4 ms·
Playing devil's advocate, keep in mind that domestic computer security is part of the NSA's charter. Remember the rainbow books? It would be completely legiti
by reeses 13y ago
Playing devil's advocate, keep in mind that domestic computer security is part of the NSA's charter. Remember the rainbow books?
It would be completely legitimate for MSFT to warn NSA about vulnerabilities in the most common desktop operating systems in the USA if the warning were intended to aid in preventing a larger attack.
It's a write-only bugtraq. :-)
- ihsw 13y agoThe head of NSA is also the head of the US military's cybercommand and offensive operations are definitely part of their bottom line. This intersection between protecting civilians and attacking our military enemies should absolutely worry you, the worst nightmare of 'responsible disclosure' has just been revealed: security updates aren't being rolled out as a matter of official policy, for the explicit purpose of military offensive operations.
- reeses 13y agoSince the head of the NSA is a senior military officer, they are likely to be the most qualified to head the military's computer offense capabilities. Theoretically, there is presidential and congressional oversight to prevent them from overstepping their bounds. Unfortunately, we've largely squandered the threat of congressional inquiry on blue dresses and cigars. What I find confusing is that, ultimately, you have to follow the money. How has MSFT been benefiting from a conspiracy to exploit their own software in overseas markets? They know that embarrassing information will get out eventually. They also have a distant planning horizon regarding continued existence. Whatever they get in return has to have been perceived as worth the loss of any trust and goodwill as a result of the eventual disclosure.