Live data from Hacker News

Google, the Wassenaar arrangement, and vulnerability research

googleonlinesecurity.blogspot.com

41–50 of 59 posts

Re: Google, the Wassenaar arrangement, and vulnerability research

#41
post #10
post #4

A couple of items I'd like to add: (I'm Founder/CEO of a busy infosec biz) While infosec is currently a smaller sector in startups than say social, casual gaming, apps, etc, it's growing furiously and Wassenaar and individual country regs will be top-of-mind for much of the YC community in the years to follow because many of you will be in this space. I'd like to emphasize one of Google's points: "Global companies sh…

Hacking Team was in the business of selling zero-days to government for the purpose of enabling surveillance. That's what people find objectionable. It's the difference between culturing a microbe to make a vaccine or make a bioweapon. The latter should get your ass droned.

> It's the difference between culturing a microbe to make a vaccine or make a bioweapon. The latter should get your ass droned.

As a last resort. Ideally, it would get your ass arrested, your lab destroyed, and a speedy trial.

Re: Google, the Wassenaar arrangement, and vulnerability research

#42
post #4

A couple of items I'd like to add: (I'm Founder/CEO of a busy infosec biz) While infosec is currently a smaller sector in startups than say social, casual gaming, apps, etc, it's growing furiously and Wassenaar and individual country regs will be top-of-mind for much of the YC community in the years to follow because many of you will be in this space. I'd like to emphasize one of Google's points: "Global companies sh…

i'm not sure the hacking team incident is the worst thing possible. hacking team was following the rules. they had export licenses. it just shows that the rules don't hurt bad players.

Re: Google, the Wassenaar arrangement, and vulnerability research

#43
post #28
post #6

Are these governments completely insane? Not allowing security research or even reporting bugs without getting a license is the stupidest thing I've heard in my lifetime. The internet cannot be regulated in this fashion without destroying it completely. The world is not a collection of islands we are all in this together and letting any government stand in the way of safety and security is insane.

I don't believe this was intentional. Wassenaar is an arms control agreement - the intention was probably to regulate the sales of weaponised exploits, not basic research. It's an overreach.

A lot of research will be very close to weaponised. Just browse googles bug tracker and you will find PoCs for a lot of their vulnerabilities.

Re: Google, the Wassenaar arrangement, and vulnerability research

#44
post #4

A couple of items I'd like to add: (I'm Founder/CEO of a busy infosec biz) While infosec is currently a smaller sector in startups than say social, casual gaming, apps, etc, it's growing furiously and Wassenaar and individual country regs will be top-of-mind for much of the YC community in the years to follow because many of you will be in this space. I'd like to emphasize one of Google's points: "Global companies sh…

> "Global companies should be able to share information globally." This is an interesting point, and to me it seems to be pitting global companies against individual countries. This makes me feel uneasy because I feel there's a better chance my government is looking out for my best interests than many global companies are. Am I just being paranoid and naive?

> I feel there's a better chance my government is looking out for my best interests than many global companies are

I'd go a step further on the cynicism scale and say that neither global companies nor the government are looking out for my interests.

Re: Google, the Wassenaar arrangement, and vulnerability research

#45
post #9

Earlier quoted context omitted.

Public disclosure apparently won't require a license anyway: > Third, export controls do not apply to any technology or software that is "published" or otherwise made publicly available. http://bis.doc.gov/index.php/policy-guidance/faqs#subcat200 (The FAQ also states that information about vulnerabilities, as opposed to how to exploit them, would not be controlled, but I believe Google if they say the legalese is ins…

There is a very simple reason why "regulation" in this space will never do anything useful. The cost of entry is very low (an individual can find vulnerabilities without any specialized infrastructure or organizational backing), and the value of vulnerabilities is high. It's basically the war on drugs if drugs could be transferred over the internet. Worse, the majority of the offenders are not in your jurisdiction to…

> There is a very simple reason why "regulation" in this space will never do anything useful. The cost of entry is very low (an individual can find vulnerabilities without any specialized infrastructure or organizational backing), and the value of vulnerabilities is high.

The cost of entry is not low though. To find a bug is one thing, to build a functioning exploit and associated payloads to weaponise it takes a team of engineers.

At the very least, we can prevent the likes of hacking team and gamma group from operating legally in western countries.

> The best thing the government could do in this context is to be the highest bidder and then immediately disclose the vulnerabilities to the vendors.

We can only dream.

Re: Google, the Wassenaar arrangement, and vulnerability research

#46
Global companies can go screw themselves, Google in particular. "People should be able to share information globally." is the motto everyone including global companies should rally behind. The crypto export ban is an apt analogy and it did hinder American companies and benefited everyone else. A good thing too when the NSA started monkeying around with crypto primitives and national security letters. Anything that slows down american tech behemoths and gives room for other european alternatives is a good thing.

Re: Google, the Wassenaar arrangement, and vulnerability research

#47

Earlier quoted context omitted.

> "Global companies should be able to share information globally." This is an interesting point, and to me it seems to be pitting global companies against individual countries. This makes me feel uneasy because I feel there's a better chance my government is looking out for my best interests than many global companies are. Am I just being paranoid and naive?

That's a really big debate: small vs big government, Keynesian vs Hayekian economics, public vs private sector and so on. I'd say from my side that government and private sector have a role in protecting you. Government tends to excel at things like air traffic control and lighthouses where there isn't much scope for competition and where competition may harm. Private sector tends to do things more efficiently when c…

I'm sorry but I don't see how a private company "protects" you in any way.

Re: Google, the Wassenaar arrangement, and vulnerability research

#48
post #47

Earlier quoted context omitted.

That's a really big debate: small vs big government, Keynesian vs Hayekian economics, public vs private sector and so on. I'd say from my side that government and private sector have a role in protecting you. Government tends to excel at things like air traffic control and lighthouses where there isn't much scope for competition and where competition may harm. Private sector tends to do things more efficiently when c…

I'm sorry but I don't see how a private company "protects" you in any way.

It doesn't have to be about protection. Just about serving your interests. When my country privatized the phone system, the time to get a phone line installed dropped from 3 months to 5 days (because suddenly they were motivated to get it installed as soon as possible so they could start making money).

Re: Google, the Wassenaar arrangement, and vulnerability research

#49
post #9

>You should never need a license when you report a bug to get it fixed That hampers people that wish to publicly disclose or sell vulnerability information. This is massively biased in favour of software companies (to some extent, like Google). You should never need a license to disclose vulnerability information, full stop. >Global companies should be able to share information globally Why should this be limited to…

Public disclosure apparently won't require a license anyway: > Third, export controls do not apply to any technology or software that is "published" or otherwise made publicly available. http://bis.doc.gov/index.php/policy-guidance/faqs#subcat200 (The FAQ also states that information about vulnerabilities, as opposed to how to exploit them, would not be controlled, but I believe Google if they say the legalese is ins…

It could, though. Right now, we in the US pro-gun camp are fighting some newly proposed ITAR regulations which, while probably aimed at the 3D/80% AR-15 receiver camps, would criminalize unlicensed disclosure of the sorts of basic data about weapons that's been freely published since forever.

See e.g. this http://weaponsman.com/?p=23824 Note the relatively innocuous data discussed (inner and outer machine gun barrel heating), and then skip to the bottom "A Note To Our Readers", these guys have consulted their lawyer on the matter. And the NRA (lobby for gun owners) take on it, which seems to be accurate: https://www.nraila.org/articles/20150605/stop-obamas-planned...

Re: Google, the Wassenaar arrangement, and vulnerability research

#50

Aren't cyberarms arms? Isn't the right to bear arms an 'inalienable right'? I don't get it. And I don't get why this is a 'privacy' or 'free speech' issue or why corporations, as Google argues, should be exceptions to the law.

For better or worse, right now the right to bear arms only holds in your house, outside of the 7th Circuit (Illinois, Indiana and Wisconsin), with litigation in the 9th Circuit (the west, specifically California and Hawaii) and D.C. Circuit in progress, and if there are adverse results in those Circuits we're almost positive the Supremes will continue to deny cert.

We in the US pro-gun camp consider self-defense to be an unalienable right (see e.g. the U.K. for a notorious counterexample), but how that applies to exploits is not to my eye simple.

Post reply on HN