5 ms·
Would security researchers or watchdogs go around and say things publicly without evidence to defend their claims? Because thats what opened up Rudy for this la
by JakeTheAndroid 6y ago
Would security researchers or watchdogs go around and say things publicly without evidence to defend their claims? Because thats what opened up Rudy for this lawsuit. He made unsubstantiated claims that possibly damaged the reputation of the company.
How would this be used against researchers or watchdogs in your opinion?
- cwkoss 6y agoVoting Machine Company: "Our machines are 100% secure. The security consultant we paid to tell us that agrees." Researcher: "Your machines have USB ports exposed, can flash firmware, connected to the internet, don't produce an auditable paper trail, and I hacked into a machine personally. 100% secure is demonstrably false." Voting Machine Company: "Well, a third party verified that it is 100% secure so we're going to sue you (and probably not win) but it will cost you tens or hundreds of thousands of dollars to defend, unless you cease and desist."
- charonn0 6y agoGuiliani didn't say any of those things.
- JakeTheAndroid 6y agoOkay, but that wouldn't open up the researcher for a lawsuit, it would just provide the company with a PR leg to stand on. Nothing about this case is similar to what you outlined, and would not meet the legal requirements for a successful libel or slander case. If any company comes out and says the product 100% secure, the tech community basically scoffs at them. It's not a good PR strategy for a company anyways. Now, relying on the reputation of another firm through audits is a totally normal way of doing business. This does not compete with researchers, and has by and large included researchers (stuff like Bug Bounty/Responsible Disclosure programs) as a good control. So any researcher looking for this stuff would likely have a protected way to disclose their findings. Further, this is supported by another compliance body in the SEC via SOX. There has to be a protected whistleblower program for publicly traded companies. So, the ability to disclose security gaps is not neutered in any way by this court case, no matter how it plays out.