Come to think of it, this NSA would probably also be responsible for chasing down companies who ask you for your SSN, wouldn't it?
They could also offer free pen-testing services (presumably through their defense subcontractors; they wouldn't have to employ any whitehats themselves) for small businesses who can't afford pen-testers, like a specialized form of industrial-development grant.
And, of course, they could also do the only legitimate/legal "active no-advance-notice" pen-testing for infrastructure they're concerned about (ISPs, hosts like AWS, etc.), converting taxpayer dollars directly into those "eyes that make bugs shallow."
Effectively, the NSA are to our sovereign data boundaries as the coast guard is to (most of) our physical ones. Since that's the case—where's our Lighthouse Service?
So you think making the NSA (or any govt agency) the gatekeeper for all data, public and private, would be a good idea? As if there's no way that could be abused? No thanks.
The one interesting thing is that this would likely enforce an open-core-SOA software development model: companies would be incentivized to build a "trust kernel" of services that the government regs apply to, exposing an API with stringent access controls; and then a view layer that consumes that API, which can have whatever sloppy code they wish. The trust kernel would then have to be at least shared-source to enable the peer review necessary for study. (The company couldn't just pass the code around within a cabal of trusted peer companies, since those peers might be unfairly positively-biased.)
Unfortunately, NIST has been dragging 140-3 in draft form on for years. 140-2 was written in the 1980's and reflects very badly on current hardware and software practices.
Another area you could look into is Common Criteria. I find these certifications to be much more modern.
I've taken products through both processes. If you're going for more than the basic levels they can be quite rigorous and thorough.
http://ec.europa.eu/justice/data-protection/bodies/authoriti...
e; well, not actually pen testing, but knowing what personal information companies store, and mandating minimum safekeeping measures and limits on sharing.
There is some merit to what you say, but I'd not use the FDA as a model. To me that sounds like a recipe for disaster, imagine the NSA auditing our software with FDA like cronyism and inefficiency? Green-light passes to be auctioned off to the highest bidder, and otherwise legitimate products will be hampered by woe-some delays. "Sorry, cant launch your new update until the NSA approves it."
But yes, it's much smaller than their SIGINT wing, and yes, I also feel that having both teams under the same roof (so to speak) is not just an 'equities problem' - it's a full-scale irreconcilable conflict of interest.
You might feel that surely the NSA wouldn't backdoor their own stuff? But no: there they are, actually using Dual_EC_DRBG even in their own most trusted crypto hardware - in, I presume, the firm belief that "nobody but us" has the private key to use the backdoor. Which seems somewhat reckless in light of a working distinguisher and how very fragile (EC)DSA is… and a stark reminder of how the recent return to talk of backdoors - sorry, "front doors" or "secure golden keys", because they want to control the language to frame the debate in the way they want - are so much bullshit, and the only reasonable discussion we can have about things which undermine all of our collective security is one where the people who are asking for such idiotic things to - they think - make their jobs easier should kindly shut the fuck up.
Ahem.
GCHQ over here have the exact same issue with CESG and the MoD CRYPTO group versus the COMINT/ELINT/SIGINT bulk of their mission. GCHQ have even selected their own suppliers and political and other infrastructure for targeted surveillance in some cases! So for those who choose to try to work with them - surprise! - that doesn't mean they're not also working against you too. It just gives them another angle.
"And third, the remainder of the NSA needs to be rebalanced so COMSEC (communications security) has priority over SIGINT (signals intelligence). Instead of working to deliberately weaken security for everyone, the NSA should work to improve security for everyone.
Computer and network security is hard, and we need the NSA's expertise to secure our social networks, business systems, computers, phones and critical infrastructure. Just recall the recent incidents of hacked accounts—from Target to Kickstarter. What once seemed occasional now seems routine. Any NSA work to secure our networks and infrastructure can be done openly—no secrecy required."
Title 10 explicitly disallows the NSA to proactively interfere (good or bad) with private industry services unless specifically requested by a law enforcement agency and in cases like you propose would have had to be requested by the private organization to the LEA in the first place.
For one, there has been little appreciable gain from this practice, but it's also way too easy for an adversary to subvert a backdoor planted for purposes of peeping around, and use it to do very serious damage. The more entrenched surveillance via cyberespionage becomes, the more it expands the attack surface for a foreign actor to exploit it.
Second, there is no guarantee at all that the NSA is impervious to the same sort of infiltration methods. If they become compromised themselves by a foreign hacking entity, then that's it for everyone they're "surveying".
And third, the remainder of the NSA needs to be rebalanced so COMSEC (communications security) has priority over SIGINT (signals intelligence). Instead of working to deliberately weaken security for everyone, the NSA should work to improve security for everyone.