U.S. tightens export controls on items used in surveillance of private citizens
commerce.gov
commerce.gov
Blue teams with a $1 Billion/year budget can not prevent total compromise by red teams with a $1 Million/year budget. If you must outspend you attackers by 1000x you are doomed.
For instance, in 2015 Microsoft committed to spending $1 Billion/year in security research and development to securing their cloud, the second largest cloud in the world [1]. What is the result of such spending? A little over a month ago the default management agent they ship for managing Linux on Azure had a security defect that allowed local privilege escalation by sending an empty password [2]. Their processes are so bad that despite spending $1 Billion/year they can not detect and prevent themselves from releasing security 101 defects in default installs of widely deployed products. This is indicative of a grossly inadequate process in much the same way that a car factory delivering cars with no brake lines would indicate that factory and manufacturing process needs to be completely redesigned from the ground up and the entire team overseeing it replaced.
The outrageous part is not that security is not being funded, it is that organizations and systems displaying such fundamental errors continue to get vast sums of money poured into them.
[1] https://blogs.microsoft.com/blog/2015/11/17/enterprise-secur...
[2] https://www.wiz.io/blog/secret-agent-exposes-azure-customers...
One example, many popular frameworks. How do you audit every single piece of code brought in by, say, laravel? And how do you do it, if developers want to be able to reuse code?
Answer? You cannot. At all. You can't even reliably handle license compliance.
Yet, we use such frameworks, because security is not first, or even last sometimes. It's not part of the process, it's a thing to think about when a dev, a department has free time.
Many companies have a security team, an audit team. What?! You don't get secure by having people look at security after development, and then spend time fighting over fiscal concerns, to get a code re-write.
I think none of this will ever be fixed, until the CTO position becomes like the CFO position. Mandatory requirements, jailtime for CTOs if they breach certain regulations, and the authority for a CTO to tell everyone from board to CEO "no, thing X will be done".
Yet no one wants that, because of cost, and a desire to get to market first.
Developers waste plenty of time (we're all on here chatting away for one!) but ask someone to even think about security seems to offend them in the way that asking a teenager to clean their bedroom would.
Now, with 20k node packages pulled in as deps for a couple of 10 line libraries, or with 100s of phars as deps often for 10 line composer sourced libraries, you often have almost no eyes on for that code reuse.
Devs just indiscriminately pull stuff in, don't care if a package is unmaintained, or was written by someone for fun 5 years ago and abandoned.
This model isn't sane code reuse.
At least with code written by an on site dev, one can have code reviews, sign offs, etc.
None of this even touches on things like hostiles taking over packages, either.
I'll put this another way. Do you audit every single non-core package installed from random sites, at each update, and all its dependencies?
Or, do you even audit each package, all deps, to make sure the project is active, and seems to have a competent admin?
Because code reuse logic means lots of eyes, and abandoned stuff, low use stuff doesn't jive with that.
Sure seems like a 1000:1 problem to me.
Seismic, Infrared, Radar, and other monitoring systems could be deployed and ALL land crossings would be known soon enough to stop anyone crossing. Of course, a shoot on sight order is the part nobody has the stomach for, nor should they, we're not at war.
Naval patrols could greatly curtail routing around the ends.
Capability based security could greatly curtail the leverage you get from access to a given computer. The current default access systems we're using everywhere are about as effective as building a fortress out of crates of C-4 explosive.
That said, I don't think any sane person would favor using things like SM-70 directional mines to secure the American border. We can make a dent on illegal labor and more importantly get some idea of who these people are without resorting to the tactics of the DDR.
Assuming you are referring to the United States, even if you deployed all of those sensors at all crossings, it would not be sufficient to deter crossings; those only provide detective capabilities. Yes, you would radically increase the number of people guarding the border, but that would also require a radical investment in enforcement, and such an investment would bankrupt the country for no real practical effect. Even if you did fund and build it, the maintenance costs of preserving the effectiveness of such a land border along the northern border with Canada means protecting a nearly 9,000 km border that about 200 km from the West Coast turns into extremely inhospitable to hostile terrain and climate for a minimum of three to four months out of the year. This terrain is absolutely awful to stalk and patrol in, but is a pleasure to sneak through (at least I really enjoyed it back in my hunting and military training days :D)
It is not feasible to scale the navy to the point where it would be practical to prevent access to the continental United States, for example, let alone the island territories. Attempting to do so would bankrupt the nation. Hell, modern technology can't even reliably prevent folks from bobbing over from Cuba despite the relatively small attack surface there.
Even if you managed to invest more than the current percentage of GDP (which is already ridiculous), you would also have to confront an increasingly hostile domestic population who is used to freedom of movement, is already paying punishingly high taxes in contrast to the value and benefit they receive for them, and rapidly diminishing quality of life.
Good luck with that!
Oh, and one last note about capability based security - it works great in lab and somewhat small environments, but I would appreciate a practical explanation of how you would scale up capability based security to an environments operating in 87 distinct countries (with disparate regulatory requirements that preclude centralized management), 3600 offices, and 800,000 employees, with approximately one third of those employees having employer managed devices, notebooks, and managing a total of 2,300 distinct software applications (granted it's been about 14 years since I worked in that environment, but that company has grown substantially since then).
I'm listening for a real, practical suggestion here, not being facetious.
However, if adequate security is actually important, such as when lives are at stake, these methodologies completely fail to fulfill such requirements. This is not merely the case when tackling the hard problem of large scale systems, where it might be forgiven to be unable to solve the hardest problem available, it is the case at every scale. At least capability-based systems have demonstrated adequate security at a usable scale, the prevailing techniques can not even do that. There is little reason to believe that abject failure at scale and an inability to solve any interesting sub-problem or smaller scale problem is a better way to success at scale than attempting to scale small successes.
I can't say which organization it was, or when it was, because I maintain enough of a public profile that it could leak specific information, but while doing a security consulting gig for a major global financial organization between 2001 and 2011, the team I was working with identified numerous serious concerns. The client company agreed that they were real risks, and even likely risks, but the financial impact, even if those risks were realized multiple times, were far below their documented thresholds for risk tolerance. In other words, the individual risks would have had to exceed $10M in impact per year, for multiple years before the financial impact of those issues would justify the massive cost of investment to remediate the risks. It's not that they didn't take them seriously, but the cost of the new system in development, which included addressing those risks, was so high that starting separate remediation efforts that would detract from those in progress changes introduced risk of the main replacement project failing. It was easier and lower risk and lower cost to just accept the impact of fraud, including compensating victims, than to try to fix it.
Whether or not those "self-insuring" risk tolerance figures are public are a different matter.
I do agree on the value and efficacy of capability-based systems, however the cost and effort to deploy and manage them, even in life critical environments, is so high that they are only practically effective in centrally planned environments where the funding for systems security is strongly decoupled from how that funding is acquired. In other words, capability based systems are, and will only be effective, at scale, in environments such as government (and even then, only military) or publicly funded, single payer, centrally managed health care systems (which don't really actually exist - most public funded healthcare in the world is centrally and publicly funded, but delivered by private service providers who bill the public funder).
It's an effective model where the cost of reliably deploying and managing capability based security can be externalized from the line of business that requires that level of security.
Most of the advantage of having a capability system is that it allows users to more transparently control what resources are given to a program at runtime. Instead of trusting the application to go pick a file and do something, the OS relies on a PowerBox UI to allow the user to directly pick files.
The closest analogy is that of a wallet (or purse) with currency in it. You chose directly which money you wish to use in a transaction, and that's the most you can lose if you make a mistake. There's no equivalent in Linux, Mac, Windows, etc... you're forced into a situation where you had your wallet to code, and hope for the best.
Users aren't the great weakness we've grown to think of them as, they just have insanely crippled tools.
That said, I don't envision shoot on sight orders or the use of SM-70 directional mines on the American border. What I find particularly interesting is the complete reversal of positions from years ago. CSPAN has a video of Dianne Feinstein talking about border security with AG Janet Reno, and you could swear they were talking points cribbed from a Trump strategy session.
Increased immigration tends to lower wages which favors employers. OTOH, protectionist immigration policies tend to keep the status quo especially for low-skilled labor, whom you would think the DNC is pledged to protect. It's just interesting to see how political fashions have switched. Is it the fear of terrorists crossing the border or..?
It hasn’t reversed, though the right-wing bipartisan consensus on the issue of the early 1990s has gone.
> Increased immigration tends to lower wages which favors employers.
Immigration mostly increases and decreases by economic conditions (at home and abroad). Immigration policy mostly influences the proportion of immigrants with legal status. More immigrants with legal immigration status means immigrants are less likely to be in fear of asserting things like labor rights, whereas more without legal status means more fear of things like that.
> It’s just interesting to see how political fashions have switched.
They haven’t switched, at least not in well over a generation. Republicans have been for narrower legal immigration policies for decades (the backward-reaching amnesty under Reagan was a component of tighter forward policies). There was a brief period of general bipartisan consensus on the direction of change (though still distance on the details), but no reversal.
If one wanted to control wages, one would want to ensure the unskilled labor supply was somewhat limited. Otherwise an employer can drive down to minimum wage rather easily.
One might do that by better securing the borders. I'm purposely leaving out the antiterrorist wish of at least getting some idea of who's coming in and out of Disneyland so to speak.
The fascist client state that collapsed due to an increasingly hostile domestic population who were angered by the growing economic challenges, and were tired of the continued state violence?
The same German Democratic Republic that has been consigned to the historical scrap heap of failed totalitarian regimes?
One might even consider holding North Korea up as a current example, since they have outlasted the GDR by 31 years so far, but they are also a client state, and their economy has been in relatively steady decline. The only thing keeping North Korea a functioning country is military and economic support from China, with even Russia's central bank continuing to push back against further economic development with North Korea.
- The response can't have a blast radius
- Human software systems can't be formally verified in a tractable amount of time
- etc.
I'd go as far as to wager that if it weren't for MAD, the US might be sending SEAL or Special Forces teams in to deal with hackers.
When we have an AGI, perhaps it will develop systems impervious to intrusion. Or maybe it'll take the simpler approach and eradicate all humans and other capable AI actors.
This is expensive because it's guerrilla warfare.
Do you have a source on this? Sounds like an interesting read
That sounds like wet dream of a genocidal maniac. There is no way this claim is credible
And no I don’t think it was likely, but there’s only so many time in history senior military people have referred to nuking something in a non joking manner.
If you wanted to use military force, you would create a power blackout in target area by destroying closest substation or powerplant.
"In the end, two California High School students were arrested and pled guilty. Their mentor, an 18 year-old Israeli, was also arrested"
Surely noone is mad enough to nuke their own country? Or would you nuke the wrong ciutry instead?
It’s that moment the options are to successfully hack the machine, do nothing and hope no physical attack is incoming, try and penetrate serious air defenses with conventional aircraft, or use an ICBM. I don’t mean to suggest people where requesting authorization from the president for a nuclear strike, just that it was considered which is a serious escalation for a cyber attack.
As to the articles, you will note Iraq is mentioned many times by military officials even the attacks originated from teens in the US and Israel. Some of that’s timing, but the other part is as I said the machine happened to be located in Baghdad. Also, the press briefing before they arrested the teens shows just how serious this was being taken. It really wasn’t business as usual.
Why can't we tell? US has a world-wide network of early warning radars and satellites specifically built for this purpose during cold war. Various allied countries have their own networks too, and would warn US.
Iraq never had ICBMs and no-one ever claimed that they do.
I am not seeing a plausible scenario of 'unnoticed incoming ICBM' on US.
"try and penetrate serious air defenses with conventional aircraft, or use an ICBM"
US has bombed Iraq (and many other contries) multiple times by then with minimal losses. I am struggling to see how nuclear holocaust was an appealing option.
Increadible thing do sometimes happen, so I would be interested in there is an article explaining the events or this line of thinking.
Lack of ICBM’s was assumed, but on the moment when your early warning system goes down while your preparing for an invasion it’s hard to stay rational.
The plausible scenario as to why the warning system went down is ARPA net was designed to keep military computers in contact through a nuclear attack. ARPA net became the internet but before SIPERnet and so it was still being used to keep those critical systems in contact. Hackers compromised those systems, because the military was using the same sendmail software as everyone else.
Now for us looking backwards it’s like wait what about computer security, but it largely didn’t exist back then.
Given that you can't refer anyone to anything written, this whole story defies logic and smells of a dead possum.
Blue team: every time
Red team: once
Then, and this is crucial, they not only teach the blue team from their findings - they also rotate out to blue teams, to become the defenders themselves. At the same time, some of the blue team rotates in. Rinse and repeat. The whole point is that you have to understand both sides properly, and continuously work with the teams involved. Otherwise you're nothing more than a consultant.
Otherwise, we actually do learn ways to converge towards more generally secure systems. Safer programming languages and safer hardware will lead the way, but it seems much slower this round than the stories we hear about the origins of everything.
However, we will not find those techniques by following the standard commercial IT methodologies which were not designed for such a task. Just ask any architect of these systems if they could stop a team of 10 people working full time for 3 years. If even the people making it think it is absurd to defend against such a minimal effort there is no chance it is actually adequate.
In fact, there is little reason to assume that the methodologies that can only get 0.1% of the way to solving the problem despite decades of work and tens of billions of dollars will ever converge to an adequate solution. It could be like trying to use the knowledge of horse buggy makers to determine how to make a machine faster than the speed of sound. And even if it could eventually get there it would require 100% improvements year over year for an entire decade to get there from existing commercial methodologies.
No, it is far more reasonable to use systems that were actually designed for these environments and have actually demonstrated success, such as systems certified to Orange Book A1, and make them more practical since, as everybody knows, it is far easier to make a cheap, working design by starting with something that works and making it cheap than starting with cheap components and figuring out how to make something that works.
As for how you can identify proven success you can just start with a $1 million red team exercise. If they are able to find any material defects that means that there are likely many such defects and your processes can not prevent the occurrence of such trivial flaws and needs to be rethought. Only when there are zero material defects are you at the starting line. Note that this is not an exhaustive test, rather it should be treated like the fizzbuzz of security design, a trivial softball to weed out the the people that know nothing and the systems that do not work.
The TCSEC, frequently referred to as the Orange Book, is the centerpiece of the DoD Rainbow Series publications. Initially issued in 1983 by the National Computer Security Center (NCSC), an arm of the National Security Agency, and then updated in 1985, TCSEC was eventually replaced by the Common Criteria international standard, originally published in 2005.
https://en.wikipedia.org/wiki/Trusted_Computer_System_Evalua...
It's not as if this was some kind of profound rock-solid architectural effort from the start. It was a race and speed was of the essence.
In many ways it has a lot in common with information science today. A high speed of innovation. Go fast and break things. High risk high reward.
I think the parent was advocating doing the opposite. Going for rock-solid and secure. Set security design standards that are mandatory. The same way that we have a building code. Good idea really but development speed and features will suffer. It'll be a big change for an industry that's totally not set up for that. I doubt many consumers will be happy either, no more huge spec improvements every year or fancy new features to show off.
And it's not all tech either. Right now the main technique of ingress is phishing and opsec weaknesses. A mindset change is needed, not just for the tech community but everyone.
It'll happen but it'll take years, maybe decades. And we'll have our own "Apollo 1"s to underline the importance and keep us on track. And we already had. It was WannaCry that started the awareness process.
That is the part of Apollo I was thinking about. Done right, the humans get back to earth...
Here, done right, the data stays where it should be and the systems do what they are intended to do. The people don't get notices...
And, like Apollo, lots of that would trickle out into industry and eventually down to ordinary people.
>Right now the main technique of ingress is phishing and opsec weaknesses. A mindset change is needed, not just for the tech community but everyone.
I am well aware. Seems solvable given a consistent culture and norms can be established, eventually polished and time tested, production proven.
No, because ultimately security isn't binary. If you can increase the cost to the attacker, that raises the bar for attacking you and reduces the number of potential attackers. And over time security practices do get generally better, raising the tide for all boats; the problems right now are that we're still wrestling with the legacy of foundational systems designed in a pre-internet world where constant adversarial networking was not the norm, and more generally we keep increasing the attack surface by adding new things to the network. But once we have software/hardware stacks that have all been designed in a post-internet world (yeah, it'll take a while) and once we've finished networking everything that could reasonably be networked, there's hope enough to suspect that it will be possible to close the security gap to all but the most determined adversaries.
I highly doubt we'll come to terms on this one.
Did they actually spend $1 billion? Or they did and spent on overpriced services? Without knowing what they did the amount is meaningless
Energy effort here: https://www.energy.gov/national-security-safety/cybersecurit...
I think the second one might be more important, because it is generally known who the big crews are, and it is actually easy to screw up the opsec on crypto.
Also it does mean bad PR on their part. Which that is part of cultural warfare.
This seems like normal old grey programming to me.
We who? I definitely do not feel that we have enough. If we did it would've percolated to some noticeable action.
Ourage builds and builds pressure until the subject reaches a tipping point and comes with a knee-jerk reaction meant to reduce the pressure. Such reactions are poorly planned, have no room for nuance or discussion of downsides, and are not aimed at solving the problem but at getting the outraged people of your back.
Joining a mob of angry people is a way to affect change. But in many cases it is not the change we (should) want.
Tell it to politicians. They're outraged every other minute.
>"But in many cases it is not the change we (should) want."
Did I say we should be outraged in "every case"?
Oh and thank you for telling me what (should) I want.
It would be interesting to speculate how close we are to replacing all networked services with provably secure implementations (like the work of Project Everest[0]). Of course there's no such thing as perfect security (or perfect proofs), but I think we are close to reaching the point where attacking implementation flaws is less fruitful than attacking the software supply chain.
In fact, we may already have reached that point, so I think that efforts to secure the supply chain (like sigstore[1]) and potential government efforts to attack it (like recent changes to iOS and Android[2]) deserve more focus.
[0] https://project-everest.github.io/
[1] https://security.googleblog.com/2021/03/introducing-sigstore...
The problem here is that we're essentially building glass cannons. Yeah, we can hit hard but you can't win a fight that way. Eventually you're going to get punched in the face.
The Internet is an interesting case. Nobody owns it. It isn't even American. The fact that it was originally created by and for universities that all implicitly trusted each other has led to a whole lot of security flaws baked into the core assumptions of the most basic protocols. But the NSA does protect the hell out of military networks. Military and IC networks are absolutely nothing like the Internet. There is an inherent difficulty in bringing the same assurance to public networks, though, because nobody on a military network expects to be anonymous or to have any privacy. Users implicitly trust the network's central authority. They have to because they work for it. Security is a lot easier with a trusted central authority.
You miss the point of these tools. They are not being used to protect country A from country B. They are being used to protect those running country A from those living in country A. Country B and its people are not in the picture. You don't blue team the target because you don't want to make it more difficult to watch. If anything, you want to deny them strong security tools. Your red team can do that very well.
https://www.wired.com/1997/01/did-gates-really-say-640k-is-e...
In order to have secure systems, you need to add a lot of complexity overhead that earlier systems simply could not afford. Proper process isolation is a good example - extra complexity, but absolutely necessary unless your chip limitations make it impractical. Permissions for memory pages eg. W^X policy. Stack canaries. Address space layout randomization. All things that add extra complexity and resource usage, but without which it's much easier to exploit systems and any single mistake means it's game over.
Privately, I speculate that they also assessed the state of play and just gave up. Microsoft back then still believed that code-signing would fix their bug-of-the-week run. Industry security practices were so weak as to be non-existent. Hell - telnet was still common.
The only nice thing I can say about it was they had an amazingly honest logo [2]. That is, until congress freaked out and made them hide it all behind a bit SECRET sign. And so we heard little more about except via a steady drip of whistleblowers like Mark Klein, Thomas Drake, William Binney, and Snowdon.
[0] - https://en.wikipedia.org/wiki/Information_Awareness_Office [1] - https://en.wikipedia.org/wiki/Total_Information_Awareness [2] - https://en.wikipedia.org/wiki/Information_Awareness_Office#/...
The public perception seems to be that the US doesn't spend enough resources to harden its and its people's defenses than it does to surveil people.
[1]: https://techcrunch.com/2021/04/13/fbi-launches-operation-to-...
Physical safeguards are both easier to implement, easier to demonstrate when funding is decided, and generally the better investment considering most compromises of government digital infrastructure come from people with direct physical access (plugging in a dropped USB, spies, phishing, etc.).
This would make it more difficult to hack those OSes in other countries and within the borders too, why would they make their own job harder for them?
Yeah, I know, their job shouldn't be to hack others, but that's how it is today.
I feel like the idea that "The US government wants to have certain powers, and wants no one else to have them" is just baked into the fact that it is the US government, and should neither surprise nor alarm anyone who isn't an Anarchist.
Ya, monopoly on violence by... who exactly? Who is wielding the power in the government? Afghanistan was horrible, right? But US just kinda let that go on for 20 years or whatever. News didn't really talk about it. That's kind of like... a lot of suffering while just pretending nothing is happening. I guess if it was you wielding the power in any real way, or i mean if the people who represented you cared about what you thought, they might have checked in to update you and see what you thought. But they didn't, so... wonder what happened there. And since we are talking about violence, i guess we all agree constructing dragnet surveillance with no regard for human and civil rights is violent, right?
Also, monopoly on violence, you mean over other states right? So then the other states... don't have a monopoly, or? Isn't that just imperialism? I've never heard that phrase used this way, i usually hear it used as monopoly on violence over the people (which the US absolutely is but will never admit because then they wouldn't be able to call every non-US gov in the world 'authoritiarian'). I guess you might be saying monopoly over so-called 'enemy states', but like i said it US is touted as such a world-renowned and representative democracy, and most people don't even understand anything about 'enemy states'. Really, they are mostly just blindly nationalistic or bask in the high standard of living afforded them with a warm and convenient lack of awareness about what is going on in the world (retirement funds did well due to that war, that's nice). Or maybe they went into some detail but it was inside a carefully crafted investigation bubble, usually under threat of losing their job or burned as a witch for having the wrong thoughts about an evil enemy if they could influence someone. Anyway, in such a situation, i hope we can agree that the state should not just blindly exercise violence for a 'monopoly'. Who said so? How was the decision acted upon? To what end? How much violence? Which kinds are ok, which are off-limits? What effect is it gonna have on the people?
Ok, so wait we get to comment on this particular export situation. Great. Despite the fact that i've heard people say even well-reasoned and popular adversarial comments in these little situations do next to nothing, we are not addressing the overall problem. People need to know the big picture of how this will be used. Did we ever even agree to surveillance in the first place, do we agree with who we've been told our enemies are? Do we agree with violating peoples' rights? Whose? Why? You know... very basic questions that will never be asked. Request for comment, ya, ok. Thanks. Also, if there's a request for comment on something, all people need to be made aware of the request through some very well-publicized channel. Is there one? I don't think so. No one bothers building such a channel because building one would make their entire political and military racket less profitable not to mention eat away at the neighbordhood of makebelieve.
> If said power becomes distributed to other parties, it becomes moot. How that power is wielded, and with what intent are separate discussions, but the power itself is core to the idea of government.
You have like some premise that all power constructed by the US is legitimate? I don't understand. We never agreed to wire up the whole world like this and it is pretty clear at this point that no one else did either. Ok. Now it's constructed, what to do? The proper answer is, i guess, to destroy the technology and not move forward, right? Since it's construction and deployment was done in secret? If they didn't want to waste resources they should maybe not build illegal things that take lots of resources using stolen public funds?
> I feel like the idea that "The US government wants to have certain powers, and wants no one else to have them" is just baked into the fact that it is the US government, and should neither surprise nor alarm anyone who isn't an Anarchist.
I guess it just smells like fascism to me when you submit to this without like... actually thinking about the specifics of each power? Or letting them just spread illegal shit around the world? Maybe i misunderstand. This all seems weird.
You kind of went off in the weeds and talked about a lot of things I wasn't saying anything about. The one point of yours I will respond to is this:
> I guess it just smells like fascism to me when you submit to this without like... actually thinking about the specifics of each power? Or letting them just spread illegal shit around the world? Maybe i misunderstand. This all seems weird.
Two things: First and foremost, I don't see how you drew a line from the U.S. preventing export of technologies that enable fascism to the U.S. 'spreading illegal shit'. Kind of a hard turn there, and not really what I, OP, or the article were commenting on.
Second, power is not equal to fascism. Personal freedoms rely on the power to defend them. You are not free to live if someone else is free to take your life. Even a loving and benevolent government requires the power to protect and care for it's constituents. (Now, don't misread that, and think I'm saying the US government is loving and benevolent, I'm making a broader point), and that power needs to be highly asymmetrical or it simply doesn't serve its purpose.
Ya, i wrote too much without getting enough clarification, sorry.
> The one point of yours I will respond to is this: >> I guess it just smells like fascism to me when you submit to this without like... actually thinking about the specifics of each power? Or letting them just spread illegal shit around the world? Maybe i misunderstand. This all seems weird. > Two things: First and foremost, I don't see how you drew a line from the U.S. preventing export of technologies that enable fascism to the U.S. 'spreading illegal shit'. Kind of a hard turn there, and not really what I, OP, or the article were commenting on.
So i didn't mean to draw the line you describe there, i should be clearer in what i write. If i understand what you are going for by adding your comment to this issue, you were kind of dismissing anyone being "surprised or alarmed", and you were maybe a little annoyed anyone was even talking about it. I am not personally really surprised, but i was suggesting alarm and discussion might be good when government decides to exercise power (and my weeds about this gov in particular and the historical events leading up to the issue at hand), because people should understand they should be a part of what power is exercised. I still don't know if i am misunderstanding, but it seemed you were kinda dismissing people being alarmed because this is kinda just what governments do -- "they do power, what's the alarm?". What i meant about fascism was not the line you suggested but the idea that someone might just glance over the entire issue by saying 'governments do power, the government is posturing to enhance this power, who cares?'. I was suggesting that a bunch of people submitting to the the state building power without involvement or question of the specifics of the powers being built is kind of fascistic.
> Second, power is not equal to fascism. Personal freedoms rely on the power to defend them. You are not free to live if someone else is free to take your life. Even a loving and benevolent government requires the power to protect and care for it's constituents. (Now, don't misread that, and think I'm saying the US government is loving and benevolent, I'm making a broader point), and that power needs to be highly asymmetrical or it simply doesn't serve its purpose.
If one state gets to build asymmetric power, that means other states don't have it, right? So.. those states under your definition here can no longer be loving and benevolent because they can't have enough highly asymmetric power in the reverse direction if something bad happens? Am i simplifying too much or missing your point? How does this work out?
Is prematurely building asymmetry with technology really necessary as you say? What if there is symmetry in all countries, then someone does something bad, we all meet and see this person is behaving incorrectly, and then unite. No individual state has asymmetric power but asymmetric power was constructed and used as needed for this situation.
Am i still way off? What are you trying to get across with your comments here? Are you dismissing people being concerned or am i misunderstanding?
I think your commentary is tautological reasoning that says the US Government's use of force is legitimate because the point of the US Government is to use force. I agree with mrobot's framing that your line of reasoning is authoritarian and proto-fascist. The "illegal shit" thing feels like a sidebar and not really important to mrobot's argument (and also a bit left-field), so I'm ignoring it entirely.
Governments don't exist for the purposes of exercising force, they exist for things like paving the roads, building hospitals, etc; for the benefit of the commons. Greater specialization leads to greater productivity, and administering things like "how do we pave the roads" is a specialization that all of society benefits from that no one person or entity should bear the responsibility of paying for. Establishing the taxation and monetary structure by which those things are funded is a core function of the government, and a legitimate one in my opinion, as I would rather live in a society where I simply pay my taxes than a society in which I have to sit around and decide which roads projects to "invest" in. I would like to "hire" someone to do that, and I do so by voting for a Superintendent of Highways (or whatever it's called in your jurisdiction), who receives a pay from the government, which is funded in part by the taxes I pay. All of that seems totally legitimate and has nothing to do with the usage of force or the legitimization of state violence.
The use of force by governments is indefensible far more often than it is defensible, and a core function of the citizenry is to question and investigate its governments use of force, and to use their voting rights to eject those in the government that would perpetrate indefensible uses of force against innocents, both domestic and foreign. We should always be questioning the government's usage of force. We should never, ever stop questioning the government's usage of force.
There are some legitimate uses of force. For example, the Nazi government used force, that was bad. We can all probably agree on that. Other governments used force to oppose them. That was good. Again, probably not controversial. Clearly, not all governments' usage of force is equivalently legitimate. It appears that your position is that the US Government's usage of force is more legitimate than other governments' usage of force, because they're the US Government. The idea that the usage of force is more legitimate if it's the US Government than if it's a different government, which is how I interpret your position, is a position so obviously jingoistic that I am embarrassed to have to clarify that I think it's preposterous.
Now let's say the US government formed a red team to attack the electrical grid of, I dunno, Iran. And let's say the Iranian government thought "we sure would like to have a blue team, let's buy some blue team tools", and all the blue team tools were made by ... American companies. Would those American companies be barred from selling blue team tools to the Iranian government, which the Iranian government would use to defend themselves against American aggression? That, in effect, is my question.
If these tools are legitimate tools, then other governments should have the ability to use them. If these tools are not legitimate tools, then no government should use them; not the US Government alone. That later position is what I'm interpreting these rules to mean: that these tools are dangerous, and so China shouldn't have them, but we're good guys, so don't worry, we can handle them safely. The rules aren't "you can't make tools that can be used to violate people's rights", the rules are "you can make and sell and profit off of making tools that can be used to violate people's rights so long as the customers are the US government and its friends, but not if the customers are governments we don't like". If those tools are illegitimate and prone to abuse, then I don't want my own government having them either! The ruling I want is "Don't make PRISM", not "You can sell PRISM to us but not to China".
> The entire premise of government is that is assumes power over others.
No I don't think that's at all the entire premise of government. I think that statement is terrifying and authoritarian, and it is so terrifying that I originally didn't want to engage you. Since you've chosen to attempt to speak for me, I felt it only fitting to clarify my position for anyone that may make the mistake of taking my silence for agreement.
Now, this is usually, like in this case, nicely wrapped up for the public.
> List of Items Controlled
> a. Any type of telecommunications equipment having any of the following characteristics, functions or features
> a.2. Specially hardened to withstand gamma, neutron or ion radiation;
is ECC memory now a controlled item?
What this primarily refers to is hardware which has been fabricated on an exotic semiconductor process (like silicon-on-insulator substrates) to resist radiation-induced upsets or latchup. This hardware is almost exclusively used in military and space applications; it's basically nonexistent in the consumer space.
No, it is exceedingly unlikely that such a bit flip will have a real world impact beyond an unexpected error that manifests as an application crash or device reboot in the worst scenario, and most likely a temporary failure such as an image not loading or rendering, or a decryption operation that fails because the flipped bit makes is treated as an error.
Is it something to be concerned about? Generally not - if you are in an environment that has sufficient radiation that it has a practical impact on your phone, one would hope that your actual concern is more heavily focused on protecting your physical self, and one would hope that your personal threat model increases in scope to justify spending on electronics that are more resilient if you have budget left over after buying protective gear.
I recall coming across a more detailed write up a long time ago but still found mention of the issue [0]
> our clients rarely have ECC memory. We see a constant rate of memory corruption in the wild and end-to-end integrity verification always pays off.
[0] https://dropbox.tech/infrastructure/-broccoli--syncing-faste...
To detect bitflipping errors? Yes. Use cryptographically secure algorithms and protocols that ensure that messages have integrity checks in transit and in memory.
To detect crashes? Probably not - if a bit flips in memory without hardware level error correction that reports the error, there isn't really a way to detect what caused the error.
Why?
What you meant to ask is, "Is telecommunications equipment using ECC memory controlled under 5A001?", and the answer is no, a.2 refers to rad-hard components.
The key words are "specifically hardened to ..." instead of something like "using any technology that might help with ...". Generally the CCLs never use vague wording like this.
There are specific definitions for those terms with technical specifications. Then there are licenses/exemptions that mean you don't have to seek a license if you are selling to nongovernment customers in certain (friendlier) countries. There's also larger exemptions in export controls related to commercial off the shelf equipment and fundamental research that would apply as well.
Generally the take away is that if you're selling malware, exploits, or network surveillance equipment, you might want to talk to an export control lawyer first.
I don't deal with legal documents enough (luckily) to have ever really needed this, but it would be a nice thing to know how to use if needed, or on creative document sets. Essentially I'm asking for something where I can import a set of machine readable text (or OCR'd) set a grammar for references in context and then easily click through. If it's easy enough to extend the grammar I could probably link new things up as I go when new kinds of references pop up. Trying to get too smart about things like acronyms might be a step too far though, I want to be able to trust this tool completely.
Not the same XML format (s), but regulatory material (both Federal Register and CFR) is also published in XML.
The Government Printing Office has a Bulk Data Repository with the machine readable (largely XML) forms of legislative, regulatory, and a bunch of other documents:
https://www.washingtonpost.com/national-security/commerce-de...
There’s a few chapters in the beginning about the history of the exploit market. Haven’t finished it yet.
To my knowledge it’s not illegal to sell vulnerabilities. If you’re not a government contractor selling/contracting to the US government it would be illegal to sell exploit chains or working software that uses the exploits/malware what have you. The book touches on how they sold multiple of the same zero days to multiple agencies. It got to the point where one of the guys was like you (3 letter agencies) need to talk to each other and stop wasting taxpayer money.
> License Exception ACE eligibility is added for 5E001.a (for 5A001.j, 5B001.a (for 5A001.j), 5D001.a (for 5A001.j), or 5D001.c (for 5A001.j or 5B001.a (for 5A001.j)). License Exception STA conditions is revised to remove eligibility for 5E001.a (for 5A001.j, 5B001.a (for 5A001.j), 5D001.a (for 5A001.j), or 5D001.c (for 5A001.j or 5B001.a (for 5A001.j)) to destinations listed in Country Groups A:5 and A:6 (See Supplement No. 1 to part 740 of the EAR for Country Groups). License Exception TSR is revised to remove eligibility for “technology” classified under ECCN 5E001.a for 5A001.j, 5B001.a (for 5A001.j), ECCN 5D001.a (for 5A001.j), or 5D001.c (for 5A001.j or 5B001.a (for 5A001.j)).
It's like a logic puzzle.
Edit: Looking at this random paragraph again and it seems they're missing a few closing parens so maybe the answer to how they confidently draft and revise these documents is... they don't.
https://en.wikipedia.org/wiki/Export_of_cryptography_from_th...
Based on other comments here, I'll assume there is no hidden agenda on encryption here but a document this messy is probably hiding "stuff" (on purpose or not).
Maybe post-quantum schemes could be affected, but it's only a question of time until people agree on a standard, and if that one gets exported and doesn't get broken, controlling crypto exports won't prevent anyone from using secure ciphers.
No idea why I can go into a store and buy an infinitely more powerful Intel laptop without a form, though.
Somehow I doubt this will lead to myself being any less surveilled... but maybe I'm just being cynical. I want power to the people! But we are all just so damn stupid these days.
I absentmindedly closed it immediately at first, and had to delete the site's cookies to check if I saw that right.
Starlink satellites route through ground stations which are subject to local controls [0].
Communication between satellites and the earth are governed by international treaties [1]. Every country controls radio spectrum use in their borders [2]. Starlink must obtain spectrum licenses and comply with local laws. If Starlink were to route traffic to ground stations outside of the country to evade local controls, the country would simply revoke their spectrum license. If Starlink decided to operate without a license, the US government would be forced to either stop them or break numerous international treaties.
I doubt that helping people circumvent censorship will have long-term positive impact. Censorship is a symptom of bad government, not a cause. For example, both the United States and Israel both have low censorship. Yet, according to [3, 4, 5 + 6], the United States and Israel would be included in a list of "the worst offenders in terms of censorship and human rights violations". Also, UK and Singapore have strong censorship [7, 8] and perform few human rights violations nowadays.
[0] https://hackaday.com/2020/02/20/how-does-starlink-work-anywa...
[1] https://oxfordre.com/planetaryscience/view/10.1093/acrefore/...
[2] https://www.itu.int/en/mediacentre/backgrounders/Pages/itu-r...
[3] https://en.wikipedia.org/wiki/Drone_strikes_in_Pakistan
[4] https://en.wikipedia.org/wiki/Iraq_War
[6] https://www.jewishvirtuallibrary.org/u-s-vetoes-of-un-securi...
[7] https://en.wikipedia.org/wiki/Censorship_in_the_United_Kingd...
Wow, you got all the state department's most wanted "bad governments" list!
Be sure to keep reading NYT and MSNBC to sell you the next reason we need to bomb and starve millions of innocent people across the globe! America #1!
How many satellites can china intercept per launch?
How many satellites can SpaceX (currently) put up per launch?
I mean, it's entirely possible that some elements of the US government might prefer that, but generally speaking, I don't think that's a winning strategy for SpaceX. I think that even the most ardent Musk fans should anticipate how quickly tolerance for Musk's cavalier attitude dries up once missiles start flying.
Probably rhetorical, but I'll be that guy: 50-60 on Falcon 9, up to 400 planned on Starship.
Well, that's news. When did that change?
If I want to order from a webshop that relies on googleapis.com or uses recaptcha, how much choice do I realistically have? How aware of webbugs (Facebook and Twitter logo's, for example) do you think the average Internet user is?
(When other nations do it, and without our permission)
https://youtu.be/ZsISWO4INTo?t=98
"Think of it, an entire nation founded on saying one thing, and then doing another!"
> Today’s rule .... Comments to the rule must be received in no later than 45 days from today, and the rule will become effective 90 days from today.
The notice is dated today, 20 October
Prior to that former Senator Jim DeMint did the same thing in Honduras with Obama admin (Hillary Clinton) help.
Quite literally nothing has changed since the former Confederate US states envisioned South America as the host of their slave-powered empire.