Earlier quoted context omitted.
Bruce Schneier has been complaining about this tradeoff for more than a decade: https://www.schneier.com/blog/archives/2014/05/disclosing_vs... >The NSA can play either defense or offense. It can either alert the vendor and get a still-secret vulnerability fixed, or it can hold on to it and use it to eavesdrop on foreign computer systems. Both are important US policy goals, but the NSA has to choose which one to purs…
I know this would be hard to keep under wraps, and extremely difficult for closed source software, but it seems like the right answer here would be for the NSA to create patches for government use. If the government only used open-source software, the NSA could create patches that only the government would use, while keeping zero days that can be used against everyone else. If the government started requiring all/mos…
U.S. government probes VPN hack within federal agencies, races to find clues
41–50 of 61 posts
Re: U.S. government probes VPN hack within federal agencies, races to find clues
#42> The U.S. plans to address some of these systemic issues with an upcoming executive order that will require agencies to identify their most critical software and promote a “bill of materials” that demands a certain level of digital security across products sold to the government. Interesting, no mention of any requirements towards software manufacturers themselves. If you think about it, this will further incentiviz…
If I were a federal contractor, wanting to make more from my cost plus contraction, what better way than generating text files full of dependencies that will cause billable meetings to discuss why we should be ok with some old insecure library being used... that will always end with even more billable work to update the old, insecure library. Even better would be if I had to incur some billable time and cost on certi…
Re: U.S. government probes VPN hack within federal agencies, races to find clues
#43Earlier quoted context omitted.
They could build in a requirement that the software has undergone penetration testing by a security firm, and that a copy of the penetration testing report along with any mitigations applied to the software be provided. I've never even heard of the software the government is using. Why aren't they using Cisco AnyConnect like literally every other company I've worked for who has a VPN?
Not all agencies, but the US gov't does use Cisco AnyConnect and pretty much everything they use for IT is COTS these days.
Re: U.S. government probes VPN hack within federal agencies, races to find clues
#44Earlier quoted context omitted.
Bruce Schneier has been complaining about this tradeoff for more than a decade: https://www.schneier.com/blog/archives/2014/05/disclosing_vs... >The NSA can play either defense or offense. It can either alert the vendor and get a still-secret vulnerability fixed, or it can hold on to it and use it to eavesdrop on foreign computer systems. Both are important US policy goals, but the NSA has to choose which one to purs…
I know this would be hard to keep under wraps, and extremely difficult for closed source software, but it seems like the right answer here would be for the NSA to create patches for government use. If the government only used open-source software, the NSA could create patches that only the government would use, while keeping zero days that can be used against everyone else. If the government started requiring all/mos…
Re: U.S. government probes VPN hack within federal agencies, races to find clues
#45Re: U.S. government probes VPN hack within federal agencies, races to find clues
#46That would be an insane waste of resources.
Re: U.S. government probes VPN hack within federal agencies, races to find clues
#47Do people know that Fortinet is pretty much a de-facto Chinese company?
Re: U.S. government probes VPN hack within federal agencies, races to find clues
#48> The U.S. plans to address some of these systemic issues with an upcoming executive order that will require agencies to identify their most critical software and promote a “bill of materials” that demands a certain level of digital security across products sold to the government. Interesting, no mention of any requirements towards software manufacturers themselves. If you think about it, this will further incentiviz…
Re: U.S. government probes VPN hack within federal agencies, races to find clues
#49Prediction: at some point (if it isn't already happening as we speak), the government insistence on "we need to be able to hack into any software if it's important" will collide with "we need to be able to keep foreign powers out of our software", and there will be bitter internal fights about it, both sides claiming national security interests.
:)
Re: U.S. government probes VPN hack within federal agencies, races to find clues
#50Prediction: at some point (if it isn't already happening as we speak), the government insistence on "we need to be able to hack into any software if it's important" will collide with "we need to be able to keep foreign powers out of our software", and there will be bitter internal fights about it, both sides claiming national security interests.