> unelected government dictating coding standards by fiat
An elected congress gives agencies regulatory authority and provides over-sight. If Congress chooses, it can dismantle the FTC or pass a law stating that DLink cannot be held liable.
Congress enables regulators to do things you don't like, because it's impossible for Congress to micro-manage the entire Federal bureaucracy and military. Congress is well within its Constitutional rights to empower third parties to enact enforce certain classes of regulations.
I understand why you find that frustrating, but it's dishonest to characterize that situation as an "unelected government". The government is elected, and regulatory agencies must answer to those elected governments.
> This precedent creates unlimited liability for so much software and hardware that gets created.
You know what? Tough luck.
Most people who build things professionally and sell those things are held liable for their work. Take a look at what DLink actually did, and tell me that their engineers/management was behaving in a responsible and reasonable manner.
Maybe it's a good thing that the gov't is forcing software and hardware companies to start taking ownership of their craft. The market is certainly failing to price in security.
> It is the ability to warranty against this type of stuff that has let OSS take off. I expect this to have a chilling effect.
On the other hand, I highly doubt this case or any resulting precedent (if any) will have a noticeable chilling effect in OSS.
I guess time will tell which of us was correct...
> damage is the result of malicious attack by criminal actors
And yet, those attacks were completely foreseeable since at least the early 00's... I could've told you the day that DLink released these webcams exactly what would happen. I'm sure plenty of DLink's engineers tried to tell their own management...
> Just because as devs we are mad when our bosses make stupid security decisions, doesn't mean this is the way to handle it.
Perhaps this is the best jumping off point for a productive conversation -- what's your proposed solution?
My solution is we prosecute botnet operators and malicious actors. We have the technology. The NSA has the ability to know who they are. Countries that harbor them should face sanction.
And ISP's could stop this DDOS activity. We should police this at that level. A system where when a DDOS is reported by a reputable web hosting company or service provider to a system that ISPs belong to, could stop DDOS in its tracks.
Enable 2 factor auth at the ISP level. If a report of DDOS comes in, send an SMS to the authorized user of the account.
And punish companies that perform bad security in the marketplace. We are getting more tech literate as a people, as a society. The market might not be fulling pricing in security right now, but the issue is new and awareness is just beginning.
Lets be clear, this is selective enforcement. D-Link is one operator, using what were very common practices at the time, and still are.
No one who created these devices was ever told that these practices were illegal, or would result in sanction. And now we are fining them. D-Link will weather this as it is big enough. But small operators wouldn't.
So the result of this government action is that startups and crowd funded projects are less viable. Now, startups and kickstarter projects need to have a line item in their budget for security insurance. And an insurer has to take on this risk. Because it wont be policed or litigated evenly. And thers no telling what the security standards of tomorrow will be.
So startups will have to buy security insurance. And that will be expensive.
Big companies will survive. They will be able to pay the protection fee, the extortion fee. The status quo will remain. We won't be more secure, because the real actors making us insecure are nation-states and Chinese manufacturing.
> the result of this government action is that startups and crowd funded projects are less viable
If those projects are being run by people who are incompetent and unable to consider the importance of protecting user privacy through competent security, maybe that isn't such a bad thing. If FAA rules stop people from crowdfunding new passenger aircraft and leave it to the companies who actually have the skills, expertise and responsibility to build a plane with the relevant safety measures, as an airline passenger, I'm okay with that.
> My solution is we prosecute botnet operators and malicious actors
But what if this course of action -- investigation, enforcement, sanctions, etc. -- ends up costing substantially more than the effective cost of device manufacturers giving a damn?
All of DLink's issues (maybe aside from command injection, but I'd argue even that) could've been trivially prevented. I could've identified and fixed these issues in a week or two of time.
So basically, you're saying the country should suffer millions or billions in lost business opportunities (via sanctions), in addition to paying tens or hundreds of millions for increased investigation and law enforcement activities. All of this, to save DLink from having to hire even a single half-decent PM or SE who knows that default passwords are a bad idea and maybe we should not post private keys on a public website?
How is that even remotely fair?
> And ISP's could stop this DDOS activity. We should police this at that level.
This doesn't address other forms of harm. If botnet owners can't use their farms for DDoS and spam services, they'll turn to identity theft and ransomware. Most already have.
> And punish companies that perform bad security in the marketplace
Isn't that exactly what the FTC is doing here? Or do you mean that the marketplace should punish them? Because the latter clearly isn't working...
> Lets be clear, this is selective enforcement
Well, yeah. Literally all enforcement is selective enforcement. From speeding tickets to illegal gambling, drug distribution, and tax fraud. Police and regulators choose which cases are most egregious, and make an example. Even in murder cases, police sometimes choose to stop investing resources in a tough/cold case.
All investigation and enforcement is selective.
> No one who created these devices was ever told that these practices were illegal, or would result in sanction
With all due respect, a lot of us have been calling on the FTC and other regulatory agencies to sue these companies under existing consumer protection laws for a long time now.
And the FTC themselves have been making some noise since at least 2013 about following best practices, together with wording that specifically points out to major companies (like DLink!) that the FTC already has the legal tools needed to pursue punitive actions.
Perhaps DLink didn't know there were already laws on the books that could be used punish particularly incompetent software engineering. If they were a small company, I might be more sympathetic. But they aren't, so IMO, that ignorance is entirely on them.
> Now, startups and kickstarter projects need to have a line item in their budget for security insurance. And an insurer has to take on this risk... So startups will have to buy security insurance. And that will be expensive.
I doubt it. They might have to start following best practices and designing secure software. And yeah, that means they can't "move fast and break things" when it comes to security. Cry me a river...
An elected congress gives agencies regulatory authority and provides over-sight. If Congress chooses, it can dismantle the FTC or pass a law stating that DLink cannot be held liable.
Congress enables regulators to do things you don't like, because it's impossible for Congress to micro-manage the entire Federal bureaucracy and military. Congress is well within its Constitutional rights to empower third parties to enact enforce certain classes of regulations.
I understand why you find that frustrating, but it's dishonest to characterize that situation as an "unelected government". The government is elected, and regulatory agencies must answer to those elected governments.
> This precedent creates unlimited liability for so much software and hardware that gets created.
You know what? Tough luck.
Most people who build things professionally and sell those things are held liable for their work. Take a look at what DLink actually did, and tell me that their engineers/management was behaving in a responsible and reasonable manner.
Maybe it's a good thing that the gov't is forcing software and hardware companies to start taking ownership of their craft. The market is certainly failing to price in security.
> It is the ability to warranty against this type of stuff that has let OSS take off. I expect this to have a chilling effect.
On the other hand, I highly doubt this case or any resulting precedent (if any) will have a noticeable chilling effect in OSS.
I guess time will tell which of us was correct...
> damage is the result of malicious attack by criminal actors
And yet, those attacks were completely foreseeable since at least the early 00's... I could've told you the day that DLink released these webcams exactly what would happen. I'm sure plenty of DLink's engineers tried to tell their own management...
> Just because as devs we are mad when our bosses make stupid security decisions, doesn't mean this is the way to handle it.
Perhaps this is the best jumping off point for a productive conversation -- what's your proposed solution?