3 ms·
There are three sides to the "making us less secure" argument. 1. If they would work with companies to get the vulnerabilities fixed, we would be more secure.
by explorigin 10y ago
There are three sides to the "making us less secure" argument.
1. If they would work with companies to get the vulnerabilities fixed, we would be more secure. The lack of action in this area doesn't make us less secure. It merely delays increasing security. Not the same thing so this argument is not logically sound. (It's like the RIAA saying that downloaded albums is directly lost revenue while there's no guarantee that the pirate would buy instead of download.)
2. Having a large cache of exploits that they cannot successfully secure creates a target for bad actors. If this cache is compromised then we all are actually less secure.
3. Other efforts by the NSA such as compromising RNGs and security protocols do actually make us all less secure.
- ryao 10y ago#1 is a false equivalence. There really is no more secure here. The system is either secure or insecure. If it is insecure, then the only questions are how bad is it and how it could be made less insecure? If something is secure (e.g. seL4), then there is no room for improvement. #2 is nonsense because the system is already insecure. #3 is a straw man because we are talking about the NSA not contributing the results of their security research to the world. The other things that they do that actually making things less secure are not the subject here.
- explorigin 10y ago#1 "the system is either secure or insecure" - only according to the particular system's threat model. Your counter-argument falls flat because it assumes all computers share one universal threat-model. "more secure" refers to probabilities built into a particular threat-model. If you're going to make security a binary thing, then without absolute knowledge of the entire system...it is insecure and we're wasting our digital ink. #2 depends on #1 #3 if the subject is "things the NSA does do to make us less secure" then it is the subject.
- ryao 10y agoSecurity like temperature. It has an absolute limit. We are really only talking about how insecure a system is. That becomes obvious when reading about things like seL4.
- Jweb_Guru 10y agoWhile I agree with you in principal and am sympathetic to your position, it is not the case that security is "absolute" without taking threat model into account. As a specific example, SeL4 does not take timing channel vulnerabilities into account.
- ryao 10y agoIf you are doing formal verification, then you can make your own model, create software and attempt to prove that the software has issues within that model. seL4 is just one example of someone doing that.
- Jweb_Guru 10y agoUh, I know. My point is that you won't always know all the security vectors you have to deal with. There's no way of just asserting that your model is free of side-channel attacks without (minimally) intimate knowledge of the hardware it's going to run on.