Google’s top security teams unilaterally shut down a counterterrorism operation
technologyreview.com
technologyreview.com
By the same token should we we also consider it reasonable for companies Huawei to avoid fixing security vulnerabilities being exploited by governments like China and not consider them to be deserving of having importation of their products blocked on this basis?
I don't think other countries would necessarily want to use google products if they are intentionally leaving security vulnerabilities open, so maybe it is better that all companies fix all security vulnerabilities they find?
"Country A can do it, but B can't because A is X and B is Y" is not an acceptable solution IMHO.
Standards like transparency, rule of law and a clear separation between corporations and the government should be uphold completely independent from the fact that this isn't done exactly as rigorous everywhere on the planet.
It's a relatively new (and IMO flawed) idea that western democracies should corrupt themselves just because non-democracies exist.
I think it's rooted in insecurity over the long term superiority of democratic institutions. This might lead to western democracy being perceived as something you do not because it's strengthening the country but because you want people to enjoy it as a luxury as long as the country can afford it.
I think that's wrong and will surely be out of fashion as soon as more prominent autocratic regimes fail to deliver as consistently as they currently do.
The ghost of Henry Stimson would disagree.
It's not rooted in 'insecurity of the belief in a style of government' it's rooted in basic security measures. Western nations spy on other nations as a matter of national security policy much like they invest in early-warning satellites.
The 'corruption' stems from the type of authority that drives the activity, their motivations, and what they do with the power.
Fixing a software bug or vulnerability is unequivocally good, and the sooner the better, regardless of who thinks they need that bug to make their global manipulations a little easier. The realpolitik BS is just too easy of an excuse for any monstrosity, and the blowback is always worse than the immediate problem.
While I don't doubt that in reality, erring on the side of closing it is probably the right thing to do, the fact is we don't know.
If the vulnerability is being used to thwart a rogue entity from developing nuclear weapons, the balance of facts may be on the other side. At very least, Google should have worked with agencies on getting it closed down.
If they were using it to make a drug bust, when then who cares, shut it down.
The rogue entities on this planet already have nuclear weapons (and no, I am not talking of North Korea). A widely overlooked fact is that the nuclear non-proliferation treaty obliges the nations with nuclear weapons to get rid of them[0]. This part of the treaty has never been uphold.
[0] https://en.wikipedia.org/wiki/Treaty_on_the_Non-Proliferatio...
There are no 'rogue entities' with nukes outside of N. Korea unless you consider Pakistan to be 'rogue', or, their benefactors, Saudi Arabia who undoubtedly have access to the tech the moment they need it to be ... but they are not 'rogue', or rather, the action would be widely condemned but a different story altogether.
Iran, would be a 'rogue nation' trying to get nukes, which they have signalled they are trying to do.
A wayward state or quasi-independent province in the Caucuses, the M/E or Africa would be that as well. Or of course some legit terrorist group.
And it would have nothing really to do with non-proliferation obviously.
If the US was trying to thwart Iran from getting nuclear weapons through some back door, then it frankly would be in Google's best interests to help.
The notion that large corporate entities can exist in a geopolitical context and yet somehow ignore it at the same time is nonsensical. Once you are 'Google Scale' your piece is on the table and you have to play.
Edit: to put another way - Google's very existence is protected and enabled by the US Economic and Geopolitical situation in a tangible way. It's not abstract at that level, like it would be for a small company.
Remember how we thought of US Army in Iraq as 'Exxon's Army'?
Well it's 'Google's Army' now ...
I think it not only acceptable but incumbent to hold yourself to a higher standard of behavior than the lowest common denominator. "An eye for an eye will make the whole world blind."
(There's also a practical reason: China is much more effective at their approach than the US is, being much more experienced at it and also having stifled internal debate about it. If the US gives up its claim of being a morally superior employer than China, why would anyone skilled want to keep working for what will inevitably be the losing team?)
It can be anything. It's intentionally X & Y, not X & !X or a more concrete word. Put whatever you fancy. Democratic, White, Sunny, Oreo...
I don't take sides or make a suggestion. I do not suggest that we should go to the lowest denominator but, we shall aim for much higher. OTOH, entropy loves lowest common denominator and drives everything down. Lowest prices in cost of quality. Chaos for minimizing energy, etc. We're trying to reverse natural chaos in many areas and it's worth it IMHO, btw.
For the same reason there are no country names in my comment. Fill the ones you want. My comment implies nothing. It's the readers' bias which puts USA/Russia/China/Moral/Ethical/Democratic/Totalitarian.
I see a lot of polarization in the world and everyone is claiming to be the good guys. We can improve when we accept that we're only guys and work upwards from there.
I am unconvinced that abandoning the attempt to be the good guys will lead people to be good. I believe it will only allow people to be bad guys without feeling bad about it. While claims to be moral have of course been used by many bad guys through history, the correct response is to argue convincingly that they're immoral, not to give up the idea that morality is a worthwhile standard.
Or, in other words, I believe morality is qualitatively different from any of those other categories you list. If a store chooses to sell Chips Ahoy instead of Oreos, that's just a question of taste; if a store chooses to sell cookies filled with razor blades and arsenic instead of Oreos, that's a different matter entirely, and we are not obligated to accept it because we've accepted that stores can sell Chips Ahoy.
I'm not suggesting abandoning the intention of being the good guy. Instead, I suggest to stop using it as a shield or plausibility cover for misdeeds. Instead I suggest the viewpoint of "Hey, we're trying to be good, but we fail sometimes. Let's accept it and collectively try to construct a better good, which is fair and equal to everyone, as much as possible." I think this is workable and can be iterated upon to make a better world (I know it's very hard, but it's not impossible).
Morality and ethics is universal. They're hugely important values to build upon, but interpreting them according to one's desires or in a subjective light, without empathy, makes them hollow. Again, a lot of misdeeds can be conducted by abusing these very important values.
I deliberately don't give any examples, because the examples may derail the conversation and take the spotlight to the examples themselves. All possible examples and evaluation of them is left to the reader, as a multi-faceted mental exercise.
Hope this clears my intentions a bit.
(I originally read your comment as saying that it is unfair for country B to be enjoined from action M if country A is engaging in it, and I think other commenters did too. I do absolutely agree with the goal of collectively constructing a better good in a fair and equal way, holding everyone to that standard, and expecting that people will fail but it's worth trying to meet that standard nonetheless.)
Also Somalia originally wanted to split in multiple countries and NATO interventions happened to prevent that and force them to remain only one country, and remain in Civil war
How the EU member states act towards parties outside the EU seems a bit beside the main point: that the EU itself actually is about international rules and not a cover for violent actions between the various member states.
The "rules based international order", on the other hand, is not voluntary. If the US decides that you are in breach, then it will be rectified with hard power. It's simply an abstraction for hegemony, and you don't get a choice to parcipate or not, the choice is made for you by the hegemon (which also happens to be its enforcer).
The "rules based international order" is supposedly the body of international laws and customs as well as their enforcement internationally, and is what the US uses to justify their hegemony, placing them as the guarantor of this order - while themselves violently breaching it.
It's also called the "US-led international order" or the "liberal international order". Put simply, it's the US and its allies enforcing a set of rules internationally with violence or the threat of violence (or economic sanctions)
See: https://en.m.wikipedia.org/wiki/Liberal_international_order
Furthermore, let's create economic programs to build a baseline nuclear arsenal in every country. That'll prevent a lot of wars.
Some countries will object to that. Why?
Isn't everlasting peace much better?
Edit: Do I need to point out that I'm not writing these comments in support of war, but with a desire to spark a thoughtful conversation?
At the same time, I feel like there's still something there. Having nuclear weapons makes existing states much more resistant to opposition. Other states can't topple them in the traditional way because of MAD.
But neither can local freedom fighters -- suppose pro-democracy forces took three major cities in China and started using them as an industrial base to wage a conventional war against the regime. The US and anyone else couldn't really help them the way France did the nascent American Revolution, because of MAD. And if they actually started winning regardless, couldn't the dying regime nuke the rebel cities?
If we don't want people to live under permanent authoritarianism, maybe we still need something to level the playing field.
Though it doesn't necessarily have to be nukes; establishing uncensorable distributed communications comes to mind as an anti-authoritarian power. The fact that Western countries aren't spending billions to comprehensively subvert the Great Firewall is a significant strategic failure.
I have strong opinions in this matter.
The GFW is only possible because of metadata leaks that Western countries are exploiting too, for security and surveillance, or whatever.
Suppose Western countries start investing billions in subverting the Golden Shield, our own infrastructure and economy would suffer too.
A very naive but simple example:
I tried to train https://github.com/Kkevsterrr/geneva against a CheckPoint and a Fortinet ... It's not been fun for those "next gen firewalls", and CheckPoint is a NASDAQ-100, Fortinet an S&P 500.
'Nukes bring peace' mostly only if they are in the hands of a few major, stable powers, otherwise, nuclear proliferation probably is very bad.
These kinds of moral absolutions, i.e. projecting 'rights' into nations etc. (either we all have the right or nobody does) are pragmatically irrational.
Every nation is different, in a different set of circumstances, there's always some degree of moral relativism, but there's some degree of objectivity as well.
We have to balance the forces to figure out what to do in a complex world, and the rules may not always be so cut and dry.
Secondly, from the point of view of the US it's also stupid. The US enjoys influence in the world because it propagates a rule-based order, not because it exploits everyone it can get its hands on. That would rapidly lead to a breakdown of trust and in this case result in every country trying to displace American technology from its markets. Which the EU say, could theoretically do.
Please read my other comments below (discussion with geofft). This is not the idea I suggest. In fact, it's the exact opposite.
> Secondly, from the point of view of the US it's also stupid.
My comment contains no countries and/or adjectives intentionally. It's neither about US or adjectives attached to US. I'm talking at a meta sense.
Again, please see my comments down the thread. This is not what I tried to say.
The core of the whole discussion is here [0].
Both 'sides' will (and really already are) marshal private sector tech, media and social media companies.
non-aligned countries would do best to develop their own tech and media infrastructure because they won't be able to trust anything else.
I think slide into a Cold War could be slowed down by people working in those companies having and enforcing ethical and professional standards. In a case like this one it would mean blocking any hacking attempts that you can, irrespective of where they come from.
For social media companies it would mean devising rules about what content you will and won't allow and enforcing those standards whether the posters are from Russia, Arizona or Afghanistan.
Better than "their own" -- develop free and open source software that will do it even in the participating countries. Which their people can trust because they can see and modify the code, rather than having to trust you, a foreign power.
That subverts the domestic propaganda machine there by allowing the people of the participating nations to talk directly to one another without being intermediated by a partisan spreading propaganda and imposing censorship.
There are a couple of issues with it though.
Let's think about Signal, Twitter, Facebook and Tor.
The US government is putting increasing pressure on social media companies like Twitter and Facebook to shape their content.
US government funded open source projects like Signal and Tor allow for the spread of US shaped social media in countries that want to limit it.
So the propaganda machine thrives , it's just that it's the US one.
(note I like and use Signal and Tor, an against censorship in China. This is just one aspect of a set of complex relationships. Etc etc)
This isn't going to happen, it's already happening and there are plenty of public examples of it.
How is obligating big tech to cooperate with Western intelligence agencies a positive move for democracies?
[0] https://www.theatlantic.com/politics/archive/2014/12/a-brief... [1] https://en.wikipedia.org/wiki/1953_Iranian_coup_d%27état [2] https://en.wikipedia.org/wiki/List_of_CIA_controversies
The distinction that this article makes is that our clandestine operations have "democratic oversight." To be clear, I think the author would say that they are attempting journalistic neutrality, but they're giving considerable space to the argument that democratic clandestine services deserve a different standard.
It was likely if it was counterterrorism this is about a Middle-Eastern ally, such Israel or Saudi Arabia?
Neither of these are always US allies, only sometimes.
The Dutch were the ones who originally warned of interference in the 2016 election IIRC and had access to Cozy Bear for a while before that.
And the users of the exploits were a state actor that was friendly to the USA.
Which is effectively saying that wanting vulnerable software is a patriotic thing.
Especially calling it a "counter terrorism" operation. Where did the author of the article get that information from?
It seems like a hit piece.
The spooks reached out to reporters with approval.
I find it is unlikely information as sensitive as means and methods, with no seaming whistleblower spying on the people type motivation, would be disclosed by leakers without approval.
Strategic leaks like this are done all the time.
Though I guess there is precedent of releasing post-mortem facts like in the charges of the alleged vault 7 leaker.
I think it would leak!
At least having seen Google from the inside, I don't think Google can keep a nefarious secret.
A lot of the time it's mentally ill people like this: https://en.wikipedia.org/wiki/Liberty_City_Seven
They want you to picture Osama in these cases, when usually it's a bunch of buffoons.
They were just annoyed that their OPSEC failed to protect their exploits.
Allowing vulnerabilities to remain open/undisclosed because your government approves of them... for one thing, they aren't only useable by your government/allies, you don't know who else knows about them.
Our government's approach of finding security vulnerabilities and keeping them for their own use (instead of responsibly reporting them to get fixed) puts all our security in danger. There isn't much we can do about that (except, well, try to use our "democracy" to get the government to behave differently).
But in USA at least, private citizens can't generally be compelled to cooperate.
If engineers at a private company find a vulnerability, it should be responsibly dealt with to fix it. No matter who else knows about it or may be taking advantage of it.
I think it is unethical for a software engineer to do or go along with anything else.
What would happen? "Order of the US gov't" makes it sounds like serious legal ramifications would be handed out if violations were to occur. First, what would this look like? The CEO gets arrested? CTO? We've already seen that doesn't happen. The dev that pushed the change to fix the bug gets arrested, the PM in charge? Sanctions? Fines? All of this would have to have some legal standing in a court somewhere, otherwise, the offenders would have to be moved to some black site to prevent them from using any/all means to defend themselves.
In otherwords, it seems sort of like an empty threat and bluffing to someone not dealing with the stress of that particular moment.
NSLs are alive and real: https://en.wikipedia.org/wiki/National_security_letter
"Nacchio believes his conviction was in retaliation for his refusal to play ball with legally dubious NSA spying requests."
So, was he in jail for insider trading or violating an NSL? There's a difference between being convicted for violating a gov't order and someone pissed off at you to dig up dirt to put you in jail for something you did do. Lot's of people in jail believe they are in jail for the wrong reasons. Don't confuse my arguments as being in support of NSA systemic invasion of privacy. Just saying sometimes guilty people try to shift blame.
I understand the concept of NSLs. What I was really trying to get at is the fact that in all of the corporate shenanigans that have ocurred in recent times, no indivduals gets punished for actually doing the thing that was bad. The evilCorps get some fines levied or something similarly slap on the wrist level, but that's it.
If a nation state wants to railroad you—a single person—with the resources of the NSA/CIA at their disposal, how are you going to defend yourself? You could live off the grid like Crazy Ted, but that's an extreme reaction that most won't take, let alone a ceo of a major corporation.
The government is made of people just like you and me. Couldn't you see some folks in the national security state thinking a person was standing in the way of keeping America safe? Collateral damage but necessary.
I'm not saying it's good or should be allowed, but I can empathize with the mindset of that individual. Same thing happens with prosecutors/detectives when they get tunnel vision over a person that later is exonerated. They deal with bad people so often they become jaded by human nature and everything looks like a nail for their hammer.
2011: "New Evidence Adds Doubt to FBI’s Case Against Anthrax Suspect": https://www.propublica.org/article/new-evidence-disputes-cas...
Which is also a silly argument; enough security researchers will watch the updates/patches and immediately spot the vulnerabilities, then accuse Google of brushing it under the carpet and being in bed with govt.
Not patching is not doable.
Patching silently is not doable.
Vendors should do what google did. All of them.
But Google's blog post weren't just about the vulnerabilities so much as the hacking operation, which had exploited multiple different vulnerabilities. As for publicizing the operation itself, which was the real controversial decision, they went halfway on it, by holding back key details.
https://googleprojectzero.blogspot.com/2021/01/introducing-i...
(Disclosure: I work for Google, speaking only for myself)
What happened to MIT? Pressing charges against Aaron Swartz; pushing what seems like blatant intelligence community propaganda...
I genuinely don't mind that law enforcement and intelligence agencies (US or otherwise) would try to find and use these vulnerabilities to achieve goals. That's their job. They wouldn't be doing their job if they didn't do such things. (And, indeed, Google's security teams wouldn't be doing their job, either, if they didn't fix such things when they discovered them.)
I might even support Five Eyes' particular operation, here, if the sole targets of the exploitation genuinely are violent terrorists who massacre innocent civilians. But the onus is on them to not get caught by Google security when developing and deploying exploits. The onus isn't on Google to let people exploit their products and services, whether or not they may subjectively judge it might be used for a moral or "patriotic" end.
IC's job is to be sneaky and covert and manipulative. MIT's job definitely is not to be sneaky and covert and manipulative. I'm not saying they couldn't or shouldn't report on it and the debate over it, but the article is clearly framed towards a pro-Five Eyes exploitation, anti-Google security angle.
MIT has been very heavily funded by the military-industrial complex since the 1940s:
https://en.wikipedia.org/wiki/Massachusetts_Institute_of_Tec...
As the first sentence of https://en.wikipedia.org/wiki/MIT_Technology_Review says:
MIT Technology Review is a magazine wholly owned by the
Massachusetts Institute of Technology, and editorially
independent of the universityFor example, if WaPo had were instead named the Amazon Post (analogous to "MIT Technology Review") and had written a highly pro-Amazon article when it didn't quite seem merited, would you say that the ownership is irrelevant since they're editorially independent?
But more to the point, the closer analogy is an Amazon Post that claims to be editorially independent that publishes an editorial that's supportive of, say, Bashar al Assad, and people taking this to mean Amazon supports Bashar al Assad.
There are basically two logical leaps going on there: (1) if the editorial writer supports X then the paper must support X (historically not how editorials work) and (2) if the paper supports X then the organization that owns the paper supports X (not how editorial independence of a paper works).
True, that's a better analogy, though I'll try to make it even closer later in the post.
> (1) if the editorial writer supports X then the paper must support X (historically not how editorials work)
Indeed, but if there's only one single editorial about a certain topic, with no differing viewpoints expressed in any other editorial, it can potentially imply where the paper on average tends to lean. I can't find any other piece about it, at the moment.
Even if it's not an official position of the paper, who they hire and what they choose to publish can still be relevant.
The author: https://www.technologyreview.com/author/patrick-howell-oneil...
>Patrick Howell O’Neill is the cybersecurity senior editor for MIT Technology Review. He covers national security, election security and integrity, geopolitics, and personal security: How is cyber changing the world? Before joining the publication, he worked at the Aspen Institute and CyberScoop covering cybersecurity from Silicon Valley and Washington DC.
He's their cybersecurity senior editor, and a large percentage or majority of what he's written appears to cover US national cybersecurity topics. He probably considers this just another: Google would be allegedly acting against the US's cybersecurity interests, here.
The fact that he's who they hired to write about such topics - with no one else offering differing viewpoints, it appears - could imply something about the paper's leanings.
>> (2) if the paper supports X then the organization that owns the paper supports X (not how editorial independence of a paper works).
Yes, this is more of a stretch, but given some of the other stuff shared in this sub-thread, it doesn't seem that far-fetched that some percentage of MIT staff might feel this way.
It's possible it really does say nothing about the university, but let's say a hypothetical Amazon Post started spewing out a lot of these pro-Assad pieces, and there was evidence Bezos has had some large business deals with Assad or his regime going back decades.
Even though it says it's editorially independent, people would rightly start to question things. Given all the work MIT has done to support the US government and military, I don't think this situation is all that different. I think it could possibly hint something about the culture, there.
But I acknowledge that the second claim is indeed a pretty big leap, and I have no actual evidence to connect this reporter's articles or opinions to the opinions of MIT staff.
> it doesn't seem that far-fetched that some percentage of MIT staff might feel this way.
I can pretty much guarantee that some percentage of MIT staff feel this way, sure. I would actually be pretty worried if MIT had, as a job requirement, anything about feelings one way or another in this area.
And yes, there has been a significant presence of military projects at MIT in general, starting with work on radar and up through the present in the form of the Lincoln Laboratory.
What I am not on board with, based on the evidence we have, is the specific claim that MIT, as an organization, is in favor of suppressing reporting of vulnerabilities that the US government or some ally is exploiting. My strong suspicion is that there is no official position on it at the Institute level, and significant diversity of opinion on the matter among MIT affiliates when viewed as individuals, though I have no data to back up those suspicions.
Something about the slanted, biased tone of the article just really rubbed me the wrong way, whether or not it's a case of it solely being the opinion of this one writer and they just don't happen to have other cybersecurity writers, or a case of the paper having had this slant in general for a long time, or the unsubstantiated (and I think unlikely) case that any powerful people at MIT itself somehow had a direct role in the article being published or that the writer independently felt they had to toe the line with such people.
One of the times I perceived that I was being given the option to be read-in to some spooky stuff on a client site my view at the time was the IC should do their job, and civilian security folks should do ours. I said that they don't need us to compromise our work if they are good enough at theirs, it's an equilibrium. When I work for them, I'll work for them, but when I work for customers, I work for customers. The world doesn't need more compromised people.
I also didn't buy the "if you only knew/ticking bomb" arguments, because they know they have jobs to do and they aren't going to let some civvy contractor geek stand in their way. I'm sure I lost a lot of professional opportunity as a result, but you have to ask what it is you're protecting.
If companies who provide products that citizens trust are being subordinated to the IC to spy on them, just what does the IC think it's protecting? When the IC "misses" open secrets like Epstein's blackmail ring, human trafficking coyotes, compromised politicians, the total infiltration and compromise of universities and public institutions by foreign influenced operators, election integrity issues, and economy altering money laundering operations in plain sight, just what job is it they are doing again?
We need an IC and general guardian class certainly, but the point is to protect the integrity of the nation. Civilians and companies aren't game pieces, and if they are, I don't think the IC wants the accountability that comes with that.
Imo, Google made the right call in this situation.
From a systems security standpoint, no. This is the same kind of idealistic naivety that causes the FBI to advocate for weak encryption, or senators to call for "security only breakable by us, because we're the good guys".
Even still, Clapper felt compelled to lie to their faces. How many others have done the same?
The same security flaw that lets “baddies” pwn us, also lets us pwn baddies. The same indefatigable crypto that keeps us safe and makes online anything possible, also lets people conspire in secret to overthrow governments — heck, I remember reading the idea of onion routing that led to TOR was a U.S. military project to help anti-government activists in China, and even if that was just an urban legend, one team’s goodies are another team’s baddies.
I don’t have any good solutions here.
This is security vs security, and my weak fleshy hardware is vulnerable to exploding things owing to a lack of backup solutions, therefore if my options were perfect security for my body or for my data, right now I would choose my body, even though loss of data has the potential to be catastrophic.
That said, if it were up to me, police investigations would involve a lot more remote sensing tech instead of hacking… but I say that knowing even that isn’t a no-downside option, and I know that I am unaware of the full implications of police having the budget and power to spy on targets of their choice.
(I’m also in favour of radical decriminalisation of just about everything that can be decriminalised, because I think omniscient surveillance is unavoidable and I don’t want criminals using it to automate blackmail).
The solution is for state actors to move their resources from offense to defense. Imagine half of the NSA budget going into auditing software, both closed source and open source. (They already do that, but AFAIK nowhere near half.)
There is a quite clear and simple line here: the people breaking security for any purpose other than fixing security problems are the "baddies", and the people defending systems are the "goodies".
If some intelligence service decides they want to covertly exploit security issues, they have made their choice to be "baddies" and should be treated as such.
(Coincidentally, this narrative of "XYZ got hacked by ABC hackers, bad ABC!" needs to change to "XYZ got hacked, bad IT sec at XYZ!" - it's your choice to plug your shit into the internet, and your responsibility to make sure you don't get 0wned.)
In this particular case I can't follow this part of the reasoning. It was a counterterrorism operation using sophisticated exploit chains.
Would you clarify what's the bad IT sec? "nobody should use a browser"? https://1.bp.blogspot.com/-37hyk7hERGk/YFDuISGgCNI/AAAAAAAAa...
This naturally leads to a chronic gap between the state of reality and belief about the state of reality.
Also, I'm not sure the clear line is that clear. There will almost always be a tipping point for people for this type of scenario. If the hacking operation that was exposed would have prevented an attack that kills 1 person, was it still OK to expose? 100 people? 10,000? It's almost impossible to know what the exposure cost will be but if people die due to it and it becomes known, some people will rethink what the "right" thing to do was.
This type of stuff seems like it should be decided by elected representatives and not by some team of coders that work for some for profit company. It seems possible to me that the decision they made was based purely on what was best for Google.
I think we as tech workers need to acknowledge and understand the viewpoints contrary to ours and try to compromise with those on the other side. This type of issue is complex and I think we really need to acknowledge that there is no easy "right" solution to something like this. Blind idealism on both sides of the issue won't be good for either side or for society in general. We as tech workers are not infallible and we don't deserve to dictate rules to society just because we know how to write code.
But that's exactly what this is not. Every big and scary gun the enemy might have is also a big and scary vulnerability that you could fix. While it's infeasible to have "perfect" security, you can absolutely make the enemy's offensive tools useless.
It's especially bad since when working offensively, you're incentivized to not fix issues. That might be OK for black hats & nations with "questionable" ethics, but how is this a thing in any democratic country? When state agencies are sitting on exploits and purposely not working to get them fixed, that's IMHO a kind of treason on your own country. It's leaving entry points open for others to find. And anything you can find, they can find too.
> Also, I'm not sure the clear line is that clear. [...] prevented an attack that kills 1 person, was it still OK to expose? 100 people? 10,000? [...]
The line is clear, because that attack that the "goodie" western hackers couldn't execute, and possibly resulted in deaths, might as well be an attack that the "baddie" hackers couldn't execute, resulting in people surviving.
Systems are generally designed such that working correctly is the intended best state (even for weapons support systems.) More work going towards keeping systems within their design parameters (i.e. not hacked) should be the best way to save lives. Even if we're talking about some terrorist building a computerized IED, there are likely systems whose correct functioning can help save lives - maybe some chemical detectors at an airport, or first responder management systems, etc.
It's also the only line that can be drawn on an objective standard. Regardless of whether you're the USA, EU, China, or North Korea - "systems functioning correctly to their design" is an universal standard. Do you think North Korea cares about any life that isn't their bonzo supreme leader?
This seems contradictory. If its not possible to have perfect security, how are you supposed to make your enemy's offensive tools useless?
> It's especially bad since when working offensively, you're incentivized to not fix issues. That might be OK for black hats & nations with "questionable" ethics, but how is this a thing in any democratic country? When state agencies are sitting on exploits and purposely not working to get them fixed, that's IMHO a kind of treason on your own country. It's leaving entry points open for others to find. And anything you can find, they can find too.
Yes, it is an extremely gray area that is tough to find an easy answer to. Whatever ideals you want to stick to, the fact is the other side more likely than not will not play by your ideal/"right" rules. It seems like China and Russia have no plans on slowing down pilfering intellectual property and causing chaos in the US. Is it really a good idea for the US to throw down all offensive cyber weapons for some ideal? That would only encourage China and Russia to act worse knowing that they don't have to worry about repercussions from their actions.
> The line is clear, because that attack that the "goodie" western hackers couldn't execute, and possibly resulted in deaths, might as well be an attack that the "baddie" hackers couldn't execute, resulting in people surviving.
In this case, the article was about google exposing a hacking operation of a government that was trying to prevent terrorism. If the terrorists are able to kill people due to this government operation being shutdown are you saying that it was better for google to have exposed it just because security flaws are bad and should be fixed? It isn't possible to know for sure which side is "right" in this situation. If the operation would have prevented deaths with no collateral deaths on the other side, how can anyone say that preventing some bits on computers being moved in unexpected ways is better than having people die?
> Even if we're talking about some terrorist building a computerized IED, there are likely systems whose correct functioning can help save lives - maybe some chemical detectors at an airport, or first responder management systems, etc.
> It's also the only line that can be drawn on an objective standard. Regardless of whether you're the USA, EU, China, or North Korea - "systems functioning correctly to their design" is an universal standard.
Clean, well designed and secure systems are nice and all but I don't a large majority of non-tech workers will agree that this standard trumps every other consideration when it comes to a functioning society. It doesn't seem fair that some tech workers like clean design and they deserve to dictate what is right and wrong in society.
> Clean, well designed and secure systems are nice and all but I don't a large majority of non-tech workers will agree that this standard trumps every other consideration when it comes to a functioning society. It doesn't seem fair that some tech workers like clean design and they deserve to dictate what is right and wrong in society.
I didn't say "clean". I said "functioning correctly to their design". I'm willing to wager a "large majority of non-tech workers" would agree that things are preferably working rather than broken.
Twisting a statement like that is very much in the domain of Eristic Dialectic. Please try to reduce your usage of such tools.
In these discussions we should also distinguish between attacks by nation states and those by non state actors. It seems the argument for weakening encryption is mostly to catch or prevent illegal activities by non state actors who likely lack the sophistication to understand weak encryption fully. State actors would almost certainly know and avoid using weak encryption.
But it gets more interesting. Law enforcement is a perennial cat and mouse game. You catch today’s criminals harnessing weak encryption, the next generation of baddies will get smarter. The end result is weak encryption for everyone, without really helping society except to maybe catch the “current generation of baddies”. Advocates for strong encryption point out that this is an extremely short term and stupid thinking that destroys the protection offered by cryptography without really giving us all that much anyway.
On the completely secure systems end of the spectrum, bad people will take advantage of that complete security. You wouldn't have to worry about having your identity stolen, but I don't know how we would prevent bad actors like organized criminals or terrorists from taking advantage of those completely anonymous and secure tools. I'm also not too sure what living in an authoritarian regime with complete security would look like. Maybe dissidents would still have tools to fight the regime or maybe the regime would be better at controlling the population and squashing dissent.
I personally don't want government to do everything. Security is a trade-off and I wish more people understood this.
It's funny that it's being used as an argument for why 702 is good, because considering the scale of the operation it's almost laughable. Even more, how many of those points would have been exposed by old fashioned spying.
[1] https://www.nsa.gov/News-Features/Feature-Stories/Article-Vi...
In that context (chess) the final evaluation reveals a well executed attack is superior to a defensive stance. I suspect the same is true of espionage and war. In other words, stop them before they have the opportunity to get to your king.
Another hypothetical: Imagine a future event when, for whatever reason, a band of twenty criminals is intent on breaking into one hundred homes in your neighborhood. The twist is: You can’t call the police for help. Which decision would lead to securing these homes: Each family stays in their home to defend it or one hundred neighbors join forces to repel them?
On a more personal scale, think about jailbreaks/rooting, DRM, "trusted" computing, and all that other user-hostile stuff. The same crypto is also being used to enslave users and enforce monopolies, in which case the security flaws are a way to regain freedom and control. Leaked information is invaluable for the third-party repair industry. Who's the authoritarian one now...?
The world is definitely not black and white. IMHO, governments being afraid of strong crypto and viewing it as a (defensive) weapon are prescient. Why this fact isn't realised by more of the general population is indeed a real issue.
In principle a government can just demand businesses provide users with a “liberty” button that changes the root of all trust in the system. Even if technical reasons mean that button has to be pressed in the factory and its state is read-only forevermore, it is an option. Still secure, more liberal; if it is rootable regardless of this, I’d say it isn’t secure, because if a user can break in a hacker probably can too.
A lot of them were democracies.
It is rather unfair to describe me as cherry-picking, however: every comment I've made firmly notes that posting an extremely broad Wikipedia article was flippant and dismissive of _actual_ atrocities. Asking for examples of the article being overly broad, then dismissing the examples as cherry-picking, is blinkered.
You're an American; that makes you the baddies. Whether it's Syria, Libya, Yemen, Iraq, Afghanistan ... Laos, Cambodia, Vietnam..., American troops have run roughshod over the rest of the world for generations.
America is not in charge of the world. It would be a better world if Americans remembered this.
> also lets people conspire in secret to overthrow governments
About that:
http://content.time.com/time/covers/0,16641,19960715,00.html
https://en.wikipedia.org/wiki/1973_Chilean_coup_d%27%C3%A9ta...
Not so, but like I said: one team’s goodies are another team’s baddies.
But after reading the article i can infer that was not the intent here. Based on the article, it seems like the exploits were found because they (exploits) :
"caught the attention of cybersecurity experts thanks to their scale, sophistication, and speed. "
Notice the word 'scale' in there.
This ops seemed to not be targeting a bunch of guys in a mudhut putting together IEDs.
This was something scalable. With the potential to ensnare hundreds maybe even thousands of people...
We restrict law enforcement from using tools like Clearview for many legitimate reasons but there is no such restriction on crime that often involves the same reasons. Even something innocuous such as being in the vicinity of a certain area at a certain time coupled with better deep fakes will create headlines or fabricate evidence to sideline business deals.
I suspect we will be forced to move towards a world where people increasingly get a free pass for past behaviour and many crimes will simply have to be decriminalized for society to function. We are beginning to see push back for many whose careers have been ruined by so little as an errant comment and I expect change to spread from that.
The USA was founded on this principle, and the framers felt it important enough to enshrine in the 1st and 4th amendment. Some could argue the possibility of citizen overthrow helped keep corruption in check for the first 200 years (but probably no longer).
I don't think this property is an absolute (in all cases) bad property.
There shouldn't be any. There is no good or moral way to perfectly control a human population. Anything of the sort inherently degrades the human condition because it requires complete submission to authority. Since humans are corruptible, authorities are also corruptible. Therefore, it is vital that crime and insurrection never become impossible even if only to preserve the threat against authority.
Which is great in theory, but raises the question of how you identify friend or foe. Since they do it indirectly by "hallmarks" of the organization, all a skilled adversary has to do is camouflage their code to look like it's from a friendly, and then enjoy flying under the radar.
>"with potentially life and death consequences that go beyond day-to-day internet security."
So this is setting up "counter-terrorism" as some sort of special thing far beyond "day-to-day internet security". But the whole problem is that day-to-day internet security absolutely can involve life-safety issues. Lots of vital infrastructure SCADA is on the internet and ludicrously exploitable. Internet monitoring is now used for all sorts of medical scenarios as well. Even in business settings like hospitals we've seen ransomware and the like cause major damage, but lots of individuals make use of internet devices to empower their ability to have the elderly stay at home longer for example, monitoring for falls or other issues. And even with "just" finance, if someone's small business is destroyed and everyone laid off, that can cause plenty of dangerous ripples.
If anything, I'd say terrorism is near the bottom of my list of threats to my own life and those close to me, right along lightning strikes. Sure, they do happen, and taking some basic transparent precautions is reasonable. But it gets lots of attention precisely because it's rare. Like, the entire point of it is right there in the name, to terrorize people into doing damage to themselves that the attacker could never manage alone. Terrorism is an expression of weakness, not strength.
Am I the only one who doesn’t see anything here that tells you why he should be working for MIT Review writing about cyber security?
Google should thread carefully here.
But Google? Our intelligence agencies are already relatively unpopular (if you can trust the polls) [1]. I'm not sure that the US government could attack Google like that without serious consequences from the public.
[1]: https://www.pewresearch.org/politics/2018/02/14/majorities-e...
People are often all to quick to jump on "democratic country" as if its a simple definition of a country that is beyond reproach. The trouble is that modern politicians spoil that rose-tinted view.
Also who says a lawfully elected representative government might not:
- act unlawfully, to undermine democracy to make sure they will stay in power.
- act unlawfully for other reasons, there are many such examples in history
- the CCP is also a lawfully elected representative government, because they make the laws so that they are. So you probably mean not "lawfully" but something like "properly"? Also I for example would say a lawfully/properly elected representative government requires that all people can vote and there is real choice about who to vote for. Guess which country has neither? (USA,it removes voting rights from citizens under certain situations and as a winner-takes-all de-facto 2 party system has no real, i.e. no democratic choice when voting. And that is ignoring the fact that the citizens votes can be overuled by a small group of propel, even if they normally don't do so).
So as we take the idealistic approach, any hacking campaign lead by Western intelligence agencies or any initiative to weaken encryption are for most people "pure" in intentions, they're anti-terrorism, they're fighting pedophiles. But any enemy doing the same, China, Russia, NK, Iran, etc. are engaging in terrorism, authoritarianism. It's always very black and white because that's how people are educated.
The absolutely overwhelming majority of people are able to go about their lives every day never questioning how they can hold such dissonant opinions in their head simply because they were told "it's ok when we do it, it's bad when they do it".
And as you can see even the "democratic" approach has a chilling effect. The suggestion most people take away from a cursory parsing of the title or article is that Google acted irresponsibly. Imagine the day this point of view becomes prevalent fueled by the typical political campaign populism. Imagine people and companies being put off from touching the topic out of fear that they're branded irresponsible and unwittingly hindering anti-terrorism efforts because they're disclosing problems of general interest.
At least for Germany this is patently untrue. Our parliament is stonewalled regularly and they get away with it. And even in the US, the congress is being lied to with no repercussions.
https://www.theguardian.com/world/2013/nov/20/us-uk-secret-d...
Maybe they shouldn't base life or death consequences on something as capricious as the existence of an undetected 0-day. It's not just Google, what about other security companies, independent white-hats, etc?
The alternative is basically saying, "you shouldn't/can't improve software security, coz terrorism", which not only feels super unethical, but also likely a 1st amendment violation.
> In some cases, security companies will clean up so-called “friendly” malware but avoid going public with it.
Ah, this explains why if you follow security-related news, it feels like U.S. or “Western” countries never conduct offensive operations ever.
If the western government in question wants to hack vulnerable software - they can create their own vulnerable software, ship it and distribute it. No one - utterly no government - democratic or not has any privileged right to hack market software and services.
Try passing a law through both houses stating the US government has the right to exploit US companies - and watch the US economy collapse.
Apart from the fact that the article seems to obscure the fact of if companies actually know about the counter-terrorism operations (they somehow say people suspect it).
It also creates this myth of "democratic oversight" and we all know how much that's worth since Snowden. Also it constructs as if Google is in such a special position here. I mean the vulnerability could be caught by anyone theoretically. Also what is a counter-terrorism operation, monitoring some environmental protestors, what about political activists (of any colour), or does it only count if it's Islamic terrorists?
And then there's the whole "putting soldiers lives at risk" which gets repeated every time this comes up. As if we should accept every violation of privacy/human rights, because it saves soldiers lives. They are soldiers, it's their job. Arguably their lives have been put at risk by sending them on the mission.
The obvious question is: if some malware is on a public website, who guarantees that only the "bad guys" will be targeted?
If you don't disclose the 0-days, who guarantees that your own citizens won't be targeted by the same kind of exploits on the very same vulnerable devices?
If you purposely keep a backdoor open in a device, who guarantees that the "bad guys" won't find that backdoor and use it themselves?
Although I usually disagree with Google's decisions a lot, this time I can't see much wrongdoing in their action.
Counter-cyber-terrorism is a double-edged sword, because it's about placing landmines and waiting for a bad guy to step on them. But nobody guarantees that only the bad guys will step on them. So it's probably time to end this "but we can do it because we're the good guys" rhetoric: it's very easy to get burned when you play with fire.
So what the NSA has been doing (even after exposure by Snowden) has had "oversight baked in"? Who are we kidding?
This posturing, pretending that " the west is better than everybody else", is downright naive and idiotic. No organisation is pure of heart, moral, or ethics, and none have crystalline motives.
That's what a whitelist is for.
Can someone help me understand why this is a good thing? By the arguments presented by other commenters, it seems to me that a) these hallmarks can be duplicated by someone else and b) by only running operations with said hallmarks, the intelligence agencies might miss other vulnerabilities.
Secondly, I think it's fair to say governments absolutely abuse any vulnerability they can at any point in time.
The article seems to be suggesting that they should have left the holes unpatched, but that wouldn't work. Rival state-backed hacker teams do the same work that the Project Zero people do and would discover the attacks, reverse engineer them, and exploit them.
It came out (either from Snowden or from other reporting) that the NSA had a term, NOBUS, short for "nobody but us". The idea was that if they had a hack that was so tricky that they thought that no one else could exploit it, they would exploit it, and if the hole they found was "easy" they would share it so it could be fixed. But that's just arrogant: nothing is NOBUS for long.
The writer assumes that western / US-affiliated elections are universally, lawfully elected, and never the product of illegalities... while writing about likely-illegal operations by some of the very same people within those very same governments.
The Government is generally in trouble, because they all covered up a staffer being raped by another staffer in the office of the Minister of Defence (literally in her office), as well as a bunch of other scandals. She was apparently pressured not to report it to police for fear of losing her job. Again, no public body that will actually prosecute anybody over that, hopefully the outrage will be enough for somebody to resign and things will change next election...
At the same time, they keep ramming through laws that increase surveillance power while removing judicial oversight and requirements for warrants. Out intelligence agencies are also severely under-supervised, because while we do have a small agency of bureaucrats to supervise them, the Senate committee made up of actually elected people (the Parliamentary Joint Committee On Intelligence and Security) can’t actually review any past, current or planned operations, they can only look at the legal frameworks (and we just have to hope the intelligences agencies are following the law, and the IGIS actually does their job...)
Google is a multinational company with most shareholders (weighted by investment amount, not control) and most employees being from outside US.
That reads like a opsec vulnerability in the approach
That's the kind of self-delusion you only get from a power-hungry government official.
I hate to be that guy, but the holocaust was literally this. Nothing has happened since the 1930s that would make me feel safer around a government just because it was lawfully elected.
The Snowden files tend to show there's not a lot of oversight.
Doubt it. They frequently abuse their surveillance powers and spy on each other's citizens. Imagine what they do to a foreign national.
They should report it the same they report any other vulnerability.
Let's suppose some terrorists are working to hack into your and many other Teslas to crash them on the highway. Would you really prefer a CT operation continue to identify the culprits using vulns or would you rather you and your family crash into an overpass support?
Infosec doesn't exist in a vacuum; there are real-world consequences to thwarting legitimate CT operations due to a strict, unyielding adherence to a "patch everything right now" religion.
Sounds like un-nuanced, black&white nerd myopia (sorry fellow nerds). Ethics dictate that the greater good should be conserved rather than mechanically-plugging holes with blinders on, no matter the fallout. (This is the kind of flawed, idealistic, un-empathetic logic Rand Paul often wades into.) If the failure of this operation leads to mass casualty events or other deaths, then you know who enabled it.
The most sensible move would've been a cooperative agreement that these holes would be plugged in a fixed amount of time, say 2 months, so the operation could have other sploits ready while not exposing the average international user to risks for too long.
Secure systems that do what they say they'll do help everyone. The idea that there's some sort of obligation to keep security vulnerabilities around so that the bad guys can get pwned feels as vile as saying that there's an obligation to keep medical knowledge secret lest enemy soldiers learn how to take care of their health.
I hope this doesn't discourage Google's threat analysis team, and others, from doing the same in the future.
The justification for not intervening is weak too - after all, we only have this article's word for it that the targets were 'terrorists'. They may well just have been freedom fighters, like Nelson Mandela was.
Won't terrorists go after you now? Close the exploit, or be mortared. You go to the feds. They say: Oh! I can't get to that now!!! My phone says I need to update!
Even if Google is legally obligated to ignore cyber attacks by allied nations, who's to say that they are even capable of accurately attribution?
1: https://www.zdnet.com/article/fortnite-epic-games-ceo-rails-...
That’s a bit too conspiracy-minded; it’s almost certainly just an accident of history. It’s certainly convenient for black-hat and national security types though.
How long until some congressperson finds out about Rust, though, and decides it’s a threat to national security since software written in Rust has many fewer security vulnerabilities.