4 ms·
EDIT: As kbenson points out below, it's not just red teams but people wanting to tinker with their own equipment: Get data out of a proprietary app, install a 3
by hackuser 10y ago
EDIT: As kbenson points out below, it's not just red teams but people wanting to tinker with their own equipment: Get data out of a proprietary app, install a 3rd party OS, unlock their phone, etc. That seems like a very difficult problem.
> It's hard to imagine a scheme under which exploits could be regulated in the US that wouldn't set precedents for whether code was protected speech
Yeah, I was thinking about that too ... and fully support freedom-to-tinker, etc. ...
First, no right is absolute. We can't slander people despite free speech rights, or commit human sacrifice despite freedom of religion, or own a fully automatic machine gun despite a right to bear arms (in the U.S.).
We'd want to create exceptions for research, etc (see below) but I don't think the line is prohibitively hard to draw. The big problem I see is open source security bug reporting: There should be a way to openly notify the vendor and public without releasing the exploit into the wild, but it is a little tricky.
> exploits are more widely used in industry (for testing and red-teaming) than they are by governments
Good point, but I don't think that's a big challenge. Exceptions could be made as they are for other 'munitions' and other illegal products (e.g., drugs used for research).
- tptacek 10y agoI'm not saying it's impossible to generate an intellectually coherent set of regulations for exploits, just that the process of doing so is going to damage the 1A protections of a lot of other things over the long run. Is it worth it? I don't think so. Unless you also regulate research, which is a non-starter, you're just driving exploit development out of the US. Substantial amounts of exploit dev are already done by foreign nationals. If virtually all of it leaves the country, what public policy problem have you solved?
- hackuser 10y ago> If virtually all of it leaves the country, what public policy problem have you solved? A good point. A couple ideas, though neither is sufficient: * International agreements control distribution of other dangerous goods; that's doable. However, look at how well that works with drugs, and even nukes get around. * At least stop sophisticated organizations (defense contractors, SV firms, etc.) from making them for foreign governments. Their skills are harder, though not impossible, to replace. Perhaps ban the sale of exploits - taking away the profit motive - but permit distribution for personal, research, etc. purposes.
- tptacek 10y agoI don't think you fully follow. The skills can't be regulated: they're pure research. The US research community will continuing doing the fundamental enabling work relied on by exploit developers; it's just the people who do the testing and integration work who'll have to have their paychecks sent to Southeast Asia. It's a very difficult problem. There's also some bigtime cognitive availability bias happening here. We read lurid stories centering on "zero-day exploits" and say "something must be done". But no matter what these articles say, it seems cosmically unlikely that an exploit dealer is worth a billion dollars; the entire exploit trade is a rounding error compared to the switching and filtering equipment companies knowingly sell China and Iran for use in putting dissidents to death.
- briandear 10y agoUnder that logic tape recorders should be regulated because they could be sold to people who would record your conversations illegally, then used to create a fake conversation using your own words in order to achieve some illegal end. Treating spyware as a munition is a dangerously slippery slope. And slander is not a criminal offense but a civil one -- one has to prove actual damages to win a slander suit (at least in the US.) So spyware could fall under the slander concept where the victims could sure based on actual damages incurred. So one would need to prove that a piece of spyware caused them actual damages. Then you get into some other interesting unintended consequences: could a browser extension or even a cookie be construed as being spyware? They kind of are -- except (generally) you consent to those things. However were would the line be drawn? Could a company like Mixpanel find themselves inadvertently having their product being considered a munition? I take to to a slightly absurd extreme to illustrate how good intentions can have ridiculous consequences. Governments don't have the best track record when it comes to anticipating unintended consequences.