13 ms·
This may seem weird, but I think the idea of what they're doing is spot on. If anyone were to get access to my things I'd rather it be the government and then h
by NZiozis 8y ago
This may seem weird, but I think the idea of what they're doing is spot on. If anyone were to get access to my things I'd rather it be the government and then have them disclose it to me. Additionally, if you don't want your information accessible you've had your notice to hire someone to lock it down or lock it down yourself. I would liken the service to the government checking the insulation on your house.
- azinman2 8y agoAs long as you trust your gov.... I think Japan is probably in better relations with its citizens than most countries...
- icebraining 8y agoWell, if you keep insecure stuff available to the world, you're trusting everyone with it, including every government.
- crankylinuxuser 8y agoPrecisely. It depends on what kind of actions they wish to do with the resulting scan/hack. If they offer services to secure people/companies free or cheaply, then its a overall large positive. If they give it to their equivalent NSA apparatus, that's a major bad.
- bg24 8y agoAgree. Skillset and response will determine the success. Japan govt has a good precedence of centralized security scanning for country’s Internet, so hopefully it is a positive. Vast majority of Internet users are not security savvy. Doing a baseline scan with appropriate remediation guidance will go a long way.
- eeZah7Ux 8y agoGiven that they are announcing it instead of doing it secretly they seem to be starting with the right foot... I'm pretty sure security researchers will set up honeypots and monitor what the government probes are doing.
- dhimes 8y agoThey are admitting they are going to do it. They didn't have to tell anybody.
- orblivion 8y agoArguably, if you don't trust the government, you wouldn't rely on them giving you a warning in the first place.
- sosborn 8y agoThe person you say "yes" to now isn't the same person you will say "yes" to in 10 years.
- ardy42 8y ago> As long as you trust your gov.... I think Japan is probably in better relations with its citizens than most countries... I'd trust any democratic government doing a preventative security scan for vulnerable devices, over some hacker who's only out to exploit them for personal gain. Most people have never patched their router nor even know how to. Someone needs to proactively inform that group that they're vulnerable, at scale, if we're even going to have a chance to solve a lot of network problems.
- johnisgood 8y agoWhy do we have to choose? Personally I don't trust either.
- gtirloni 8y agoIf you're competent enough to manage your digital security, you're fine (99% of the population isn't). If you're not, you're endangering the society you live in (by providing attackers with a device they can use). That's one way of looking at it.
- Thorrez 8y agoYou can't nicely ask the hacker not to do it. The hackers are constantly scanning the internet regardless of what you want.
- johnisgood 8y agoSame goes for most Governments though.
- hanniabu 8y agoInvalid logic. If you don't trust the government then you probably assume they're already accessing your information.
- Johnny555 8y agoYou don't need to trust the government - just secure your devices and they won't be able to get in. It's not like they are requiring that you supply them passwords - they are hacking into your devices the same way anyone else in the world can.
- dontbenebby 8y agoYou can trust the government's intentions while still being wary of the unintended consequences of a policy.
- AngryData 8y agoId trust them more than my own government just by them admitting that they are doing it. The US government for example would never admit to hacking random people's shit, but we know they can and that they do and they have been exposed doing even more shady shit without oversight and with zero public reports about it. Instead we get PR campaigns to try and cover up the shit that got leaked.
- ekianjo 8y agoMost countries? How is that a good benchmark when most countries are dictatures? Compare with the best, if anything.
- TheAceOfHearts 8y agoBased on what I've heard from some natives I befriended online, there is allegedly rampant corruption, many people don't really trust the government, and there's a big problem with organize crime (the Yakuza). I'll note that I'm not Japanese and I've never lived in Japan, so I am unable to ascertain the veracity of this claim, thus I would suggest taking this statement with a gigantic grain of salt.
- dontbenebby 8y ago>This may seem weird, but I think the idea of what they're doing is spot on. If anyone were to get access to my things I'd rather it be the government I feel very differently, especially if it's a government whose "expert" minister doesn't know what a USB drive is: https://www.theguardian.com/world/2018/nov/15/japan-cyber-security-ministernever-used-computer-yoshitaka-sakurada https://www.theguardian.com/world/2018/nov/15/japan-cyber-se...
- Gpetrium 8y agoAlthough I agree with the base of your point, I think it is worth noting that there are likely plenty of folks underneath him with the knowledge to sway policies and implement them. In other words, a department can still be functional and even successful if their boss listens and applies the ideas offered.
- dontbenebby 8y ago>Although I agree with the base of your point, I think it is worth noting that there are likely plenty of folks underneath him with the knowledge to sway policies and implement them. True, and while I understand that high level officials do not necessarily need to be able to write code or explain the difference between public and private key crypto, they should have a base level of understanding to make decisions on the materials prepared by their employees. I don't think someone who isn't familiar with the concept of a USB drive is at that base level of understanding.
- flattone 8y agoRecently saw a pentester post stating that entry occurred when she asked a person to print something from usb which required showing the employee how to identify the usb once plugged in etc. (Baseline may be terrifying)
- zepearl 8y agoI agree - nobody needs to be a crack in any area, but whoever will take decisions needs at least a base understanding of the theme to judge the validity of the foundations on which those recommendations are based upon; anybody could be a manager if blindly following recommendations by subordinates would always end up in the best choice. EDIT: but "Gpetrium"'s statement is actually still correct ("a department can still be functional and even successful if their boss listens and applies the ideas offered") - maybe from this perspective it's more a "must" for a successful manager, but, after the "listening" comes the "judging" and that MUST be based on own know-how.
- ip26 8y agoI'm with you, seems like a core service for improving digital security of a nation. Yeah, people don't trust the government. But most of the conspiracists are convinced the government is already secretly accessing their home devices (or trying to). If that's your belief, then really, nothing has changed!
- sandov 8y ago>If anyone were to get access to my things I'd rather it be the government I feel the complete opposite way. The government having access to my things is worse than cyber-criminals having access to my stuff.
- claudiawerner 8y agoIn the liberal imagination, governments are at least beholden to the people - with criminals you don't even have that much.
- sandov 8y agoThe way I see it: Democratic states are institutions that enslave people in ways that the majority of people living there decided. If you think the same way as the majority then it doesn't feel like enslavement to you. Anyway, the state has complete physical domination over you. Cyber-criminals, on the other hand do not have the power to exercise physical violence over you, they can only harm you in non-violent ways. Practically speaking, you are more likely to be harmed by cyber-criminals than by your country's state, but if tomorrow there's a new law against certain political ideologies (not uncommon in third world countries), or against encryption, or against privacy and they happen to know that you're interested in those things, the consequences could include physical violence.
- mindslight 8y agoI agree with you philosophically with regards to democratic totalitarianism. But it's a moot point when we're talking about devices that are already vulnerable. The government is in the same position as any other Internet background radiation - if you want to keep them out, then just secure your shit. There is a philosophical point to be made about one's right to willfully violate what are considered best practices (eg toad.com), but we're not debating penalties for running "insecure" devices. The sheer majority of vulnerabilities they find are going to be due to straight cluelessness.
- porpoisely 8y agoIt's incredible that this is the top comment in this thread. When did blind trust in government become the norm on "hacker" news?
- chrinic83 8y ago> When did blind trust in government become the norm on "hacker" news? I trust my government more than Facebook or Huawei. Open source or neutral 3rd parties don't exist for this kind of thing.
- noir_lord 8y agoSome trust is not blind trust and there are areas where I do trust government. It’s why I don’t worry the medication I take is not genuine, why the water that comes out the tap is safe to drink and why if I get run over I’ll get medical treatment. It’s why I can walk down the street without unduly fearing I’ll get robbed etc. Blind distrust is as silly as blind trust is what I’m saying here. The government taking cyber security seriously is a good thing if you trust that government and the Japanese government is pretty good in that specific area. Also given that Japan is a regional and major economic competitor to China which along with Russia and the other major powers is currently waging and undeclared series of wars in the global networks it seems like a pretty smart move to me,
- porpoisely 8y agoJapanese government is pretty good in what specific area? "Japan's cyber-security minister has 'never used a computer'" https://news.ycombinator.com/item?id=18459016 https://news.ycombinator.com/item?id=18459016 As for medicine, water and medical treatment... Your government makes the medicine, your government runs the water company and your government runs your hospitals? Seems like a recipe for disaster. Just out of curiosity, what country do you live in? Yes. Japan is a regional and major economic competitor to china, russia and korea and the US. But what's your point? They are also a major trading partner to all those countries. Sure, blind mistrust is bad as blind trust. But there are plenty of reasons for people to distrust governments. It's why we have rights to protect ourselves from the government. And the last government I'd trust is the japanese government if I were the japanese people considering how they were so willing to throw their citizens lives away on kamikaze missions and endure endless firebombings and nukes.
- etnos 8y agoExactly, I'm more annoyed about private institutions owning every single piece of my personal data (I'm looking at you google!) than an actual public institution At least with government you have public representation
- johnisgood 8y ago> Additionally, if you don't want your information accessible you've had your notice to hire someone to lock it down or lock it down yourself. What do you mean? Is it not the case that in some countries encryption, let alone hiding anything from the government is illegal?
- MrZongle2 8y ago"If anyone were to get access to my things I'd rather it be the government and then have them disclose it to me." In the United States, I'm inclined to think that the former has already taken place and the latter will only happen after an extensive FOIA battle and enough years to make disclosure useless to the average citizen.
- w00kie 8y agoI live in Japan. The main issues I see with this is, rather than just "I don't trust the government": 1. They'll do a scan of all devices then ask the ISPs to provide customer information for the vulnerable IPs found so that the government can contact them. So now you'll end up with a big fat list somewhere with names and addresses next to known vulnerability and that list is bound to leak sooner than later. See "My Number" (Japanese equivalent of social security numbers) leaks recently. 2. This makes for great phishing. All newspapers and TV channels have said you might receive notice from the government about security. Now you just have to send emails or letter claiming to be the government, saying "we have found your network to be vulnerable, please run this program to clean it up" and it's way more likely people will run your malware. FREE Advertisement provided by public funds!
- NZiozis 8y agoI really don't have a rebuttal to your first point. The way people handle PII will always be an issue. My frame of mind comes from the fact that I'd rather some public entity privy to it than a private one like someone lower mentioning Google or Facebook. The second point seems more like a problem with tech literacy than this program. There should be some way to differentiate a government email from a regular one. That and people should understand how to confirm it. Now I get it, I've had family members believe they have a virus because a pop up told them they did, but sitting down with them for 5 mins and telling them not to stopped that. I'm curious, lower someone mentioned the idea that the government was already taking this kind of action. How do you respond to that?