Defence is only card in this game worth playing especially when it comes to infrastructure attacks.
Defence is only card in this game worth playing especially when it comes to infrastructure attacks.
NSA isn't a hardware or software vendor, and the corporations that are don't have much of a profit motive to heavily invest in security. They aren't actually liable for problems unlike say a car manufacturer that releases a faulty product, which leaves what exactly... reputation that takes a hit? But every vendor has bugs and security issues and the market isn't really punishing anyone.
Is the future effectively an enormous government subsidy to profitable corporations (i.e. NSA and other US government agencies basically become extensions of corporate America's QA department)? Is the future heavy regulations to create the proper financial incentives and/or penalties so corporations start seriously spending on security?
It's easy to say "the government should do something!!" but what exactly will that look like?
The reason we're vulnerable is because we're unwilling to pay the cost of finding the exploits but people in developing nations ARE because they work for "less".
Right now our economies and systems reward those that fly by their pants and don't care for security. That is the problem. The free buffet of infinite growth from technology startups is the very thing that also gives us this pain and we need to learn to eat less.
Can you imagine the outcry if a new Linux fork had to seek government approval in order to post their distribution?
Can you expect Google or Oracle to fail to lobby the government to make sure they don't have to get each major revision certified?
Critical infrastructure, IMO, should:
- not use general purpose operating systems
- maybe not use general purpose computers (just build custom FPGA logic to control power grids and stuff)
- not use internet connected computers
- maybe not use computers at all when possible
When we're trying to protect ourselves from the vulnerabilities hoarded by our government, I think that asking them to regulate the OS might just be a step backward.
I'm not sure why we collectively decided to lack courage, but it's unsettling.
In this case courage is stupidity. Why waste time knocking out their power when we can spend that time making our power more secure. You're like a web master with a downed site due to a DDOS going:
> Well I've DDOSed the attacker's site so its okay
no its not, you've achieved nothing. Get with the program; this is a defence world not an offence one.
My mind is open. Convince me. Why is it a good idea to remove the threat of retaliation from our toolkit? It seems like one of the most persuasive reasons not to attack us.
Just put all the effort into keeping the grid up. Absorb all attacks and then export that IP and tech for healthy profit. Its the only winning move.
You're acting like the power grid going offline is equivalent to a thermonuclear explosion. Yes, it will suck, but it's temporary. And afterwards, those exploit vectors will be patched.
No its not, its the whole point. The point of the age of information is that it is a departure from the age of blood and steel. The tactics of blood and steel that you are supporting have no place in this future and are counter-productive. The point of the age of information is that power is no longer solely in the hands of nations. Therefore treating it as a case of "stomping on the bad people" means your attack spread increases from all the nations in the world to all the people in the world. Added to that the evidence of those attacks can and will be forged. You're chasing shadows and its not worth it. Just build a better shield, that's all that matters.
Or post-apocalyptic.