Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

5/2/2019
04:14 PM
Dark Reading
Dark Reading
Products and Releases
50%
50%

With Launch of Securepairs.org Top Cybersecurity Experts stand up for Digital Right to Repair

Boston, Massachusetts, April 30, 2019 -- Leading information security experts are speaking up in support of right to repair laws that are being debated in state capitols and calling out electronics and technology industry efforts to keep replacement parts, documentation and diagnostic tools for digital devices secret in the name of cyber security.

Declaring “fixable stuff is secure stuff,” the group called for “facts not FUD” (fear, uncertainty and doubt) in the face of recent efforts to paint the right to repair as a cyber security risk. The group of more than 20 cyber security professionals includes some of the most regarded names in information security. Among them: Bruce Schneier of IBM and Harvard University, an author and globally recognized expert in cryptography; Gary McGraw, the computer scientist and author of 12 books on software security; pioneering vulnerability disclosure expert Katie Moussouris of Luta Security; Chris Wysopal, Chief Technology Officer at Veracode, Joe Grand (aka “Kingpin”) of Grand Idea Studio and Dan Geer, the Chief Information Security Officer of In-Q-Tel, a non-profit, venture arm of the CIA.

 “As cyber security professionals, we have a responsibility to provide accurate information and reliable advice to lawmakers who are considering Right to Repair laws,” said Joe Grand of Grand Idea Studio, a hardware hacker and embedded systems security expert.

No cyber risk in repair

“False and misleading information about the cyber risks of repair is being directed at state legislators who are considering right to repair laws,” said Paul Roberts, the founder of securepairs.org and Editor in Chief at The Security Ledger, an independent cyber security blog. “Securepairs.org is a voice of reason that will provide policy makers with accurate information about the security problems plaguing connected devices. We will make the case that right to repair laws will bring about a more secure, not less secure future.”

With right to repair laws proposed in 20 states, the technology, electronics and home appliance industries have gone on the offensive. Working through front groups and public relations firms, they are floating specious arguments about the cyber security risks of repair. In opinion pieces, blog posts and interviews, these groups are painting pro-consumer, pro-competition laws granting digital device owners access to service manuals, diagnostic software or replacement parts as a safety risk and a giveaway to hackers and cyber criminals. 

"We've seen industry opponents using dubious cybersecurity arguments to claim we shouldn't have the freedom to fix the things we own,” said Nathan Proctor, the head of U.S. PIRG’s Right to Repair campaign. “I'm grateful the real experts are standing up, and setting the record straight: There is no cyber threat from repair. Just let us fix our stuff."

Security issues with connected devices are real enough, notes Roberts. But they have nothing to do with the kinds of measures promoted in right to repair laws. “Home electronics, personal electronic devices and smart appliances too often ship with easily exploitable software vulnerabilities or insecure configurations. These are the digital equivalent of unlocked or unlockable doors that hackers can step through,” Roberts said. “Sadly, device manufacturers, working through their industry groups, PR firms and paid lobbyists, are spending money trying to sink right to repair legislation that is totally unrelated to these problems,” he said.

“We know from hard experience that security through obscurity is a myth,” said Grand. “Keeping the workings of electronic devices secret does nothing to reduce the threat from motivated, resourceful hackers or cyber criminals. Instead, it prevents legitimate owners from maintaining and repairing their property as they see fit. Manufacturers who support Right to Repair will actually improve, not weaken, security by providing access to documentation and genuine, high quality replacement components,” he said.

Building a nation-wide network of security professionals

Securepairs.org is launching to help mobilize information security professionals to help secure the right to repair in their home states: writing letters and emails and providing expert testimony about the real sources of cyber risks in connected devices. The group is looking to brief lawmakers and to encourage other information security professionals to sign up via its website.

About securepairs.org

Securepairs.org is a not-for-profit, volunteer organization representing information security professionals who support the right to repair. Lawmakers and the public need facts not FUD regarding a digital right repair. Securepairs.org provides a platform for information (“cyber”) professionals to speak with one voice in support of the digital repair rights of owners.

Securepairs.org:
Paul Roberts, Founder Securepairs.org

Email: [email protected] |

Mobile: +1 617 817-0198
Twitter: @paulfroberts | @securepairs

US PIRG

Nathan Proctor

Campaign Director Right to Repair

Email: [email protected]

Mobile: +1 203 522-3860

Twitter: @nproctor

 

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Mobile Banking Malware Up 50% in First Half of 2019
Kelly Sheridan, Staff Editor, Dark Reading,  1/17/2020
Exploits Released for As-Yet Unpatched Critical Citrix Flaw
Jai Vijayan, Contributing Writer,  1/13/2020
Microsoft to Officially End Support for Windows 7, Server 2008
Kelly Sheridan, Staff Editor, Dark Reading,  1/13/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-7227
PUBLISHED: 2020-01-18
Westermo MRD-315 1.7.3 and 1.7.4 devices have an information disclosure vulnerability that allows an authenticated remote attacker to retrieve the source code of different functions of the web application via requests that lack certain mandatory parameters. This affects ifaces-diag.asp, system.asp, ...
CVE-2019-15625
PUBLISHED: 2020-01-18
A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and permissions to the victim's memory processes to extract sensitive information.
CVE-2019-19696
PUBLISHED: 2020-01-18
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishi...
CVE-2019-19697
PUBLISHED: 2020-01-18
An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. An attacker must already have administr...
CVE-2019-20357
PUBLISHED: 2020-01-18
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.