Actually, NSA creating exploits of their own is much better for the security of the Internet, because it doesn't capture resources that could have been directed at improving software. I'm fine with an NSA that competes with the commercial software industry over software security.
NSA finding exploits is good. NSA keeping those exploits secret, for use as tools, is probably good; NSA disclosing those exploits to vendors and getting them fixed may or may not be better. NSA convincing vendors to insert bugs (or features) that can be exploited is bad. I don't know a whole lot about how much they do each of these.
I agree, but try to keep the terminology clear. The things you're saying are bad aren't "exploits"; they're "implants". There are modes of implanting code that I think are clearly bad, but even more modes where I think "well, that's SIGINT for you."
Sure, I'll readily accept a preference for the term "implants". I just wanted to state things (what I hope was) clearly lest people talk past each other.
I'd agree if we shared our knowledge with the NSA. But they keep it secret, in fact threaten to put a bag over your head and send you to Guantanamo if you tell anyone.
So what could be a healthy tension becomes a rigged game, with the NSA busting heads and breaking things all over the place.
Curious - what can it mean for the NSA not to be capturing resources? Surely they use competent engineers to do what they do - who could have been directed at improving software instead of subverting it?
Once again: it's fine if NSA is discovering exploits, as long as they aren't also paying off commercial researchers not to disclose flaws to vendors. A private NSA exploit development capability merely puts them in competition with commercial industry, and industry has the upper hand, because they can actually fix whole bug classes all at once, and NSA has to find them piecemeal.
I guess I didn't understand the previous then. The NSA isn't just discovering exploits, they are an exploit factory. They develop chips and hardware, coerce internet backbone corporations to create exploits, generally have broken the whole game. While we were arguing about cookies, they were recording the whole conversation, breaking the encryption, reducing privacy worldwide to a sham.
Competition implies some sort of level ground. But they gag the communications suppliers as they subvert the networks. If not for a whistle-blower this could have continued undetected for decades.
I wish I were some sort of conspiracy-theorist spouting hyperbole. I know this sounds like one.
I'm reading "exploit", "chips", "hardware", "backbone", "cookies", and "encryption", but not seeing a coherent argument or evidence that we mean the same things when we use these words. NSA is not getting "backbone corporations" to create "exploits".
I guess I'm not qualified to speak on this subject, I can't say anything without sounding like a newb. The NSA requires Google, wireless operators, everybody who has or transmits data, to hand it over assembly-line fashion and that's not an 'exploit'. But if I managed to do that, it would be.
So the NSA doesn't get labeled as a rogue hacker or exploit-creator because, well, because of semantics.
Comments
Actually, NSA creating exploits of their own is much better for the security of the Internet, because it doesn't capture resources that could have been directed at improving software. I'm fine with an NSA that competes with the commercial software industry over software security.
NSA finding exploits is good. NSA keeping those exploits secret, for use as tools, is probably good; NSA disclosing those exploits to vendors and getting them fixed may or may not be better. NSA convincing vendors to insert bugs (or features) that can be exploited is bad. I don't know a whole lot about how much they do each of these.
I agree, but try to keep the terminology clear. The things you're saying are bad aren't "exploits"; they're "implants". There are modes of implanting code that I think are clearly bad, but even more modes where I think "well, that's SIGINT for you."
Sure, I'll readily accept a preference for the term "implants". I just wanted to state things (what I hope was) clearly lest people talk past each other.
I'd agree if we shared our knowledge with the NSA. But they keep it secret, in fact threaten to put a bag over your head and send you to Guantanamo if you tell anyone.
So what could be a healthy tension becomes a rigged game, with the NSA busting heads and breaking things all over the place.
Curious - what can it mean for the NSA not to be capturing resources? Surely they use competent engineers to do what they do - who could have been directed at improving software instead of subverting it?
I don't understand what this comment means.
Once again: it's fine if NSA is discovering exploits, as long as they aren't also paying off commercial researchers not to disclose flaws to vendors. A private NSA exploit development capability merely puts them in competition with commercial industry, and industry has the upper hand, because they can actually fix whole bug classes all at once, and NSA has to find them piecemeal.
I guess I didn't understand the previous then. The NSA isn't just discovering exploits, they are an exploit factory. They develop chips and hardware, coerce internet backbone corporations to create exploits, generally have broken the whole game. While we were arguing about cookies, they were recording the whole conversation, breaking the encryption, reducing privacy worldwide to a sham.
Competition implies some sort of level ground. But they gag the communications suppliers as they subvert the networks. If not for a whistle-blower this could have continued undetected for decades.
I wish I were some sort of conspiracy-theorist spouting hyperbole. I know this sounds like one.
I'm reading "exploit", "chips", "hardware", "backbone", "cookies", and "encryption", but not seeing a coherent argument or evidence that we mean the same things when we use these words. NSA is not getting "backbone corporations" to create "exploits".
I'm confused too. Which of these things (http://www.wnyc.org/story/running-list-what-we-know-nsa-can-...) are exploits and which 'implants'? Why does it matter? What is the NSA doing that is worth all that?
I guess I'm not qualified to speak on this subject, I can't say anything without sounding like a newb. The NSA requires Google, wireless operators, everybody who has or transmits data, to hand it over assembly-line fashion and that's not an 'exploit'. But if I managed to do that, it would be.
So the NSA doesn't get labeled as a rogue hacker or exploit-creator because, well, because of semantics.