The main issues I see with this is, rather than just "I don't trust the government":
1. They'll do a scan of all devices then ask the ISPs to provide customer information for the vulnerable IPs found so that the government can contact them. So now you'll end up with a big fat list somewhere with names and addresses next to known vulnerability and that list is bound to leak sooner than later. See "My Number" (Japanese equivalent of social security numbers) leaks recently.
2. This makes for great phishing. All newspapers and TV channels have said you might receive notice from the government about security. Now you just have to send emails or letter claiming to be the government, saying "we have found your network to be vulnerable, please run this program to clean it up" and it's way more likely people will run your malware. FREE Advertisement provided by public funds!
Yeah, people don't trust the government. But most of the conspiracists are convinced the government is already secretly accessing their home devices (or trying to). If that's your belief, then really, nothing has changed!
I feel very differently, especially if it's a government whose "expert" minister doesn't know what a USB drive is:
https://www.theguardian.com/world/2018/nov/15/japan-cyber-se...
True, and while I understand that high level officials do not necessarily need to be able to write code or explain the difference between public and private key crypto, they should have a base level of understanding to make decisions on the materials prepared by their employees.
I don't think someone who isn't familiar with the concept of a USB drive is at that base level of understanding.
EDIT: but "Gpetrium"'s statement is actually still correct ("a department can still be functional and even successful if their boss listens and applies the ideas offered") - maybe from this perspective it's more a "must" for a successful manager, but, after the "listening" comes the "judging" and that MUST be based on own know-how.
1) don't do it at all. Vulnerable families remain vulnerable to organised crime and we have systemic weakness to state and/or vandal attack (worms, botnets or whatever else.)
2) Government does it, in public, performed by public servants, with appropriate guidelines that are enforced under pain of criminal prosecution. This has the opportunity to shame and possibly sue ISPs who provide default routers that suck giving indirect systemic benefits.
3) Private enterprise does it. Facebrick and Gogglers being the obvious candidates who one would think would just love to get in there, probably with the same checks and balances they've enjoyed so far.
4) Some rumsfeld style unknown unknown, beyond my limited imagination - really keen to hear if anyone has an idea here.
I absolutely agree with you that the number of people in positions of power who are completely f&^ing clueless about the domain over which they make decisions is astounding and a huge, massive problem. It still isn't required to have someone who knows what a usb drive is on your board of directors while they sign billion dollar contracts with Oracle, IBM Global Services, Accenture and whoever else has the best con, for example. Same for public service IT consulting contract ripoffs of which ripoffs utterly dominate the space.
So the "expert" minister thing you raise is really bad. Just as you say it is in fact and must be remedied across the board in all countries.
And I'm still going with (2) govt. doing it, with public scrutiny as the best of the available options.
It depends on what kind of actions they wish to do with the resulting scan/hack.
If they offer services to secure people/companies free or cheaply, then its a overall large positive.
If they give it to their equivalent NSA apparatus, that's a major bad.
Vast majority of Internet users are not security savvy. Doing a baseline scan with appropriate remediation guidance will go a long way.
I'm pretty sure security researchers will set up honeypots and monitor what the government probes are doing.
I'd trust any democratic government doing a preventative security scan for vulnerable devices, over some hacker who's only out to exploit them for personal gain.
Most people have never patched their router nor even know how to. Someone needs to proactively inform that group that they're vulnerable, at scale, if we're even going to have a chance to solve a lot of network problems.
In the United States, I'm inclined to think that the former has already taken place and the latter will only happen after an extensive FOIA battle and enough years to make disclosure useless to the average citizen.
What do you mean? Is it not the case that in some countries encryption, let alone hiding anything from the government is illegal?
I feel the complete opposite way. The government having access to my things is worse than cyber-criminals having access to my stuff.
Cyber-criminals, on the other hand do not have the power to exercise physical violence over you, they can only harm you in non-violent ways.
Practically speaking, you are more likely to be harmed by cyber-criminals than by your country's state, but if tomorrow there's a new law against certain political ideologies (not uncommon in third world countries), or against encryption, or against privacy and they happen to know that you're interested in those things, the consequences could include physical violence.
There is a philosophical point to be made about one's right to willfully violate what are considered best practices (eg toad.com), but we're not debating penalties for running "insecure" devices. The sheer majority of vulnerabilities they find are going to be due to straight cluelessness.
I trust my government more than Facebook or Huawei. Open source or neutral 3rd parties don't exist for this kind of thing.
It’s why I don’t worry the medication I take is not genuine, why the water that comes out the tap is safe to drink and why if I get run over I’ll get medical treatment.
It’s why I can walk down the street without unduly fearing I’ll get robbed etc.
Blind distrust is as silly as blind trust is what I’m saying here.
The government taking cyber security seriously is a good thing if you trust that government and the Japanese government is pretty good in that specific area.
Also given that Japan is a regional and major economic competitor to China which along with Russia and the other major powers is currently waging and undeclared series of wars in the global networks it seems like a pretty smart move to me,
"Japan's cyber-security minister has 'never used a computer'"
https://news.ycombinator.com/item?id=18459016
As for medicine, water and medical treatment... Your government makes the medicine, your government runs the water company and your government runs your hospitals? Seems like a recipe for disaster. Just out of curiosity, what country do you live in?
Yes. Japan is a regional and major economic competitor to china, russia and korea and the US. But what's your point? They are also a major trading partner to all those countries.
Sure, blind mistrust is bad as blind trust. But there are plenty of reasons for people to distrust governments. It's why we have rights to protect ourselves from the government. And the last government I'd trust is the japanese government if I were the japanese people considering how they were so willing to throw their citizens lives away on kamikaze missions and endure endless firebombings and nukes.
I agree with you 100% and up voted you too. Furthermore people speak of "Government" as if it were a thing--akin to say an apple, as opposed to what it is in reality: a random group of random people with possibly, if not probably, virtually unlimited ideas on the nature of what the citizens under their thumb (or hopefully stewardship) have the right to see, hear, think, say or do.