TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Google: Stop Burning Counterterrorism Operations

35 pointsby avastel11 months ago

13 comments

halJordan11 months ago
I remain unconvinced that the benefits of secrecy are outweighted by the benefits of transparency. It's unfortunate that the threat actor was caught so hard, but that is the cost of doing business. Couching it as protect the children or punish the terrorists doesn't change the fundamentals. Police work, soldier work, IRS work. They all have to work within and around the "normal" world. They aren't allowed to just demand obeisance because it makes their job easier
ein0p11 months ago
So much trouble over creating, funding, and arming “freedom fighters”/“moderate rebels” to (unsuccessfully) take down Assad. I think I concur with Google TAG here. I think exposing and fixing zero days is better than not doing so, simply because other countries can find them also. Which this article openly acknowledges thus defeating its own argument
评论 #40785505 未加载
rs_rs_rs_rs_rs11 months ago
I personally am thankful to Google for doing the thing that's right for everyone(fixing security vulnerabilities) not just some "Western" countries as the author put it(not sure why the capital w but I am not a native english speaker)
评论 #40781440 未加载
schoen11 months ago
Upvoted despite vast disagreement because I (sort of) appreciate someone openly arguing this.
评论 #40781620 未加载
评论 #40781882 未加载
评论 #40779690 未加载
poincaredisk11 months ago
I&#x27;m a security researcher close to the field of the author. I&#x27;m usually very sceptical of what Google is doing.<p>In this case though, Google really did nothing wrong. They did what they should to protect their users. They didn&#x27;t know they&#x27;re interfering with a counter terrorist operation (according to the post), and even if they knew, who knows how many other less commendable operations they disrupted. And who knows who else was using the same vulnerabilities? I&#x27;m sure if Google disrupted Chinese or Russian operation the author would be very happy about that.<p>&gt;However, burning operations, no matter the actor and no matter the reason, demonstrates a grave misunderstanding of the critical role that cyber plays in reducing harm in the world.<p>I honestly don&#x27;t understand what the author tries to convey. What about Iranian operations targeting independent journalists? What about Chinese operations against Uyghurs? Is it also not OK to disrupt those? How should Google decide which operations are OK to disrupt? Especially since they don&#x27;t really have full insight into campaigns.
notactuallyben11 months ago
Interesting blog post that was long overdue, I think Google should probably disclose all the details (URLs&#x2F;actors responsible, methodology for catching these exploits ITW and targeting) around the ITW samples when they kill the bugs, so we can have nuanced discussion with actual facts. It would also help the threat intelligence industry ;)
ano-ther11 months ago
How are Google (and other security researchers) supposed to know that they are about to disturb a counter-terrorism operation?
评论 #40785910 未加载
jauntywundrkind11 months ago
The framing is absurd &amp; fascist to the core.<p><i>Someone</i> was cyber attacking Chrome. Unclear if Google had <i>even so much as a guess</i> they knew who from. There were bugs in Chrome. Google fixed the vulnerabilities, making the software obey the contract websites &amp; users have with each other, &amp; detailed why they were changing the open source code in such a fashion.<p>This is not burning an operation. Google didn&#x27;t name any operation or country. Google probably didn&#x27;t know who it even was!<p>If they had some guesses, &amp; did try to pick up the phone &amp; call say MI6, about this topic of leaving this exploit jeapordizing everyone running - <i>which they may well have done</i> (if they confidently track down the cyber attack) - the first most likely response is &quot;we have no idea what you re talking about&quot; in which case fixing the vulnerability &amp; writing a blog post is basically the only remotely acceptible option. You spent a while trying to find out who the cyber attack is launching from, you&#x27;ve gone crazy far to do due diligence to track down whose attack it is, and they say it&#x27;s not theirs. Ok your diligence was wrong, the cyber attack is coming from somewhere else or from multiple people, you need to resolve it.<p>Next option is whichever security agency either fesses up &amp; does the right thing. Google addresses the vulnerabilities, and writes a blog post about them.<p>Or, stand-in Intelligence Agency [SIIA] declares, no, we&#x27;re SIIA, and you&#x27;re leaving the defect in place, because we say so.<p>It&#x27;s unclear what the author is really protesting here? Bugs are critical to national security so we should let people exploit them? Oh that&#x27;s exactly what they&#x27;re saying.<p>&gt; <i>However, burning operations, no matter the actor and no matter the reason, demonstrates a grave misunderstanding of the critical role that cyber plays in reducing harm in the world.</i><p>&#x27;The military&#x27;s active use of indiscriminate cyberwarfare trump&#x27;s the right to find and correct defects.&#x27; Wow. That is a <i>bold</i> position.
评论 #40782316 未加载
lucasRW11 months ago
Part of the game... With Crowdstrike, Mandiant, Google, Kaspersky, etc, it&#x27;s hard to remain undetected these days !
hi-v-rocknroll11 months ago
Maybe instead of spending taxpayer money on weaponized &#x27;sploits from Zerodium while keeping everyone vulnerable, these three letter agencies should get off their lazy asses and develop HUMINT and use conventional intelligence sources and methods.
评论 #40788139 未加载
g8oz11 months ago
This is a real &quot;think of the children&quot; style argument the author is making. I&#x27;m sure if there are some unsavory operations that have been burnt they will not be trotted out.
ta11211211 months ago
maybe it&#x27;s payback for the time the NSA hacked Google and were siphoning off data after HTTPS decryption
评论 #40781772 未加载
tachyons11 months ago
TLDR:<p>USA should be allowed to use 0 days for their &quot;counter&quot; terrorism operations. This is interesting at the time of USA being complicit in a genocide against a community.
评论 #40785568 未加载