20 ms·
Google’s top security teams unilaterally shut down a counterterrorism operation
- deleted 6y ago[deleted]
- resoluteteeth 6y agoThis article seems to be saying that it's reasonable to expect that google should avoid reporting or fixing security vulnerabilities being actively exploited by the US government, and this isn't something that should make other counties consider Google to be working as an agent for the US government and therefore deserving of being blocked or sanctioned. By the same token should we we also consider it reasonable for companies Huawei to avoid fixing security vulnerabilities being exploited by governments like China and not consider them to be deserving of having importation of their products blocked on this basis? I don't think other countries would necessarily want to use google products if they are intentionally leaving security vulnerabilities open, so maybe it is better that all companies fix all security vulnerabilities they find?
- bayindirh 6y agoIt should be fair and equal. It's either everybody acts on behalf of their country of origin or everybody fixes all problems they find. "Country A can do it, but B can't because A is X and B is Y" is not an acceptable solution IMHO.
- fwn 6y agoNo, I don't think that's practical. Standards like transparency, rule of law and a clear separation between corporations and the government should be uphold completely independent from the fact that this isn't done exactly as rigorous everywhere on the planet. It's a relatively new (and IMO flawed) idea that western democracies should corrupt themselves just because non-democracies exist. I think it's rooted in insecurity over the long term superiority of democratic institutions. This might lead to western democracy being perceived as something you do not because it's strengthening the country but because you want people to enjoy it as a luxury as long as the country can afford it. I think that's wrong and will surely be out of fashion as soon as more prominent autocratic regimes fail to deliver as consistently as they currently do.
- bigbillheck 6y ago> relatively new ... idea The ghost of Henry Stimson would disagree.
- jariel 6y agoIt's not 'corrupt' to spy on other nations and it's not 'corrupt' to facilitate it. It's not rooted in 'insecurity of the belief in a style of government' it's rooted in basic security measures. Western nations spy on other nations as a matter of national security policy much like they invest in early-warning satellites. The 'corruption' stems from the type of authority that drives the activity, their motivations, and what they do with the power.
- nitrogen 6y agoWhen spying on and manipulating other countries takes priority over protecting everyone including yourselves, that is indeed corrupt or twisted or whatever word you want to use. Fixing a software bug or vulnerability is unequivocally good, and the sooner the better, regardless of who thinks they need that bug to make their global manipulations a little easier. The realpolitik BS is just too easy of an excuse for any monstrosity, and the blowback is always worse than the immediate problem.
- jariel 6y agoIt's not 'unequivocal' though - we don't have enough information to say that. You have to know what the vulnerability is, how it's exploited and what the consequences are. While I don't doubt that in reality, erring on the side of closing it is probably the right thing to do, the fact is we don't know. If the vulnerability is being used to thwart a rogue entity from developing nuclear weapons, the balance of facts may be on the other side. At very least, Google should have worked with agencies on getting it closed down. If they were using it to make a drug bust, when then who cares, shut it down.
- chopin 6y ago> If the vulnerability is being used to thwart a rogue entity from developing nuclear weapons, the balance of facts may be on the other side. At very least, Google should have worked with agencies on getting it closed down. The rogue entities on this planet already have nuclear weapons (and no, I am not talking of North Korea). A widely overlooked fact is that the nuclear non-proliferation treaty obliges the nations with nuclear weapons to get rid of them[0]. This part of the treaty has never been uphold. [0] https://en.wikipedia.org/wiki/Treaty_on_the_Non-Proliferation_of_Nuclear_Weapons https://en.wikipedia.org/wiki/Treaty_on_the_Non-Proliferatio...
- geofft 6y agoTo be clear, by "X" you mean "amoral" and "y" you mean "moral"? I think it not only acceptable but incumbent to hold yourself to a higher standard of behavior than the lowest common denominator. "An eye for an eye will make the whole world blind." (There's also a practical reason: China is much more effective at their approach than the US is, being much more experienced at it and also having stifled internal debate about it. If the US gives up its claim of being a morally superior employer than China, why would anyone skilled want to keep working for what will inevitably be the losing team?)
- bayindirh 6y ago> To be clear, by "X" you mean "amoral" and "y" you mean "moral"? It can be anything. It's intentionally X & Y, not X & !X or a more concrete word. Put whatever you fancy. Democratic, White, Sunny, Oreo... I don't take sides or make a suggestion. I do not suggest that we should go to the lowest denominator but, we shall aim for much higher. OTOH, entropy loves lowest common denominator and drives everything down. Lowest prices in cost of quality. Chaos for minimizing energy, etc. We're trying to reverse natural chaos in many areas and it's worth it IMHO, btw. For the same reason there are no country names in my comment. Fill the ones you want. My comment implies nothing. It's the readers' bias which puts USA/Russia/China/Moral/Ethical/Democratic/Totalitarian. I see a lot of polarization in the world and everyone is claiming to be the good guys. We can improve when we accept that we're only guys and work upwards from there.
- geofft 6y agoYour comment is in reply to a comment about China, which is why I referenced China. (But if you wish to say your point is abstract, then my comment also applies equally well in any direction - I don't think China should use the US's misdeeds, which are plentiful, as justification for their misdeeds either!) I am unconvinced that abandoning the attempt to be the good guys will lead people to be good. I believe it will only allow people to be bad guys without feeling bad about it. While claims to be moral have of course been used by many bad guys through history, the correct response is to argue convincingly that they're immoral, not to give up the idea that morality is a worthwhile standard. Or, in other words, I believe morality is qualitatively different from any of those other categories you list. If a store chooses to sell Chips Ahoy instead of Oreos, that's just a question of taste; if a store chooses to sell cookies filled with razor blades and arsenic instead of Oreos, that's a different matter entirely, and we are not obligated to accept it because we've accepted that stores can sell Chips Ahoy.
- kalleboo 6y agoIt should be fair and equal, and countries that do not agree to the fair and equal rules, they should be excluded from free trade.
- bayindirh 6y agoShall we start with ones which insist that fair and equal means what they choose to mean instead of what they mean universally?
- shadowgovt 6y ago"What they mean universally" is actually a harder thing to peg down than one might assume, which is one of the reasons we still have separate countries in the first place.
- sudosysgen 6y agoIt's also why the "rules based international order" is not much more than PR for violent hegemony.
- shadowgovt 6y agoI don't think I understand what you mean. Is the European Union a rules-based international order? It doesn't seem to be a violent hegemony from the outside looking in.
- speeder 6y agoEU happily bombed seasteading projects. Also Somalia originally wanted to split in multiple countries and NATO interventions happened to prevent that and force them to remain only one country, and remain in Civil war
- SiempreViernes 6y ago> EU happily bombed seasteading projects How the EU member states act towards parties outside the EU seems a bit beside the main point: that the EU itself actually is about international rules and not a cover for violent actions between the various member states.
- kspacewalk2 6y agoThe exact same logic applies to nuclear weapons. How many lives have they saved by being a credible deterrent over the decades? Every country should be allowed to possess them, or else none should. I'm not even sure if the latter is desirable (it'll lead to millions of deaths in conventional warfare), but it doesn't matter, since it is completely impossible (the tech exists, so it will be used, invariably). We're left with only one logical option.
- bayindirh 6y agoThen let's declassify all nuclear weapon designs and allow everyone to build a lot of them. Furthermore, let's create economic programs to build a baseline nuclear arsenal in every country. That'll prevent a lot of wars. Some countries will object to that. Why? Isn't everlasting peace much better? Edit: Do I need to point out that I'm not writing these comments in support of war, but with a desire to spark a thoughtful conversation?
- AnthonyMouse 6y agoMAD works because both sides have something to lose. If you give a nuke to Osama bin Laden, he uses it. At the same time, I feel like there's still something there. Having nuclear weapons makes existing states much more resistant to opposition. Other states can't topple them in the traditional way because of MAD. But neither can local freedom fighters -- suppose pro-democracy forces took three major cities in China and started using them as an industrial base to wage a conventional war against the regime. The US and anyone else couldn't really help them the way France did the nascent American Revolution, because of MAD. And if they actually started winning regardless, couldn't the dying regime nuke the rebel cities? If we don't want people to live under permanent authoritarianism, maybe we still need something to level the playing field. Though it doesn't necessarily have to be nukes; establishing uncensorable distributed communications comes to mind as an anti-authoritarian power. The fact that Western countries aren't spending billions to comprehensively subvert the Great Firewall is a significant strategic failure.
- tgragnato 6y ago
- gadders 6y agoDo you think the Chinese Communist Government is morally equivalent to the US government?
- FpUser 6y agoYou can have "good democratic" country on a block and "bad authoritarian". If the good one commits murder it is still a fucking murder and hiding under "we are the good guys" umbrella is not going to help the cause. You either behave accordingly to standard or forget calling yourself "good guys". The fact that country X treats its own citizens better then country Y is irrelevant here.
- bayindirh 6y agoFrom the viewpoint of which country and under which definition of morality?
- sudosysgen 6y agoYes, they are equivalent. The USG is somewhat nicer inside of its borders if you're not poor or exposed to crime, but is directly or closely responsible for over ten million deaths abroad, and nothing China has done in living memory abroad comes close to that amount of death, while domestically it is responsible for a lot of death but still maintained a death rate due to economic matters lower to similar countries. Morally, they are more or less equivalent. Of course, this doesn't matter, neither of them care about being good guys, they just want to appear that way to accumulate power.
- gadders 6y ago>>The USG is somewhat nicer inside of its borders if you're not poor or exposed to crime, but is directly or closely responsible for over ten million deaths abroad, and nothing China has done in living memory abroad comes close to that amount of death, LOL. You obviously have never heard of the Cultural Revolution: "Mao launched more than a dozen campaigns during his rule, which began when he founded Communist China in 1949 and ended with his death in 1976. Some are well known while others, such as a bloody campaign to "purify class ranks" in the late 1960s, which involved army units, have received little publicity. While most scholars are reluctant to estimate a total number of "unnatural deaths" in China under Mao, evidence shows he was in some way responsible for at least 40 million deaths and perhaps 80 million or more. This includes deaths he was directly responsible for and deaths resulting from disastrous policies he refused to change."
- deleted 6y ago[deleted]
- Barrin92 6y agono, that's terrible, and also stupid. It's terrible because bad behaviour by one actor isn't an excuse to act in the same way. My neighbour steals thus I'm going to steal is morally bankrupt. Secondly, from the point of view of the US it's also stupid. The US enjoys influence in the world because it propagates a rule-based order, not because it exploits everyone it can get its hands on. That would rapidly lead to a breakdown of trust and in this case result in every country trying to displace American technology from its markets. Which the EU say, could theoretically do.
- bayindirh 6y ago> no, that's terrible, and also stupid... Please read my other comments below (discussion with geofft). This is not the idea I suggest. In fact, it's the exact opposite. > Secondly, from the point of view of the US it's also stupid. My comment contains no countries and/or adjectives intentionally. It's neither about US or adjectives attached to US. I'm talking at a meta sense. Again, please see my comments down the thread. This is not what I tried to say. The core of the whole discussion is here [0]. [0]: https://news.ycombinator.com/item?id=26592112 https://news.ycombinator.com/item?id=26592112
- stjohnswarts 6y agoAnyone who doesn't realize that the US government can rifle through Google's data on a whim (aka secret warrant via Patriot Act) is an idiot. That said they aren't direct intelligence agency like a lot of Chinese corporations. The US government doesn't have real time access to every bit of data that google has, but they are only one rubber stamp away from it. If you keep data on google encrypt it before you upload it.
- padraic7a 6y agoIt really feels like we're heading into or at least towards a new Cold War, with the U.S. and allies on one side and anyone they consider to be a threat on the other. Both 'sides' will (and really already are) marshal private sector tech, media and social media companies. non-aligned countries would do best to develop their own tech and media infrastructure because they won't be able to trust anything else. I think slide into a Cold War could be slowed down by people working in those companies having and enforcing ethical and professional standards. In a case like this one it would mean blocking any hacking attempts that you can, irrespective of where they come from. For social media companies it would mean devising rules about what content you will and won't allow and enforcing those standards whether the posters are from Russia, Arizona or Afghanistan.
- AnthonyMouse 6y ago> non-aligned countries would do best to develop their own tech and media infrastructure because they won't be able to trust anything else. Better than "their own" -- develop free and open source software that will do it even in the participating countries. Which their people can trust because they can see and modify the code, rather than having to trust you, a foreign power. That subverts the domestic propaganda machine there by allowing the people of the participating nations to talk directly to one another without being intermediated by a partisan spreading propaganda and imposing censorship.
- padraic7a 6y agoYeah that's an interesting idea. There are a couple of issues with it though. Let's think about Signal, Twitter, Facebook and Tor. The US government is putting increasing pressure on social media companies like Twitter and Facebook to shape their content. US government funded open source projects like Signal and Tor allow for the spread of US shaped social media in countries that want to limit it. So the propaganda machine thrives , it's just that it's the US one. (note I like and use Signal and Tor, an against censorship in China. This is just one aspect of a set of complex relationships. Etc etc)
- ganoushoreilly 6y ago
- Debug_Overload 6y agoSpecial pleading is a hell of a drug.
- dehrmann 6y agoNot reporting vulnerabilities used by a friendly government is a backdoor backdoor.
- kritiko 6y agoTFA - "democratic" hacking is good: "How one treats intelligence activity or law enforcement activity driven under democratic oversight within a lawfully elected representative government is very different from that of an authoritarian regime."
- Fuzzy_Logic 6y agoThe CIA has a history of spying on Congress[0], overthrowing democratic governments [1], among a long list of nefarious activities I would not consider proper "democratic hacking." [2] How is obligating big tech to cooperate with Western intelligence agencies a positive move for democracies? [0] https://www.theatlantic.com/politics/archive/2014/12/a-brief-history-of-the-cias-unpunished-spying-on-the-senate/384003/ https://www.theatlantic.com/politics/archive/2014/12/a-brief... [1] https://en.wikipedia.org/wiki/1953_Iranian_coup_d%27état https://en.wikipedia.org/wiki/1953_Iranian_coup_d%27état [2] https://en.wikipedia.org/wiki/List_of_CIA_controversies https://en.wikipedia.org/wiki/List_of_CIA_controversies
- kritiko 6y agoI'm quite skeptical of the viewpoint in this article - just answering the question from the parent comment of "would China be justified in exploiting Huawei?" The distinction that this article makes is that our clandestine operations have "democratic oversight." To be clear, I think the author would say that they are attempting journalistic neutrality, but they're giving considerable space to the argument that democratic clandestine services deserve a different standard.
- bhouston 6y agoIt doesn't say "US government", it says "the hackers in question were working for a US ally", which makes it even more complex. It was likely if it was counterterrorism this is about a Middle-Eastern ally, such Israel or Saudi Arabia? Neither of these are always US allies, only sometimes.
- egwor 6y agoI think you made a jump there. This could equally be one of the other in the Five Eyes group e.g. Canada, Uk, Australia, NZ.
- finiteseries 6y agoDenmark, the Netherlands, France, and Germany are also all well equipped for this sort of thing and are as close of allies as you can get outside Five Eyes (DK/NL especially). The Dutch were the ones who originally warned of interference in the 2016 election IIRC and had access to Cozy Bear for a while before that.
- cycomanic 6y agoWell and for all the "legal oversight" much of the five eyes operations seems to have been designed around economic advantages, circumventing the rules about spying on your own citizens (it's not us who is doing the spying, it's the Australians). So I'm not sure if it being a five eyes operation makes it better or worse.
- joe_the_user 6y agoThere's no "jump". The poster simply raised one hypothetical to consider. "Could be anyone", right?
- dirtyid 6y agoMore likely domestic counter terrorisms under FVEY. I don't know about Google, FB has called out Israeli and Saudi influence before. I imagine only Anglo countries gets default hush hush privileges.
- tremon 6y ago"How one treats intelligence activity or law enforcement activity driven under democratic oversight within a lawfully elected representative government is very different from that of an authoritarian regime.” From a systems security standpoint, no. This is the same kind of idealistic naivety that causes the FBI to advocate for weak encryption, or senators to call for "security only breakable by us, because we're the good guys".
- lenkite 6y agoObeying the law is not naivety. Protecting your customers is not naivety. Pass legislation through both houses of the US enforcing such privileged "Government Right to Hack" first before claiming any morality. Of-course that will likely lead to economic collapse as no-one (allies or enemies) will trust US software or services.
- indymike 6y agoThis is one of the best comments I've read in a long time on HN.
- adamcstephens 6y agoFrom my viewpoint the oversight given to the intelligence agencies is handled by intelligence friendly members of Congress. They don’t seem to let critical people into the committees and if they do they are minor players. Even still, Clapper felt compelled to lie to their faces. How many others have done the same?
- ben_w 6y agoWhile this is absolutely correct, it is also true that the world we live in is not the clean world of Boolean algebra. The same security flaw that lets “baddies” pwn us, also lets us pwn baddies. The same indefatigable crypto that keeps us safe and makes online anything possible, also lets people conspire in secret to overthrow governments — heck, I remember reading the idea of onion routing that led to TOR was a U.S. military project to help anti-government activists in China, and even if that was just an urban legend, one team’s goodies are another team’s baddies. I don’t have any good solutions here. This is security vs security, and my weak fleshy hardware is vulnerable to exploding things owing to a lack of backup solutions, therefore if my options were perfect security for my body or for my data, right now I would choose my body, even though loss of data has the potential to be catastrophic. That said, if it were up to me, police investigations would involve a lot more remote sensing tech instead of hacking… but I say that knowing even that isn’t a no-downside option, and I know that I am unaware of the full implications of police having the budget and power to spy on targets of their choice. (I’m also in favour of radical decriminalisation of just about everything that can be decriminalised, because I think omniscient surveillance is unavoidable and I don’t want criminals using it to automate blackmail).
- strong_opinions 6y agoGood. Such vulnerabilities should always be reported and fixed, no matter who is abusing them. And it's even better if it wrecks a government operation, they shouldn't even be using these, they should always be reporting them to the software vendor. I hope this doesn't discourage Google's threat analysis team, and others, from doing the same in the future. The justification for not intervening is weak too - after all, we only have this article's word for it that the targets were 'terrorists'. They may well just have been freedom fighters, like Nelson Mandela was.
- exabrial 6y agohttps://archive.is/xAtvD https://archive.is/xAtvD
- beshrkayali 6y agoThis new trend of "sign up to my newsletter to open a link" is infuriating.
- sodality2 6y agoDisable JS. Been manually whitelisting sites for 2 weeks now, rarely encounter a site I use often that breaks.
- beshrkayali 6y agoI would but that breaks many sites I frequent, but even if I can use (yet another) browser for this, it's just an annoying hassle.
- chopin 6y ago> “The oversight is baked into Western operations at the technical, tradecraft, and procedure level,” they added. At least for Germany this is patently untrue. Our parliament is stonewalled regularly and they get away with it. And even in the US, the congress is being lied to with no repercussions.
- 13415 6y agoWhat's even worse about this is that intelligence agencies are highly suspect of outsourcing surveillance that would be illegal for them to conduct (e.g. because it's on their own citizens on their home soil) to allied intelligence agencies, thereby circumventing judicial oversight and local laws.
- ceejayoz 6y agoSpecifically: the various Five Eyes nations can share intelligence to the point where if the Americans can't access information on an American without a warrant, they can just ask the Brits to do it, and vice versa. https://www.theguardian.com/world/2013/nov/20/us-uk-secret-deal-surveillance-personal-data https://www.theguardian.com/world/2013/nov/20/us-uk-secret-d...
- geofft 6y agoI dunno, I feel like "the only thing that can stop a bad guy with a buffer overflow is a good guy with a buffer overflow" makes even less sense than the original form of that. Secure systems that do what they say they'll do help everyone. The idea that there's some sort of obligation to keep security vulnerabilities around so that the bad guys can get pwned feels as vile as saying that there's an obligation to keep medical knowledge secret lest enemy soldiers learn how to take care of their health.
- Jonnax 6y agoThis is a lot of words to say that Google found and caused the patching of security exploits in consumer devices such as Safari, iPhones and Android phones. And the users of the exploits were a state actor that was friendly to the USA. Which is effectively saying that wanting vulnerable software is a patriotic thing. Especially calling it a "counter terrorism" operation. Where did the author of the article get that information from? It seems like a hit piece.
- adamcstephens 6y agoThe article quoted anonymous and named intelligence officials. Not a stretch to see where they’re getting their info from.
- ok123456 6y agoThey glow in the dark.
- dillondoyle 6y agoThis is probably an intentional story. The spooks reached out to reporters with approval. I find it is unlikely information as sensitive as means and methods, with no seaming whistleblower spying on the people type motivation, would be disclosed by leakers without approval. Strategic leaks like this are done all the time. Though I guess there is precedent of releasing post-mortem facts like in the charges of the alleged vault 7 leaker.
- asdfasgasdgasdg 6y agoIt's an interesting tactic. I think a lot of people in the tech community are a bit skeptical of the NSA, CIA, etc. I wonder if the publicist's notion here is to gain some ground in public sentiment by pitting the intelligence apparatus against a yet more hated enemy -- big tech.
- elliekelly 6y agoI don’t hold Google in high regard and actively avoid using their products but this article has raised my opinion of them ever so slightly. I’m pleasantly surprised to see they aren’t (yet) completely in bed with the “counter terrorism”-justifies-all thinking that seems to be prevalent among western governments and their surveillance tactics.
- exabrial 6y agoThere is a happy medium here: stop using the government to jail non-violent offenders. If someone orders a drink with too much sugar, doesn't want to pay a 38% tax rate, or put solar cells in their yard without permission, wants to smoke a certain plant, just let them. We spend extensive police resources jailing these people. If we use a society agreed to just leave people alone for stuff that doesn't matter, when the government is conducting an operation like this it'd be a little easier to let it go as there is no target for abuse. Right now we're training in the opposite direction where everything that upsets someone needs a law and needs to be illegal.
- geofft 6y ago"Counterterrorism" implies to me that the targets were not under the jurisdiction of the United States, and therefore could not have been jailed for ordering a drink with too much sugar (not that anyone in the US could, either, but let's pretend they could).
- dirtyoldmick 6y agoYet. Nobody has been jailed for too much sugar yet.
- DanBC 6y agoWhere does this idea that all law is enforced by police come from? Why is it so prevalent on HN?
- flyingfences 6y agoBecause it is: it's either enforced by the police, or by some other group that will fall back to calling the police if you don't go along with their enforcement.
- kube-system 6y agoThat's unequivocally false. For example: there are many legal concepts which are not a crime to disobey (and therefore there is no criminal reason for police to be involved) and/or it is not in the jurisdiction of any police force.
- kortex 6y ago> But while protecting customers from attack is important, some argue that counter-terrorism operations are different, with potentially life and death consequences that go beyond day-to-day internet security. Maybe they shouldn't base life or death consequences on something as capricious as the existence of an undetected 0-day. It's not just Google, what about other security companies, independent white-hats, etc? The alternative is basically saying, "you shouldn't/can't improve software security, coz terrorism", which not only feels super unethical, but also likely a 1st amendment violation.
- LockAndLol 6y ago> “The oversight is baked into Western operations at the technical, tradecraft, and procedure level,” they added. So what the NSA has been doing (even after exposure by Snowden) has had "oversight baked in"? Who are we kidding? This posturing, pretending that " the west is better than everybody else", is downright naive and idiotic. No organisation is pure of heart, moral, or ethics, and none have crystalline motives.
- juanani 6y agoBlind exceptionalism is required to get by in the West. I can't see good reasons for it, Hollywood plays the fiddle.
- deleted 6y ago[deleted]
- eptcyka 6y agoYou don't launch an exploit like one launches an attack. You can only ever share an exploit. As such, the more patriotic thing to do is to defend yourself and plug the holes.
- eplanit 6y agoGoogle, Facebook, and Twitter see themselves as nation-states now, it's becoming clear. It's time to knock these guys down a few notches. China doesn't have fickle, smug, spoiled, naive zealots working on their offensive and defensive cyber efforts -- but man, we sure do. I think the CCP has already beaten us. Sad that an adtech company like Google is involved at all in national defense.
- deleted 6y ago[deleted]
- arthropodSeven 6y agoAuthoritarian 0-day bad!! Democracy 0-day A-OK, no problem!!
- jrochkind1 6y agoTo me, this is not a difficult decision or a debate. Allowing vulnerabilities to remain open/undisclosed because your government approves of them... for one thing, they aren't only useable by your government/allies, you don't know who else knows about them. Our government's approach of finding security vulnerabilities and keeping them for their own use (instead of responsibly reporting them to get fixed) puts all our security in danger. There isn't much we can do about that (except, well, try to use our "democracy" to get the government to behave differently). But in USA at least, private citizens can't generally be compelled to cooperate. If engineers at a private company find a vulnerability, it should be responsibly dealt with to fix it. No matter who else knows about it or may be taking advantage of it. I think it is unethical for a software engineer to do or go along with anything else.
- cowmoo728 6y agoThe article cites that it raised alarms inside Google. I'm trying to imagine the furor that would be unleashed if Google told its employees that they weren't allowed to fix a security bug on order of the US government. There would have been massive pushback.
- SpicyLemonZest 6y agoYeah, it's weird that this is even a question from an employee perception perspective. I'm extraordinarily sympathetic to US intelligence agencies by our industry's standards, and even I would see that as a red line.
- dylan604 6y ago>weren't allowed to fix a security bug on order of the US government What would happen? "Order of the US gov't" makes it sounds like serious legal ramifications would be handed out if violations were to occur. First, what would this look like? The CEO gets arrested? CTO? We've already seen that doesn't happen. The dev that pushed the change to fix the bug gets arrested, the PM in charge? Sanctions? Fines? All of this would have to have some legal standing in a court somewhere, otherwise, the offenders would have to be moved to some black site to prevent them from using any/all means to defend themselves. In otherwords, it seems sort of like an empty threat and bluffing to someone not dealing with the stress of that particular moment.
- oefrha 6y ago> This is far from the first time a Western cybersecurity team has caught hackers from allied countries. Some companies, however, have a quiet policy of not publicly exposing such hacking operations if both the security team and the hackers are considered friendly—for example if they are members of the “Five Eyes” intelligence alliance, which is made up of the United States, United Kingdom, Canada, Australia, and New Zealand. Several members of Google’s security teams are veterans of Western intelligence agencies, and some have conducted hacking campaigns for these governments. > In some cases, security companies will clean up so-called “friendly” malware but avoid going public with it. Ah, this explains why if you follow security-related news, it feels like U.S. or “Western” countries never conduct offensive operations ever.
- wffurr 6y agoIs the C++ programming language the ultimate back door? Did the NSA or whoever encourage it specifically because of its unsafety and prevalence of security flaws? Are any of the C++ standards committee members sock puppets for the NSA to water down any proposals to evolve the language towards safe defaults? That’s a bit too conspiracy-minded; it’s almost certainly just an accident of history. It’s certainly convenient for black-hat and national security types though. How long until some congressperson finds out about Rust, though, and decides it’s a threat to national security since software written in Rust has many fewer security vulnerabilities.
- eqvinox 6y agoGoogle can neither truly verify an origin, nor do they have (or should they have!) the moral authority to determine an origin to be "good" or "bad". A security breach is a security breach and needs to be shut down on sight. I would've done the same in Google's techie's position.
- baybal2 6y agoSo, what espionage operation it was, by whom, and against whom?
- thefreeman 6y agoI think this is a net positive in the long run. Google has every right to publicly disclose and fix vulnerabilities. And while I support governments need to to perform counter intelligence, if this keeps happening hopefully it will cause them to start being more selective in who and what they target with these type of campaigns. If random google security guy visiting a site is being targeted with these payloads it's obviously not differentiating enough.
- DarkContinent 6y ago> There are certain hallmarks in Western operations that are not present in other entities… you can see it translate down into the code Can someone help me understand why this is a good thing? By the arguments presented by other commenters, it seems to me that a) these hallmarks can be duplicated by someone else and b) by only running operations with said hallmarks, the intelligence agencies might miss other vulnerabilities.
- jowsie 6y agoIt's good because they can choose to omit the hallmarks if they wish to hinder attribution, or they can take on the hallmarks of an enemy nation state to point the finger elsewhere/create false flags.
- jessaustin 6y agoIf "they" can include or omit "hallmarks", so can any other "nation state" operatives. In other words, this whole idea is complete bullshit, as it seemed to be when I first read it?
- williesleg 6y agoGoogle is the top of the new world order! Bravo!
- bogwog 6y agoEven though I've been skeptical about Google's "Project Zero" thing ever since they used it to attack a competitor[1], this seems like more of a fuck up by the intelligence agency than by Google. Even if Google is legally obligated to ignore cyber attacks by allied nations, who's to say that they are even capable of accurately attribution? 1: https://www.zdnet.com/article/fortnite-epic-games-ceo-rails-against-google-vulnerability-disclosure/ https://www.zdnet.com/article/fortnite-epic-games-ceo-rails-...
- Aissen 6y agoA fundamental question I haven't seen addressed: if Google' security/threat analysis/whatever team can find evidence of "counterterrorism" 0days in the wild, what's to stop "terrorists" to find those 0days used in the wild as well and reuse them ? Or simply non-allied states that would use them against allied targets ?
- stevespang 6y ago"They took matters into their own hands . . . ". Dissension in the ranks ? Treason ?
- motohagiography 6y agoIt's a relief to see that people at Google made this call, but for a specific reason. One of the times I perceived that I was being given the option to be read-in to some spooky stuff on a client site my view at the time was the IC should do their job, and civilian security folks should do ours. I said that they don't need us to compromise our work if they are good enough at theirs, it's an equilibrium. When I work for them, I'll work for them, but when I work for customers, I work for customers. The world doesn't need more compromised people. I also didn't buy the "if you only knew/ticking bomb" arguments, because they know they have jobs to do and they aren't going to let some civvy contractor geek stand in their way. I'm sure I lost a lot of professional opportunity as a result, but you have to ask what it is you're protecting. If companies who provide products that citizens trust are being subordinated to the IC to spy on them, just what does the IC think it's protecting? When the IC "misses" open secrets like Epstein's blackmail ring, human trafficking coyotes, compromised politicians, the total infiltration and compromise of universities and public institutions by foreign influenced operators, election integrity issues, and economy altering money laundering operations in plain sight, just what job is it they are doing again? We need an IC and general guardian class certainly, but the point is to protect the integrity of the nation. Civilians and companies aren't game pieces, and if they are, I don't think the IC wants the accountability that comes with that. Imo, Google made the right call in this situation.
- lolthishuman 6y agoSounds like you have some interesting stories. Care to share anything you find most perplexing or wish more focus was on?
- motohagiography 6y agoHah, no, but thank you, new account created to comment on intel related threads. This question of how technologists should deal with pressure of all kinds would benefit from peoples experiences and more mature frameworks of ethical considerations. It's not unique to spies.
- 6y ago
- lenkite 6y agoCongrats to Google for making the right decision here. Doesn't matter which govt agency is hacking vulnerable software, plugging the vulnerabilities and kicking them out is the _absolutely_ right thing to do as a private multi-national corporation. If the western government in question wants to hack vulnerable software - they can create their own vulnerable software, ship it and distribute it. No one - utterly no government - democratic or not has any privileged right to hack market software and services. Try passing a law through both houses stating the US government has the right to exploit US companies - and watch the US economy collapse.
- goodluckchuck 6y ago> under democratic oversight within a lawfully elected representative government The writer assumes that western / US-affiliated elections are universally, lawfully elected, and never the product of illegalities... while writing about likely-illegal operations by some of the very same people within those very same governments.
- stephen_g 6y agoYeah, hard to trust that they’re actually following the law. Here in Australia, the chief law officer (Attorney General Christian Porter, who incidentally is on leave because just recently it came out that he allegedly violently raped a minor 30 years ago) has failed to produce the reports on the use of various surveillance powers as required of him by our National Security Information Act for the last three years... And nothing will happen on that, because his own department would have to prosecute him! The Government is generally in trouble, because they all covered up a staffer being raped by another staffer in the office of the Minister of Defence (literally in her office), as well as a bunch of other scandals. She was apparently pressured not to report it to police for fear of losing her job. Again, no public body that will actually prosecute anybody over that, hopefully the outrage will be enough for somebody to resign and things will change next election... At the same time, they keep ramming through laws that increase surveillance power while removing judicial oversight and requirements for warrants. Out intelligence agencies are also severely under-supervised, because while we do have a small agency of bureaucrats to supervise them, the Senate committee made up of actually elected people (the Parliamentary Joint Committee On Intelligence and Security) can’t actually review any past, current or planned operations, they can only look at the legal frameworks (and we just have to hope the intelligences agencies are following the law, and the IGIS actually does their job...)
- someonehere 6y agoWere the developers complicit in allow these exploits? That’s the bigger question. Are Apple and Microsoft intentionally leaving these things open?
- blacklight 6y agoFrom what I understand this counter-terrorism operation consisted in a well-crafted website that delivered malware to visitors by leveraging some undisclosed 0-days. The obvious question is: if some malware is on a public website, who guarantees that only the "bad guys" will be targeted? If you don't disclose the 0-days, who guarantees that your own citizens won't be targeted by the same kind of exploits on the very same vulnerable devices? If you purposely keep a backdoor open in a device, who guarantees that the "bad guys" won't find that backdoor and use it themselves? Although I usually disagree with Google's decisions a lot, this time I can't see much wrongdoing in their action. Counter-cyber-terrorism is a double-edged sword, because it's about placing landmines and waiting for a bad guy to step on them. But nobody guarantees that only the bad guys will step on them. So it's probably time to end this "but we can do it because we're the good guys" rhetoric: it's very easy to get burned when you play with fire.
- Toutouxc 6y ago> law enforcement activity driven under democratic oversight within a lawfully elected representative government I hate to be that guy, but the holocaust was literally this. Nothing has happened since the 1930s that would make me feel safer around a government just because it was lawfully elected.
- bsimpson 6y ago> How one treats intelligence activity or law enforcement activity driven under democratic oversight within a lawfully elected representative government is very different from that of an authoritarian regime. That's the kind of self-delusion you only get from a power-hungry government official.
- thrasumachos 6y ago“Google Project Zero maintains public policies around vulnerability publication and attribution” Would be an accurate headline. Assigning to Google the act of shutting down counterterrorism is highly misleading and purely for emotive effect. Explaining to those who may not be experts what some of the consequences of aforementioned policies are, which they might find surprising, would be educational. Obviously it worked: we read it and came hear to comment :(
- jefftk 6y agoImagine the headline had Google made the opposite decision: "Google suppresses disclosure of zero day security vulnerability under active Five Eyes exploitation". Seems to me they made the right call! (Disclosure: I work for Google, speaking only for myself)
- meowface 6y agoIndeed. Given this is being published by MIT, it's especially gross. What happened to MIT? Pressing charges against Aaron Swartz; pushing what seems like blatant intelligence community propaganda... I genuinely don't mind that law enforcement and intelligence agencies (US or otherwise) would try to find and use these vulnerabilities to achieve goals. That's their job. They wouldn't be doing their job if they didn't do such things. (And, indeed, Google's security teams wouldn't be doing their job, either, if they didn't fix such things when they discovered them.) I might even support Five Eyes' particular operation, here, if the sole targets of the exploitation genuinely are violent terrorists who massacre innocent civilians. But the onus is on them to not get caught by Google security when developing and deploying exploits. The onus isn't on Google to let people exploit their products and services, whether or not they may subjectively judge it might be used for a moral or "patriotic" end. IC's job is to be sneaky and covert and manipulative. MIT's job definitely is not to be sneaky and covert and manipulative. I'm not saying they couldn't or shouldn't report on it and the debate over it, but the article is clearly framed towards a pro-Five Eyes exploitation, anti-Google security angle.
- bzbarsky 6y agoThis is published by "MIT" in about the same way that an editorial in the Washington Post is published by "Amazon". As the first sentence of https://en.wikipedia.org/wiki/MIT_Technology_Review https://en.wikipedia.org/wiki/MIT_Technology_Review says: MIT Technology Review is a magazine wholly owned by the Massachusetts Institute of Technology, and editorially independent of the university
- meowface 6y agoI admit it's genuinely possible the correlation is a coincidence, but I wouldn't be surprised if it wasn't. For example, if WaPo had were instead named the Amazon Post (analogous to "MIT Technology Review") and had written a highly pro-Amazon article when it didn't quite seem merited, would you say that the ownership is irrelevant since they're editorially independent?
- myko 6y agoSeems like Google did the right thing here. Is this truly controversial?
- xiphias2 6y agoIt's only ,,controversial'' because Google's management and HQ is in the US and in bed with US government. Google is a multinational company with most shareholders (weighted by investment amount, not control) and most employees being from outside US.
- not2b 6y agoEven if you accept the rationale that the team behind the exploits were good guys going after bad guys, it's the job of Google's security teams to keep its products (Chrome and Android) secure. I think that they made the right call by disclosing the exploits after the security holes were fixed, but not outing the details of who the attackers were. The article seems to be suggesting that they should have left the holes unpatched, but that wouldn't work. Rival state-backed hacker teams do the same work that the Project Zero people do and would discover the attacks, reverse engineer them, and exploit them. It came out (either from Snowden or from other reporting) that the NSA had a term, NOBUS, short for "nobody but us". The idea was that if they had a hack that was so tricky that they thought that no one else could exploit it, they would exploit it, and if the hole they found was "easy" they would share it so it could be fixed. But that's just arrogant: nothing is NOBUS for long.
- stadium 6y ago> There are certain hallmarks in Western operations that are not present in other entities … you can see it translate down into the code That reads like a opsec vulnerability in the approach
- arkh 6y ago> How one treats intelligence activity or law enforcement activity driven under democratic oversight within a lawfully elected representative government is very different from that of an authoritarian regime. The Snowden files tend to show there's not a lot of oversight.
- JohnCClarke 6y agoWho was the ally? UK or Israel?
- stephen_g 6y agoThere should be no debate. If a vulnerability is found and used by intelligence agencies, it can be found and used by criminals. Any zero day must be fixed. They should report it the same they report any other vulnerability.
- airhead969 6y agoSploits used by state actors are typically novel, expensive, and niche. It's extremely unlikely criminals would have them, so it's a false equivalency. "Must be fixed" without considering the "what," "why," and "by whom to whom" isn't realistic. Let's suppose some terrorists are working to hack into your and many other Teslas to crash them on the highway. Would you really prefer a CT operation continue to identify the culprits using vulns or would you rather you and your family crash into an overpass support? Infosec doesn't exist in a vacuum; there are real-world consequences to thwarting legitimate CT operations due to a strict, unyielding adherence to a "patch everything right now" religion.
- thegeekbin 6y agoIn my opinion, the right decision is to release your research and have the vulnerabilities patched. I'm not a fan of the argument "only we know the bug" "it's for counterterrorism, seriously"... because I'm doubtful. If you found the bug, odds are someone else given the effort could. Secondly, I think it's fair to say governments absolutely abuse any vulnerability they can at any point in time.
- steve76 6y agoYou just blew an undercover international federal investigation on terrorism. I would say that's a bad idea. Won't terrorists go after you now? Close the exploit, or be mortared. You go to the feds. They say: Oh! I can't get to that now!!! My phone says I need to update!
- airhead969 6y ago:-/ Sounds like un-nuanced, black&white nerd myopia (sorry fellow nerds). Ethics dictate that the greater good should be conserved rather than mechanically-plugging holes with blinders on, no matter the fallout. (This is the kind of flawed, idealistic, un-empathetic logic Rand Paul often wades into.) If the failure of this operation leads to mass casualty events or other deaths, then you know who enabled it. The most sensible move would've been a cooperative agreement that these holes would be plugged in a fixed amount of time, say 2 months, so the operation could have other sploits ready while not exposing the average international user to risks for too long.
- cycomanic 6y agoThis reads like such a propaganda piece I really don't know what to say. Apart from the fact that the article seems to obscure the fact of if companies actually know about the counter-terrorism operations (they somehow say people suspect it). It also creates this myth of "democratic oversight" and we all know how much that's worth since Snowden. Also it constructs as if Google is in such a special position here. I mean the vulnerability could be caught by anyone theoretically. Also what is a counter-terrorism operation, monitoring some environmental protestors, what about political activists (of any colour), or does it only count if it's Islamic terrorists? And then there's the whole "putting soldiers lives at risk" which gets repeated every time this comes up. As if we should accept every violation of privacy/human rights, because it saves soldiers lives. They are soldiers, it's their job. Arguably their lives have been put at risk by sending them on the mission.
- matheusmoreira 6y ago> The oversight is baked into Western operations at the technical, tradecraft, and procedure level Doubt it. They frequently abuse their surveillance powers and spy on each other's citizens. Imagine what they do to a foreign national.
- Klwohu 6y agoSo was it Israel?
- aaron695 6y agoI'd assume Israel using American assets.
- deleted 6y ago[deleted]