5 ms·
Sounds great but that isn't the NSA's mission, not even the defensive mission. Their defensive mission is limited to DoD networks and national security related
by thoth 11y ago
Sounds great but that isn't the NSA's mission, not even the defensive mission. Their defensive mission is limited to DoD networks and national security related systems, and producing various recommendations.
DHS and/or NIST cover commercial and non-DoD government. But even then it is a voluntary and/or advisory capacity too - there is no authority to make a company fix a software product (unlike say a car defect, which gets into liability issues nobody wants to open for software).
As for discovering and preventing bugs, I think that would be a waste of time/effort in the current towards NSA and software in general. Nobody is going to take a binary patch from them, nobody is going to submit their source code for review, any help given to a company would draw complaints from their competitors, and fundamentally as long as companies aren't actually liable for damages due to bugs or security issues, they aren't going to care much about spending money to improve the situation. A corporation would just rather add another clause to a EULA to disclaim more and more responsibility.
It's a free market failure since bottom line profits aren't affected so there is no incentive to improve. That leaves the question of whether the government should be subsidizing the business world's failure to meaningfully invest in bug fixes and security improvements.
- wpietri 11y agoMy point isn't that the NSA should suddenly become that agency. My point is that it would be pretty handy to have an agency like that. And the joke is that the agency we have under that name is doing the opposite. > That leaves the question of whether the government should be subsidizing the business world's failure to meaningfully invest in bug fixes and security improvements. One good way to sum up what government is good for is "things the market can't or won't do on its own." So I'd say yes.
- thoth 11y ago>"things the market can't or won't do on its own." This is one of those situations - be careful what you ask for, you might get it. Apple and Microsoft between them make $35 billion in profit a quarter (not picking on them, just examples) - corporations don't need government handouts for this, they need proper motivation which is absent because security issues don't cost them anything except PR. Actual monetary damages would alter that however. Fines, penalties, liability assumption, etc. You really want to see that? Otherwise, how would it work exactly? Existing models of the FDA (and its drug approval process) or the DoT (and its ability to force auto recalls) would introduce monetary damages, legal liability, government authority to pull products, and regulatory approval as ways to the free market ignoring costs related to security/defects - you really want to see that for the software market? How would you REQUIRE corporations to have their code vetted by the "future software security agency" (FSSA)? Or say FSSA provides reference implementations or reviews open-source code only? That's only part of the software universe, is it enough? If participation is voluntary/optional, corporations still aren't going to care; they will need to be compelled to participate.
- wpietri 11y agoIf you're looking for a model, consider the CDC. Or your local health department. The world isn't neatly divided into things that people care about (and do) and don't care about and therefore will never do). It's a continuum. For example, many people in companies care about security but never have time to do enough. If you make it so that they can do more per unit of time, they'll do more.
- tikums 11y agoThat's wrong. NSAs new IDS also protects enterprises that the state considers to be "critical infrastructure", such as banks.