Live data from Hacker News

Google, the Wassenaar arrangement, and vulnerability research

googleonlinesecurity.blogspot.com

11–20 of 59 posts

Re: Google, the Wassenaar arrangement, and vulnerability research

#11
post #6

Are these governments completely insane? Not allowing security research or even reporting bugs without getting a license is the stupidest thing I've heard in my lifetime. The internet cannot be regulated in this fashion without destroying it completely. The world is not a collection of islands we are all in this together and letting any government stand in the way of safety and security is insane.

On top of all that it seems very likely that such licenses will be used to excuse what should be crimes against humanity, in the form of creating exploits and related software to enable hunting down dissidents.

Re: Google, the Wassenaar arrangement, and vulnerability research

#12
post #3

> Global companies should be able to share information globally. If we have information about intrusion software, we should be able to share that with our engineers, no matter where they physically sit. This statement goes through just as well when applied to missiles, nuclear engineering knowledge, bio-weapons knowledge, etc. Governments have decided that they wish to use commercial entities as a proxy method for pr…

The key difference between those technologies and this is that industrial production hardware (centrifuges or specialized biological equipment, etc) are needed in addition to specialized knowledge of the topic at hand. These additional requirements make export controls a lot more enforceable, and why you can, say, send regulators to the site of a nuclear engineering facility and get a reasonable answer about if they have sent nuclear materials to another country.

With infosec this would be basically impossible, since the specialized knowledge and the equipment are both non-physical and intimately entwined.

Re: Google, the Wassenaar arrangement, and vulnerability research

#13
post #3

> Global companies should be able to share information globally. If we have information about intrusion software, we should be able to share that with our engineers, no matter where they physically sit. This statement goes through just as well when applied to missiles, nuclear engineering knowledge, bio-weapons knowledge, etc. Governments have decided that they wish to use commercial entities as a proxy method for pr…

No, exploits have the unique property that the "attack" and "defence" information are mirror images of one another.

Also, deployment of nuclear and bio weapons against civilians is against international law, whereas western governments seem to have chosen to deploy offensive hacking themselves rather than attempt to get it banned internationally.

Re: Google, the Wassenaar arrangement, and vulnerability research

#14
post #4

A couple of items I'd like to add: (I'm Founder/CEO of a busy infosec biz) While infosec is currently a smaller sector in startups than say social, casual gaming, apps, etc, it's growing furiously and Wassenaar and individual country regs will be top-of-mind for much of the YC community in the years to follow because many of you will be in this space. I'd like to emphasize one of Google's points: "Global companies sh…

> "Global companies should be able to share information globally."

This is an interesting point, and to me it seems to be pitting global companies against individual countries. This makes me feel uneasy because I feel there's a better chance my government is looking out for my best interests than many global companies are. Am I just being paranoid and naive?

Re: Google, the Wassenaar arrangement, and vulnerability research

#15
post #4

A couple of items I'd like to add: (I'm Founder/CEO of a busy infosec biz) While infosec is currently a smaller sector in startups than say social, casual gaming, apps, etc, it's growing furiously and Wassenaar and individual country regs will be top-of-mind for much of the YC community in the years to follow because many of you will be in this space. I'd like to emphasize one of Google's points: "Global companies sh…

> "Global companies should be able to share information globally." This is an interesting point, and to me it seems to be pitting global companies against individual countries. This makes me feel uneasy because I feel there's a better chance my government is looking out for my best interests than many global companies are. Am I just being paranoid and naive?

That's a really big debate: small vs big government, Keynesian vs Hayekian economics, public vs private sector and so on. I'd say from my side that government and private sector have a role in protecting you.

Government tends to excel at things like air traffic control and lighthouses where there isn't much scope for competition and where competition may harm. Private sector tends to do things more efficiently when competition is feasible.

So both have a role and the role of private sector is an important one. If we pass laws that restrict innovation, the risk is that things that would normally be in private sector will become government roles and won't be done as efficiently or as effectively as they could be.

I'd say at the rate we're seeing attacks escalate, providing the most effective protection we can in infospace is very important. I'm completely ignoring issues like investment opportunities, job creation and so on because I think the core problem we're all trying to solve is to protect individuals and businesses. We need to get that right first and move from there.

Re: Google, the Wassenaar arrangement, and vulnerability research

#16
post #9

>You should never need a license when you report a bug to get it fixed That hampers people that wish to publicly disclose or sell vulnerability information. This is massively biased in favour of software companies (to some extent, like Google). You should never need a license to disclose vulnerability information, full stop. >Global companies should be able to share information globally Why should this be limited to…

Public disclosure apparently won't require a license anyway: > Third, export controls do not apply to any technology or software that is "published" or otherwise made publicly available. http://bis.doc.gov/index.php/policy-guidance/faqs#subcat200 (The FAQ also states that information about vulnerabilities, as opposed to how to exploit them, would not be controlled, but I believe Google if they say the legalese is ins…

There is a very simple reason why "regulation" in this space will never do anything useful. The cost of entry is very low (an individual can find vulnerabilities without any specialized infrastructure or organizational backing), and the value of vulnerabilities is high. It's basically the war on drugs if drugs could be transferred over the internet. Worse, the majority of the offenders are not in your jurisdiction to begin with, and they never have been or will be.

It doesn't matter what law you pass, you will not stop this from happening. But just because passing laws can't do any good doesn't mean it can't do any bad. Bad laws can still do plenty of harm to the good guys.

The best thing the government could do in this context is to be the highest bidder and then immediately disclose the vulnerabilities to the vendors.

Re: Google, the Wassenaar arrangement, and vulnerability research

#18
post #9

>You should never need a license when you report a bug to get it fixed That hampers people that wish to publicly disclose or sell vulnerability information. This is massively biased in favour of software companies (to some extent, like Google). You should never need a license to disclose vulnerability information, full stop. >Global companies should be able to share information globally Why should this be limited to…

Public disclosure apparently won't require a license anyway: > Third, export controls do not apply to any technology or software that is "published" or otherwise made publicly available. http://bis.doc.gov/index.php/policy-guidance/faqs#subcat200 (The FAQ also states that information about vulnerabilities, as opposed to how to exploit them, would not be controlled, but I believe Google if they say the legalese is ins…

Yes, we need a war on warez to go with our wars on terror and drugs, which have been rousing successive, having driven both of those social ills to extinction.

Re: Google, the Wassenaar arrangement, and vulnerability research

#19
The problem I have with this sort of arrangement is that the more rules they put in place on lawful disclosure, the more they hamper the good guys who follow the laws and the more of a comparative advantage that gives to the bad guys who can simply ignore the laws.

We really don't want to hand the bad guys any more advantages than they already have, no matter how good our intentions are.

Re: Google, the Wassenaar arrangement, and vulnerability research

#20
post #9

Earlier quoted context omitted.

Public disclosure apparently won't require a license anyway: > Third, export controls do not apply to any technology or software that is "published" or otherwise made publicly available. http://bis.doc.gov/index.php/policy-guidance/faqs#subcat200 (The FAQ also states that information about vulnerabilities, as opposed to how to exploit them, would not be controlled, but I believe Google if they say the legalese is ins…

There is a very simple reason why "regulation" in this space will never do anything useful. The cost of entry is very low (an individual can find vulnerabilities without any specialized infrastructure or organizational backing), and the value of vulnerabilities is high. It's basically the war on drugs if drugs could be transferred over the internet. Worse, the majority of the offenders are not in your jurisdiction to…

As much as I would like the government to make such bids, I don't agree regulation is useless. Sure, no policy can completely prevent zero days from being sold - in fact, this particular policy doesn't even try; it just limits who you can sell them to. But if that means that organizations and individuals who wish to remain respectable and avoid any trouble with the law, however unlikely it is to be enforceable in practice, limit their trade to quite nefarious actors rather than extremely nefarious ones... it's better than nothing.

edit: that is, it's better than nothing if it avoids harming the good guys too much, and as I said, I am skeptical of many of the critical comments that have been made, though, buying Google's, I hope the rule will be amended. Argh, I'm too tired to express myself properly.

Post reply on HN