Bombs vs. Bugs
edwardsnowden.substack.com
edwardsnowden.substack.com
I don't see how prohibition would solve the problem here, people would just sell it in [insert rogue market].
Raison d'être is not trade, it's demand, and demand doesn't care about the DOJ.
Also, exploits aren't just an arbitrary good, but a tool of power themselves, so effective prohibition seems even more absurd.
What am I missing?
I suspect that distinction is what you are missing.
The Manhattan project consumed 10% of the total US energy output in the mid 1940s. And obviously uranium is hard to come across.
Also, unlike software vulnerabilities, nuclear weapons don't have a half-life counted in weeks.
NSO style products are used by one entity against another entity. As a result enforcement is a fundamentally different sort of problem. There is a complainant.
This is such a shallow comparison, which seems to come up with every discussion around criminalization. Law enforcement isn’t 100% effective but that doesn’t mean every criminalized activity should be legal.
This is a specific form of a general argument against any law - "people would just break the law by [insert a way to break the law]".
These arguments are obviously generally true (any law can be broken) but you usually don't need an absolute victory, just a legal weapon against the bad guys, which hopefully is hard to use against the good guys.
Mind you, the genie is out of the bottle. A half-hearted moratorium is unlikely to undo what Pointexter wrought.
- things that are in itself bad. (E.g. killing, stealing, ...)
- things that are neutral, but could be used to do other illegal things (encrypted message, selling weapons, ...)
The second category of things doesn't need to be illegal since the perpetrators would only be doing something bad if they violate a law for the first category and therefore can be prosecuted for that. But making it illegal prevent the potentially good use of it.
Strunk and White sounds "old" to many modern ears.
Williams': "Style" is hands-down the best modern guide. https://sites.duke.edu/niou/files/2014/07/WilliamsJosephM199...
There's nothing wrong with an individual style to writing and speech, but editors can help push authors towards a more uniform standard.
> One of the interesting things for me about this shared space of ours is to be able to see what it is that you most enjoy
This is pretty clearly a backwards way of writing a normal American English sentence.
> ... to witness indicia of that ...
> ... the ultima ratio regum of a state that has exhausted ...
> ... which is the raison d’etre of the insecurity industry ...
> Though my relationship to time fluctuates, the gravamen of my disclosures remains constant. In the past eight years, the depredations of surveillance have merely become more entrenched, with the capabilities that used to be the province of governments now in the hands of private companies, too, which employ them to track and tether us and attenuate our freedoms.
I really believe that it's not in the US government interest to increase computer security.
I think the NSA is at least 5 or 6 steps ahead of the security game, so for now the NSA dominates cyber warfare, which is why they don't want more security in software, so they will constantly make everything possible so that software is insecure.
But at some point, it is going to sting because China, Russia and others are catching up.
I always found it weird that there are a lot of security standards for other industries, OSHA, etc, but for software, there is nothing, no companies are required to comply to software security standards. No software is being inspected at all. Isn't it weird?
Agreed. It's just doublespeak[0]. We all know it's the National Insecurity Agency, and that the NSA hoards & stockpiles 0day. They very rarely release tools and research papers designed to strengthen our IT infra, since they sit on so much 0day. There's no balance.
I don't buy that they're 50% red team, and 50% blue team. More like 99% red team and 1% blue team.
NSA isn't.
There is no lead, and the barrier for entry is at a historical low.
Many people just don't bother because it's boring, not because it's hard.
Breaking into stuff became so simple that it just doesn't attract talent any more.
Can't speak for all, but look into things like the CISA[1]. I don't think they have much of legal authority over industries, perhaps in some deemed critical but not others, but to say there's no "standards" is a bit wrong.
If the "use of exploit code" is protected then why bother? The law would have to prove an unauthorized use or "for-profit exploitation" of code, and at that point it doesn't matter if it's exploit code; any code could be used for unauthorized use.
Worse this would put corporations at the center of what's an exploit. Every time a company makes software there could be someone arguing that its an exploit or makes unauthorized use (of info or computing). Companies already avoid the GPL when they can because of legal FUD and this would extend those fears to all software they release. The Sony CD rootkit [0] was clearly over the line but what of iTunes encrypting local music files? Apple locked you out of your files by encrypting them and then offered to sell you the key -- sound familiar?
[0] https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...
Commercial trade isn't the right definition. Exploit code is: using or bypassing an API in an unintended manner (for the benefit?, or to the detriment?, of the owner.)
Yes, and? That is malware/cyberattack and should be subject to felony prosecution.
Did Apple actually do this? Locking people out of files they already had without DRM?
Too soon, man, too soon.
On the other hand, once an exploit is used against a _good_ actor, they can neutralize the use of that kind of "bomb" against anyone.
I'm searching for a good comparison about mutating codes and innoculations against them...
If Saudi Arabia has to develop their own 0-day spying toolkit instead of buying one off the shelf, then at the margin they will be able to do less spying.
There's nothing stopping Saudi Arabia from setting up their own team to build such hacks, but it would cost them more. Further down the road, there's nothing stopping a bunch of smaller countries from teaming up to get the economies of scale that NSO brings by selling to multiple countries -- but these toolkits seem to be the sort of closely guarded secrets that even allies don't share (if the NSA is anything to go by they are more likely to use these techniques to spy on their allies), so I doubt that is very likely; could be wrong on that point though.
He's a traitor, plain and simple. But he parlayed that treachery into a highly lucrative position, where he occasionally comments and gets paid to speak on some obvious points about whatever is in the news, and is now seen as some kind of guru when he never really did anything of note. He's not a computer scientist. He's not a security expert. He's a cause célèbre for certain factions of people who would like to see the US knocked down a peg.
1) The NSA was illegally and unconstitutionally spying on US citizens without warrants.
2) The NSA and other intelligence agencies explicitly lied about this to congress and other elected/appointed bodies responsible for overseeing the activities of these agencies. See, in particular, James Clapper perjuring himself before congress.
3) Without Snowden or someone similar leaking this information to the public, we never would have found out about these blatant illegal and unconstitional acts, since everyone with the power to do anything about it was either complicit or ignorant (see point 2).
> He's not a security expert.
Which is such an incredibly vacuous statement that you deserve a downvote for saying provably incorrect things.
Where's the research? Where's the white papers? Where's the detailed technical blogs of some security related issues he's handling?
The guy is an impostor. He's been an impostor his entire life. He's just highly intelligent and really good at it.
Correct me if I'm wrong, but isn't the oath they took to defend the US Constitution, against all threats, foreign and domestic?
Snowden literally fulfilled that oath at great personal cost.
Your friend, on the other hand, is an accessory to enormous (and ongoing) crimes against every man, woman and child in America.