> It's even a truism now that computer defence against a well funded nation state is hopeless.
It's interesting how many of those same early hackers [1] went on to working for those same governments or selling them exploits/offensive tools to make sure this stay true. None of that could have been accomplished by any gov without real legitimate talent joining on. Especially in the early days.
Largely because the governments of the world decided they were far, far more interested in the offensive side because of the mountains of intelligence they were getting. Which then filtered down to industry to where all the money, fun, and very importantly, how much easier it is to break something than to protect it. Or maybe it was a side-effect of all the vast majority of talent/money going into the intelligence community and defence contractors instead of just the "government" in general. Probably a combination of both.
The talent that did end up working on the defensive side (that was actually useful) was, and is, usually some super complicated and expensive systems that only big companies could afford. And/or you have a major budget to hire, or pay consultancies, with equal/superior talent than the adversary. Which leaves out the vast majority of companies and almost all civilians with useless or negative utility anti-virus software, or nothing at all besides the odd operating system, software, and public crypto progress.
That's not to say great strides haven't been made on the civilian side in recent years, since the public has caught on to the true scale of the surveillance/offensive stuff and the implications that has given the general weakness of the technology we use everyday.
The significance of WhatsApp adopting Signal's E2E, Telegrams popularity, and people moving to iMessage and other encrypted non-SMS text, emailing properly adopting transit encryption, and the Google TLS charts [2] reaching ~90% from around 40-60% only 7yrs ago is a really, really big deal IMO.
[1] https://www.wired.com/story/cult-of-the-dead-cow-at-stake-ha...
[2] https://transparencyreport.google.com/https/overview?hl=en