2 ms·
I think one of the big issues here is that for an intelligence agency, good defensive security is essentially silent. There's not a lot of money or political ca
by summerdown2 12y ago
I think one of the big issues here is that for an intelligence agency, good defensive security is essentially silent. There's not a lot of money or political capital in "nothing broke today."
On the other hand, good offensive capabilities, even if kept secret externally, are loud and flashy within the organisation, and come with lots of political capital beyond it.
Because of this asymmetry, I think it's almost impossible for an intelligence organisation to stop its "defense" mission being swallowed by the "attack" one. And so we all end up less free and less safe.
I do sometimes wonder what the world would be like if the NSA took it as its mission to secure the internet and chain of encryption, rather than constantly breaking it. If, for example, they used their resources to seek out vulnerabilities and exploits and fix them.
Maybe such a world is impossible. But I do think there's a valid space for a national cyber defense organisation that runs counter to this trend, that acts to shore up the infrastructure rather than constantly subverting it.