Email: Password: Remember Me | Create Account (Free)

Back to Subject List

Old thread has been locked -- no new posts accepted in this thread
???
02/16/08 23:37
Read: times


 
#150943 - If you really want to do that
Responding to: ???'s previous message
Jan Waclawek said:
Richard Erlacher said:
I've had pretty good success with "security through obscurity," using such methods as inserting a flatpack between the inner layers of an 8-layer board.


Actually, this is "security through surprise". You are not announcing, "my product is secure and I won't tell you why do I say so". The chipmakers do.

I agree, they should not be allowed to make such claims unless they're willing to indemnify the statement with, say, a $1E15 award to anyone who can defeat their "security" and a $1E24 payment to anyone who sustains any loss on account of reliance upon it.

Richard Erlacher said:
I think you can see where I sit on this matter.


Yes, certainly. Actually, it matters in 99.9% of discussions on this (and other) Forum... ;-)

??? to what does that "it" refer?

Richard Erlacher said:
I agree with you, in that I would allow and even encourage such discussion, but wouldn't encourage it in a public forum, as the probability of doing good is small, while the risk of doing harm is large.


What risks and harms are you talking about, exactly?

What risk is in reproducing what others have already published on the Internet? What is the risk of concentrating this knowledge? Those, who are determined enough to break into somebody's house, will do that regardless if there is a lockpicking "manual" or not. They will find ways how to learn lockpicking. On the other hand, the existence of the "manual" will at least teach the public on the true risks of relying on easily pickable locks...

JW


There's no risk in referring to an already published item on the www, so long as it's a link and not a paraphrase. The courts here in the U.S. have already established that selling guns to known criminals is not, in itself, a crime, despite the fact that it's against the law to sell to known felons, the difference being that the criminals who aren't yet known felons simply haven't been convicted yet.

The sad fact that there are many who'd like to break into our houses for various reasons does not suggest in any way that we, in this forum, should help them, despite the fact that there are lock picking manuals and the like already published on the www, e.g. on youtube.

If I want your code, I'll ask you for it. If, for any reason, you think I shouldn't have it, I'll just have to do without. I certainly wouldn't buy your product and then attempt to copy it. I've been doing this reverse-engineering thing for many years. Back in the early '80's, my partner and I used to go to conventions and look at various products. We'd look at someone's board, and then my partner and I would sit down with a coffee and draw schematics of what we thought it was on a napkin. On those occasions where we learned something, it generally was that one could use this component instead of that, or this technique instead of that one. Not once did we replicate someone's circuitry, though we did easily learn how to improve on it. Not once did I have to "crack" a PAL, or a "secure" PROM. It can all be done from behavioral observation. I've never made a dime selling someone else's technology, though I have, at times, learned from it. I've believed that, by the time I can produce a copy, the original circuitry has been vastly improved upon by those who bothered to learn how it works rather than blindly copying it.

Maybe you believe in copying from your neighbor's test paper in examinations, or from his homework in school. I did that once, when I was about 10 years old, and haven't done it since, since it taught me not to rely on the other guy.

I think we should help people use their imaginations to be creative rather than helping them to steal in ordr to replicate what's already been done.

As for the manufacturers' claims of "security" ... that's an area where full disclosure is indicated. If there's a way ... any way at all, of defeating advertised "security" that's understood to work reliably, it should be disclosed to everyone. If the manufacturer still insists his product is totally secure, it should be trumpeted far and wide that it's not, ... "and here's how we prove it!" That position, IMHO, should be taken whenever a manufacturer claims anything that can be proven false, and the conditions under which it is false be published as well.

Encouraging people to attack protected devices for the purpose of gaining unwelcome access to them, however, is not what I think should be encouraged in this forum.

If you haven't anything more productive to do with your talents, then go ahead. It's not yet illegal.

RE







List of 71 messages in thread
TopicAuthorDate
Security-breaking threads            01/01/70 00:00      
   Mostly bad            01/01/70 00:00      
      put that in the rulse and ...            01/01/70 00:00      
   Reverse Engineering            01/01/70 00:00      
      Why would this be the case?            01/01/70 00:00      
         legal, maybe, but worthless            01/01/70 00:00      
      Reverse Engineering            01/01/70 00:00      
         locked doors            01/01/70 00:00      
            a couple of points ...            01/01/70 00:00      
               Thief?            01/01/70 00:00      
                  Ironically the Chinese Wall            01/01/70 00:00      
                  IANAL, but...            01/01/70 00:00      
                     Are you sure?            01/01/70 00:00      
                  the law can be interpreted in many ways            01/01/70 00:00      
               by the time you'll decide...            01/01/70 00:00      
                  the short happy life of ... Jan Waclawek?            01/01/70 00:00      
                     you apparently don't understand my point, Richard            01/01/70 00:00      
                        It should be how to Protect Your MCU rather then h            01/01/70 00:00      
                        perhaps I do            01/01/70 00:00      
                           Fair use, security, and all that            01/01/70 00:00      
                              It's simpler than that            01/01/70 00:00      
                                 What harm?            01/01/70 00:00      
                                    If you really want to do that            01/01/70 00:00      
                                       A greater harm            01/01/70 00:00      
                                          Have you gone one assumption too far?            01/01/70 00:00      
                                             Republicans, believe .... AIDS            01/01/70 00:00      
                                                mingling the issue            01/01/70 00:00      
                                                   Which link ?            01/01/70 00:00      
                                                      find it yourself            01/01/70 00:00      
                                                         You find it and Its IAR policy not yours            01/01/70 00:00      
                                                            no, it is not, I'm sure            01/01/70 00:00      
                                                               what an IAR in code ...            01/01/70 00:00      
                                                                  not witrh a Keil eval            01/01/70 00:00      
                                                                     Thats company policy            01/01/70 00:00      
                                                                        I sure can make this decision that            01/01/70 00:00      
                                                                           Is leasing Compiler legal ? . I will never do that            01/01/70 00:00      
                                                                              I don't quite understand this..            01/01/70 00:00      
                                                                                 That's why it requires no treatment here            01/01/70 00:00      
                           Would you?            01/01/70 00:00      
   Slap in the face!            01/01/70 00:00      
      Recovering lost code            01/01/70 00:00      
   Don't help pirates but...            01/01/70 00:00      
   FAQ            01/01/70 00:00      
   it sure is immoral to steal code            01/01/70 00:00      
      The morality of repairs.            01/01/70 00:00      
   I've done it legally and ...            01/01/70 00:00      
      Faulty logic            01/01/70 00:00      
         evidently you missed my exception            01/01/70 00:00      
            False statements            01/01/70 00:00      
               GPL as 'protection' LOL            01/01/70 00:00      
      Security through obscurity            01/01/70 00:00      
         other possibilities            01/01/70 00:00      
            Malund you come to conclusion very early !            01/01/70 00:00      
               Are you sure?            01/01/70 00:00      
                  OK, so let's circumvent this problem...            01/01/70 00:00      
               then why have you done so?            01/01/70 00:00      
                  Did that link open your eyes            01/01/70 00:00      
                     I do not care, my code is worthless in hex            01/01/70 00:00      
         This one is on you, Craig ... the buck stops there            01/01/70 00:00      
            Competence.            01/01/70 00:00      
               I know of many 'unteachable'            01/01/70 00:00      
                  That's what put options are for ...            01/01/70 00:00      
                     Let's not promote fakery in the profession            01/01/70 00:00      
   Answer to the original question            01/01/70 00:00      

Back to Subject List