Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"Cyberwarfare" cannot be analogized to traditional war. There is no analog to mutually assured destruction. There are no open battlefields; every system attacked has a private or government owner. Every dollar spent on attacks instead of patching vulnerabilities leaves everyone else vulnerable to those attacks.

Instead of analogies and aphorisms, let's talk about actual consequences to actual tactics.



Software vulnerabilities are now the most important vector for signals intelligence, so really the argument here is whether there's a purpose to conducting signals intelligence, and whether it outweighs the harm done by postponing fixes for bugs that NSA could otherwise report.


Before I would ever change sides in that argument, I would need to see definitive proof that vulnerabilities in software I use are better for me than having those vulnerabilities fixed.

Unlike nuclear weapons, there aren't a lot of rare resources required for discovering vulnerabilities, so the approaches that help with nuclear nonproliferation will not help with digital security. All one needs is to find vulnerabilities is smart people (and maybe a lot of computing resources to brute force fuzz a lot of software). There are a lot of smart people and fast computers out there, and the ones not in the US almost certainly outnumber those that are inside the US. It seems it would be much better to defend against them and disarm entirely rather than hope to stay ahead of them.


I'll admit up front that I don't have a clearance of any sort, and I don't work in intelligence. But as a citizen of the USA, that particular argument is really quite irrelevant. I don't want my systems used by IDF Unit 8200, The Equation Group (or whatever the NSA calls themselves) or PLA Unit 61398. The "important vector" is a wide open hole I want patched. All the NSA arguments are pretty irrelevant, except for signs for the rest of us to regard the NSA as a rogue agency.

On some authority, you're asking me to put myself in the position of an NSA leader. I'm not an NSA leader. Postponing the bug fixes hurts me, and the rest of the people like me. Fix them.


That's not really the choices available. The options aren't NSA reports bugs/uses them for intelligence collection, its NSA uses bugs for intelligence collection or they don't find bugs at all.

Its possible that the right answer is we should have a US agency finding bugs and getting them patched, but it certainly shouldn't be any of the intelligence agencies. That feels a little too like putting the military in charge of the police force.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: