4 ms·
Liability. If the NSA was actually forced to be liable for the damage of their hoarded 0-day's should they leak, that might have a bigger effect than any 'guid
by windlep 9y ago
Liability.
If the NSA was actually forced to be liable for the damage of their hoarded 0-day's should they leak, that might have a bigger effect than any 'guidance' I would imagine politicians might pass in a law. I hate to suggest something that involves yet more lawyers, but its amazing how effective that can be to make people in charge do some serious risk-assessment analysis about what they hoard and for how long.
- JumpCrisscross 9y agoWondering if someone will reciprocate JASTA [1] against the U.S. in respect of these attacks. Given this involves the American government indirectly distributing exploits against an American company, the chain of liability seems tight. [1] https://www.congress.gov/bill/114th-congress/senate-bill/2040 https://www.congress.gov/bill/114th-congress/senate-bill/204...
- tuxxy 9y agoHow would this work for a private individual? Would this help create a precedent for private security researchers where they might be held liable for not disclosing 0days? I agree that this would definitely curb potential damage, but I'm not sure if this is exactly the right way to go about it. NSA is first and foremost an intelligence agency. What do you think the best policy is for maintaining an effective arsenal and maintaining "0day responsibility"?
- setq 9y agoThere isn't one. Report the vulnerabilities to the vendor and move on. The trade off is too dangerous. Do you stockpile munitions that can damage global infrastructure so you can target a small number of individuals? No that's just stupid and irresponsible.
- mcintyre1994 9y agoIs there any legitimate reason to hold 0 days without disclosing them to the vendor? There probably are reasons I haven't thought of, but do they apply to as active a company as Microsoft? Edit: I think I misread this and you're asking in the context of the NSA holding them. I still doubt there's a way to do it responsibly, so they probably shouldn't be doing it.
- downandout 9y agoSure there is a legitimate reason to withhold them, though many would say it's not a very ethical one: money. Private researchers hold them for sale to the NSA and other agencies all the time. Here are a few exchanges (there are also high end "agents" - akin to Hollywood agents - that broker these deals): [1] https://zerodium.com/ https://zerodium.com/ [2] https://www.mitnicksecurity.com/shopping/absolute-zero-day-exploit-exchange https://www.mitnicksecurity.com/shopping/absolute-zero-day-e... And some info on this market: https://en.wikipedia.org/wiki/Market_for_zero-day_exploits https://en.wikipedia.org/wiki/Market_for_zero-day_exploits
- frubar 9y agoEvery possible job doesn't need to exist. We shouldn't put the whole online world at risk so a handful of people can make a buck.
- Asooka 9y agoI would say there is a difference between having a bare-bones proof of concept and a fully developed malware.
- syshum 9y ago>>What do you think the best policy is for maintaining an effective arsenal and maintaining "0day responsibility"? I think the best policy is for them to not maintain an "effective arsenal" at all, the second they find a vulnerability they should report it.
- speedplane 9y agoIt's not a crazy thought to think people may actually sue the government. Under centuries old law, all someone would have to prove to make the government liable is that the government (1) was the cause (2) of damage (3) that was the result of their negligence. The negligent part will be tricky, as the NSA was probably using the best tech available to protect their secrets. Also, proving #1 may be tricky as most of the information you would need to prove it is highly classified.
- jfoutz 9y agoNSA is also responsible for the defense of government computer systems and communications. There may be a duty there, to ensure email from a the government is virus free. If someone can show their worm came from a .gov address, there might be something there. The NSA made the dangerous part of the weapon, and then they lost it. They knew they lost it, and didn't do enough to harden fed computers. The government isn't allowed to just randomly attack someone, but attacked my hypothetical person that can prove the attack vector anyway. Of course, i'm not a lawyer.
- Godel_unicode 9y ago> NSA is also responsible for the defense of government computer systems and communications. Incorrect, with the exception of DOD (and even there it's shared with DISA). > didn't do enough to harden fed computers. Interesting statement considering there have so far been 0 cases of fed computers being exploited. That figure is from US-CERT, the entity actually responsible for defending Federal systems.
- jfoutz 9y ago1) looks like the mission has been adjusted, they simply take the lead in information assurance now. Although, a foreign power seizing control of government computers to make unauthorized transmissions sounds like something a jury would think the NSA should be responsible for. 2) Indeed, my entire argument depends critically on the existence of a .gov propagating the worm.
- logicallee 9y agowhat do you expect them to do - (as long as they exist?) Threaten their employees with torture for leaks? I mean these things are pretty much why the NSA exists, it's kind of its mandate. It's not like their employees don't know they're really, really, really, really not supposed to leak their whole horde of zero days, or protect it to the utmost. these things weren't in a dropbox with the password "password123" or something... what do you expect greater "liability" to do exactly? (Of course this is assuming the agency continues to exists, which you're kind of presupposing when you write "if the NSA were actually forced to be liable") Edit: Don't know why I'm getting downvoted...could you explain what changes to their operating procedured you would expect them to make, if they had greater liability?
- sillysaurus3 9y agoIt's important to remember that the NSA isn't why the world was insecure. The NSA discovered the flaw. That's their job. We need the NSA just like we need a military. As an offensive cyberweapon, this exploit was operationally one of the most effective weapons that the NSA had at its disposal. Most of the world runs unpatched Windows systems, as Stuxnet showed us. This would've been the perfect tool for a similar operation. Unless your stance is that computers should never be used by a state actor to intentionally cause harm, like the military, then you can't logically also hold the position that the NSA should voluntarily neuter its own arsenal. I don't like it either. But the alternatives seem objectively worse.
- godmodus 9y agoThem working with the industry on making your country secure doesnt seem like a bad alternative.
- sillysaurus3 9y agoIran becoming a nuclear superpower seems objectively worse. And it was thanks to cyberweapons that this was delayed.
- godmodus 9y agoSure, lets ignore deplomacy failures and the CIAs misdoings in actually enabling and even partially triggering that pathway and make sure we endanger the whole planets network to get an edge in a war were too proud\patriotic to think differently about. That way of thinking is whats making us need cyber weapons. Not to mention it shapes foriegn policy.
- syshum 9y agoIran becoming nuclear is a direct result of US Intervention in the region. so yes if we did not have a CIA then Iran likely would not be attempting to become Nuclear today CIA is attempting to clean up their mess
- csydas 9y ago
- moonbug22 9y agoAnd how would that liability work, exactly?