3 ms·
This is why the mission of securing America's networks needs to be removed from the NSA. “What’s more noteworthy is how little regard the government seems to h
by vaadu 11y ago
This is why the mission of securing America's networks needs to be removed from the NSA.
“What’s more noteworthy is how little regard the government seems to have for the process of deciding to exploit vulnerabilities,” wrote Nate Cardozo and Andrew Crocker of the Electronic Frontier Foundation. “As we’ve explained before, the decision to use a vulnerability for ‘offensive’ purposes rather than disclosing it to the developer is one that prioritizes surveillance over the security of millions of users.”
- wahsd 11y agoTo be fair, they don't monitor whether the 0Day exploits are widely used so they have no idea when they should make them public for general security purposes. (yes, that's sarcasm) But the way the entities operate that are actually seeking these, is by thinking of themselves as outside of the regular set of rules and even reality. They are seeking 0Day exploits with an assumption that the individual or individuals that provide them will not sell them to someone else or even use them for themselves. I can guarantee that these "cyber wars" are going to result in some sort of cluster-fuck-up at some point because humans have a tendency to entrust the least responsible people with the most devastating technologies even remotely before we fully understand the ramifications. On a side note; please take note of the fact that many of the current issues regarding anonymity and security on the internet and in technology in general is a direct fractal result of prior decisions by researchers and developers to not focus on anonymity and security as a primary requirement. The internet is a security nightmare, precisely because some researchers decided to ignore security requirements early on.
- jallmann 11y ago> This is why the mission of securing America's networks needs to be removed from the NSA. And who should be responsible for this mission? Are you saying that the offensive and defensive cyber capabilities should be split between different agencies? > “What’s more noteworthy is how little regard the government seems to have for the process of deciding to exploit vulnerabilities,” The article mentions that the government itself acknowledges that there is a delicate balance between disclosure and maintaining the ability to accomplish other missions [1]. That dilemma never going away, no matter how the responsibilities are organized. > “As we’ve explained before, the decision to use a vulnerability for ‘offensive’ purposes rather than disclosing it to the developer is one that prioritizes surveillance over the security of millions of users.” Haven't read the EFF paper yet (and I hold the EFF in high regard), but in the context of zero-days, that quote is a bit of a strawman. You don't burn zero-days by indiscriminately propagating exploits (eg, for mass surveillance), it would be found out pretty quickly. You tap cables and get NSLs for mass surveillance. Payloads attached to a zero-day would be used for more specific purposes, rather than slurping up data en masse. [1] https://www.whitehouse.gov/blog/2014/04/28/heartbleed-understanding-when-we-disclose-cyber-vulnerabilities https://www.whitehouse.gov/blog/2014/04/28/heartbleed-unders...
- Kalium 11y ago> And who should be responsible for this mission? Are you saying that the offensive and defensive cyber capabilities should be split between different agencies? In theory, they already are. The Navy, Air Force, Army, and NSA all maintain somewhat separate cyber capabilities.