In a recent Wall Street Journal Op-Ed, Bruce Schneier nicely summarizes this dilemma stating,
what happens when both the good guys the NSA wants to protect, and the bad guys the NSA wants to eavesdrop on, use the same systems? They all use Microsoft Windows, Oracle databases, Internet email, and Skype. When the NSA finds a vulnerability in one of those systems, does it aler the manufacturer and fix it - making both the good and bad guys more secure? Or does it keep quiet about the vulnerability and not tell anyone - making it easier to spy on the bad guys but also keeping the good guys insecure?
Can this dilemma be resolved via a calculation regarding our exposure to a vulnerability compared to the potential value of intelligence gained through the vulnerability? Is it possible to calculate our total exposure to a vulnerability when many of the targets of cyber crime and cyber espionage are in the private sector?
No comments:
Post a Comment