Google, the Wassenaar arrangement, and vulnerability research
googleonlinesecurity.blogspot.com
googleonlinesecurity.blogspot.com
While infosec is currently a smaller sector in startups than say social, casual gaming, apps, etc, it's growing furiously and Wassenaar and individual country regs will be top-of-mind for much of the YC community in the years to follow because many of you will be in this space.
I'd like to emphasize one of Google's points: "Global companies should be able to share information globally." With existing laws we are already running into limits on where we can hire and what our own internal staff can send us. So it really is critical for any small or large global org that internal comms are not squashed by this.
BIS's comment period ends today, so if you want to take action, now is the time. As in, before COB today.
One last thing: The Hacking Team compromise and stolen data (including the zero-days they were hoarding) couldn't come at a worse time. It is fuel for the argument that zero-days, vulnerabilities, vectors etc should be tightly regulated and it's really thrown some weight behind the argument to close borders (WRT info exchange) rather than open them. So your help is really needed on this if you think you should be able to have open conversations about technical infosec issues with your colleagues in other countries.
~mark
It's the difference between culturing a microbe to make a vaccine or make a bioweapon. The latter should get your ass droned.
As a last resort. Ideally, it would get your ass arrested, your lab destroyed, and a speedy trial.
This is an interesting point, and to me it seems to be pitting global companies against individual countries. This makes me feel uneasy because I feel there's a better chance my government is looking out for my best interests than many global companies are. Am I just being paranoid and naive?
Government tends to excel at things like air traffic control and lighthouses where there isn't much scope for competition and where competition may harm. Private sector tends to do things more efficiently when competition is feasible.
So both have a role and the role of private sector is an important one. If we pass laws that restrict innovation, the risk is that things that would normally be in private sector will become government roles and won't be done as efficiently or as effectively as they could be.
I'd say at the rate we're seeing attacks escalate, providing the most effective protection we can in infospace is very important. I'm completely ignoring issues like investment opportunities, job creation and so on because I think the core problem we're all trying to solve is to protect individuals and businesses. We need to get that right first and move from there.
I'd go a step further on the cynicism scale and say that neither global companies nor the government are looking out for my interests.
1) Commercial Penetration Testing Software is already controlled. Here's a self-post to reddit on how these controls work and apply today:
https://www.reddit.com/r/netsec/comments/36obxt/what_i_know_...
If you choose to comment; it's helpful to understand the current law and how it works. This way it's easier to know what to ask for.
2) If you use software that may be controlled (for example: pen testing software); this issue affects you. Here are a few suggestions of things you could put in your comment:
https://www.reddit.com/r/netsec/comments/3dusae/the_public_c...
3) As of last night, there were 101 public comments posted. Most were far below the quality you would hope for a good discussion on HN, let alone a note to a policy maker to request a change. If you have an interest in this area and have something constructive to suggest--the public comment process is your opportunity to do it.
http://www.regulations.gov/#!docketBrowser;rpp=25;so=DESC;sb...
That hampers people that wish to publicly disclose or sell vulnerability information. This is massively biased in favour of software companies (to some extent, like Google). You should never need a license to disclose vulnerability information, full stop.
>Global companies should be able to share information globally
Why should this be limited to the employees of a company?
> Third, export controls do not apply to any technology or software that is "published" or otherwise made publicly available.
http://bis.doc.gov/index.php/policy-guidance/faqs#subcat200
(The FAQ also states that information about vulnerabilities, as opposed to how to exploit them, would not be controlled, but I believe Google if they say the legalese is insufficient to establish this.)
I agree that defining boundaries rigidly in terms of companies would be limiting in today's world and especially in infosec.
In general, though, I personally really despise the practice of selling vulnerabilities for the purpose of enabling people to attack others with them - which in practice means selling them to anyone but the vendor, or intermediary organizations like ZDI. True, there are so many ways for this to go wrong... but I cannot join with some of the infosec people who blast any regulations on the industry as inherently harmful, infringements of freedom of speech, useless against the real bad guys, etc. Even as I hesitate to even think in terms of things like 'increased threats' or 'acceptable infringement', or oppose 'absolutist thinking', considering how harmful such ideology has been in other, quite different but analogous realms (surveillance, airport security), and while I have little faith in the ability of a government so hyped up about "cyber" threats to avoid serious blunders, I simply cannot bring myself to find the current almost total lack of regulation in infosec, which you hint at in saying a license should never be required to share information, acceptable.
It doesn't matter what law you pass, you will not stop this from happening. But just because passing laws can't do any good doesn't mean it can't do any bad. Bad laws can still do plenty of harm to the good guys.
The best thing the government could do in this context is to be the highest bidder and then immediately disclose the vulnerabilities to the vendors.
edit: that is, it's better than nothing if it avoids harming the good guys too much, and as I said, I am skeptical of many of the critical comments that have been made, though, buying Google's, I hope the rule will be amended. Argh, I'm too tired to express myself properly.
In theory there is an ideal rule with ideal enforcement that will cause less trouble than it prevents. But as Yogi Berra once said, in theory there is no difference between theory and practice; in practice there is.
Here's a example of a serious problem this actually causes. Suppose Nefaristan is on the list of places nobody can sell to. The evil government of Nefaristan will just send an operative to Jordan or Saudi Arabia or whatever nominally less nefarious place didn't make the list, and buy their exploits there. So either way the evil government of Nefaristan will have embargoed exploits to use against against their domestic dissidents. The dissidents need the embargoed patch right away or they'll be found out and executed. But now the stupid law prohibits anyone from giving it to them because they're in Nefaristan.
It's difficult to imagine how a law could fail harder than "helps bad guys send good guys to death camps" -- but here we are.
Causing serious harm is not better than doing nothing.
And private patches are a thing. Vendors often distribute an early version of the patch to major customers for validation testing.
Or if you like, substitute "patch" for vulnerability information that enables a workaround. You can defeat Heartbleed by turning off TLS heartbeat support but that information is enough to quickly reverse engineer the vulnerability.
That's half the problem. If you're AT&T or Google you can hire said team of lawyers to tell you what it says, but what is an individual graduate student or security consultant supposed to do?
The other half of the problem is that what it says doesn't change the outcome, because the insolubility of the issue comes from economics rather than policy. There is no policy that will keep vulnerability information out of the hands of the bad guys only, because there is no practical way for most people to even identify who the bad guys are.
The cost of entry is not low though. To find a bug is one thing, to build a functioning exploit and associated payloads to weaponise it takes a team of engineers.
At the very least, we can prevent the likes of hacking team and gamma group from operating legally in western countries.
> The best thing the government could do in this context is to be the highest bidder and then immediately disclose the vulnerabilities to the vendors.
We can only dream.
"Team of engineers" is a bit of an overstatement. It's well within the capacity of an individual engineer. And the payload doesn't really change based on the exploit anyway; different RCE vulnerabilities are essentially fungible.
> At the very least, we can prevent the likes of hacking team and gamma group from operating legally in western countries.
How is that even useful? If it's going to happen anyway then you want it to happen in the open so you at least know what is happening. Push it underground or into places like Russia where you have limited visibility and it only makes it harder to catch the real bad guys.
> We can only dream.
I don't understand why they aren't already doing that. It's essentially a publicly-funded bug bounty program. The only disadvantage at all is that it costs money, and that's a pretty dumb excuse if this is half the problem they're making it out to be.
That said, when you consider things like Stuxnet, which physically destroyed industrial facilities, I'd say the idea that malware can be a weapon is harder to dismiss these days than in teh past. Admittedly, most zero-day exploits do not have so close an analogy, but in the wrong hands they can certainly help put people in physical danger.
In any case, surveillance is hardly something the 'hacker community' is thrilled about - as per the zeitgeist in this forum, at least...
I agree with you that surveillance is unpopular among hackers, but I am old enough to remember when censorship was considered at least as bad I would like it to stay that way.
See e.g. this http://weaponsman.com/?p=23824 Note the relatively innocuous data discussed (inner and outer machine gun barrel heating), and then skip to the bottom "A Note To Our Readers", these guys have consulted their lawyer on the matter. And the NRA (lobby for gun owners) take on it, which seems to be accurate: https://www.nraila.org/articles/20150605/stop-obamas-planned...
We really don't want to hand the bad guys any more advantages than they already have, no matter how good our intentions are.
if anyone wants some more background on all the negative side-effects of the current regulation, I wrote a lengthy blog post on the problems with the current phrasing of the Wassenaar amendments here:
http://addxorrol.blogspot.ch/2015/05/why-changes-to-wassenaa...
(Background: I am a security researcher who designed industry-standard patch analysis algorithms / software, built algorithms & a startup for malware reverse engineering that was acquired by Google, pioneered several exploitation techniques, and worked heavily on the recent Rowhammer vulnerability)
This statement goes through just as well when applied to missiles, nuclear engineering knowledge, bio-weapons knowledge, etc.
Governments have decided that they wish to use commercial entities as a proxy method for protecting the status quo. If Google wish to challenge that policy then, well, OK. But there is no reasonable argument for making a special exception for "cyber security" over other forms of security-related engineering.
With infosec this would be basically impossible, since the specialized knowledge and the equipment are both non-physical and intimately entwined.
A word document describing the specification for an export controlled technology is as prohibited from export as the implementation.
Having the word document on a laptop you take to another country is as much a breach of the law as shipping a centrifuge.
Also, deployment of nuclear and bio weapons against civilians is against international law, whereas western governments seem to have chosen to deploy offensive hacking themselves rather than attempt to get it banned internationally.
I would even argue that, especially in the case of bio-weapons, it would be a moral imperative to spread knowledge that could cure people.
Remember that (going back to the cybersecurity analogy) the criminals already have the weapons, as well as the knowledge and capability to develop completely novel weapons from scratch (they might even be better at it than the US).
For missiles the argument doesn't really hold, because knowledge of how to detect and protect oneself from missile attacks neither requires, nor strictly includes knowledge of how to actually build and use said missile.
So the two big reasonable arguments are:
- cyber attacks are already widespread, including global criminal organisations targeting civilians
- both cyber offence and cyber defence enabled by the same knowledge of cyber security
The Wassenaar Arrangement is likely to result in similar unintended effects combined with a similar lack of intended effects.
It shows that the _export_ controls have been in places for years and that is something that should worry us.
Publish your exploits to github before you send them overseas or travel to the conference to announce them.
Isn't the right to bear arms an 'inalienable right'?
I don't get it. And I don't get why this is a 'privacy' or 'free speech' issue or why corporations, as Google argues, should be exceptions to the law.
Inalienable rights are human rights - which extend (at least in theory) to foreigners.
I read the story.
But anyway if the Supreme Court ruling holds from Zimmerman it would apply equally well to everything in the article. Of course the Zimmerman case was about foreign exports as well.
Try to be charitable.
Not in any American sense of the term. The "unalienable" rights were to life, liberty, and the pursuit of happiness as outlined in the Declaration of Independence. Selling guns to redcoats isn't on that list.
We in the US pro-gun camp consider self-defense to be an unalienable right (see e.g. the U.K. for a notorious counterexample), but how that applies to exploits is not to my eye simple.