3 ms·
> Does everyone here actually believe that the NSA shouldn't hoard vulnerabilities? Nope! We know it's more complicated than that. But we think the NSA strikes
by JackC 9y ago
> Does everyone here actually believe that the NSA shouldn't hoard vulnerabilities?
Nope! We know it's more complicated than that. But we think the NSA strikes the wrong balance between offense and defense. If you want to understand where people are coming from a little more you could start with some of Bruce Schneier's articles:
https://www.schneier.com/blog/archives/2016/08/the_nsa_is_hoar.html https://www.schneier.com/blog/archives/2016/08/the_nsa_is_ho...
https://www.schneier.com/blog/archives/2017/06/wannacry_and_vu.html https://www.schneier.com/blog/archives/2017/06/wannacry_and_...
... where, for example, Schneier proposes that NSA should keep vulnerabilities for no more than six months, based on how far ahead of adversaries it doesn't appear to be.
The general point Schneier tends to make is: we are a huge fat defensive target with limited offensive targets. Vulnerabilities hurt you in proportion to how much infrastructure you run; we run a lot. Sitting on a vuln so you can use it a dozen times, while powering your society with billions of machines that have the same vuln, is a bad tradeoff.