5 ms·
If NSA had spent all its resources in increasing the security of internet, they would have a lot less reasons for such spying.
by kisna72 11y ago
If NSA had spent all its resources in increasing the security of internet, they would have a lot less reasons for such spying.
- ibejoeb 11y agoI think of this as part of a broader failure of the USA to build, repair, and fortify infrastructure. We have crumbling roads, failing bridges, and, now, telecom and computing services that are rather unimproved since inception, decades ago. Now, I realize that, as an intelligence agency, NSA's core mission is to spy. But I take issue with the intentional weakening of our infrastructure, e.g., Dual EC DRBG. You don't see DOT going around sabotaging asphalt production.
- forgottenpass 11y agoNow, I realize that, as an intelligence agency, NSA's core mission is to spy. Funnily enough, the NSA has a dual mission: spy on their communications, protect ours. Now that everyone uses the same tech, one of those missions has overshadowed the other. Makes their weakening even harder to stomach, eh?
- chiph 11y agoTechnically (yes, I am being that guy), their protection mission only extends to the DoD and selected US government agencies. Not to the general public or US business. That's done by NIST and the Department of Commerce. The NSA does occasionally cooperate with NIST on encryption matters, but that's fairly arms-length.
- Eridrus 11y ago> cooperate with NIST on encryption matters, but that's fairly arms-length Heh, you might want to read up on Dual_EC_DRBG. Technically you're right, and I think that people who claim that these missions are fundamentally at odds have not fully games out what options the NSA have; where they see fixing bugs as the only way to increase security, but despite their responsibility being technically only to the government, there has been quite a push for the NSA to help defend civilian networks too since they're being routinely targeted by nation state actors too, and the economic damage there is arguably worse.
- Alupis 11y ago> Funnily enough, the NSA has a dual mission: spy on their communications, protect ours. Even more funny, if the NSA succeeds one part of their mission, they fail the other. Therefore it's an impossible mission... so they've just seemingly resorted to only the spying part...
- Lawtonfogle 11y ago'Their' includes anyone outside of the NSA. Not just other nations. Not just normal US citizens and corporations. But also others within the US government.
- rbanffy 11y agoThey gave us SELinux. Also, keep in mind that by freely giving tools to secure everything, they also end up making their own job of spying on others harder.
- Someone1234 11y agoSELinux was incredible and we should be thankful to the NSA for that. But, not to sound ungrateful, that was 18 years ago now and the NSA's supposed mission to strengthen America's [digital] infrastructure seems to have stalled. It seemed like pre-9/11 the NSA was doing both of their roles (spy and strengthen) but since 9/11 all they do is spy and ignore the other role. Maybe that role should be moved out of the NSA completely, and they can just concentrate on spying and let someone else concentrate on improving digital security. It is fair to say that those two roles are somewhat contradictory.
- dmix 11y agoAttackers and security researchers seem to have figured out how to bypass SELinux relatively easily. Looking at any recent major examples of real-life attacks on Linux, SELinux never came up as a roadblock for any of them. It reduces the attack surface which is a good thing, but there are plenty of entry points still available to gain root. Privilege escalation on stock Linux systems has never been a major challenge, attackers can then simply turn off SELinux or modify the rules once they get root - as plenty of public exploit PoCs have demonstrated. Which is more of a indication of the state of Linux kernel security rather than MAC software. Sysadmins seem to talk highly of SELinux, but its rare to find people in offensive infosec who do. Not to mention attackers can use SELinux toolsets to gain root: http://seclists.org/oss-sec/2015/q1/1011 http://seclists.org/oss-sec/2015/q1/1011
- mhurron 11y agoDo you have examples? I haven't seen anything that said SELinux was thwarted in anything, and it is still pretty standard procedure to turn SELinux off instead of learning it.
- 11y ago