3 ms·
NOBUS is a disaster. Knowingly leaving citizens unprotected is an absolute failure of government. Having a robust policy of identifying a resolving cybersecurit
by numbsafari 2y ago
NOBUS is a disaster. Knowingly leaving citizens unprotected is an absolute failure of government. Having a robust policy of identifying a resolving cybersecurity faults, and holding organizations accountable for patching and remediation is necessary if we are going to survive a real cyber “war”. We are absolutely unprepared.
- deleted 2y ago[deleted]
- sneak 2y agoThis presupposes that the purpose of government is to protect citizens. The purpose of government is to take and maintain power and prevent any other organization from displacing them. It involves citizens only as a means to an end. It would be a failure of government to place citizen safety over continuity of government.
- ambicapter 2y agoIt can be both at the same time. A government won't be great at protecting its citizens if it has no power over bad actors, both inside and outside.
- acdha 2y agoYour first sentence seems like a distraction because the same criticism of NOBUS holds either way. Even if the leaders do not care about the citizens except as a means to an end, an oppressive government especially needs to maintain security because it needs to project force to deter threats to its power. If they have a known vulnerability, they should be even more worried that internal dissidents or an external foe will find it because they are even more dependent on power in the absence of democratic legitimacy.
- pythonguython 2y agoThis is a classic security dilemma that is not easily resolvable. Suppose we just look at the US and China. Each side will discover some number of vulnerabilities. Some of those vulnerabilities will be discovered by both countries, some just by one party. If the US discloses every vulnerability, we’re left with no offensive capability and our adversary will have all of the vulnerabilities not mutually discovered. Everyone disclosing and patching vulnerabilities sounds nice, but is an unrealistic scenario in a world with states that have competing strategic interests.
- tptacek 2y agoThe US VEP, which is like 10 years old now, is explicit about the fact that zero-day exploits are not fundamentally "NOBUS". That term describes things like Dual EC, or hardware embedded vulnerabilities; things that are actually Hard for an adversary to take advantage of. Chrome chains don't count.