Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Small compared to the risk of under-funding security research as a cost cutting measure knowing that weaken security will allow for these exploits to occur.


Using violent methods (such as intentionally sabotaging a car on a busy freeway with someone in it) to get media attention in order to further a political goal sounds a lot like the definition of terrorism.


Only if your sense of scale has stopped functioning. It is a dangerous journalistic prank that probably does deserve a telling off from traffic cops, to much the same level as someone who is drunk driving. But I think trying to classify it as terrorism is not helpful or particularly sane.


Seeing as how drunk driving kills a very large number of people every year and is now punishable by imprisonment and extremely steep fines, you might be onto something here.


If people were screwing with cars like this as often as drunks were driving, I think you would end up with mortality figures that were at least in the same ballpark.


At what scale would you consider it to be terrorism?


To my mind, it would have to be some form of an attack, if untargeted, at least hundreds of cars, and if small would have to be targeted and strongly political, dangerous stupidity in a single instance for the purposes of having a good press story, doesn't qualify as either causing terror, or having an intent to, notwithstanding the broad legal definition that has been adopted over the past 15 years.


OK, just making sure I follow: They should exploit security holes and put people at risk to ensure that security research is not underfunded, which could lead to someone exploiting security holes, which would put people at risk.


Your argument would make sense if all exploits were equal. Think of it more like infecting people with weakened/dead forms of potentially deadly diseases so they will be better protected against that disease. The weakened form, while it may not be risk free, is not equal to the harm of a full own infection.


> Think of it more like infecting people with weakened/dead forms of potentially deadly diseases so they will be better protected against that disease.

If these guys want to be regarded as researchers, they need to act like them and be accountable like them. No ethics committee would ever approve a test like this.


The IRB as it currently stands it too strict with its regulations. Also, why should the researchers be regulated when the ones producing the things that are initially putting people into danger are not regulated (or are regulated by bureaucrats who couldn't tell you the difference between a buffer overflow and a SQL injection).


> The IRB as it currently stands it too strict with its regulations.

WTF are you talking about? There is no the IRB.


>The IRBs as they currently stand are too strict with their regulations.

Better?


So they should get away with it to ensure that their funding isn't cut? I'm intrigued what you'd consider a "big enough" risk that they should face punitive measures.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: