Thursday, October 2, 2014

Current Event Post #3 - Controversy over releasing BadUSB hacker code

The BadUSB hack creates a serious ethical dilemma for us as a society. The question is, what should be done about really powerful hacks like the one that Karsten Nohl found? The first option is to keep them completely secret. This is what Nohl intended to do at first, but it didn't work because somebody else reverse engineered his code. The second option is to make it public as soon as possible; however, this also freely gives the code to those with bad intentions. In the time that a hack is being developed, a lot of damage could be done using this hack. I personally think the best solution is to contact the major manufacturers of USB chips and make sure that they had the code without disclosing it to the world. It would be a long and arduous process of getting the code to all of them, but it would provide the greatest protection to society as a whole.

1 comment:

  1. Your solution sounds very nice, but I personally would not want to try to contact manufacturers directly to tell their about a security flaw. That would require far more work, especially because many of them would likely be rather slow to respond.

    ReplyDelete