6 ms·
Should exploits like this be treated as munitions, with sale to foreign governments restricted? Or any sale at all restricted? Some thoughts: * The only uses f
by hackuser 10y ago
Should exploits like this be treated as munitions, with sale to foreign governments restricted? Or any sale at all restricted? Some thoughts:
* The only uses for the exploits are either illegal or by government security organizations
* I don't think you can just make an explosive and sell it to a foreign government; I think there are strict export controls (though I know very few details, I only read about companies applying, getting approval, etc.).
* In the 1990s, strong encryption was called a 'munition' and export was restricted. That turned out to be impractical (it was available in many countries and the Internet has no borders), morally questionable (restricting private citizen's privacy), and it fell apart.
While I believe in liberty and freedom-to-tinker, as I said, this stuff has no legitimate use.
- AgalmicVentures 10y agoAnd to extend your thought further, should US based VC's be backing this? NSO is backed by San Fransisco based Fransisco Partners [1]. [1] http://www.reuters.com/article/us-nsogroup-m-a-idUSKCN0SR2JF20151103 http://www.reuters.com/article/us-nsogroup-m-a-idUSKCN0SR2JF...
- jacquesm 10y agoWhich foreign governments though? Not all security researchers are from your country (whichever one that may be).
- kbenson 10y agoI had the same thought as hackuser when reading the article, and then it was quickly followed by your point. I think an important first step would be to get certain things classified as arms. Once that's done, normal options may be able to handle them appropriately, such as not allowing the purchase or sale of certain types of arms within or over borders, etc. This would of course open up a whole new can of worms in the US, as we are constitutionally guaranteed the right to bear arms, but that's just makes it hard, not impossible (and could possibly even serve to provide some much needed nuance to that discussion in the US). That said, I haven't put a lot of thought into this, so a well reasoned criticism could completely change my stance.
- tedunangst 10y agoWould it then be illegal for Google Project Zero to publish a blog post about a vulnerability that a vendor refuses to fix?
- kbenson 10y agoI was thinking less of the knowledge being considered an armament, and more that an actual program that takes advantage of it being one. I don't consider the the scientific knowledge required to create a gun as an armament, nor even specific schematics, but governments may view it differently (indeed, they weren't happy about the 3D printable gun). Also, I don't think this concept is limited specifically to exploiting bugs. I think a program that was meant to access and catalog social media accounts for a person while hiding it's accesses as much as possible, but run from a third party's location, might be considered an armament. Same with something designed to DoS a service.If the purpose is to cause harm, it might be an armament. I am aware there's probably a fine line here, and one that would inevitably be abused. I'm not sure how to deal with that, and whether the negatives there outweigh the possible positives overall.
- tedunangst 10y agoSeparating code from knowledge was part of the fun of the decss debacle. "That's not a haiku; that's an illegal perl script!"
- AnthonyMouse 10y agoAnd fundamentally it's the knowledge that matters. Programmers are "expensive" but not that expensive. Give any decent off-the-shelf code monkey the specifics of a vulnerability and he can give you exploit code. Which means restricting the exploit code is quite useless. But restricting the knowledge itself doesn't work because the same knowledge is necessary to mitigate the vulnerability and to test that the mitigation is effective.
- 10y ago
- tptacek 10y agoNo, exploits are more widely used in industry (for testing and red-teaming) than they are by governments, simply because there are more red teams than there are government-sponsored intelligence and police agencies. It's hard to imagine a scheme under which exploits could be regulated in the US that wouldn't set precedents for whether code was protected speech. I think very few people on HN would be comfortable with those precedents.
- smokeyj 10y agoIsn't cryptography a controlled export?
- rdtsc 10y agoYes in some contexts. Most people don't know about it though. I think everyone thinks we won that "war" completely. Even talking to someone like Phil Zimmermann, he was wasn't aware about it. Granted it is more about exporting to "rogue states" and more of a registration requirement. But it is something, companies (especially startups) probably forget to do. And I don't know of anyone personally who got in trouble over it.
- hackuser 10y agoEDIT: As kbenson points out below, it's not just red teams but people wanting to tinker with their own equipment: Get data out of a proprietary app, install a 3rd party OS, unlock their phone, etc. That seems like a very difficult problem. > It's hard to imagine a scheme under which exploits could be regulated in the US that wouldn't set precedents for whether code was protected speech Yeah, I was thinking about that too ... and fully support freedom-to-tinker, etc. ... First, no right is absolute. We can't slander people despite free speech rights, or commit human sacrifice despite freedom of religion, or own a fully automatic machine gun despite a right to bear arms (in the U.S.). We'd want to create exceptions for research, etc (see below) but I don't think the line is prohibitively hard to draw. The big problem I see is open source security bug reporting: There should be a way to openly notify the vendor and public without releasing the exploit into the wild, but it is a little tricky. > exploits are more widely used in industry (for testing and red-teaming) than they are by governments Good point, but I don't think that's a big challenge. Exceptions could be made as they are for other 'munitions' and other illegal products (e.g., drugs used for research).
- digi_owl 10y ago> * In the 1990s, strong encryption was called a 'munition' and export was restricted. That turned out to be impractical (it was available in many countries and the Internet has no borders), morally questionable (restricting private citizen's privacy), and it fell apart. IIRC, thats still on the books. Its just one of those sleeping paragraphs since the PGP release.
- tedunangst 10y agoThe book in question: https://www.bis.doc.gov/index.php/policy-guidance/encryption https://www.bis.doc.gov/index.php/policy-guidance/encryption
- avian 10y agoDebian documents mention that "BXA revised the provisions of the EAR governing cryptographic software" in October 2000. Debian no longer has separate non-us repositories for crypto because of that. https://www.debian.org/legal/cryptoinmain https://www.debian.org/legal/cryptoinmain
- makomk 10y agoOpen source software is now basically exempt from the crypto export restrictions, which is why Debian doesn't need separate non-US repositories for it anymore. As far as I know closed-source software is still restricted.
- jeff_marshall 10y agoOnly "Military or intelligence cryptographic (including key management) systems" are included in the current US munitions list [1]. Everything else is handled by the Department of Commerce as part of the export administration regulations (EAR) [2]. [1]https://www.pmddtc.state.gov/regulations_laws/documents/official_itar/2014/ITAR_Part_121.pdf https://www.pmddtc.state.gov/regulations_laws/documents/offi... [2] https://www.bis.doc.gov/index.php/policy-guidance/encryption https://www.bis.doc.gov/index.php/policy-guidance/encryption
- chetanahuja 10y ago
- givinguflac 10y agoThe only legitimate use of this is a jailbreak tool. Obviously 'this' being the root exploit and not the malware/data capturing portion. I agree malware like that should be treated as munitions.
- briandear 10y agoReally then, a tape recorder should be considered a munition under that logic. Malware shouldn't be considered a munition any more than encryption should have been. Unless the malware actually makes your phone explode, then it's a stretch to call it a munition. Do we really want governments getting into the code review business?