Live data from Hacker News

Google, the Wassenaar arrangement, and vulnerability research

googleonlinesecurity.blogspot.com

1–10 of 59 posts

Re: Google, the Wassenaar arrangement, and vulnerability research

#2
The UK and Australia have already implemented part or all of these agreements. Does Google already hold licenses in these jurisdictions? If we report a security bug to a Googler in these (or other similarly restricted jurisdictions) will they be able to share security bug details with their overseas Googler colleagues?

Re: Google, the Wassenaar arrangement, and vulnerability research

#3
> Global companies should be able to share information globally. If we have information about intrusion software, we should be able to share that with our engineers, no matter where they physically sit.

This statement goes through just as well when applied to missiles, nuclear engineering knowledge, bio-weapons knowledge, etc.

Governments have decided that they wish to use commercial entities as a proxy method for protecting the status quo. If Google wish to challenge that policy then, well, OK. But there is no reasonable argument for making a special exception for "cyber security" over other forms of security-related engineering.

Re: Google, the Wassenaar arrangement, and vulnerability research

#4
A couple of items I'd like to add: (I'm Founder/CEO of a busy infosec biz)

While infosec is currently a smaller sector in startups than say social, casual gaming, apps, etc, it's growing furiously and Wassenaar and individual country regs will be top-of-mind for much of the YC community in the years to follow because many of you will be in this space.

I'd like to emphasize one of Google's points: "Global companies should be able to share information globally." With existing laws we are already running into limits on where we can hire and what our own internal staff can send us. So it really is critical for any small or large global org that internal comms are not squashed by this.

BIS's comment period ends today, so if you want to take action, now is the time. As in, before COB today.

One last thing: The Hacking Team compromise and stolen data (including the zero-days they were hoarding) couldn't come at a worse time. It is fuel for the argument that zero-days, vulnerabilities, vectors etc should be tightly regulated and it's really thrown some weight behind the argument to close borders (WRT info exchange) rather than open them. So your help is really needed on this if you think you should be able to have open conversations about technical infosec issues with your colleagues in other countries.

~mark

Re: Google, the Wassenaar arrangement, and vulnerability research

#5
I have quite an interest in this area too. Here are a few things that may help:

1) Commercial Penetration Testing Software is already controlled. Here's a self-post to reddit on how these controls work and apply today:

https://www.reddit.com/r/netsec/comments/36obxt/what_i_know_...

If you choose to comment; it's helpful to understand the current law and how it works. This way it's easier to know what to ask for.

2) If you use software that may be controlled (for example: pen testing software); this issue affects you. Here are a few suggestions of things you could put in your comment:

https://www.reddit.com/r/netsec/comments/3dusae/the_public_c...

3) As of last night, there were 101 public comments posted. Most were far below the quality you would hope for a good discussion on HN, let alone a note to a policy maker to request a change. If you have an interest in this area and have something constructive to suggest--the public comment process is your opportunity to do it.

http://www.regulations.gov/#!docketBrowser;rpp=25;so=DESC;sb...

Re: Google, the Wassenaar arrangement, and vulnerability research

#6
Are these governments completely insane? Not allowing security research or even reporting bugs without getting a license is the stupidest thing I've heard in my lifetime. The internet cannot be regulated in this fashion without destroying it completely. The world is not a collection of islands we are all in this together and letting any government stand in the way of safety and security is insane.

Re: Google, the Wassenaar arrangement, and vulnerability research

#7
>You should never need a license when you report a bug to get it fixed

That hampers people that wish to publicly disclose or sell vulnerability information. This is massively biased in favour of software companies (to some extent, like Google). You should never need a license to disclose vulnerability information, full stop.

>Global companies should be able to share information globally

Why should this be limited to the employees of a company?

Re: Google, the Wassenaar arrangement, and vulnerability research

#8

The UK and Australia have already implemented part or all of these agreements. Does Google already hold licenses in these jurisdictions? If we report a security bug to a Googler in these (or other similarly restricted jurisdictions) will they be able to share security bug details with their overseas Googler colleagues?

If I understand correctly, the UK and Australian implementations are much narrower, and much less problematic than the proposed US implementation. So presumably licenses will not be necessary in those other countries.

Re: Google, the Wassenaar arrangement, and vulnerability research

#9

>You should never need a license when you report a bug to get it fixed That hampers people that wish to publicly disclose or sell vulnerability information. This is massively biased in favour of software companies (to some extent, like Google). You should never need a license to disclose vulnerability information, full stop. >Global companies should be able to share information globally Why should this be limited to…

Public disclosure apparently won't require a license anyway:

> Third, export controls do not apply to any technology or software that is "published" or otherwise made publicly available.

http://bis.doc.gov/index.php/policy-guidance/faqs#subcat200

(The FAQ also states that information about vulnerabilities, as opposed to how to exploit them, would not be controlled, but I believe Google if they say the legalese is insufficient to establish this.)

I agree that defining boundaries rigidly in terms of companies would be limiting in today's world and especially in infosec.

In general, though, I personally really despise the practice of selling vulnerabilities for the purpose of enabling people to attack others with them - which in practice means selling them to anyone but the vendor, or intermediary organizations like ZDI. True, there are so many ways for this to go wrong... but I cannot join with some of the infosec people who blast any regulations on the industry as inherently harmful, infringements of freedom of speech, useless against the real bad guys, etc. Even as I hesitate to even think in terms of things like 'increased threats' or 'acceptable infringement', or oppose 'absolutist thinking', considering how harmful such ideology has been in other, quite different but analogous realms (surveillance, airport security), and while I have little faith in the ability of a government so hyped up about "cyber" threats to avoid serious blunders, I simply cannot bring myself to find the current almost total lack of regulation in infosec, which you hint at in saying a license should never be required to share information, acceptable.

Re: Google, the Wassenaar arrangement, and vulnerability research

#10
post #4

A couple of items I'd like to add: (I'm Founder/CEO of a busy infosec biz) While infosec is currently a smaller sector in startups than say social, casual gaming, apps, etc, it's growing furiously and Wassenaar and individual country regs will be top-of-mind for much of the YC community in the years to follow because many of you will be in this space. I'd like to emphasize one of Google's points: "Global companies sh…

Hacking Team was in the business of selling zero-days to government for the purpose of enabling surveillance. That's what people find objectionable.

It's the difference between culturing a microbe to make a vaccine or make a bioweapon. The latter should get your ass droned.

Post reply on HN