Live data from Hacker News

Google, the Wassenaar arrangement, and vulnerability research

googleonlinesecurity.blogspot.com

31–40 of 59 posts

Re: Google, the Wassenaar arrangement, and vulnerability research

#31
Hey there,

if anyone wants some more background on all the negative side-effects of the current regulation, I wrote a lengthy blog post on the problems with the current phrasing of the Wassenaar amendments here:

http://addxorrol.blogspot.ch/2015/05/why-changes-to-wassenaa...

(Background: I am a security researcher who designed industry-standard patch analysis algorithms / software, built algorithms & a startup for malware reverse engineering that was acquired by Google, pioneered several exploitation techniques, and worked heavily on the recent Rowhammer vulnerability)

Re: Google, the Wassenaar arrangement, and vulnerability research

#32
post #24

Earlier quoted context omitted.

Having read the definitions of what is controlled in the proposed rule, I'm pretty confident a patch wouldn't come close. And in any case, since the rules don't apply to public software, that only matters in the case of private patches, which aren't really a thing, and would be a pretty big moral hazard if they were.

Most patches inherently reveal the vulnerability they fix. Patches not being controlled would be a loophole big enough to fit a whole planet through. And private patches are a thing. Vendors often distribute an early version of the patch to major customers for validation testing. Or if you like, substitute "patch" for vulnerability information that enables a workaround. You can defeat Heartbleed by turning off TLS he…

Out of curiosity, have you read the actual proposal?

Re: Google, the Wassenaar arrangement, and vulnerability research

#33
post #9

>You should never need a license when you report a bug to get it fixed That hampers people that wish to publicly disclose or sell vulnerability information. This is massively biased in favour of software companies (to some extent, like Google). You should never need a license to disclose vulnerability information, full stop. >Global companies should be able to share information globally Why should this be limited to…

Public disclosure apparently won't require a license anyway: > Third, export controls do not apply to any technology or software that is "published" or otherwise made publicly available. http://bis.doc.gov/index.php/policy-guidance/faqs#subcat200 (The FAQ also states that information about vulnerabilities, as opposed to how to exploit them, would not be controlled, but I believe Google if they say the legalese is ins…

I find the idea that I can write a weapon on my computer laughable and I can't see how the hacker community can justify attacks on freedom of speech. This is pre-emptive censorship and as such self evidently entirely morally wrong.

Re: Google, the Wassenaar arrangement, and vulnerability research

#34
post #29

Earlier quoted context omitted.

You should read the whole story before commenting; this is about foreign trade in exploits.

Inalienable rights. Not civil rights. Inalienable rights are human rights - which extend (at least in theory) to foreigners. I read the story. But anyway if the Supreme Court ruling holds from Zimmerman it would apply equally well to everything in the article. Of course the Zimmerman case was about foreign exports as well. Try to be charitable.

If the downvoter needs help understanding the historical analogy that makes this above comment make sense: https://en.wikipedia.org/wiki/Pretty_Good_Privacy#Criminal_i...

Re: Google, the Wassenaar arrangement, and vulnerability research

#35

Aren't cyberarms arms? Isn't the right to bear arms an 'inalienable right'? I don't get it. And I don't get why this is a 'privacy' or 'free speech' issue or why corporations, as Google argues, should be exceptions to the law.

> Isn't the right to bear arms an 'inalienable right'?

Not in any American sense of the term. The "unalienable" rights were to life, liberty, and the pursuit of happiness as outlined in the Declaration of Independence. Selling guns to redcoats isn't on that list.

Re: Google, the Wassenaar arrangement, and vulnerability research

#36
post #33
post #9

Earlier quoted context omitted.

Public disclosure apparently won't require a license anyway: > Third, export controls do not apply to any technology or software that is "published" or otherwise made publicly available. http://bis.doc.gov/index.php/policy-guidance/faqs#subcat200 (The FAQ also states that information about vulnerabilities, as opposed to how to exploit them, would not be controlled, but I believe Google if they say the legalese is ins…

I find the idea that I can write a weapon on my computer laughable and I can't see how the hacker community can justify attacks on freedom of speech. This is pre-emptive censorship and as such self evidently entirely morally wrong.

In fact, this is a point I am curious about. IANAL, but the case of Bernstein v. United States, while mooted before it could come to a true conclusion, seems to demonstrate that there is legal plausibility to the argument that publishing source code of "dangerous" systems is protected by the First Amendment. While cryptography is less immediately harmful than some of the things prohibited in this case, the circumstances still seem pretty similar to me; and if these rules were overturned on such grounds, I cannot say I would be all that upset, as such a decision would likely also imply protection for a lot of stuff I like more than this.

That said, when you consider things like Stuxnet, which physically destroyed industrial facilities, I'd say the idea that malware can be a weapon is harder to dismiss these days than in teh past. Admittedly, most zero-day exploits do not have so close an analogy, but in the wrong hands they can certainly help put people in physical danger.

In any case, surveillance is hardly something the 'hacker community' is thrilled about - as per the zeitgeist in this forum, at least...

Re: Google, the Wassenaar arrangement, and vulnerability research

#37
Previous export restrictions on crypto and certificates gave non-US participants (Mark Shuttleworth) the opportunity to take up the slack and build a business where there were no such restrictions. He simply had to fulfill the demand that existed outside of the US in large part due to export restrictions.

The Wassenaar Arrangement is likely to result in similar unintended effects combined with a similar lack of intended effects.

Re: Google, the Wassenaar arrangement, and vulnerability research

#38
post #12
post #3

> Global companies should be able to share information globally. If we have information about intrusion software, we should be able to share that with our engineers, no matter where they physically sit. This statement goes through just as well when applied to missiles, nuclear engineering knowledge, bio-weapons knowledge, etc. Governments have decided that they wish to use commercial entities as a proxy method for pr…

The key difference between those technologies and this is that industrial production hardware (centrifuges or specialized biological equipment, etc) are needed in addition to specialized knowledge of the topic at hand. These additional requirements make export controls a lot more enforceable, and why you can, say, send regulators to the site of a nuclear engineering facility and get a reasonable answer about if they…

This is not a practical distinction with regard to the legislation.

A word document describing the specification for an export controlled technology is as prohibited from export as the implementation.

Having the word document on a laptop you take to another country is as much a breach of the law as shipping a centrifuge.

Re: Google, the Wassenaar arrangement, and vulnerability research

#39
It's probably worth remembering that there is an open source exemption. If a piece of 'intrusion software' has been published the export controls no longer apply.

Publish your exploits to github before you send them overseas or travel to the conference to announce them.

Post reply on HN