2 ms·
I assume that any piece of technologically backed infrastructure is a potential target for state-level actors. If rando security researcher finds the vuln in 15
by yojo 2y ago
I assume that any piece of technologically backed infrastructure is a potential target for state-level actors. If rando security researcher finds the vuln in 15 minutes, I guarantee China already has it.
Anyone operating infrastructure hardware is negligent if they won't take basic measures to harden it against disclosed threats.
I’m not worried about malfeasant citizens mucking with the traffic lights, there are simpler ways to make mayhem. But in the event of a war, you can bet every unpatched vulnerability in your infrastructure will be used against your country.
- rvnx 2y agoWhen you work for a state-actor it's no different than anywhere else; you don't have exploits coming out of the sky. You either research these vulnerabilities (and you have limited capacity and knowledge) or you purchase vulnerabilities from vendors, exchanges and "research companies". In such case, it was an unnecessary free gift to an enemy state or a malicious actor. The same with NSA, they do not know all the vulns of the universe (due to budget, resources, or simply focus). You may actually have some vulns they are interested into but unless someone points these vulns to them, they will not get aware that they exists.