4 ms·
Who cares what nation state actor alledgedly moved the exploits from an NSA employee to WikiLeaks? Why would the medium matter in the least, in the case of hoar
by cryptarch 9y ago
Who cares what nation state actor alledgedly moved the exploits from an NSA employee to WikiLeaks? Why would the medium matter in the least, in the case of hoarding 0days?
- TheSpiceIsLife 9y agoI agree with this and want to further add to it. Firstly by saying: isn't it interesting that, if it is Russia who moved the exploits from the NSA employee / contractor to WikiLeaks then they (the Russians) have acted in the service of the global public. But let's not get distracted. The source of all NSA leaks is never some rogue employee, or contractor. It's never "The Russians"™ or "The Chinese"™. The source of NSA leaks is the goddamn NSA.
- sillysaurus3 9y agoWe probably need the NSA. It's their job to exploit computers the same way it's the job of the military to apply force. It's difficult to say that we can do without the NSA any more than we can do without a military. In that light, the context is to reduce the impact of the NSA's necessary goals. Higher up in the thread, it was claimed that one of the most feared branches of the intelligence arm of the most powerful government in the world was so incompetent that they had no idea who was behind these leaks, and that there was evidence to support this assertion. I have an open mind, so I was hoping to see this evidence.
- noir_lord 9y ago> It's their job to exploit computers the same way it's the job of the military to apply force. That's one half of their job, the other half is to secure government infrastructure from exactly the type of attacks they use on other countries. The problem there is that it sets up an incredible tension since how do you get the message out about a 0-day in windows to protect your 'own' side without your opponents getting the same message. I've thought for years that the NSA doing both jobs is silly since one side will inevitably win that argument (as seems to be the case). It needs to be a separate agency concerned purely with securing government and infrastructure from external threats with a decent firewall between the two sides (and possibly an oversight clearing committee to keep an eye on what both sides are up to). Over here in the UK we have largely the same problem with GCHQ having a dual mandate.
- JumpCrisscross 9y ago> how do you get the message out about a 0-day in windows American companies get disclosures, foreign companies do not.
- hiram112 9y agoWhat's an 'American' company these days? US companies like Oracle, MS, Google, etc. have offices all over the world. They also tend to use various visas to import 10% of their own US based staff (probably a much higher ratio of engineers) from foreign nations. The US has gotten very wealthy from offshoring, foreign talent, and technical exports, but it causes a massive problem when keeping secrets locally.
- cryptarch 9y ago> how do you get the message out about a 0-day in windows Force-push a Windows 10 update? That seems like one of the few legitimate usecases of Win10 being a corporate botnet.
- tastythrowaway2 9y agoI think the obvious answer here is to go full open-source on the infrastructure. if they can afford to pay engineers to craft exploits, the can afford to pay engineers to fix them.