{"id":15224,"date":"2019-04-30T10:45:02","date_gmt":"2019-04-30T18:45:02","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/04\/30\/news-8973\/"},"modified":"2019-04-30T10:45:02","modified_gmt":"2019-04-30T18:45:02","slug":"news-8973","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/04\/30\/news-8973\/","title":{"rendered":"Security Experts Unite Over the Right to Repair"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5cc7691e8e3893122fe422bc\/master\/pass\/Electronics-1074358684.jpg\"\/><\/p>\n<p><strong>Credit to Author: Louise Matsakis| Date: Tue, 30 Apr 2019 13:51:14 +0000<\/strong><\/p>\n<p><span class=\"lede\">Two years ago, <\/span>as Nebraska was considering a \u201c<a href=\"https:\/\/www.wired.com\/2017\/03\/right-to-repair-laws\/\">right to repair<\/a>\u201d bill designed to make it easier for consumers to fix their own gadgets, an Apple lobbyist made a frightening prediction. If the state passed the legislation, it would turn into a <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/pgxgpg\/apple-tells-lawmaker-that-right-to-repair-iphones-will-turn-nebraska-into-a-mecca-for-hackers\" target=\"_blank\">haven for hackers<\/a>, Steve Kester told then-state senator Lydia Brasch. He argued the law would inadvertently give bad actors the opportunity to break into devices like smartphones. The bill was later <a href=\"https:\/\/www.theguardian.com\/us-news\/2017\/mar\/11\/nebraska-farmers-right-to-repair-bill-stalls-apple\" target=\"_blank\">shelved<\/a>, in part because of industry pressure.<\/p>\n<p>Now, with right-to-repair legislation gaining traction across the country, a new nonprofit advocacy group called Securepairs.org wants to push back against that kind of messaging, arguing instead that devices can be both easy to fix <em>and<\/em> secure. Democratic presidential candidate Elizabeth Warren recently <a href=\"https:\/\/medium.com\/@teamwarren\/leveling-the-playing-field-for-americas-family-farmers-823d1994f067\" target=\"_blank\">proposed<\/a> a national <a href=\"https:\/\/www.wired.com\/story\/right-to-repair-elizabeth-warren-farmers\/\">right-to-repair law<\/a>, and the Federal Trade Commission is holding a <a href=\"https:\/\/www.ftc.gov\/news-events\/events-calendar\/nixing-fix-workshop-repair-restrictions\" target=\"_blank\">hearing<\/a> on the issue in July. More than a dozen states are also considering right-to-repair bills, including Apple\u2019s home state of California, which will hold a hearing on its version today.<\/p>\n<p>They plan to arrange for expert witnesses to testify at legislative hearings across the country.<\/p>\n<p class=\"paywall\">Repair advocates say manufacturers have increasingly used restrictive warranties, digital locks, and more to make it hard, or in some cases even impossible, for consumers to fix everything from iPhones to <a href=\"https:\/\/www.wired.com\/story\/john-deere-farmers-right-to-repair\/\">John Deere tractors<\/a>. To fix the problem, right-to-repair bills often mandate companies release manuals and diagnostic software, as well as sell replacement parts and repair tools to the public so device owners and third-party technicians can find problems and do repairs more easily. The laws are designed to foster competition in the repair industry, as well as benefit the environment, since people may simply buy a new device if they can\u2019t get it fixed.<\/p>\n<p class=\"paywall\">Securepairs.org, founded by technology journalist Paul Roberts, has attracted the support of more than 20 security experts, including <a href=\"https:\/\/www.wired.com\/author\/bruce-schneier\/\">Harvard University security technologist Bruce Schneier<\/a>, bug bounty expert Katie Moussouris, and ACLU technologist Jon Callas. They plan to arrange for expert witnesses to testify at legislative hearings across the country in an effort to convince lawmakers that the right to repair is inherently safe.<\/p>\n<p class=\"paywall\">Roberts created Securepairs.org after he noticed industry groups drumming up fear about the potential security \u201crisks\u201d associated with the right to repair. Last year, a newly formed lobbying group called the Security Innovation Center began placing op-eds in local newspapers like the Minnesota <em><a href=\"https:\/\/www.sctimes.com\/story\/opinion\/2019\/04\/22\/keep-repair-secure\/3502493002\/\" target=\"_blank\">St. Cloud Times<\/a><\/em> and the Illinois <a href=\"https:\/\/www.sj-r.com\/opinion\/20180419\/guest-view-new-bill-would-set-dangerous-precedent-for-cybersecurity-in-illinois\" target=\"_blank\"><em>State Journal-Register<\/em><\/a> advocating against right-to-repair bills in those states. The articles often argued, without much evidence, that the proposed laws would allow hackers to steal people\u2019s personal information and sow chaos.<\/p>\n<p class=\"paywall\">\u201cAt first it was kind of ridiculous, but then we started realizing that, no, they\u2019re really scaring people,\u201d says Nathan Proctor, the director of the right-to-repair campaign at US PIRG, a liberal advocacy organization.<\/p>\n<p class=\"paywall\">In a statement, Josh Zecher, executive director of the Security Innovation Center, said, \u201cWe welcome any group that is focused on ensuring that consumers have access to safe and secure repair.\u201d But he also argued that current right-to-repair legislation offers \u201csignificant opportunities for hackers to steal personal information, putting consumers at risk of losing money, privacy, and safety.\u201d Zecher didn\u2019t answer a question about who funds the group, but Security Innovation Center lists a number of organizations that represent the technology industry <a href=\"https:\/\/securityinnovationcenter.com\/about-the-security-innovation-center\/\" target=\"_blank\">on its website<\/a> as partners.<\/p>\n<p class=\"paywall\">Securepairs.org <a href=\"https:\/\/securepairs.org\/statement-of-principles\/#obscurity\" target=\"_blank\">believes<\/a> instead in the notion that there\u2019s no such thing as security through obscurity; a robust system will still be secure even if people know how it works. Releasing repair manuals and spare parts shouldn\u2019t undermine an already sound smartphone. The group even takes the idea one step further, arguing that right-to-repair laws would make devices <em>more<\/em> safe by allowing consumers to quickly replace failing parts or update buggy software. For example, John Deere tractors often can be updated only by licensed technicians. Farmers who can&#x27;t afford to wait have resorted to <a href=\"https:\/\/www.wired.com\/story\/john-deere-farmers-right-to-repair\/\">hacking into their tractors<\/a> with <a href=\"https:\/\/motherboard.vice.com\/en_us\/article\/xykkkd\/why-american-farmers-are-hacking-their-tractors-with-ukrainian-firmware\" target=\"_blank\">black-market firmware<\/a>, a far less safe option than, say, using diagnostic tools John Deere could release itself.<\/p>\n<p class=\"paywall\">Roberts and his organization are up against an industry with deep pockets, and it\u2019s hard to know how well they will succeed in persuading lawmakers to enact right-to-repair initiatives. So far, only one repair law, targeting the auto industry, has passed in the US, in Roberts\u2019 home state of Massachusetts in 2012. But the bill had an outsize impact: After it was put in place, major car manufacturers <a href=\"https:\/\/www.nytimes.com\/2014\/02\/02\/automobiles\/carmakers-to-share-repair-data.html\" target=\"_blank\">agreed to share repair information<\/a> with independent mechanics across the entire country.<\/p>\n<p class=\"paywall\">The hope now is that Securepairs.org could help bring similar legislation to other places, starting with California. It&#x27;s an enormous state and the home of many of America&#x27;s largest technology companies. This is the second time California has tried introducing a right-to-repair bill; a previous effort failed last year. A representative from the Security Innovation Center is set to testify at the hearing, but so are experts who believe the right to repair won\u2019t pose any security risks to be worried about.<\/p>\n<p class=\"related-cne-video-component__dek\">Nathan Seidle\u2019s wife gave him this already locked safe as a gift with no combination. Weird present, but he loves a good challenge. So he built a safecracking robot.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/right-to-repair-security-experts-california\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/5cc7691e8e3893122fe422bc\/master\/pass\/Electronics-1074358684.jpg\"\/><\/p>\n<p><strong>Credit to Author: Louise Matsakis| Date: Tue, 30 Apr 2019 13:51:14 +0000<\/strong><\/p>\n<p>Securepairs.org is pushing back against a tech industry that wants independent repair legislation to be scary.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21357],"class_list":["post-15224","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-security-news"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15224","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=15224"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15224\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=15224"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=15224"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=15224"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}