Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Fri, 23 Jun 2023 11:34:28 +0300
From: Georgi Guninski <gguninski@...il.com>
To: oss-security@...ts.openwall.com
Subject: Opinion: Governments don't want IT security, they want to have cyber weapons

Some time ago i posted this on my blog [1] and on linkedin [2]

What the security community thinks about it?

Inline:

Tue Aug 17 14:35:14 EEST 2021
Opinion: Governments don't want IT security, they want to have cyber weapons


Support for the above claim:

    In 2015 exploits of NSA were leaked by Shadow crew. Search terms:
nsa leak shadow crew. E.g. see NSA Hacked? 'Shadow Brokers' Crew
Claims Compromise Of Surveillance Op
    From 2015 search terms "hacking team" leak, E.g. Hacking Team Leak
Shows How Secretive Zero-Day Exploit Sales Work

    It provides both the exploits and RCS to government intelligence
and law enforcement agencies around the world, and has come under
attack for selling to repressive regimes, who've used them to target
political activists and dissidents. But more interesting than the fact
that the company possessed zero days---this was already known---is the
correspondence around how Hacking Team acquired these valuable tools,
prized equally by criminal hackers and government intelligence
agencies.

    From 2021: Search terms pegasus spying scandal. The allegations
that spy software known as Pegasus may have been used to carry out
surveillance on journalists, activists - and even perhaps political
leaders - highlights that surveillance is now for sale.

If governments wanted security, they would report the bugs to the vendors.

Like in traditional warfare, cyber warfare requires weapons. It is
very hard to construct physical nuclear bomb, but to construct cyber
nuclear bomb requires just skills and zero budget. Some drunk skilled
kid may do a lot of damage in the real world.

Who watches the watchers?


[1]:  https://j.ludost.net/blog/archives/2021/08/17/opinion_governments_dont_want_it_security_they_want_to_have_cyber_weapons/index.html
[2] https://www.linkedin.com/pulse/opinion-governments-dont-want-security-have-cyber-weapons-guninski

-- 
guninski https://j.ludost.net/resumegg.pdf

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.