The amendments to the Investigatory Powers Bill, allegedly intended to make people safer, will undoubtedly make UK digital infrastructure a tempting target as the regulations will be weaken security there. The biggest problem for Apple, other than the steady erosion of encryption, is that essential security and privacy updates might be delayed or never appear — and without any transparency or scrutiny at all.

If passed, the law would mean that every tech security update must be reviewed by UK authorities before release, which will immediately delay distribution of vital security patches.

Hackers will immediately see this means any patched vulnerabilities will be secured in the UK last, making the nation an incredibly attractive target to attack. Hackers are organized enough to spot and exploit weakness. It’s what they do.

And if the UK rejects an update, that update cannot be released in any other nation and the public would not be informed of the decision.

You are viewing a single thread.
View all comments View context
0 points

Police knocking on your door stop you. This is clearly an attempt to protect their own backdoors from being patched so they can continue eavesdropping

permalink
report
parent
reply
0 points

First - if I’m not from the UK, thats very unlikely. At least because the UK wants it to happen and not for other reasons.

Second - the moment the information is out, it’s too late. Their zero day is burned.

Third - the police needs to know where to knock. If I publish the information in a way that can be associated with my identity and I’m the one that alerted the vendor, sure. But even if I’m a completely random person that immediately goes full disclosure - doing so may in a way that identifies me might hurt me anyways, depending on my jurisdiction. So for individuals it might be the smarter play to make it less traceable.

Fourth - imagine Google’s Project Zero or another “huge player” finds the Bug and alerts the vendor. Google e.g. has a policy to fully disclose the bug, if there’s no fix within a specified time-frame. This might be extended for reasons, but only of there’s a good reason. If the vendor cannot say why they don’t patch, well that’s none of these reasons.

permalink
report
parent
reply

Europe

!europe@feddit.de

Create post

News/Interesting Stories/Beautiful Pictures from Europe 🇪🇺

(Current banner: Thunder mountain, Germany, 🇩🇪 ) Feel free to post submissions for banner pictures

Rules

(This list is obviously incomplete, but it will get expanded when necessary)

  1. Be nice to each other (e.g. No direct insults against each other);
  2. No racism, antisemitism, dehumanisation of minorities or glorification of National Socialism allowed;
  3. No posts linking to mis-information funded by foreign states or billionaires.

Also check out !yurop@lemm.ee

Community stats

  • 1

    Monthly active users

  • 2K

    Posts

  • 10K

    Comments

Community moderators