Live data from Hacker News

Google, the Wassenaar arrangement, and vulnerability research

googleonlinesecurity.blogspot.com

21–30 of 59 posts

Re: Google, the Wassenaar arrangement, and vulnerability research

#21
post #20

Earlier quoted context omitted.

There is a very simple reason why "regulation" in this space will never do anything useful. The cost of entry is very low (an individual can find vulnerabilities without any specialized infrastructure or organizational backing), and the value of vulnerabilities is high. It's basically the war on drugs if drugs could be transferred over the internet. Worse, the majority of the offenders are not in your jurisdiction to…

As much as I would like the government to make such bids, I don't agree regulation is useless. Sure, no policy can completely prevent zero days from being sold - in fact, this particular policy doesn't even try; it just limits who you can sell them to. But if that means that organizations and individuals who wish to remain respectable and avoid any trouble with the law, however unlikely it is to be enforceable in pra…

> that is, it's better than nothing if it avoids harming the good guys too much

In theory there is an ideal rule with ideal enforcement that will cause less trouble than it prevents. But as Yogi Berra once said, in theory there is no difference between theory and practice; in practice there is.

Here's a example of a serious problem this actually causes. Suppose Nefaristan is on the list of places nobody can sell to. The evil government of Nefaristan will just send an operative to Jordan or Saudi Arabia or whatever nominally less nefarious place didn't make the list, and buy their exploits there. So either way the evil government of Nefaristan will have embargoed exploits to use against against their domestic dissidents. The dissidents need the embargoed patch right away or they'll be found out and executed. But now the stupid law prohibits anyone from giving it to them because they're in Nefaristan.

It's difficult to imagine how a law could fail harder than "helps bad guys send good guys to death camps" -- but here we are.

Causing serious harm is not better than doing nothing.

Re: Google, the Wassenaar arrangement, and vulnerability research

#24
post #20

Earlier quoted context omitted.

As much as I would like the government to make such bids, I don't agree regulation is useless. Sure, no policy can completely prevent zero days from being sold - in fact, this particular policy doesn't even try; it just limits who you can sell them to. But if that means that organizations and individuals who wish to remain respectable and avoid any trouble with the law, however unlikely it is to be enforceable in pra…

> that is, it's better than nothing if it avoids harming the good guys too much In theory there is an ideal rule with ideal enforcement that will cause less trouble than it prevents. But as Yogi Berra once said, in theory there is no difference between theory and practice; in practice there is. Here's a example of a serious problem this actually causes. Suppose Nefaristan is on the list of places nobody can sell to.…

Having read the definitions of what is controlled in the proposed rule, I'm pretty confident a patch wouldn't come close. And in any case, since the rules don't apply to public software, that only matters in the case of private patches, which aren't really a thing, and would be a pretty big moral hazard if they were.

Re: Google, the Wassenaar arrangement, and vulnerability research

#26
post #24

Earlier quoted context omitted.

> that is, it's better than nothing if it avoids harming the good guys too much In theory there is an ideal rule with ideal enforcement that will cause less trouble than it prevents. But as Yogi Berra once said, in theory there is no difference between theory and practice; in practice there is. Here's a example of a serious problem this actually causes. Suppose Nefaristan is on the list of places nobody can sell to.…

Having read the definitions of what is controlled in the proposed rule, I'm pretty confident a patch wouldn't come close. And in any case, since the rules don't apply to public software, that only matters in the case of private patches, which aren't really a thing, and would be a pretty big moral hazard if they were.

Most patches inherently reveal the vulnerability they fix. Patches not being controlled would be a loophole big enough to fit a whole planet through.

And private patches are a thing. Vendors often distribute an early version of the patch to major customers for validation testing.

Or if you like, substitute "patch" for vulnerability information that enables a workaround. You can defeat Heartbleed by turning off TLS heartbeat support but that information is enough to quickly reverse engineer the vulnerability.

Re: Google, the Wassenaar arrangement, and vulnerability research

#27

The solution is to ignore the law. Governments have no moral legitimacy and therefore no legal legitimacy.

They tend to react poorly to being ignored, though. And as a rule, they're not the ones that fare badly in such a conflict.

Re: Google, the Wassenaar arrangement, and vulnerability research

#28
post #6

Are these governments completely insane? Not allowing security research or even reporting bugs without getting a license is the stupidest thing I've heard in my lifetime. The internet cannot be regulated in this fashion without destroying it completely. The world is not a collection of islands we are all in this together and letting any government stand in the way of safety and security is insane.

I don't believe this was intentional. Wassenaar is an arms control agreement - the intention was probably to regulate the sales of weaponised exploits, not basic research. It's an overreach.

Re: Google, the Wassenaar arrangement, and vulnerability research

#29

Aren't cyberarms arms? Isn't the right to bear arms an 'inalienable right'? I don't get it. And I don't get why this is a 'privacy' or 'free speech' issue or why corporations, as Google argues, should be exceptions to the law.

You should read the whole story before commenting; this is about foreign trade in exploits.

Re: Google, the Wassenaar arrangement, and vulnerability research

#30
post #29

Aren't cyberarms arms? Isn't the right to bear arms an 'inalienable right'? I don't get it. And I don't get why this is a 'privacy' or 'free speech' issue or why corporations, as Google argues, should be exceptions to the law.

You should read the whole story before commenting; this is about foreign trade in exploits.

Inalienable rights. Not civil rights.

Inalienable rights are human rights - which extend (at least in theory) to foreigners.

I read the story.

But anyway if the Supreme Court ruling holds from Zimmerman it would apply equally well to everything in the article. Of course the Zimmerman case was about foreign exports as well.

Try to be charitable.

Post reply on HN