Legal Issues

Legal Issues

by Mike Masnick


Filed Under:
disclosure, lawsuits, security, smart cards

Companies:
nxp semiconductors



Dutch Chipmaker Sues To Prevent Researchers From Publishing Info About Security Flaws

from the security-by-obscurity? dept

NXP Semiconductors, which was formerly Philips Semiconductor division, is suing some researchers to prevent the publication of a paper outlining the security flaws in smartcards made by NXP. These smartcards are widely used for transit systems and building locks. Of course, the fact that these cards have been insecure has actually been known for quite some time. Rather than fixing the problem, though, NXP spent plenty of effort denying any problem existed. Now that multiple researchers have demonstrated that the problem really does exist, NXP is claiming it hasn't had enough time to fix the problem, and thus is suing to prevent publication.

Of course, if NXP hadn't wasted so much time insisting there was no problem, perhaps it would have been closer to a fix. And, most importantly, those who are looking to use this vulnerability already have access to it. Publication in a journal isn't going to alert criminals -- they already know about it. What it could do, however, is get more researchers helping on a solution. But, apparently, NXP would rather pretend that if they keep the details hidden, they can pretend there is no problem.

8 Comments | Leave a Comment..

 
 

Reader Comments

(Flattened / Threaded)

    Jul 10th, 2008 @ 8:31am
  • Next, Voting Machines

    by Josh Martin

    Do these people make electronic voting machines, too?

    (reply to this comment) (link to this comment)

  • Jul 10th, 2008 @ 9:18am
  • by Jake

    I can kind of see the argument in favour of not publicising leaks like this until after you get a satisfactory official response from the company, and the YouTube video demonstrating the 'attack' looks more than a little contrived. I would however have more sympathy for NXP if they'd written back to say they were working on a solution and asking the university to hold off on publishing its results until they'd sorted it out.

    (reply to this comment) (link to this comment)

  • Jul 10th, 2008 @ 10:36am
  • What's the claim?

    by Willton

    With the caveat that I don't know jack about Dutch law, what is the claim here? I understand NXP would want to keep this from getting published, but I don't see what the underlying claim is to bar publication of this. Is it defamation?

    (reply to this comment) (link to this comment)

  • Jul 10th, 2008 @ 10:38am
  • Don't play hardball when you're the one who will lose

    by TravisO

    NXP is making a very bad move, especially if multiple separate people or groups know about the flaw. They're just asking for a writeup of the flaw to be posted anonymously on some key forums.

    Obviously the group that discovered the problem alerted the company, have them time to fix, no fix is available (the problem isn't always easy or quick) but NXP should have made a plea to hold back, but instead they're resorting to hardball tactics, and I say you fight fire with fire, release the hounds!

    (reply to this comment) (link to this comment)

    • Jul 10th, 2008 @ 11:38am
    • Re: Don't play hardball when you're the one who will lose

      by Anonymous Coward

      zero tolerance for folks who dont take security vulnerabilities seriously. that is the only way to make them learn. times are a-changing and hardball firewall tactics are no longer acceptable.

      (reply to this comment) (link to this comment)

    Jul 10th, 2008 @ 12:24pm
  • here we go again

    by dkp

    I have a problem with companies spending time and money on fighting in this case the publication of information about flaws instead of fixing the problem this also goes for other things such as ip and others

    (reply to this comment) (link to this comment)

  • Jul 10th, 2008 @ 12:36pm
  • security is too important ...

    It seems to me that any problem that compromises security (which is incredibly important in this day and age, more than ever before) and affects others should be reported as a warning immediately, even before a solution has been reached. People do need to know what they’re using, and when it goes “bad,” they need to know how to adjust their behavior with it accordingly and protect sensitive and important information. Even Microsoft, who has been pretty seriously hurt (though not necessarily financially!) by Vista’s many initial failures and problems admitted to their mistakes and provided quick solutions or at least work-arounds and adjustments.

    (reply to this comment) (link to this comment)

  • Jul 11th, 2008 @ 7:58am
  • after it's broken, it keeps that way

    by Merijn

    As far as I know, Professor Bart Jacobs and his crew have already had a few free rides to prove that the system is broken. Trying to silence a university professor won't fix your problem. Also I do not know the laws of my country, the Netherlands, well enough to guess what they try to use as a legal means to their cause in the attempt to silence their neighbor. Radboud university and NXP are located in the same city.

    (reply to this comment) (link to this comment)

Add Your Comment

Have a Techdirt Account? Sign in now.
Get Techdirt’s Daily Email
Plain Text HTML
Save me a cookie
  • Plain Text: A CRLF will be replaced by break <br> tag, all other allowable HTML is intact
  • HTML: No formatting of any kind is done without explicitly being written in
  • Allowed HTML Tags: <b> <i> <p> <a> <em> <br> <strong> <blockquote> <hr> <tt>
Close
Have a Techdirt Account? Sign in now.
Get Techdirt’s Daily Email
Plain Text HTML Save me a cookie

Search Techdirt
And now, a word from our Sponsors..



Subscribe to Techdirt's Daily Email Newsletter

Techdirt's Daily Email Newsletter

Related Stories
Close
E-mail It