3 ms·
Yes and no. They are tasked with protecting national security assets within the US, most of which rely on commercial systems. When they find a dangerous flaw
by sandworm 12y ago
Yes and no. They are tasked with protecting national security assets within the US, most of which rely on commercial systems. When they find a dangerous flaw in those systems, especially one loose in the wild, they are to help fix it. To not fix it is to leave US systems at risk.
"in almost all instances, for widely used code, it is in the national interest to eliminate software vulnerabilities rather than to use them for US intelligence collection" ( quote from the 2013 panel report, not wired.)
http://www.wired.com/wp-content/uploads/2014/04/White-House-NSA-Panel-Report-2013.pdf http://www.wired.com/wp-content/uploads/2014/04/White-House-...
- csandreasen 12y agoNot all 0-days affect national security assets. Heck, I'm sure there's plenty of software out in the world that isn't even used in the US at all.