4 ms·
Tl;dr the argument is if three letter agencies can’t buy or make exploits anymore because all vulnerabilities are patched, they will ramp up legal and legislati
by turtletontine 2mo ago
Tl;dr the argument is if three letter agencies can’t buy or make exploits anymore because all vulnerabilities are patched, they will ramp up legal and legislative pressure to make vendors install backdoors. Which is bad and we should all worry about.
One of the author’s blind spots here is the concept of “digital sovereignty”. The US is continuing to ban more and more Chinese-made hardware out of fear that the Chinese govt has installed backdoors in them… which you could interpret as an admission that the US does exactly that with American made products. Globalized supply chains are, erm, complex, and few if any companies are really going to be able to achieve “digital sovereignty” with hardware. But with software it’s actually plausible, though obviously hard. Whether or not the feds have actually installed backdoors in Microsoft Outlook, foreign govts are rightly concerned that they have, and are increasingly pushing to avoid US made software for simple national security reasons.
- leonidasrup 2mo agoThe author of the article, Matthew Daniel Green, knows the capabilities of US to put backdoors into software and standards very well. Green's blog entries on NSA's backdoor in Dual_EC_DRBG, and RSA Security's usage of the backdoored cryptographically secure pseudorandom number generator (CSPRNG), have been widely cited in the mainstream news media. https://en.wikipedia.org/wiki/Matthew_D._Green https://en.wikipedia.org/wiki/Matthew_D._Green