Characterizing flaws in a publicly available product is not anywhere near insider trading. It's obviously research, not proprietary information.
It's also likely to be quite easy to avoid libel/slander. Just specify when you obtained the product and demonstrate the flaw in the product you obtained.
Except that demonstrating a flaw _by predatory profit-driven entities that have a direct stake in said flaw_ leaves plenty of room for spin and hype. This is already obvious if you read the MW report, some of the "vulnerabilities" are so contrived that the real-world impact is miniscule if not entirely absent, yet they present them (whilst omitting key facts and occulting others) in such a way as to elicit a certain response from the readers.
Given that security is not a solved problem, by far, if you allow this sort of behavior you're opening up the gates of Hell.
There needs to be an objective overseer, that is not profit-driven, for proper evaluation.
This Muddy Waters-MedSec fiasco is evoking memories of the Wild West and is surely not where we want to end up.
> There needs to be an objective overseer, that is not profit-driven, for proper evaluation. This Muddy Waters-MedSec fiasco is evoking memories of the Wild West and is surely not where we want to end up.
So, another Federal bureaucracy? Or what? And how could you guarantee that such a body would remain objective, and avoid regulatory capture?
I think the solution you propose could easily be worse than the problem.
All I said was It's also likely to be quite easy to avoid libel/slander.
I didn't evaluate this case or claim that all researchers/shorts would succeed in doing so.
In the end think I'm more concerned about devices that crash/fail due to unauthenticated radio traffic (claimed in the report) than I am about some dude accidentally libeling a company.
> Except that demonstrating a flaw _by predatory profit-driven entities that have a direct stake in said flaw_ leaves plenty of room for spin and hype.
I think we're at a point where getting some money behind spinning and hyping the seriousness of security vulnerabilities is probably a Good Thing™.
In my view, this is the naive outsider perspective.
Security vulnerabilities are everywhere. The old adage 'seek and ye shall find' is king and it doesn't take particular expertise or resources to enter this arena. Moreover, you have hidden cascade/network effects that are growing stronger every day.
With that in mind, one needs to think longer and harder in order to begin to realize what a Good Thing would even be.
When you open the gates of Hell, you have no control over what comes out of it. I'm fully in favor of holding corporations liable when it comes to security vulnerabilities, but making deals with the devil is certainly not the best way
of doing that. If this case sets a strong precedent you can expect to see similar speculatory attacks in widely disparate domains, not just medical. I do not share Thomas Ptacek's pessimism re: limited domain applicability of such attacks.
In order to at a minimum avoid chilling effects, you need clear evaluation protocols.
We do not have that in this case, it seems rather that the downside for MW is minimal (and also heavily hedged against).
The objective overseer is the market. If the flaw described is not noteworthy or material (i.e. just hype), then no profit can be made, as there won't be a market impact.
It's also likely to be quite easy to avoid libel/slander. Just specify when you obtained the product and demonstrate the flaw in the product you obtained.
edit edit: reading fail.