Live data from Hacker News

The Government Uses Zero Days for “Offense”

eff.org

61–70 of 111 posts

Re: The Government Uses Zero Days for “Offense”

#61

Earlier quoted context omitted.

Are you seriously suggesting you don't think the security services have decades of experience in weighing the pros and cons of information release?

Their history has shown a trend toward less and less disclosure over time. Each successive "war" takes longer and longer for things to be declassified. I've got extremely detailed material in my library published within years of the end of WW1 the sorts of detail I honestly never expect to see again. The long cold war "taught" them to not trust the public, and the global media environment and the Internet only multip…

Each war has an increasing media presence, did you really not notice that?

Re: The Government Uses Zero Days for “Offense”

#62

Earlier quoted context omitted.

Their history has shown a trend toward less and less disclosure over time. Each successive "war" takes longer and longer for things to be declassified. I've got extremely detailed material in my library published within years of the end of WW1 the sorts of detail I honestly never expect to see again. The long cold war "taught" them to not trust the public, and the global media environment and the Internet only multip…

Each war has an increasing media presence, did you really not notice that?

Yes. Not necessarily an accurate media presence. The media is also part of the war.

Re: The Government Uses Zero Days for “Offense”

#63
post #33
post #30

Earlier quoted context omitted.

If it were all a matter of interpretation we wouldn't need an actual written constitution. If it were all up to judges the constitution wouldn't be on display and would be written in Latin or somesuch. But the constitution is public, readable and fairly plain. Now maybe the constitution is outdated. Maybe it should be changed. I don't know that. But from what the constitution reads at this point a number of these mea…

> If it were all a matter of interpretation we wouldn't need an actual written constitution. This is false, given that there is no settled jurisprudence until interpretation happens. If the Constitution said "there may be no dog-walking on Thursday", the constitutionality of dog-walking on Thursday would rest entirely upon the decisions of the judiciary with regards to its constitutionality (and this is important, as…

> If the Constitution said "there may be no dog-walking on Thursday", the constitutionality of dog-walking on Thursday would rest entirely upon the decisions of the judiciary with regards to its constitutionality

What you are asserting is that we are not ruled by written law, but by a judiciary, who feels themselves free to invent "escape hatches" to avoid old commitments now deemed undesirable.

Re: The Government Uses Zero Days for “Offense”

#64

It's good news to me. The NSA's mission means they're going to have to get in somehow . FBI, too. Bulk collection and subversion have huge issues. Targeted collection with 0-days in endpoints that we know are insecure is much closer to Constitution than most of what they do. If people want that to go away, they could always apply methods for building secure systems from ground up. I've posted plenty here and elsewher…

I'm glad you brought this up. I know people who benefit from secure software today (they actually exist) and they are all customers . I don't know many users who can say the same. For example, I've heard rumours about a formally-verified and usable replacement for PGP. Great... until the conversation turns to price: PGP sucks! Would you pay $10 for something better? Heck no! PGP is free. I think of security in terms…

Personally I would pay $10 (or $50) for something better. But for a communication tool, I would not want to force that payment on everyone I interact with, and I would most definitely not accept a closed source security tool at any price.

Re: The Government Uses Zero Days for “Offense”

#65

Earlier quoted context omitted.

This is such a laughably typical strawman excuse that is used to shut down all discussion on this topic.

I believe the parent may have been referring to Stuxnet. https://en.wikipedia.org/wiki/Stuxnet It is indeed possible that if the NSA used a very different strategy with vulnerabilities, Iran might be further along with its nuclear weapons development.

Iran was using out of date software and hardware IIRC, so Stuxnet would still have been possible.

Re: The Government Uses Zero Days for “Offense”

#66
post #17

Earlier quoted context omitted.

That point is so important that I hesitated to add a distraction but I think it's also worth remembering that the NSA has a defensive role, too. It's been much neglected in recent decades but the entire country would be better off if the NSA helped patch things. They're hoping some suspected bad guy doesn't get patched but odds are high that many Americans, particularly important IP-heavy businesses, are going to get…

Are you seriously suggesting you don't think the security services have decades of experience in weighing the pros and cons of information release?

Since you mention decades of experience and information releases...

A book I just read about the history of the KGB and GRU listed techniques they used to unmask CIA spies. Choice stuff. If the cultural atttache has three assistants, and two of them has offices next to the cultural attache but the third has an office in the maximum-security area, which one is the spy? If that third assistant was hired at the age of 33 to an employer that never hires anyone over 31? And did not go through the regular training? And is listed in the State Department's employee list as "Reserve", ie. not a regular officer? And so on. A long and embarrassing list, and it worked for decades. The CIA knew about it in 1964 (probably not in detail) but the Soviets still used thee techniques to unmask three CIA spies per week in 1980.

Maybe the real stupidity was to locate the spies' offices where they were. But the office lists were published, for decades. The employee list was published, including the "Reserve" marking, for decades.

Decades of experience do not automatically confer competence.

Re: The Government Uses Zero Days for “Offense”

#67
post #48

Now the question is, are vendors deliberately putting in security flaws at NSA's instigation? Intel's "system management mode" and code need to be viewed with extreme suspicion. So do network controllers which accept management commands from the network side. It would be so easy to add some system management passwords to a network controller that don't show up when you list them. (In fact, if you're willing to have t…

I doubt the NSA needs to instigate much. There is so much bad code in the world, and it just keeps growing, they would be in business forever just sitting on their thumbs.

>There is so much bad code in the world, and it just keeps growing

Security Compliance is hygiene and reduces the attack surface. We should all be more diligent about complying to reduce the bad code.

Re: The Government Uses Zero Days for “Offense”

#68

Let's just keep writing operating systems and security-sensitive code in C. I'm sure this time we'll have even better development practices. This time we'll do better code reviews. This time the static analysis tools will catch more problems. If we all close our eyes and wish really hard we can avoid inconveniencing a few programmers, save a few CPU cycles, and keep using C. After all, the performance is totally wort…

You may have a point there, but what are you suggesting we do about making progress on this?

Re: The Government Uses Zero Days for “Offense”

#69
post #17

Earlier quoted context omitted.

That point is so important that I hesitated to add a distraction but I think it's also worth remembering that the NSA has a defensive role, too. It's been much neglected in recent decades but the entire country would be better off if the NSA helped patch things. They're hoping some suspected bad guy doesn't get patched but odds are high that many Americans, particularly important IP-heavy businesses, are going to get…

Are you seriously suggesting you don't think the security services have decades of experience in weighing the pros and cons of information release?

Of course they don't. Security services don't have experience. People have experience. People are often incompetent. Security services have long, glorious histories of incompetence. Every day, someone with very little experience is having to make decisions.

Here's a similar example. The British armed forces have decades and decades of experience of COIN. Yet they were bloody awful at it for most of the recent Iraq and Afghanistan debacles. The fact that someone who had a job fifty years ago and was good at is it meaningless. It only matters if the person who has the job now is good at it.

Re: The Government Uses Zero Days for “Offense”

#70
post #66

Earlier quoted context omitted.

Are you seriously suggesting you don't think the security services have decades of experience in weighing the pros and cons of information release?

Since you mention decades of experience and information releases... A book I just read about the history of the KGB and GRU listed techniques they used to unmask CIA spies. Choice stuff. If the cultural atttache has three assistants, and two of them has offices next to the cultural attache but the third has an office in the maximum-security area, which one is the spy? If that third assistant was hired at the age of 3…

> The CIA knew about it in 1964 (probably not in detail) but the Soviets still used thee techniques to unmask three CIA spies per week in 1980.

If you're the CIA and you know the Soviets are using this technique, you don't fix the problem, you use it to your advantage by letting the Soviets unmask the identities of lesser spies while not putting your most important spies on the employee list.

Post reply on HN