being treated as silly and ignored". After all, to hire enough officers to totally prevent all crime is prohibitively expensive, therefore there's just no need for cops at all.

    34. Re:Not important enough by Bengie · · Score: 1

      Well, the idea is to fine companies who don't try "enough". There will always be security problems, but companies that don't even keep up with the industrial minumum should be heavily fined.

      How we determine this, I don't know.

    35. Re:Not important enough by dubl-u · · Score: 1

      There's definitely a big difference, which is why I think the "any risk" standard you suggest is too extreme.

      "Knowingly" is a good start. But there's a problem with that, too; it discourages knowing, or activities that lead to knowing, like investigation or research. A lot of the corporate criminals who caused the economic crash we're suffering from got away with it because they had plausible deniability. They just didn't know! And we happily ignored that they could have known, and probably should have known, and that they rigged things so that they wouldn't know.

      We need corporate cultures that encourage investigation and honest reporting, but a standard of "knowingly" works against that.

    36. Re:Not important enough by davester666 · · Score: 1

      Companies have stopped making and/or selling the chemicals for executions because of investor pressure.

      But these kind of calculations by corporations have been going on for a long time, in many more ways that common people would think of as morally bankrupt. For example, for auto manufacturing design flaws, auto manufacturers regularly price out the cost of fixing the problem versus the cost of settlements to families of people who will be injured or killed. See Ford Pinto gas tank, GM Truck gas tank.

      --
      Sleep your way to a whiter smile...date a dentist!
    37. Re:Not important enough by darth+dickinson · · Score: 1

      It's been my experience (working for a subsidiary of an international bank) that the opposite is true. "Oh we should do what the consultants say, they do this all the time."

    38. Re:Not important enough by maxume · · Score: 1

      Chip cards seem to work for the Netherlands (but they are relatively small and the banking industry chose to work together on it).

      If American Express offered a secure payment system that meant I was authorizing single transactions to a single vendor, I'd use it in a heartbeat.

      --
      Nerd rage is the funniest rage.
    39. Re:Not important enough by Obfuscant · · Score: 1

      There's a big difference between selling jelly at the farmers market and knowingly releasing devices that facilitate identity theft,

      Xerox, Canon, Ricoh, and several other companies knowingly manufacture devices that facilitate not only identity theft but copyright violation and child pornography. They're called "copy machines". Several companies knowingly manufacture devices that facilitate copyright violations, namely "DVD recorders".

      Many many companies knowingly distribute devices that knowingly allow the violation of many different laws. I can buy radios from Kenwood, Motorola, Tait, EF Johnson, and a host of other companies that allow me trivially to jam police communications. Or aircraft/ATC communications. I can buy credit card readers that allow the theft of CC info. I can buy cars that allow me to speed, and even run people over.

      or knowingly selling meat that was contaminated with feces when the guy working in the factory cut too deep.

      There's a big difference between commiting an act that by itself causes damage to individuals, and providing a device that can be used in illegal or damaging ways.

      Somebody sold that guy who "cut too deep" the knife he used to make that cut. Is the knife manufacturer liable for the misuse of the product because he knew that someone using the product to "cut too deep" at a meat packing plant would cause contamination of the meat product? Note the word "knowingly".

    40. Re:Not important enough by maxume · · Score: 1

      And I guess the more sarcastic response is something like "Yeah, that's the part that is a joke."

      Or whatever. The general point is that the activities they classify as 'security' are largely tilting at windmills, at least when compared to what is technically possible.

      --
      Nerd rage is the funniest rage.
    41. Re:Not important enough by shadowfaxcrx · · Score: 1

      Exactly. No, I don't think more on-site monitoring is necessary, provided the penalties for *knowingly* dicking around with safety/security are severe.

      That DC10 crash you're talking about happened because of company stupidity. Douglas had told them to remove the engine, and then the pylon from the wing when performing maintenance. Some airlines, including AA, figured they could save time if they removed the engine/pylon as one unit rather than taking 2 steps to do it. It was tricky, but saved money. On this particular plane, ground maintenance didn't get it right, and rammed the pylon into the wing. Then they re-attached everything, didn't make sure there was no damage (there was) and as a result the engine fell off. There were also problems with the crew's action during the disaster (the DC10 can take off just fine with 1 engine dead, but the aircrew tried to climb too fast, there was no stick shaker on the copilot's controls, and the pilots controls had been knocked out by the engine falling off, and the flight engineer failed to hit the switch that would have brought the pilot's side back online) but the primary cause was corporate penny pinching in violation of the (for want of a better term) service manual.

      AA should have been fined so heavily that it would have damn near gone out of business as a result of this crash. Instead, they were fined half a million dollars, which to an airline is beer money, and meanwhile people were dead and Douglas's business was badly hurt as a result of undeserved animosity toward the DC-10.

      If AA had been fined as heavily as it should have been, I think industry would have taken the lesson more to heart. "If I'm gonna try to pull shenanigans with safety, I'd better be damned sure I can get away with it or I might just lose my whole company." That's a pretty good incentive to make sure you're not cutting corners.

      --
      "I disagree with you" does not equal "flamebait."
    42. Re:Not important enough by shadowfaxcrx · · Score: 1

      That's great. And I don't mind you having that choice. But the company should be giving you that choice, by clearly labeling their product as "NOT SECURE."

      Instead they're shipping this shit out, telling customers "oh it's great, you can shop and bank with this thing from anywhere!" without telling them "oh and by the way when you do anyone who wants it can steal your info and also shop and bank with your account."

      --
      "I disagree with you" does not equal "flamebait."
    43. Re:Not important enough by Anonymous Coward · · Score: 1

      Open source is distributed for free, as-is, with no warranty, and plenty of disclaimers that the product may not be suitable for your purposes, or any other purposes.

      Unlike the other side of the road, where the code is a closely held secret, you pay for the privilege of using it, and there are generally at least implied warranties that the product is fit for consumer use.

      Umm... You might want to *read* the EULA for one of those 'other side of the road' products. They disclaim all liability that they're legally allowed to, and then additionally limit their liability to the price you paid for the product. You're in, *at best*, exactly the same situation with 'the other side of the road' as you are with Open Source.

    44. Re:Not important enough by shadowfaxcrx · · Score: 1

      Xerox, Canon, Ricoh, and several other companies knowingly manufacture devices that facilitate not only identity theft but copyright violation and child pornography. They're called "copy machines". Several companies knowingly manufacture devices that facilitate copyright violations, namely "DVD recorders".

      Oh come on. That's bullshit. You know as well as I that the intended use standard applies. Copy machines are not intended to be used for kiddie porn or counterfeiting. Conversely, meat is meant to be eaten, and smart phones are meant to be used on the internet. There's a very obvious difference.

      --
      "I disagree with you" does not equal "flamebait."
    45. Re:Not important enough by Runaway1956 · · Score: 1

      No, you seem to have missed the point completely. The other side of the road CHARGES you for using their stuff. "I've got some great software, but you have to pay me if you want to use it, and you can never look at how it works!"

      On my side of the road, it's more like, "I've got some stuff that works sometimes, for what I want to do. You can use it, or you can improve on it, or whatever you like. But, be warned, it's just a hack to make things work the way I like."

      Do you still fail to see the difference? Proprietary software CHARGES, while Open Source does not. Regulation is for business, not for hobbyists.

      --
      "Windows is like the faint smell of piss in a subway: it's there, and there's nothing you can do about it." - Charlie Br
    46. Re:Not important enough by asdfghjklqwertyuiop · · Score: 1

      A service you paid for and had a right to have went down for a month or so and this made you laugh?

    47. Re:Not important enough by Anonymous Coward · · Score: 0

      The above after going through the US far right filter:

      Why is it always the other side's fault? Don't you get tired at pointing fingers all day?

    48. Re:Not important enough by aix+tom · · Score: 1

      It *could* be a small little step to just force companies to give a refund when they ship a faulty product.

      Like it is the case with any *REAL* product, which has to have a warranty.
      The manufacturer or seller can try a few times to fix a problem, but when they can't the customer can demand his money back if it doesn't work as advertised. That should just be applied to software sales exactly same way.

    49. Re:Not important enough by jafac · · Score: 1

      I don't understand this comment. What's wrong with the masses pissing soup? They could sell the soup and make money!

      --

      These are my friends, See how they glisten. See this one shine, how he smiles in the light.
    50. Re:Not important enough by Obfuscant · · Score: 1

      Oh come on. That's bullshit. You know as well as I that the intended use standard applies.

      Whatever "standard use" policy you think applies does not change the fact that those companies knowingly make and knowingly distribute devices that facilitate illegal activities. That "standard use" policy may make them eventually not liable for producing those devices, but produce them to do. And you might note that "standard use" did not protect Napster.

      Conversely, meat is meant to be eaten,

      In your rush to call me a liar, did you even bother to note that I clearly differentiated between actions that are themselves a danger to others and actions that are indirectly a danger? Like producing tainted meat is a direct danger, while producing a copy machine, or any other "device" with "security issues", is not.

      There's a very obvious difference.

      Thank you for agreeing with me.

    51. Re:Not important enough by HappyPsycho · · Score: 1

      If the regulation is that wide ranging that such a disclaimer is void it would kill any sort of hobbyist or if you don't care about that, any sort of research in the industry until a full solution (with ALL risks calculated) can be developed, last I checked no industry can claim such mastery far less a particular member of an industry.

      The great news about that world is that we wouldn't need patents because no one would release their product till they knew they could dominate the market.

    52. Re:Not important enough by jellomizer · · Score: 1

      That is why you need to worry about regulations. If you are a small minority group you can get hit by a regulation that see you as a fringe player.

      --
      If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    53. Re:Not important enough by shadowfaxcrx · · Score: 1

      In your rush to call me a liar, did you even bother to note that I clearly differentiated between actions that are themselves a danger to others and actions that are indirectly a danger? Like producing tainted meat is a direct danger, while producing a copy machine, or any other "device" with "security issues", is not.

      Nope, I didn't notice that. And having re-read your post, I still didn't notice that, because you didn't differentiate anything.

      But, given that you *meant* to differentiate, if you're acknowledging that there's a difference, what exactly was your point?

      --
      "I disagree with you" does not equal "flamebait."
  2. Greed by TaoPhoenix · · Score: 1

    Nah, the author and submitter made a valiant attempt but the real reason is that we are "satisfied" to just release stuff and let the general public be un/underpaid debug labor.

    If all that debug was properly full-costed these companies would lose years of profits.

    --
    My first Journal Entry ever, in 8 years! http://slashdot.org/journal/365947/aphelion-scifi-fantasy-horror-poetry-webzine
    1. Re:Greed by Anrego · · Score: 1

      That and customers arn't willing to pay the costs of doing it properly. Especially when your competitor is not doing it properly and as such can offer their product cheaper than yours.

      Consumers are as cheap and greedy as the companies who make the products. Can't sell what people don't care about and arn't willing to pay for..

    2. Re:Greed by Anonymous Coward · · Score: 0

      Not true. most customers want a secure product but it is impossible to make an informed decision because relevant information is almost never released. Companies usually do not tell us how many known bugs there are in their product, they do not tell us how big their security related budget is, they do not tell us their policies, there is no public auditing and they do not show us the source code.

      Since there is no information to base a decision on, you might as well go for the cheapest product. After all, experience has learned that the more expensive product is not automatically better or more secure.

    3. Re:Greed by Anrego · · Score: 1

      I think you are giving people way too much credit!

      I used to work at a hardware store.. and would always amaze me when people'd come in looking for locks for their door. "do you have anything cheaper that I can protect me, my family and all my worldly possessions??". I know locks are at best a deterrent.. but damn.. I want the best deterrent money can buy...

      And then you've got all the people who use "1234" as their pin number and "password" as their password.

  3. WE AIM TO PLEASE !! by Anonymous Coward · · Score: 0

    We just don't care who that is !!

  4. Re:Only Apple does security by Anonymous Coward · · Score: 0

    I like Granny Smiths too. I mean, you can't climb through one of those, unlike those damned Windows.

  5. Business Pressures by Anonymous Coward · · Score: 0

    Full stop. You can either make money or take the time to do it right and go bankrupt, and then someone else picks up your project on the cheap and profits from it.

  6. Re:Only Apple does security by billcopc · · Score: 0

    I'm going to laugh that one into the weekend... Cheers mate!

    --
    -Billco, Fnarg.com
  7. For those of us who've been in development .... by Anonymous Coward · · Score: 0

    For those of us who've been in development for any length of time, we all learn that the ship date that the PHBs set the most important thing to them. Ship it and worry about the little things later. Miss the ship date? Well the World comes to an end! The Mayans predicted this: in 2012, a developer will miss his ship date, that's how the World will end - at least that's the attitude of the PHBs!

  8. Re:Only Apple does security by MobileTatsu-NJG · · Score: 1

    Hmm cant tell if trolling or just stupid.

    --

    "I like to lick butts!" by MobileTatsu-NJG (#32700246) (Score:5, Informative)

  9. Say it ain't so! by barlevg · · Score: 1

    Engineers are saying their products are being rushed to market, and that they're not being given enough time to come out with a perfect product?

    What's the world coming to?

    Next thing you'll be seeing teachers complain about being underpaid and under-appreciated and the president saying that partisan bickering is preventing him from getting anything accomplished.

    Just because it's true doesn't make it news.

  10. And time by Weaselmancer · · Score: 1

    Remember that sales people typically make percentages based on sales. You don't get that percentage until you ship. So you get a lot of pressure to deliver quickly. And you can't do security in a rush. Typically your engineering head will do a security assessment and sales will go over it (usually in a series of small hops and jumps) and then ship anyways, because that's how they get paid. They'll have engineering bang out patches later on. If anyone complains.

    Bottom line is that engineers don't get to make these kinds of decisions usually.

    --
    Weaselmancer
    rediculous.
  11. Re:Only Apple does security by mfh · · Score: 1

    This is pretty funny considering that all laptops are manufactured by the same company, including Apple's laptops. As for security, they just demonstrated a total kernel pwn for ios recently, so I'd be willing to go on record that all the companies suck at security. When it comes down to it, if you want to break into something you can find a way. These companies would get a lot farther if they realized that nothing is really secure and instead they decided to give people what they want out of the box instead of collectively dismissing our rights to purchase real property.

    --
    The dangers of knowledge trigger emotional distress in human beings.
  12. History needs to repeat by Tablizer · · Score: 1

    GM engineers discovered a safety problem in a vehicle they were designing, and designed an extra part to fix it. But management decided to save $5 per vehicle and skip it. GM ended up getting their cabooses sued off for that decision after the legal "discovery" process found out about the intentional shortcut. They Jury handed them their ass.

    Perhaps a similar situation has to happen with software in gizmos before companies "care".

    1. Re:History needs to repeat by kbonin · · Score: 1

      This is the real reason why most large companies now have email retention policies and auto-delete everything after 30..90 days.

      It is a cheaper "fix".

    2. Re:History needs to repeat by 0123456 · · Score: 1

      GM engineers discovered a safety problem in a vehicle they were designing, and designed an extra part to fix it. But management decided to save $5 per vehicle and skip it.

      [citation needed]

      I remember some similar stories (the Pinto gas tank?) of poor engineering design in American cars that management wouldn't change until they had to, but I'm pretty sure the story as you tell it is an urban legend.

    3. Re:History needs to repeat by dubl-u · · Score: 1

      This is the real reason why most large companies now have email retention policies and auto-delete everything after 30..90 days.

      It is a cheaper "fix".

      That is an incredibly important point. You could fix the email problem, but you can't fix people refusing to know. Almost everybody responsible for crashing our economy escaped accountability, and many of them claimed that they were blameless because they didn't know what was going on, after setting up companies in such a way that they were guaranteed to not know what was going on.

      It's an endemic problem in corporate America, and we need to find a way to fix it.

    4. Re:History needs to repeat by Anguirel · · Score: 1

      Yes, the Pinto was the one that would be the origin of that sort of story. The Exploding Gas Tank could have been fixed by a $1 plastic bit, and they knew that before they went to manufacturing.

      http://motherjones.com/politics/1977/09/pinto-madness

      --
      ~Anguirel (lit. Living Star-Iron)
      QA: The art of telling someone that their baby is ugly without getting punched.
  13. Re:Only Apple does security by wsxyz · · Score: 1

    Being manufactured by Foxconn does not mean that Foxconn does the hardware design and writes the bios and OS code too.
    I hesitate to believe that the screwing, and and glueing that Foxconn does affects the security in any significant way.

  14. What kind of security problems by Osgeld · · Score: 1

    there is a huge fucking difference inbetween "oops we left the programming interface exposed so some hacker can rewrite the firmware in his xbox controller" and "oops we just gave all your personal data to the Chinese, dont enter any credit cards"

    And please drop this magic cloud of "embedded devices" just for the sake of clarity? Cause for fucks sake that could mean anything from the intellegent disk controllers in a C-64 to a ipad to a army rifle

    1. Re:What kind of security problems by 0123456 · · Score: 1

      Take my webcam for example. Telnet to port 50000 and you get a root shell with no password required; took two minutes to discover that with nmap after I connected it to my home LAN.

      Or you did, as the first firmware upgrade removed that feature.

    2. Re:What kind of security problems by Andy+Dodd · · Score: 1

      Yup. It's interesting, some of the things done in the name of "security" actually piss off a vocal minority of technically-oriented users. This vocal minority is often trusted by less-technical friends to make recommendations on what to buy.

      As a result, a device that's locked-down from tinkerers is going to get less recommendations from "trusted friends". A device that's open to tinkerers might have those tinkerers rave about their device to their less-techie friends.

      The problem is that a lot of routes used by tinkerers to bypass lockdown can also be used by malware. For example, the root exploits in Android were probably used 95%+ of the time for good (users rooting their own device), and 5% of the time for bad (malware installed by dumb people). In the case of iOS jailbreaks, it's probably 99/1. (Although from Apple's perspective, those 99% are in the "bad" category.)

      --
      retrorocket.o not found, launch anyway?
    3. Re:What kind of security problems by Anonymous Coward · · Score: 0

      I'm willing to bet Google is slow in fixing these holes (z4root and Gingerbreak worked for HOW long?) because the OEMs don't ship handsets with standard root access, and devs need root access. On the other hand, the root method for my phone boils down to "write a .img file directly to internal flash and use the "su" binary therein," which is impossible to block against if you want write access on your root partition at all.

  15. Re:Only Apple does security by Anonymous Coward · · Score: 0

    I think you're probably trolling, but just in case:

    Every time you see a jailbreak, that's a root exploit. When you see a site like Jailbreakme.com that's an exploit that can be executed through your browser, which is incredibly disturbing. If someone wanted to use the same hole to deliver malware they would have no problems doing so. That payload doesn't necessarily have to be a jailbreak for your device, it could be wiping the entire device, sending your contacts to an unknown person, etc.

  16. They don't care because you don't care by Opportunist · · Score: 1

    Quite frankly, and in a nutshell: Why should a company spend time and money on securing a device if the customer does not honor it?

    Take two companies, A and B. A spends engineering time on working out and ironing out all the security bugs and flaws, ending up with a more expensive product than company B who doesn't. Net result? Customer goes and buys the insecure product from company B.

    Then there's that part where insecurity actually works in the customer's benefit. For reference, see DRM and how it gets circumvented ("softmodding" pretty much means "using a security bug to gain root access" nearly every time).

    Companies will not spend time and money on securing a product if the customer does not care, or even prefers an insecure product. It's that simple.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    1. Re:They don't care because you don't care by erroneus · · Score: 1

      The insecurity that favors the customer is where companies are more inclined to spend their time and money.

      And "customers don't care" is not the same as "customers don't understand" or "customers don't know about it." Customers, when informed of a security issue, almost always care. I refer you to the classic slashdot car-analogy and ask yourself if you were informed, before purchase, of a serious vulnerability in your car, would you buy it? And if you bought it without knowing and were later informed, would you be upset? I think it goes without saying that presuming the customer doesn't care is false. The reality is that the customer isn't informed and cannot care about something he doesn't know.

    2. Re:They don't care because you don't care by brainzach · · Score: 1

      Try telling customers to develop unique passwords with special characters for every website they have an account with. They might care about security, but they care more about remembering their passwords so that they can log in.

    3. Re:They don't care because you don't care by Comrade+Ogilvy · · Score: 1

      "Caring" is a meaningless word, unless proven with action. The question is how much resources, in both time and money, are the consumers willing to invest in order to be more secure.

      "Informing" the consumer is problematic, because once we get past some rock bottom basics about passwords and credit card numbers and phishing, the average consumer cannot understand the specific issues involved without enormous, tedious research and education which they just are not going to do. Informing sounds nice, but if they lack the fundamental understanding to make a sound decision in the full technical context, it is a lot of noise that makes the product look bad to no obvious useful purpose.

      The answer is to have standards, created by experts. Something like the moral equivalent of UL certification that this toaster is very unlikely to kill you.

      The less than ideal but practical answer is to have name brands. It is one of the many reasons that Apple can charge a premium -- it is very rare for their products to be screwed up by random viruses or driver issues. For all that serious hackers often decry the locked gates, many consumers are intentionally paying more money for exactly that.

    4. Re:They don't care because you don't care by Opportunist · · Score: 1

      And "customers don't care" is not the same as "customers don't understand" or "customers don't know about it." Customers, when informed of a security issue, almost always care.

      Oh yes, I can see the PSN being virtually deserted now.

      And oh yes, the people were mighty upset about it. I can still see the laments on many, many message boards what an outrage it is. They shut up quickly as soon as PSN went back online and they could play again.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    5. Re:They don't care because you don't care by erroneus · · Score: 1

      I'll respond in the form of a comic:

      http://xkcd.com/936/

      To make a password strong, 8 characters, having punctuation, numbers and mixed case is not as great an idea as you might think.

      On the other hand, if you tell people to pick four words of varying length that normally don't have anything to do with one another, and you have a pretty good password. It would invariably be longer than 8 characters and WAY harder for traditional cracking methods.

    6. Re:They don't care because you don't care by erroneus · · Score: 1

      Actually, informing the consumer is the responsibility of the manufacturer and in many states in the US, failure to disclose such knowledge is a serious violation of law. We are talking about products shipping where the producer is already aware of problems and vulnerabilities aren't we?

      As for "...it is a lot of noise that makes the product look bad..." goes, that argument doesn't stop them from pushing EULAs in peoples faces and then expecting the user to abide by them.

      There are standards... or there were... before the MBAs started taking over. Engineers have standards "built in." It is "other factors" which compromise those standards.

    7. Re:They don't care because you don't care by erroneus · · Score: 1

      Point taken... Sony consumers are pretty damned stupid.

    8. Re:They don't care because you don't care by Comrade+Ogilvy · · Score: 1

      On your first point, it is an interesting question. When it comes to risk of life and limb, the law may be clear cut. Does Microsoft send us notification for every new known theoretical vulnerability? Did the manufacturer of your old wireless sitting in the corner of your home office firewall/router send your notification about every new hack that could compromise security? I think the answer here is no, but maybe someone has useful information on that question.

      On your second point, EULAs protect the manufacturer. And they have already expanded to a size that 99.99% of the purchasers surely do not read them. Whether the EULA is 5 pages or 15 pages is no longer important.

      Most Civil Engineers and Architects have passed rigorous certifications, and it is an absolute requirement for promotions. Some Mechanical Engineers have passed rigorous certifications. Some Electrical Engineers have.

      But the weak point in security is usually the design of the software and the implementation details of the software. Have you ever seen a certified Software Security Engineer sign off on the fitness of a product for a certain purpose, affirm that it meets explicit industry standards, and accept possible civil and criminal liability for any egregious flaw with the product?

      Senior civil engineers do as much all the time.

    9. Re:They don't care because you don't care by Anonymous Coward · · Score: 0

      it's the same attitude about moving production to China... "They're taking our jobs! Boycott A corp!".. later that same day: "Wow... ShinyPoSProduct is $1.00 off at Walmart!"

      They only care about the price. There was a study in Harvard Business Review about green products. IIRC, Clorox launched a line of green cleaning products; when the recession hit, their sales dropped 40%. They did a bunch of surveys, interviews, etc and found people care _A LOT_ about the environment. And if two products were priced the same, they would choose the green product.

      In other words, they really really care about the environment, as long as it doesn't take a penny out of their pocket.

      Just replace "green" with "security."

  17. Why does anyone do anything by rossdee · · Score: 1

    Because its cheaper

  18. Re:Only Apple does security by CCarrot · · Score: 1

    Here's a refreshing WHOOSH for you!

    Don't feel bad, judging by the modding so far, you're not the only one...

    --
    "I love animals! Some are cute, others are tasty, what's not to like?" - Betsy Schroeder, Jeopardy contestant
  19. i suppose the story by nimbius · · Score: 1

    can be approached from a standard of practicality. Those of us who have spent time working in computing and technology will readily concede security as an illusion and that devices can and will always manifest some element of insecurity. The question the author is trying to ask i suspect is 'are manufacturers doing enough to ensure the security of their devices.'

    harkening back to the days of manufacturing before the CPSC, Americans basked in the glory of such products as stainless steel lawn darts and carcinogenic drink additives. the common board game 'operation' was unquestionably fed from a 120 volt AC source. In short it took a federal regulatory agency to ensure customers were protected against the ruthless profiteering of conglomerates willing to drive their product, in the case of lawn darts quite literally, into their market without so much as a second thought.

    I cant propose a government agency because these days even the most controversial items to be regulated, for example hydraulic fracturing, are met with "cautious optimism" and nothing less. Our relentless pursuit of the golden calf called the free market has made us incapable of asking questions like 'why does my favorite company ship something insecure?' Because there are no penalties on their part for the insecurity of their product, theres no incentive. Because customers are barely capable of understanding the products controls in most cases, let alone the repercussions of misuse, the customer is complacent. And thanks to hardworking patrio-tastic lobbyists and ideological politicians, no regulatory body on the planet can approach the manufacturer with anything less than 'cautious optimism.'

    the solution is death. more customers with more insecure products must exist and a tipping point must be reached before a digital CPSC is created to ensure your internet-capable refridgerator cant be hacked to burn down your house, or your pacemaker doesnt allow a malevolent 14 year old to use it as a midi controlled device. You arent a lobbyist, and you hold no corporate or political power beyond "voting" and "buying" dis-respectively.

    --
    Good people go to bed earlier.
    1. Re:i suppose the story by Grapes4Buddha · · Score: 1

      the common board game 'operation' was unquestionably fed from a 120 volt AC source

      I'm pretty sure that "Operation" has always been a battery-powered game.

    2. Re:i suppose the story by cdrguru · · Score: 1

      Operation was introduced in 1965 well after the time when things were "unquestioningly fed from a 120 volt AC source". There is no question it was always battery powered. Heck, I remember wanting one when it first came out when I was like 10 or something.

    3. Re:i suppose the story by russotto · · Score: 1

      harkening back to the days of manufacturing before the CPSC, Americans basked in the glory of such products as stainless steel lawn darts and carcinogenic drink additives.

      Lawn darts weren't banned until 1988, the CPSC having been founded in 1972. Carcinogenic drink additives were not regulated by the CPSC, but rather the FDA. The two additives you are most likely referring to were actually both eventually ruled non-carcinogenic; one was never banned in the first place.

  20. TL;DR? It's the MBAs by erroneus · · Score: 1

    Most people here on Slashdot understand very well the "engineering" perspective of product development. We tend to believe that a better product will sell better and that, conversely, products that sell better are presumed to be better products.

    MBAs know better. What they know is that marketing, public relations and public image/perception is far more critical to "success" than quality.

    So is it any wonder that quality takes a back seat to marketing and releasing a product?

  21. Re:Only Apple does security by rickb928 · · Score: 1

    Acer, for one, would not find that funny at all. They seem to think they manufacture laptops also.

    There are more than three laptop manufacturers, even if you limit yourself to mainstream brands.

    --
    deleting the extra space after periods so i can stay relevant, yeah.
  22. Re:Only Apple does security by CCarrot · · Score: 1

    Whoosh much?

    --
    "I love animals! Some are cute, others are tasty, what's not to like?" - Betsy Schroeder, Jeopardy contestant
  23. Re:Only Apple does security by Anonymous Coward · · Score: 0

    Anybody can look at Apple code

    Wahahaha! Thank-you, that made me laugh!

    Excuse me while I go compile iOS. Or better yet, I'll just download the Mac OSX source, remove the hardware checks, and compile and run it on my super-badass custom-built PC with more processing power than a handful of iPads put together.

    I think you're getting confused between Linux and Apple. Linux is "very open-model and it's unix" and "anybody can look at [Linux] code and file a report if it's insecure and [Linux developers] [fix] it right away".

  24. Re:TL;DR? It's the MBAs by 0123456 · · Score: 1

    MBAs know better. What they know is that marketing, public relations and public image/perception is far more critical to "success" than quality.

    No, that's what they believe... and in the short term they're correct. In the long term, however, it's hard to keep selling people crap when they've had too many bad experiences with your earlier products.

    Look at Sony, for example. My first two Sony camcorders lasted a decade each; in fact, I'm still using the DV camcorder I bought in 1996 because of the design flaw in the HD camera I bought in 2004 where if you remove the battery before the hardware has completely shut down it fries the logic board and costs more to fix than the camera is worth.

    Suffice it to say, my next camcorder probably won't be Sony, no matter how good their marketing and PR may be.

  25. We don't need to worry by phantomfive · · Score: 1

    At my company, we code in Java. Memory leaks never happen either.

    --
    "First they came for the slanderers and i said nothing."
  26. 24% of companies liable already by Anonymous Coward · · Score: 0

    Why do people think we need MORE laws to protect us. Depending on the devices function we already have sufficient consumer protection laws to guard against 'faulty equipment'. If a device is supposed to be secure (e.g. a firewall) and a company knowingly ships it with a defect, than they can be sued...any decent lawyer should be able to do the job...if it's not a device designed for 'security' (e.g. a simple web server) than it's got nothing to do with the price of rice in china...

    A door in and of itself is totally insecure...but the if you put an expensive deadbolt on it that can be easily 'cracked' than the manufacturer of the deadbolt lock is liable not the door maker...

  27. Adding security costs money by sl4shd0rk · · Score: 1

    And doesn't necessarily increase revenue. Besides that, in my history anyway, managers do not want to spend another $5k because a product is "More Secure". They would much rather put the $5k into a product with a dead-simple API than put it into some hypothetical circumstance which they have no direct experience with.

    Security is one of those things you can only truly understand by getting burned by it.

    --
    Join the Slashcott! Feb 10 thru Feb 17!
  28. Re:Only Apple does security by DickBreath · · Score: 1

    > Hmm cant tell if trolling or just stupid.

    The choices are not mutually exclusive. Think checkboxes, not option buttons.

    Which?
    (*) Trolling
    (_) Stupid


    Which?
    [x] Trolling
    [x] Stupid

    --

    I'll see your senator, and I'll raise you two judges.
  29. Re:TL;DR? It's the MBAs by brainzach · · Score: 1

    Security is only one element of a quality product. Adding a new feature or improving ease can increase a products quality at the expense of security.

  30. Re:TL;DR? It's the MBAs by erroneus · · Score: 1

    Good for you, Mr. Engineer. You display logic and wisdom that few people display.

    For example, people continue to vote for Democrats and Republicans and completely exclude alternatives despite the fact that the two leading "brand names" continually fail them. And Sony's continued success despite their quality issues is an important indicator that you are an anomaly and not a mainstream consumer. Mainstream consumers keep buying Sony because they believe Sony is cool technology.

  31. Re:TL;DR? It's the MBAs by erroneus · · Score: 1

    You are presuming they are always mutually exclusive. While it is often the case, it is not ALWAYS the case.

    But you are right in that people tend to favor convenience at the expense of security for consumer products. However, this is best coupled with consumer ignorance because once they discover there is something about their product that makes them or their information vulnerable to attack, they won't care that it was so they could have a more convenient user experience. They will just be pissed off.... and then they will buy "version 2" of the same thing from the same company.

  32. Insecure? by Lysander7 · · Score: 1

    Do the devices have a low self-esteem?

    Or do you mean UNSECURED?

  33. Re:Only Apple does security by Hognoxious · · Score: 2

    Hmm cant tell if trolling or just stupid.

    The choices are not mutually exclusive.

    Yes they are.

    --
    Confucius say, "Find worm in apple - bad. Find half a worm - worse."
  34. The answer by Anonymous Coward · · Score: 0

    Got to ship it first to get market share, so: Don't worry..... Be Crappy

  35. W.C Fields... by Anonymous Coward · · Score: 0

    I already took your money now, so go away kid... you bother me.

  36. Re:TL;DR? It's the MBAs by ilsaloving · · Score: 1

    I don't buy from Sony either, for the same reasons. However, I seen more than enough people walking home with a sony product under their arm to realize most people really don't care enough to do their research before buying. Heck, look at all the PS3s being sold, and the rabid fanboy community that exists around it.

    So now I just sit back and laugh when someone gets all indignant that their Sony product either failed or somehow abused the purchaser.

  37. tighter security = more returns by Miamicanes · · Score: 1

    The more secure you make an embedded device or appliance against information leakage and harvesting-type vulnerabilities, the more likely it is to end up getting returned to stores by frustrated consumers who can't get it to work.

    Just look at WPA-2 -- it's unquestionably more secure than WEP. It's also rarely used in public settings because statistically, it never fucking works. You can take any access point, and any device that supposedly supports WPA-2, and know beyond doubt that there's about a 50-50 chance it won't work on the first try, and only slightly better odds that it'll eventually work after an hour or more of work (likely victims include anything with Vista or newer, or an Android phone that hasn't been rooted & reflashed to AOSP or Cyanogen.

  38. Re:TL;DR? It's the MBAs by Anonymous Coward · · Score: 0

    I'm a software engineer, and I'll be honest: if I am making an attempt to improve product quality, it's not necessarily because I think that will make the product sell better. Neither is it the other common motivation I see at work: improving some perception of "quality" as a form of sucking up to managers. For the most part I don't do it for the monetary or career rewards, I mostly do it because to a certain extent I feel like I have some obligations that are beyond economics and beyond office politics.

    To know of a serious problem in the product and let it ship like that... Many people I work with have no problem with this. I'm bothered by it. If I know that some percentage of customers are inconvenienced due to lack of foresight at my workplace, even if the percentage is small, that's bad. Never mind that the customer is paying money for our product and it ends up causing them some amount of distress in return; that's like I've just inconvenienced a stranger for no good reason. I am not at all a religious person, but that bothers me ethically, in the sense that I don't go around punching strangers in the face, so why should I do the moral equivalent through software? Sometimes working with managers I feel that they forget the consequences of their actions in real terms; all they care about is the perception of their managers so it doesn't matter if they're churning out crap.

    There is of course the other side of this coin: There is no such thing as bug-free software; bug fixes can introduce other bugs; a disproportionate amount of time fixing bugs will lead to something that never ships. That's just no excuse to write off all your bugs without blinking and neglect quality.

  39. 'Secure' is not a boolean by Junta · · Score: 1

    If you ask me if a product I've worked on is 'secure', my immediate thought is 'what is your criteria?'. There are 'degrees' of secure and the line where someone says 'it's secure' shifts according to whose making the call. Some may say they 'secured' their unattended installer data because they base64 encoded the administrator password (looking at you, microsoft). They would argue they did enough to protect from over the shoulder (visual exposure only, with no opportunity to transcribe it to paper). The attacker couldn't remember the base64 string long enough to put it into a base64 decode. In theory they could have taken it a step farther (like kickstart and autoyast for example), and stored the NTLMv2 hash in the file instead of password. More would say 'secure', but then some would say 'NTLMv2 hashes are trivially broken by rainbow table, so it's not appreciably better'. Let's say they even went so far as to redo their local account store to use something as well salted as modern /etc/shadow entries. Some would still say it's insecure because even with the cipher text pretty well protected against practical rainbow tables, GPUs can crunch through the problem space too quickly.

    Then when faced with the continuum between 'wide open' and 'uselessly secure', there are tradeoffs. For example, ssh keys are widely used for convenience (and frequently can be fairly considered 'more' secure). When used for convenience, they are often stored without a passphrase. This means some will say it's less secure because they fear an offline attack or other attack that compromises the key. So you slap a passphrase on and have to type it everytime. You are back to the same level of inconvenience of password every time. ssh-agent mitigates this and things like gnome-keyring mitigate it further, but I'm sure some would call the 'attack surface' larger and therefore less secure somehow.

    Some tasks can be rendered impossible by 'perfect' security. Like auto-deploy of new equipment being enabled by well-known default credentials being very convenient, but we all know how 'default credentials' can be considered very very bad if a piece of equipment is popular and installers are lazy.

    --
    XML is like violence. If it doesn't solve the problem, use more.
  40. Dev reaction to security bugs by losttoy · · Score: 1

    I have worked long and hard in my profession to get devs to fix security bugs. The reaction mostly falls in one of these categories:
    1. I do not understand the issue (read, I am just copying code of the interwebs and have no clue about my job).
    2. I understand the issue but we are under the gun to release the product.
    3. I understand the issue but the vulnerability is theoretical (read, I don't understand anything about large scale production infrastructure)

    Bottom-line: Unless a security big breaks functionality, a dev doesn't care.

    Sorry to devs who care but after a decade of trying devs to release secure code, my opinion maybe a bit biased.

  41. "Companies will not pack up and leave" by tlambert · · Score: 1

    "Companies will not pack up and leave"

    I respectfully disagree. Why are most air ambulance / life flight helicopters in the US manufactured by Eurocopter (French) and Agusta Westland (Anglo/Italian), rather than Bell (US) these days, even though there are a few Bell helicopter models that are CAMTS certified?

    when was the last time you even saw an air ambulance that didn't use a ducted fan tail rotor, i.e. one that wasn't an EC-135 (Eurocopter)?

    -- Terry

    1. Re:"Companies will not pack up and leave" by said213 · · Score: 0

      "when was the last time you even saw an air ambulance that didn't use a ducted fan tail rotor, i.e. one that wasn't an EC-135 (Eurocopter)?"

      this morning?

      --
      help me fix this "Terrible" karma, please!
    2. Re:"Companies will not pack up and leave" by shadowfaxcrx · · Score: 1

      Yeah. Yesterday. Admittedly I'm cheating since my job requires that I be at accident scenes, and so I see them a whole lot more than the average guy, but every life flight chopper around here is a Bell 407.

      --
      "I disagree with you" does not equal "flamebait."
  42. Time for SOX for Security by Anonymous Coward · · Score: 0

    Sarbanes-Oxley requires executives to sign off on all financial docs or face penalties. When it came to one company I was at I was thrilled, I got to lock down the datacenter (they had a startup mentality long after they went public).

    But the exec's were a little nervous, to say the least.

    We should have something similar for hw and sw. I know there would be problems implementing and enforcing, but it's inexcusable to put people's financial and personal lives on the line for a quick profit.

  43. In most cases it's an annoying misfeature. by ron_ivi · · Score: 1

    So what if my cell phone can access voicemail without a 15 character minimum password.

    So what if my Wii or Xbox can let people chat with me.

    So what if my GPS could theoretically be told to trick me into turning into a lake.

    For 99% of of devices I buy, security "features" are an annoyance end user's don't want.

    When I buy a post card - it's OK someone who theoretically intercepts the mail can read it. I understand that and won't write my credit card number on the back of it. The last thing I want is some legislation saying that postcards must be wrapped in tinfoil with a tamper-proof seal.

    Same should be true for hardware.

  44. There's one basic problem here by Paul1969 · · Score: 1

    They surveyed engineers. Engineers *never* think they have enough time or resources for a project.

  45. Right, but "SMALL CORRECTION"... apk by Anonymous Coward · · Score: 0

    MODIFIED CORRECT VERSION:

    "They would much rather put the $5k into THEIR YEAR-_END BONUSES than put it into some hypothetical circumstance which they have no direct experience with." - by sl4shd0rk (755837) on Friday August 12, @12:25PM (#37069636)

    Now, that's MORE LIKE IT, wouldn't you agree? After all, IF you've been there, I think you'd agree... especially from the guys that don't really do anything more than babysit, & yet get paid more than the people who actually DO do things!

    Now, from being in software development professionally since 1994? I can tell you, point-blank, that of around 10 bosses I've had (CIO's etc.), ONLY 2 HAD ANY ACTUAL EXPERIENCE "hands-on in the trenches" actually DOING the job themselves (but THOSE 2 guys absolutely rocked... the others? Do I have to say it??).

    ---

    ORIGINAL INCORRECT VERSION:

    "They would much rather put the $5k into a product with a dead-simple API than put it into some hypothetical circumstance which they have no direct experience with." - by sl4shd0rk (755837) on Friday August 12, @12:25PM (#37069636)

    It's true enough, but, you omitted the REAL REASONING behind it, shown in the modified version above your original words quoted here...

    APK

    P.S.=> You're correct that adding security does cost money, but, the "infamous they from the corporatocracy" aren't out to produce superior "perfect" product, by any means: THIS IS "BAD FOR BUSINESS" IN FACT! No - they're out to keep you chasing a carrot in front of your nose, releasing a 'better product' that corrects KNOWN problems next round to do so...

    Yes, I've seen this in software development (albeit, MOSTLY with "intermittent errors" that ships admittedly, that get fixed in a patch so ship dates can be met (because businesses take penalties the same as their venture capitalists who took out bank loans, NOT THEIR OWN CASH mind you, to finance these ventures... they pay a penalty if the deadlines aren't met, this gets passed onto the development house also, shit flows downhill right into the consumers' pockets, everytime...))...

    No - There's the "way it oughtta be", & then, THERE'S THE WAY IT REALLY IS...period!

    ... apk