4 ms·
Dave's article's certainly worth reading, and he makes some good points. He's certainly closer to the intelligence agency and vulnerability market side of thin
by jdp23 10y ago
Dave's article's certainly worth reading, and he makes some good points. He's certainly closer to the intelligence agency and vulnerability market side of things than EFF is; but that's not the only aspect of the issue.
And as others have pointed out, closeness isn't always an advantage. Dave criticized the EFF post by saying
"This is a fundamental misstatement of how 0days work in the real world—in reality, the vulnerabilities used by the US government are almost never discovered or used by anyone else—and these falsehoods further confuse the conversation about 0day policy solutions."
Except of course that as the Shadow Brokers leak showed, quite a few of these vulnerabilities _have_ been discovered (and for all we know, used). The risk of something like this happens is something that EFF et al. always bring up, and the intelligence agencies and their supporters always dismiss it ... where's the "falsehood"?
- tptacek 10y agoThe point you're making is orthogonal to the point Aitel is. Aitel is saying that on a day-to-day operational basis, Russia and China are usually using a different set of vulnerabilities than the USG is. So, putting Russian discoveries of USG tradecraft aside, the point he's making is very simple: is the USG is obligated to disclose its bugs, and meanwhile Russia is clearly not and never will be, then Russia has an advantage: it's bugs are safe, but its adversary has to churn through new ones. That's all I think he's saying.
- krupan 10y agoAnd the EFF's point is, that sounds nice, but how do we know the US is using different vulns than Russia and China? Especially when the US is sourcing those vulns from third parties?
- tptacek 10y agoIf I had to choose who to believe, some rando at EFF or Dave Aitel, I believe Dave Aitel.
- jdp23 10y agoNo, this is where he's talking about how "The phenomenon of adding more noise than signal is now practically characteristic of misguided policy proposals in this area". Specifically, he's using the EFF's statement "The problem is that if a vulnerability has been discovered, it is likely that other actors will also find out about it" as an example -- describing it as a "fundamental misstatement" because "the vulnerabilities used by the US government are almost never discovered or used by anyone else". And then just ten days after his article, we've just seen a bunch of vulnerabilities not only discovered by somebody else but actually released on the web.