Topic > Siemens Safety Violations - 607

From 2009 to present, Toyota has issued recalls of many vehicles for various reasons [1]. Many will remember the largest vehicle recall to date, with Toyota recalling millions of vehicles due to a problem with the car's brakes. The recall cost more than $2 billion [2], but we can deduce that they responded quickly and handled the incident responsibly. Most defective products usually have guidelines [3] that allow vendors to do what's right, but what about software? Most readers of this article will be involved with security in some way, it is a security driven website after all. To you, the reader, where did we go wrong when we learned to "make do" with whatever supplier they choose to give us? After seeing the ongoing Siemens fiasco [4], I have to wonder at what point would a government body start issuing fines against companies that fail to meet their obligations. "Obligation: 2. a. A social, legal, or moral requirement, such as a duty, contract, or promise that obliges one to follow or avoid a particular course of action." [5] Certainly it is the government that holds enough “weight” to hold companies accountable, however, the government appears to be oblivious to safety at this level. Now Siemens is no stranger to security flaws, remember it was Stuxnet that targeted and exploited Siemens' software two years ago. Even now - two years after Stuxnet - many in the SCADA arena are fully aware that Siemens has still fallen behind in solving all the problems associated with Stuxnet. Imagine that two years ago, security professionals discovered Stuxnet and concluded that Siemens' software had huge holes. Two years later, they still haven't repaired those initial holes. Now, we're listening and reading...half of an article...in the researchers, I see little that condemns marketers who are putting their marketing teams' lives on the line. Works Cited[1] http ://en.wikipedia.org/wiki/2009%E2%80%932011_Toyota_vehicle_recalls[2] http://news.bbc.co.uk/2/hi/business/8493414.stm[3 ] http://www.cpsc.gov/businfo/8002.html[4] http://www.bloomberg.com/news/2011-05-25/siemens-tweaks-industry-software-after-us-cautions - on-hacking.html[5] http://www.thefreedictionary.com/obligation[6] http://en.wikipedia.org/wiki/Stuxnet[7] http://seclists.org/bugtraq/2011 /Mar/231[8] http://www.cbsnews.com/8301-504083_162-20065621-504083.html[9] http://www.msnbc.msn.com/id/35893905/ns/business-autos /t/toyota-recalls-may-cost-automaker-billion/[10] http://www.imdb.com/title /tt0065063/[11] http://news.cnet.com/8301-27080_3-20064112 -245.html[12] http://www.immunitysec.com/products-canvas.shtml