Are these governments completely insane? Not allowing security research or even reporting bugs without getting a license is the stupidest thing I've heard in my lifetime. The internet cannot be regulated in this fashion without destroying it completely. The world is not a collection of islands we are all in this together and letting any government stand in the way of safety and security is insane.
Google, the Wassenaar arrangement, and vulnerability research
11–20 of 59 posts
Re: Google, the Wassenaar arrangement, and vulnerability research
#12> Global companies should be able to share information globally. If we have information about intrusion software, we should be able to share that with our engineers, no matter where they physically sit. This statement goes through just as well when applied to missiles, nuclear engineering knowledge, bio-weapons knowledge, etc. Governments have decided that they wish to use commercial entities as a proxy method for pr…
With infosec this would be basically impossible, since the specialized knowledge and the equipment are both non-physical and intimately entwined.
Re: Google, the Wassenaar arrangement, and vulnerability research
#13> Global companies should be able to share information globally. If we have information about intrusion software, we should be able to share that with our engineers, no matter where they physically sit. This statement goes through just as well when applied to missiles, nuclear engineering knowledge, bio-weapons knowledge, etc. Governments have decided that they wish to use commercial entities as a proxy method for pr…
Also, deployment of nuclear and bio weapons against civilians is against international law, whereas western governments seem to have chosen to deploy offensive hacking themselves rather than attempt to get it banned internationally.
Re: Google, the Wassenaar arrangement, and vulnerability research
#14A couple of items I'd like to add: (I'm Founder/CEO of a busy infosec biz) While infosec is currently a smaller sector in startups than say social, casual gaming, apps, etc, it's growing furiously and Wassenaar and individual country regs will be top-of-mind for much of the YC community in the years to follow because many of you will be in this space. I'd like to emphasize one of Google's points: "Global companies sh…
This is an interesting point, and to me it seems to be pitting global companies against individual countries. This makes me feel uneasy because I feel there's a better chance my government is looking out for my best interests than many global companies are. Am I just being paranoid and naive?
Re: Google, the Wassenaar arrangement, and vulnerability research
#15A couple of items I'd like to add: (I'm Founder/CEO of a busy infosec biz) While infosec is currently a smaller sector in startups than say social, casual gaming, apps, etc, it's growing furiously and Wassenaar and individual country regs will be top-of-mind for much of the YC community in the years to follow because many of you will be in this space. I'd like to emphasize one of Google's points: "Global companies sh…
> "Global companies should be able to share information globally." This is an interesting point, and to me it seems to be pitting global companies against individual countries. This makes me feel uneasy because I feel there's a better chance my government is looking out for my best interests than many global companies are. Am I just being paranoid and naive?
Government tends to excel at things like air traffic control and lighthouses where there isn't much scope for competition and where competition may harm. Private sector tends to do things more efficiently when competition is feasible.
So both have a role and the role of private sector is an important one. If we pass laws that restrict innovation, the risk is that things that would normally be in private sector will become government roles and won't be done as efficiently or as effectively as they could be.
I'd say at the rate we're seeing attacks escalate, providing the most effective protection we can in infospace is very important. I'm completely ignoring issues like investment opportunities, job creation and so on because I think the core problem we're all trying to solve is to protect individuals and businesses. We need to get that right first and move from there.
Re: Google, the Wassenaar arrangement, and vulnerability research
#16>You should never need a license when you report a bug to get it fixed That hampers people that wish to publicly disclose or sell vulnerability information. This is massively biased in favour of software companies (to some extent, like Google). You should never need a license to disclose vulnerability information, full stop. >Global companies should be able to share information globally Why should this be limited to…
Public disclosure apparently won't require a license anyway: > Third, export controls do not apply to any technology or software that is "published" or otherwise made publicly available. http://bis.doc.gov/index.php/policy-guidance/faqs#subcat200 (The FAQ also states that information about vulnerabilities, as opposed to how to exploit them, would not be controlled, but I believe Google if they say the legalese is ins…
It doesn't matter what law you pass, you will not stop this from happening. But just because passing laws can't do any good doesn't mean it can't do any bad. Bad laws can still do plenty of harm to the good guys.
The best thing the government could do in this context is to be the highest bidder and then immediately disclose the vulnerabilities to the vendors.
Re: Google, the Wassenaar arrangement, and vulnerability research
#17Re: Google, the Wassenaar arrangement, and vulnerability research
#18>You should never need a license when you report a bug to get it fixed That hampers people that wish to publicly disclose or sell vulnerability information. This is massively biased in favour of software companies (to some extent, like Google). You should never need a license to disclose vulnerability information, full stop. >Global companies should be able to share information globally Why should this be limited to…
Public disclosure apparently won't require a license anyway: > Third, export controls do not apply to any technology or software that is "published" or otherwise made publicly available. http://bis.doc.gov/index.php/policy-guidance/faqs#subcat200 (The FAQ also states that information about vulnerabilities, as opposed to how to exploit them, would not be controlled, but I believe Google if they say the legalese is ins…
Re: Google, the Wassenaar arrangement, and vulnerability research
#19We really don't want to hand the bad guys any more advantages than they already have, no matter how good our intentions are.
Re: Google, the Wassenaar arrangement, and vulnerability research
#20Earlier quoted context omitted.
Public disclosure apparently won't require a license anyway: > Third, export controls do not apply to any technology or software that is "published" or otherwise made publicly available. http://bis.doc.gov/index.php/policy-guidance/faqs#subcat200 (The FAQ also states that information about vulnerabilities, as opposed to how to exploit them, would not be controlled, but I believe Google if they say the legalese is ins…
There is a very simple reason why "regulation" in this space will never do anything useful. The cost of entry is very low (an individual can find vulnerabilities without any specialized infrastructure or organizational backing), and the value of vulnerabilities is high. It's basically the war on drugs if drugs could be transferred over the internet. Worse, the majority of the offenders are not in your jurisdiction to…
edit: that is, it's better than nothing if it avoids harming the good guys too much, and as I said, I am skeptical of many of the critical comments that have been made, though, buying Google's, I hope the rule will be amended. Argh, I'm too tired to express myself properly.