While this topic is about the NSA I feel this are relevant questions:
Why do we still have a FDA given they fail so regularly to catch food and drugs that harm people?
Why do we still have a FTC given they've fail so regularly to prevent monopolistic behavior from telecoms?
Why do we still have a FBI given they fail so regularly to prevent mass shootings and domestic terror attacks?
Why do we still have a NSA given they fail so regularly at sharing information allowing foreign entities penetrating our financial and tech sectors?
Surely you recognize at some point inefficiency must give way to the question, has this been done intentionally? Especially since that is supported historically.
The question at hand is: Is a recommendation to use memory-safe programming languages evidence that those languages are less safe than we previously thought?
There are two competing notions:
A. This being announced now is evidence that the NSA has recently succeeded in finding a way to subvert the security guarantees of rust.
B. This being announced now is evidence that the good actors (or actors who want to appear good) in the NSA have finally gotten through the red tape to do what is nominally their jobs.
Their track record is spotty at best, and has only gotten worse over time. So to the extent that they are recommending using memory safe languages, that's great...it's advice that would be corroborated by other institutions, researchers, and practitioners. But the moment they recommend a specific set of technologies to use, that should give you pause.
That being said, the report doesn't specifically recommend just those specific languages, and merely provides them as examples...so as long as I'm not in charge of securing an adversarial nation/state's infrastructure, I'm not gonna worry about the potential nefariousness of this recommendation.
1) do black hat shit and risk prison time for gains that are hard to realize
2) work in white hat security and get paid a ton of money
3) work for the government and make very little money, but get to do black hat shit with impunity
It's pretty easy to imagine that the people submitting applications to work for the NSA have no interest in protecting the US from big bad overseas hackers.
1. Enjoy shooting guns and driving fast.
2. Have an interest in protecting the US.
and that's just a glimpse into how bad things really are
Almost everybody misunderstands NSA's defensive mandate. They aren't corporate America's QA department, they don't have a "let's find and report exploits" mission - their defensive mission applies to "national security systems" and other "defense industrial base" ones. Those are computers/networks running fairly specific tasks; they are generally not internet connected, and sitting in secure buildings with 24 hour security and surveillance, so securing them revolves around a lot of physical security and controlled access.
YOU don't have one of these systems, corporation XYZ doesn't have one, there is no requirement NSA disclose jack shit to anybody unless they want to. And in the ETERNALBLUE case one of their tools leaked so they helped head off a lot of problems by voluntarily telling Microsoft about it.
As for who is responsible for this - I thought all the people here are free market worshipers. If Silicon Valley tech companies, one of the richest class of private enterprises in the world, need what are effectively government subsidies to cover their bug ridden insecure products, well that sounds like multiple market failures to me.