TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

The FBI is working hard to keep you unsafe

93 pointsby colincarter41about 9 years ago

6 comments

tptacekabout 9 years ago
We don't accept this argument when it's turned on independent researchers. Researching vulnerabilities doesn't create vulnerabilities --- bad software engineering does.
评论 #11564655 未加载
评论 #11564965 未加载
评论 #11564721 未加载
评论 #11565108 未加载
评论 #11565586 未加载
评论 #11564705 未加载
评论 #11564668 未加载
评论 #11565170 未加载
评论 #11565214 未加载
评论 #11564718 未加载
评论 #11564984 未加载
评论 #11565239 未加载
chatmastaabout 9 years ago
As long as software exists, by definition, zero-days will exist. A zero-day is simply a bug in its most nascent state; one person has found it, and nobody else knows about it. Whether the finder is a &quot;security researcher,&quot; a &quot;blackhat,&quot; or a &quot;nation-state&quot; has no impact on whether the bug exists or not. In fact, the bug exists even if nobody finds it! The distinction of who found it, and what they do with it, is purely political. Anyone can still exploit the bug.<p>Sure, maybe the &quot;friendlier&quot; bug finders will responsibly disclose any bugs they find. But there will <i>never</i> be a way to guarantee that all bugs found will be responsibly disclosed. Even if we convince the FBI&#x2F;NSA to &quot;responsibly disclose&quot; every bug they find (will never happen), what about every other country? The hundreds of security firms? The thousands of independent hackers and &quot;researchers?&quot;<p>Zero-days will ALWAYS exist. Software will ALWAYS be exploitable. Worrying about how people react when they find those exploits is the similar to arguing about gun control. Sure, maybe we can convince <i>some</i> actors to responsibly disclose, but the bad actors will always keep the exploits for themselves and use them &quot;irresponsibly.&quot; And there will always be bad actors.<p>So instead of fretting about what happens when someone finds a bug, why don&#x27;t we prepare for the eventuality that all bugs will be found and exploited, often times without anyone&#x27;s knowledge? Why don&#x27;t we build security systems to be <i>tolerant</i> of exploits, instead of resistant to them? There is no security panacea, just as there is no reliability panacea.<p>We build distributed systems with the assumption that nodes will fail, and we call that &quot;fault tolerance.&quot; We don&#x27;t say a system is broken because a node fails. We say it&#x27;s broken if it cannot handle a node failing.<p>Why can&#x27;t we do the same for our security systems? Exploits are as inevitable as any type of system failure. We need to design for <i>exploit tolerance</i> with the same enthusiasm we design for <i>fault tolerance.</i>
评论 #11565451 未加载
评论 #11565152 未加载
busterarmabout 9 years ago
Let&#x27;s not forget that Sabu, while an informant for the FBI, supplied Jeremy Hammond with the 0day that he used to hack Stratfor et al.<p>No 0day, no Stratfor hack. No FBI, no Stratfor hack.<p>Sometimes I wonder if penetrating other agencies and corporations was part of their gameplan. The FBI were entirely behind the formation of antisec.<p>Aside: Other interesting observation... The FBI and Apple seem to have an odd antagonistic relationship with one another. One of the Antisec hacks was against an FBI laptop that caused the release of millions of Apple users&#x27; data. The FBI was recording and debriefing Sabu every day. How did they allow that to happen?
评论 #11564611 未加载
rm_-rf_slashabout 9 years ago
Let&#x27;s all accept a depressing fact: effective cyber-security places all of us in a state of perpetual war. You cannot learn from your enemy without invasive action, and you cannot test your capabilities without constantly attacking your adversaries, whether they know it or not. We cannot simply fork their nation&#x27;s Github repo and try out zero-days in a safe and isolated environment.<p>We shouldn&#x27;t be so quick to rail against government zero-day stockpiling. It is likely that other branches of government are using these flaws for their own means to monitor foreign states and other entities. If we give up that power we risk crippling our offensive capabilities more than we might stand to gain by having a stronger defense.<p>I cannot vouch for one side or the other. I am not a senior intelligence official and I do not have all the facts.
评论 #11564927 未加载
评论 #11564599 未加载
guard-of-terraabout 9 years ago
&quot;Terrorists hurt you, so we have to hurt you to compensate&quot;.
lasermike026about 9 years ago
&quot;Power tends to corrupt, and absolute power corrupts absolutely.&quot; - John Emerich Edward Dalberg-Acton