4 ms·
> We are struggling with a broken model of "security" and the emergence of a global insecurity industry. I have a take that isn't too close to the focus of thi
by MSFT_Edging 2y ago
> We are struggling with a broken model of "security" and the emergence of a global insecurity industry.
I have a take that isn't too close to the focus of this article, but there is a big underlying point.
There are known vulnerabilities in consumer and enterprise tech that are purposefully not closed in order to maintain a tactical advantage. Consider the tech used to break into phones, Pegasus. This is a highly visible peak of an iceberg in an otherwise massive industry of finding and weaponizing vulnerabilities that can have real world consequence, see WannaCry.
This is both hugely political, and not political at all. It's almost a guarantee that a nation-state with cyber resources will use said resources to find a tactical advantage and constantly lob attacks back and forth. Each side will loudly exclaim "Look they're hacking us!" while staying quiet on their own attacks. You can set your watch to it.
Basically any government is spending vast resources to find vulnerabilities and keep them open, which makes everyone less safe. Coupled with the constant war on encryption, gov sponsored "Cyber" is a money pit for hawks that wish to start trouble.
- JumpCrisscross 2y ago> almost a guarantee that a nation-state with cyber resources will use said resources to find a tactical advantage and constantly lob attacks back and forth Guns versus butter. There is probably a rational amount of cyber insecurity, given writing secure software comes with tradeoffs. (Nothing that comes with tradeoffs optimises to zero or infinity.) Perhaps being able to run insecure software is a form of peace dividend. Doesn’t cover intentional security holes. But we don’t have evidence that is a prevalent problem.
- arminiusreturns 2y agoActually we do have evidence it is a prevalent problem. A few data points ok, but we have repeated data points (at foundational pivot points) supporting it. (example: NIST infiltration and manipulation of encryption standards. Vault 7. etc).
- JumpCrisscross 2y ago> few data points ok, but we have repeated data points This is no evidence it’s a prevalent problem. It’s absolutely a problem. But I’m unconvinced we’re e.g. at a material military disadvantage or at economic risk as a result of it.