Google: Stop Burning Counterterrorism Operations
poppopret.org
poppopret.org
All of this stuff is very complicated ethically, but I don't think you can simply say that it is always in the public good to expose bugs (stuxnet is a good example of a bug chain avoiding a far deadlier outcome)..
I've personally worked for vendors of software and done offensive research, and now I do neither.
"I visited a few of America's major cities, and was especially struck by how many New Yorkers speak English as a second language. "
So it's correct to capitalise "Meanwhile, Western countries might [...]" but not "There's a brisk westerly wind coming in over the sea".
I would call New Zealand a "Western country", but not a "western country". Chile is a "western country" but probably not a "Western country" (although the map linked seems to sometimes include it).
In this case though, Google really did nothing wrong. They did what they should to protect their users. They didn't know they're interfering with a counter terrorist operation (according to the post), and even if they knew, who knows how many other less commendable operations they disrupted. And who knows who else was using the same vulnerabilities? I'm sure if Google disrupted Chinese or Russian operation the author would be very happy about that.
>However, burning operations, no matter the actor and no matter the reason, demonstrates a grave misunderstanding of the critical role that cyber plays in reducing harm in the world.
I honestly don't understand what the author tries to convey. What about Iranian operations targeting independent journalists? What about Chinese operations against Uyghurs? Is it also not OK to disrupt those? How should Google decide which operations are OK to disrupt? Especially since they don't really have full insight into campaigns.
Citation needed?
Someone was cyber attacking Chrome. Unclear if Google had even so much as a guess they knew who from. There were bugs in Chrome. Google fixed the vulnerabilities, making the software obey the contract websites & users have with each other, & detailed why they were changing the open source code in such a fashion.
This is not burning an operation. Google didn't name any operation or country. Google probably didn't know who it even was!
If they had some guesses, & did try to pick up the phone & call say MI6, about this topic of leaving this exploit jeapordizing everyone running - which they may well have done (if they confidently track down the cyber attack) - the first most likely response is "we have no idea what you re talking about" in which case fixing the vulnerability & writing a blog post is basically the only remotely acceptible option. You spent a while trying to find out who the cyber attack is launching from, you've gone crazy far to do due diligence to track down whose attack it is, and they say it's not theirs. Ok your diligence was wrong, the cyber attack is coming from somewhere else or from multiple people, you need to resolve it.
Next option is whichever security agency either fesses up & does the right thing. Google addresses the vulnerabilities, and writes a blog post about them.
Or, stand-in Intelligence Agency [SIIA] declares, no, we're SIIA, and you're leaving the defect in place, because we say so.
It's unclear what the author is really protesting here? Bugs are critical to national security so we should let people exploit them? Oh that's exactly what they're saying.
> However, burning operations, no matter the actor and no matter the reason, demonstrates a grave misunderstanding of the critical role that cyber plays in reducing harm in the world.
'The military's active use of indiscriminate cyberwarfare trump's the right to find and correct defects.' Wow. That is a bold position.
>Bugs are critical to national security so we should let people exploit them? Oh that's exactly what they're saying.
The author is just a tiny step from saying that the government should have a right to exploit every device and decrypt every communication. It's a scary and authoritarian position, but sadly quite common for IT people working in law enforcement. From experience they are good people with good intentions, but we know what the road to hell is paved with.
What about if the targets are like Osama Bin Laden's (* INSERT MORE MODERN TERRORIST) family (I have no idea who they are targeting).
Are you meant to have some dude speak arabic and become close friends with the top terorist leaders? Like how do you propose that even work? Would HUMINT actually work in those cases?
I think it's a nice idea for everyone to work on fixing the vulnerabilities, I don't think that will scale with whatever organisations mandate to stop terrorism or whatever.
USA should be allowed to use 0 days for their "counter" terrorism operations. This is interesting at the time of USA being complicit in a genocide against a community.
As an aside, I'm concurrently and in parallel concerned about the domestic front: cheap IoT, substitute control system products having backdoors, and supply chain vulnerabilities of otherwise reputable products being implanted in an NSA COTTONMOUTH, FIREWALK, or GODSURGE manner by other nation-states or ransomware actors.