Live data from Hacker News

Google, the Wassenaar arrangement, and vulnerability research

googleonlinesecurity.blogspot.com

51–59 of 59 posts

Re: Google, the Wassenaar arrangement, and vulnerability research

#51
post #3

> Global companies should be able to share information globally. If we have information about intrusion software, we should be able to share that with our engineers, no matter where they physically sit. This statement goes through just as well when applied to missiles, nuclear engineering knowledge, bio-weapons knowledge, etc. Governments have decided that they wish to use commercial entities as a proxy method for pr…

Well, if people all over the world were under a constant daily threat getting seriously ill from bio-weapons used by criminals and governments world wide (even against their own people), as is the current global situation in software security, then yes, I would very much make that same statement.

I would even argue that, especially in the case of bio-weapons, it would be a moral imperative to spread knowledge that could cure people.

Remember that (going back to the cybersecurity analogy) the criminals already have the weapons, as well as the knowledge and capability to develop completely novel weapons from scratch (they might even be better at it than the US).

For missiles the argument doesn't really hold, because knowledge of how to detect and protect oneself from missile attacks neither requires, nor strictly includes knowledge of how to actually build and use said missile.

So the two big reasonable arguments are:

- cyber attacks are already widespread, including global criminal organisations targeting civilians

- both cyber offence and cyber defence enabled by the same knowledge of cyber security

Re: Google, the Wassenaar arrangement, and vulnerability research

#52
post #4

A couple of items I'd like to add: (I'm Founder/CEO of a busy infosec biz) While infosec is currently a smaller sector in startups than say social, casual gaming, apps, etc, it's growing furiously and Wassenaar and individual country regs will be top-of-mind for much of the YC community in the years to follow because many of you will be in this space. I'd like to emphasize one of Google's points: "Global companies sh…

Also decriminalisation of software security research public image must happen and it needs some serous PR effort backed by a solid industry association or stakeholder. Otherwise big fish will PR-down all the small fish into regulation network woven by itself.

Re: Google, the Wassenaar arrangement, and vulnerability research

#53
post #47

Earlier quoted context omitted.

That's a really big debate: small vs big government, Keynesian vs Hayekian economics, public vs private sector and so on. I'd say from my side that government and private sector have a role in protecting you. Government tends to excel at things like air traffic control and lighthouses where there isn't much scope for competition and where competition may harm. Private sector tends to do things more efficiently when c…

I'm sorry but I don't see how a private company "protects" you in any way.

Neither does any state. I am afraid, security is individual responsibility these days.

Re: Google, the Wassenaar arrangement, and vulnerability research

#54
post #10

Earlier quoted context omitted.

Hacking Team was in the business of selling zero-days to government for the purpose of enabling surveillance. That's what people find objectionable. It's the difference between culturing a microbe to make a vaccine or make a bioweapon. The latter should get your ass droned.

> It's the difference between culturing a microbe to make a vaccine or make a bioweapon. The latter should get your ass droned. As a last resort. Ideally, it would get your ass arrested, your lab destroyed, and a speedy trial.

Welcome to the real world, Neo. If you dig deeper, you will probably find shady Bahamas funds backing companies like that, and one may get an enlightenment, that government of one unspecified country feeds the company in question with zero-days to make a careful provocation to become able to receive public mandate on building tighter regulations for some future markets. Uhh...

Re: Google, the Wassenaar arrangement, and vulnerability research

#55
post #9

Earlier quoted context omitted.

Public disclosure apparently won't require a license anyway: > Third, export controls do not apply to any technology or software that is "published" or otherwise made publicly available. http://bis.doc.gov/index.php/policy-guidance/faqs#subcat200 (The FAQ also states that information about vulnerabilities, as opposed to how to exploit them, would not be controlled, but I believe Google if they say the legalese is ins…

Yes, we need a war on warez to go with our wars on terror and drugs, which have been rousing successive, having driven both of those social ills to extinction.

The war is on and we are losing. Yesterday a 56 year old bricky from Watford called my in panic. His old XP laptop was literally taken as hostage asking to call some paid phone number to unlock computer back again.

Re: Google, the Wassenaar arrangement, and vulnerability research

#56
post #36
post #33

Earlier quoted context omitted.

I find the idea that I can write a weapon on my computer laughable and I can't see how the hacker community can justify attacks on freedom of speech. This is pre-emptive censorship and as such self evidently entirely morally wrong.

In fact, this is a point I am curious about. IANAL, but the case of Bernstein v. United States, while mooted before it could come to a true conclusion, seems to demonstrate that there is legal plausibility to the argument that publishing source code of "dangerous" systems is protected by the First Amendment. While cryptography is less immediately harmful than some of the things prohibited in this case, the circumstan…

But Stuxnet harmed nobody and nothing until it was hooked into physical hardware. This is my main point - I can't actually change anything in the real world, unless I am controlling some hardware, but then the situation is the same as if I was operating it directly.

I agree with you that surveillance is unpopular among hackers, but I am old enough to remember when censorship was considered at least as bad I would like it to stay that way.

Re: Google, the Wassenaar arrangement, and vulnerability research

#57
post #45

Earlier quoted context omitted.

There is a very simple reason why "regulation" in this space will never do anything useful. The cost of entry is very low (an individual can find vulnerabilities without any specialized infrastructure or organizational backing), and the value of vulnerabilities is high. It's basically the war on drugs if drugs could be transferred over the internet. Worse, the majority of the offenders are not in your jurisdiction to…

> There is a very simple reason why "regulation" in this space will never do anything useful. The cost of entry is very low (an individual can find vulnerabilities without any specialized infrastructure or organizational backing), and the value of vulnerabilities is high. The cost of entry is not low though. To find a bug is one thing, to build a functioning exploit and associated payloads to weaponise it takes a tea…

> The cost of entry is not low though. To find a bug is one thing, to build a functioning exploit and associated payloads to weaponise it takes a team of engineers.

"Team of engineers" is a bit of an overstatement. It's well within the capacity of an individual engineer. And the payload doesn't really change based on the exploit anyway; different RCE vulnerabilities are essentially fungible.

> At the very least, we can prevent the likes of hacking team and gamma group from operating legally in western countries.

How is that even useful? If it's going to happen anyway then you want it to happen in the open so you at least know what is happening. Push it underground or into places like Russia where you have limited visibility and it only makes it harder to catch the real bad guys.

> We can only dream.

I don't understand why they aren't already doing that. It's essentially a publicly-funded bug bounty program. The only disadvantage at all is that it costs money, and that's a pretty dumb excuse if this is half the problem they're making it out to be.

Re: Google, the Wassenaar arrangement, and vulnerability research

#58
post #32

Earlier quoted context omitted.

Most patches inherently reveal the vulnerability they fix. Patches not being controlled would be a loophole big enough to fit a whole planet through. And private patches are a thing. Vendors often distribute an early version of the patch to major customers for validation testing. Or if you like, substitute "patch" for vulnerability information that enables a workaround. You can defeat Heartbleed by turning off TLS he…

Out of curiosity, have you read the actual proposal?

The actual proposal is dozens of pages of legalese that would take a team of lawyers a week to decipher. I have no idea what it says because it is totally incomprehensible.

That's half the problem. If you're AT&T or Google you can hire said team of lawyers to tell you what it says, but what is an individual graduate student or security consultant supposed to do?

The other half of the problem is that what it says doesn't change the outcome, because the insolubility of the issue comes from economics rather than policy. There is no policy that will keep vulnerability information out of the hands of the bad guys only, because there is no practical way for most people to even identify who the bad guys are.

Re: Google, the Wassenaar arrangement, and vulnerability research

#59

Earlier quoted context omitted.

Yes, we need a war on warez to go with our wars on terror and drugs, which have been rousing successive, having driven both of those social ills to extinction.

The war is on and we are losing. Yesterday a 56 year old bricky from Watford called my in panic. His old XP laptop was literally taken as hostage asking to call some paid phone number to unlock computer back again.

My point, since you missed it, is the instrumenting a "war on warez" in the style of "war on drugs" or "war on terror" is a joke, and should be disregarded as just the talking point of someone with a different idea trying to sell you something.
Post reply on HN