Earlier quoted context omitted.
DRM is more about who has the keys , than security itself.
Modern computer security is all about who has the keys.
Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools
51–60 of 84 posts
Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools
#521) were the tools taken out of a secure environment? Or did he download it from the net when it was published?
2) how could he have taken such sensitive tools out?
3) why so many leaks of an ongoing investigation?
Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools
#53The fundamental flaw is employing contractors.. Governments should be doing all things they are responsible for in house. Contracting anything out costs in terms of added security risk and in profits a contractor will want.
It's not like DoD contractors are doing classified work from home in their sleepwear. They're still subject to the same security procedures, and in fact the same security people are overseeing the contractors and direct employees.
I would still roll in before sunrise during what looked to be a beautiful day and work in a windowless chainsaw-resistant room with a steel door. I'd daydream of a nice sunny lunch break just like my direct employee colleagues, and be just as disappointed that it was raining when I exited isolation.
Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools
#54Earlier quoted context omitted.
DRM is surprisingly security oriented, if you think about it,the premise of DRM is not trusting the user, which is more extreme than most security models (allow the user root/admin access to the OS is anithetical to not trusting the user).
DRM is more about who has the keys , than security itself.
Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools
#55Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools
#56Earlier quoted context omitted.
DRM is about neither security nor freedom.
But the more secure we make our devices, the more opportunities we create for them to be locked down. One person's security update is another's anti-jailbreak patch. Trusted computing can be used to protect against malware and to block users from saving Netflix streams.
Without reference to a specific user, all you can talk about is a computing system being restricted or unrestricted, and I don't want my computing devices to have restrictions imposed by someone other than myself.
Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools
#57As far as I'm concerned, the NSA are the enemy - so props to anybody who can poke a stick in their eye. I just hope this guy doesn't wind up in Guantanamo for the rest of his life.
What is interesting to me is that even super security gurus at NSA can't contain their most sensitive data (well, maybe tools aren't highest level?). At some point I think we need a better security strategy than trying to stop data from leaving, and more about how to make sure data is useless outside of its domain. edit: I say that now in retrospect that security and freedoms of data seem always at odds. DRM being a…
Everyone, the NSA, rest of our government, all governments, all citizens of the world, all businesses should be protected. If we just spent a small percentage of what we spend on endless wars for profit, then I think we could mostly reach these goals.
I would like to think that we could still catch and prosecute criminals, and I include terrorists when I say criminals, without violating rights to privacy and our general rights.
Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools
#58> "F.B.I. agents on the case, advised by N.S.A. technical experts, do not believe Mr. Martin is fully cooperating, the officials say. He has spoken mainly through his lawyers" As is his right and what every sensible entirely innocent individual in his position should be doing. If the government (at any level from civic to federal to international) arrests you for any crime with serious charges, it is ABSOLUTELY the m…
Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools
#59> F.B.I. agents on the case, advised by N.S.A. technical experts, do not believe Mr. Martin is fully cooperating, the officials say. He has spoken mainly through his lawyers, James Wyda and Deborah Boardman of the federal public defender’s office in Baltimore. It sounds like they're just mad that he didn't confess immediately, instead of doing the smart thing of having professional handle everything. Do they really e…
Yes. They're the FBI. They're not used to people exercising their rights.
Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools
#60Earlier quoted context omitted.
I contract for many large state and federal agencies. For better or worse, contractors are easier to hire and fire for the federal government. That gives them more budgetary flexibility. You can also hire people and companies that specialize in the specifics of the project quickly through established contracting channels with established reputations. Contractors are also able to legally bypass red tape and bureaucrac…
What I find astonishing is that these machines have working USB ports at all. And even if there are some external media connections like DVD burner or USB, wouldn't it make sense to at least hardwire them to some tamper-resistant logging device that protocols who used them at which time?