Leaving pretty much the entire IT infrastructure vulnerable seems like a very dangerous strategy.
Leaving pretty much the entire IT infrastructure vulnerable seems like a very dangerous strategy.
From NSA's perspective? I'm not so sure. A severe attack on US infrastructure would probably mean just more money and more legal power thrown at NSA to "fix it". Then NSA will continue to do what they've done so far - put most of that "security" money, into offensive capabilities. So the cycle will continue, as the systems remain vulnerable.
A big assumption that lots of bug-hunters make, that "this is one of the last bugs, and once fixed, the product will be much more secure." But there are always more bugs. If you assume that are more exploitable bugs beyond the one you are fixing now, it means that the vendors and customers have to spend time and money patching things, and won't really be any more secure afterwards.
Also "if I found it, so can The Bad Guys" is something that applies to individuals and small research teams. It's not necessarily the case that when the NSA finds something that other people are going to find it, too.
Also, unlike most security researchers, the NSA has the resources to monitor if other people are exploiting the vulnerabilities they found.
I'm not saying that the country wouldn't be safer if the NSA disclosed these vulnerabilities to vendors. I'm only saying that many of the common heuristics that researchers assume as true may not be, and especially not when applied to the NSA.
True but trivial. It's much more instructive to pay attention to the rate at which vulnerabilities are discovered. For e.g. qmail that rate is very close to zero per decade. For less secure products the rate varies over time; some researchers have noted a sort of "honeymoon" period that protects new code. Packages that don't in some sense eventually "settle down" after that period ends might ought to be replaced. Or perhaps they are important or unimportant enough to mitigate their vulnerabilities through other means.
Furthermore it's an inevitability that our adversaries learn of these offensive techniques, so attempting to keep them a secret is simply a race against time -- and I don't think that's a race we can win. At this point we're arrogantly exercising recklessness and negligence on the hope that we can stay ahead of the wave.