They were doing exactly what NSA was supposed to do. We moved from NSA should not spy on everyone to NSA should be toothless ...
They were doing exactly what NSA was supposed to do. We moved from NSA should not spy on everyone to NSA should be toothless ...
This could have various consequences, but one obvious one is how it affects a jury. It would probably be a lot easier to conclude there is a reasonable doubt the accused did not commit some type of computer or network crime when the NSA is attacking so much infrastructure. If the NSA was known to be targeting legitimate targets with limited, targeted activities that did not affect everybody else, the doubt that any random computer crime could have been the NSA's responsibility would not be reasonable.
> or that evidence of NSA activities would be admitted in trial.
What repercussion should the US have received if the Iranian uranium enrichment had exploded and thrown fine radioactive dust into the environment? Would NSA take responsibility for the deaths and environment damage for their spying, or would they hide and put the blame on a third-party?
The answer to your question is that the potential for damage that malware has, and the responsibility we expect from those who make it is extremely disproportional. It is a big deal, and the risk/cost to human lives is why we should be very careful allowing organizations to spread malware.
That's usually the point of this sort of work, yes. Espionage isn't just about acquiring information, it's about spreading false information, and dragging your enemies through the mud.
I don't approve of this shit, but "the them" have been up to it since forever, and the answers to your queries are a straightforward: "None", "No", "Yes" - unless someone else's intelligence agency outwits them, and has a media mouthpiece that can't be drowned out by chaff.
Edit: Your post got me thinking about Chernobyl and Reagan. The CIA had a programme to export defective technology to the USSR - which (apparently) culminated in http://en.wikipedia.org/wiki/Siberian_pipeline_sabotage
One has to wonder. Yes, I'm aware that the questions as to how Chernobyl are well answered, and all the rest, case closed, etc. - but one still has to wonder. Nothing should be trusted 100%.
People should probably not kid themselves about geopolitics and military competition vanishing if we somehow manage to regulate "electronic warfare".
I know that you didn't mean for your comment to be taken literally but there is literally zero chance of enemy airplanes invading US skies and dropping munitions from great heights onto buildings with people in them. It is a silly thing to say and it does nothing to justify the current situation vis a vis the NSA et al. Try not to hyperventilate.
It's an ugly situation, since Iran's geopolitical strategy involves gaining concessions through a game of chicken with the US counter-proliferation regime. At some point, unless it's resolved in a way that ends the Iranian nuclear arms program, it is going to end in explosions, and scores of lost lives.
This is a descriptive observation, not a normative one.
It is also true that if Iran somehow arranged for explosions at US nuclear facilities, the USG's response would be world- historically horrific. Any reasonable observer knows this to be a fact, so we can acknowledge it without getting into philosophy and move on.
The chances of a full-blown Iranian nuclear weapons program not eventually bearing an attack by explosive munitions are pretty close to zero; see Osirak. If malware that only really impacts centrifuges forestalls that for a couple years, I see it as a good thing.
[1] https://www.schneier.com/blog/archives/2013/12/more_about_th...
I'd actually like to see the outcome of that. By all means, please go ahead and do this -- in Brussels.
As a citizen I'd be pretty alarmed by NSA-level activities of my local agencies because quite frankly it's way too excessive and privacy is a lot more important to me than the supposed security massive and not very transparent surveillance activities alledgedly brings. Most importantly it just shows a worldview that doesn't care about privacy at all and just wants to absorb all data. Which is very alarming.
In the past, you had "privacy" speaking with someone in your own home. Even though the vibrations could theoretically be felt through the walls, we didn't have sufficiently sensitive instruments to recover that into speech. Now we do, and that technology is never going to be uninvented - it's only going to get better.
If you can't adapt to changing times, no hard feelings. The same thing happens every generation. The world can move on after you grow old and die.
Also, are we really thinking "Grok" is some sort of identifying name/tag?
The leaks from Snowden that I've read thus far they do not mention anything about what TAO does. They are hinted at as the "big guns" you go talk to when you have actionable intelligence.
As a foreign citizen of the US (or UK) where this type of activity seems king, I'm threatened and consider these activities hostile and reason enough to not do any sort of business with US based companies or US residents.
There are no legitimate spying efforts, these agencies from day one have used and abused their positions to misdirect the public, start wars, spy on those they had no business spying, hack infrastructure on foreign land (which should be considered an act of war pure and simple), and the list goes on, including torture and murder.
I have no respect for these agencies and the work they do and they have no business existing.
It's fairly unclear what the NSA is supposed to be doing. They appear to be attempting to destabilize the internet in a way that is advantageous to them and them only.
In conventional espionage sabotage does not have the same footprint as intelligence collection. They are easier to tell apart. For this reason merely copying the rules and norms of HUMINT and SIGINT into computer network operations is very dangerous.
Of course you can't prevent efforts to break into systems. But you can spend enough resources on making it difficult and fruitless that it is reasonably certain that our data can't be accessed by spooks of any nation.
We get what we pay for. Right now we spend vastly more on surveillance than on privacy and security. Guess which one we have more of?