I liked Kurt Wismer's post Flame's Impact on Trust. He says:
if you haven't watched it yet, i encourage you to check out the video of chris soghoian's talk at personal democracy forum 2012. the TL;DR version is that, because it compromised the microsoft update channel, the flame worm damaged our trust in automatic updates and that's a bad thing because automatic updates have done so much good for consumer security.
mikko hypponen is even reported to be planning to write a letter to barack obama to ask him to stop the US government from doing this sort of thing again.
Kurt links to this story US Government Behind Flame Virus According to Expert with choice quotes like this:
Hypponen believes that making Microsoft digital certificates untrustworthy in the eyes of some of the 900 million Windows users around the globe is a very serious and worrying move...
Hypponen told IBTimes UK that he was planning on writing an open letter to Barack Obama this week to say: "Stop taking away the trust from the most important system we have, which is Microsoft Windows Updates."
To be blunt, this is one of the dumbest arguments I've ever heard. I don't think this is the right approach. The reason is simple:
If a "security researcher" discovered and weaponized the vulnerability, the argument would be totally different.
The security research community would be pointing at Microsoft for being at fault for developing such vulnerable software and processes. The "security researcher" would present his or her findings at a major security conference and receive rock star treatment. Those promoting "full disclosure" would push back on any attempts to contain information about the attack. And so on...
The bottom line is that a "security researcher" discovered and weaponized the vulnerability. Critics should start with that fact and let their normal security instincts take over.
Update: I struck the inflammatory language because I didn't intend for this post to be interpreted as a personal attack. To be honest I was feeling ornery after my early morning flight was cancelled, and an eight hour wait at the airport wasn't doing my mood any favors. Sorry Mikko and Chris!
0 komentar:
Posting Komentar