![]() It also allows each access or access attempt to be logged to create a detailed audit trail. That allows a CyberLock to impose tight-knit restrictions on each key holder that among other things controls the times of day someone can access a particular area or locked storage container and the duration of time the key is valid. IOActive's five-page advisory warns that some of the bugs undermine fundamental assurances about the security of the product, which looks and acts like a traditional lock, but is locked and unlocked with a programmable digital key known as a CyberKey. Officials from CyberLock didn't respond to e-mails seeking comment for this post. They characterized it as an abuse of the legal system that threatens the public's right to know about vulnerabilities in products they use to secure their property and secrets. Word of the letter touched off wails of protest on social media sites from security researches and privacy advocates. It also provides substantial civil penalties copyright holders may recover. The Digital Millennium Copyright Act of 1998 makes it a felony to circumvent technology intended to prevent access to copyrighted material. Presumably, IOActive is aligned with ensuring responsible disclosure and compliance with the laws." " also takes the protection and enforcement of its intellectual property rights seriously and, prior to any public reporting, wants to ensure that there has been no violation of those rights, including 's license agreements or other intellectual property laws such as the anticircumvention provision of the Digital Millennium Copyright Act. ![]() "Of course, as you know, the public reporting of security vulnerabilities can have significant consequences," Jeff Rabkin, a partner at the Jones Day law firm wrote in a letter dated April 29, one day before IOActive published the advisory. A redacted version of a letter CyberLock outside attorneys sent IOActive researcher Mike Davis has reignited a long-standing tension between whether it should be legally permissible for researchers to publicly disclose unfixed vulnerabilities in the products they test. ![]() The report is also the topic of a legal threat from CyberLock attorneys who invoked draconian provisions of the Digital Millennium Copyright Act if IOActive disclosed the vulnerabilities. ![]() ![]() Thursday's advisory from security firm IOActive is notable not only for the serious security issues it reported in the CyberLock line of access control systems, which are certified to meet a wide range of US governmental requirements and certifications. Critical vulnerabilities in a market-leading line of digital locks securing hospitals, airports, and water treatment facilities makes it possible for rogue employees or outside attackers to clone digital keys, researchers reported late last week. ![]()
0 Comments
Leave a Reply. |
Details
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |