3 ms·
If they know of a vulnerability, not announcing it is simply hoping (or worse presuming) that others haven't found it. Not all vulns are found by people who ma
by anexprogrammer 10y ago
If they know of a vulnerability, not announcing it is simply hoping (or worse presuming) that others haven't found it. Not all vulns are found by people who make a nice blog post, claim their $2k, and move on - some will be keeping very quiet and actively exploiting for poltical or financial reasons.
Even with the most positive view, some small subset of those vulnerabilities will be known to others and some will be actively exploited. Hence making us less secure.
- ryao 10y agoSecurity of a system is an intrinsic property that does not change upon scrutiny. Rather than accuse those not reporting the results of their researchers we should focus on building systems that are secure like seL4. This blame game is counterproductive and distracts from making secure systems.
- anexprogrammer 10y agoI'm not suggesting accusation of researchers, but in the case of NSA isn't part of their mission improving network security? They founded SELinux after all. It's not like vulnerabilities are rare or aren't going to be exploited if not revealed.
- ryao 10y agoI do not think that it is feasible to expect a government agency to solve bad engineering. There is no pixie dust that the NSA can sprinkle on systems to make them secure, even if it dedicated all of its resources to trying. If anything, by doing what they are doing, they are exposing the fallacy of such expectations and hastening the development of systems that are actually secure. By that measure, this is actually improving security in the long term far more than attempting to bolster the status quo ever could.