Why is scanning web servers for vulnerabilities bad?
I suspect those opposing it are the ones that eventually get caught with glaring vulnerabilities and then we have to hear BS like "they care for security and privacy" when they didn't even use password hashes
No, it refers to a state that is intrusive into personal choices.
"pre-presumes"?
The gist of your argument is if I go up and try to pick your pocket but say my intentions are only to help you from real pickpockets, there's nothing but your personal choice to walk on public sidewalk and should just accept it.
the people who would opt in aren't likely to be the problem. The problem with your pickpocket example is that you lose something when someone picks your pocket, but you lose nothing when someone checks to see what ports are open.
In fact, that's something that's already happening all the time anyway. The only difference is that in this case the person checking for your failures to secure your devices will notify you of the problem instead of exploiting your devices like everyone else will (assuming that they haven't already).
This should not only help people secure their devices, but it should also make the internet a better place for everybody.
If this service causes a bunch of crashes (somehow) or they end up DoSing someone they should be responsible for the harm that they cause, but since these scans are no different that what criminals are already doing every day I don't imagine it'll be a huge problem unless they really screw something up.
I'd also guess that the costs in both time and money spent on the traffic generated by DDoS attacks, malware infections, and phishing sites are much much greater than the costs for 'security guys' to review logs, safely automate scans, and notify webhosts of problems. This is a sensible measure that should save massive amounts of time and money for people all around the globe and make the internet better for UK citizens in the process.
Not the OP.
I think it's fine in general with one big proviso, that they change the law first to make it lawful.
With a different government it would look more benevolent, with the current government growing ever-more fascist--having now found a surreptitious way to ditch the ECHR, for example--it gets somewhat worrying.
We already know where that path leads, thanks to countries like the former USSR and China. Do not want!
* It is pretty obvious to the user if their door is locked, so they don't need pentesters to help them figure it out.
* Houses aren't under attack from the entire planet at all times.
* It not that uncommon to have circumstances arranged such that if someone does barge into your house, you know about it.
If the local government wanted to do something that is closer to to what's going on here -- maybe go door to door offering a security assessment for non-obvious stuff -- that might be a well-received service.
Is it, in your view, better that criminals jiggle the handles?
They're maintaining a vulnerability database. That's like what CERTs do. It's analagous to maintaining a database of safe foodstuffs or drugs.
CISA will jiggle your door handles for free, if you ask and consent first. Web server operators who aren't asking for vuln assessments aren't apt to keep them regularly patched to begin with.
Connecting to a webserver using HTTP is not a criminal act, under any colour of the law. If you have a listening port open to the internet, you are inviting connections.
Picking pockets is stealing; this is more like saying "Hello!" to someone who is standing in their own open doorway, and observing their response.
I don't think there's anything in the article about this programme providing server operators with reports. They're not trying to save operators from themselves.
I suppose the differences in how those two equivalent departments approach this, likely come from national mindset differences, and the political differences they cause. At least it seems reasonable to me: that in Washington people might all agree that the right to decide if you are tested is more important than finding insecure webservers, whilst in London people might well all agree on the opposite.