4 ms·
> This is why the mission of securing America's networks needs to be removed from the NSA. And who should be responsible for this mission? Are you saying that
by jallmann 11y ago
> This is why the mission of securing America's networks needs to be removed from the NSA.
And who should be responsible for this mission? Are you saying that the offensive and defensive cyber capabilities should be split between different agencies?
> “What’s more noteworthy is how little regard the government seems to have for the process of deciding to exploit vulnerabilities,”
The article mentions that the government itself acknowledges that there is a delicate balance between disclosure and maintaining the ability to accomplish other missions [1]. That dilemma never going away, no matter how the responsibilities are organized.
> “As we’ve explained before, the decision to use a vulnerability for ‘offensive’ purposes rather than disclosing it to the developer is one that prioritizes surveillance over the security of millions of users.”
Haven't read the EFF paper yet (and I hold the EFF in high regard), but in the context of zero-days, that quote is a bit of a strawman. You don't burn zero-days by indiscriminately propagating exploits (eg, for mass surveillance), it would be found out pretty quickly. You tap cables and get NSLs for mass surveillance. Payloads attached to a zero-day would be used for more specific purposes, rather than slurping up data en masse.
[1] https://www.whitehouse.gov/blog/2014/04/28/heartbleed-understanding-when-we-disclose-cyber-vulnerabilities https://www.whitehouse.gov/blog/2014/04/28/heartbleed-unders...
- Kalium 11y ago> And who should be responsible for this mission? Are you saying that the offensive and defensive cyber capabilities should be split between different agencies? In theory, they already are. The Navy, Air Force, Army, and NSA all maintain somewhat separate cyber capabilities.