> Following Microsoft’s original disclosure in early March 2021, the United States Government also identified other vulnerabilities in the Exchange Server software. > Rather than withholding them, the United States Government recognized that these vulnerabilities could pose systemic risk and the National Security Agency notified Microsoft to ensure patches were developed and released to the private sector. Finally th…
The United States Atomic Energy Commission of the 1950s and 60s had the same problem. Their mission was to both regulate nuclear power as well as research and promote the widespread adoption of nuclear power. Making things safe and keeping them safe while also making things easy and cheap are often in conflict. Ultimately it was split into two different agencies: One tasked with regulation and one Tasked with research and promotion.
I believe both missions of the NSA are important. However I believe it should be split into two agencies each Enthusiastically pursuing a single mission to the best of their abilities.
Imagine a cyber defense agency that does nothing but find and fix holes in computing infrastructure and major software projects. It pays for exploits and then works to patch them, promotes bug bounties, develops secure coding standards, audits open source projects, etc. Imagine something like The National Endowment for the Arts (NEA) that instead funds critical pieces of software like openSSL, etc.
Is that necessarily the best form? Probably not but it’s way better than what we have now: every time the NSA suggests changes to “make something more secure “ there is a looming specter that they are lying and are actually trying to compromise things.