3 ms·
I don't really see how that fits into this scenario. Computer Security is more like chemical warfare. Were you can either do research or try to make everyone mo
by throwaway349823 12y ago
I don't really see how that fits into this scenario. Computer Security is more like chemical warfare. Were you can either do research or try to make everyone more secure by international treaties. Here you can either undermine encryption, infiltrate networks, keep exploits to yourself or you can make everyone secure by patches, standards and encryption that works.
- jallmann 12y ago> Computer Security is more like chemical warfare Ignoring this nonsensical analogy... > undermine encryption, infiltrate networks, keep exploits to yourself This is really the MO of any intelligence agency; that is their job. > you can make everyone secure by patches, standards and encryption that works Interesting statement, because it shows some things. Firstly, there is a difference in incentives -- why publish a vulnerability when it could be used to further your mandate? For the specific case of NSA though, that also ignores their broader role in securing federal communications (eg, vetting SHA, AES, FIPS, etc). Of course, there are always exceptions (DES, Dual-EC-DRBG, etc) -- but in a way, that precisely illustrates why we have intelligence agencies in the first place: trust no one.