9 ms·
Their job is to collect signals intelligence and execute cyber warfare operations. Not whatever you think it is.
by xrayzerone 7y ago
Their job is to collect signals intelligence and execute cyber warfare operations. Not whatever you think it is.
- mrchucklepants 7y agoTheir job is more than that. "The National Security Agency/Central Security Service (NSA/CSS) leads the U.S. Government in cryptology that encompasses both signals intelligence (SIGINT) and information assurance (now referred to as cybersecurity) products and services, and enables computer network operations (CNO) in order to gain a decision advantage for the Nation and our allies under all circumstances." [1] https://www.nsa.gov/about/mission-values/ https://www.nsa.gov/about/mission-values/
- xrayzerone 7y agoSo...SIGINT and CNO. Exactly as I stated.
- toomuchtodo 7y agoSecurity assurance isn’t necessarily cyber warfare. To have the high ground is not the same as using it offensively, hence the expectation of defensive posture as part of the NSA’s mission (although admittedly some offensive activities are to be expected, depending on the situation, such as Stuxnet and Iran).
- ericmason 7y agoNot sure if you’re just being snarky, but the NSA’s stated mission includes helping with cyber security: https://www.nsa.gov/about/mission-values/ https://www.nsa.gov/about/mission-values/
- xrayzerone 7y agoAnd what do you think the end state of all that cybersecurity research is?
- wolf550e 7y agoNSA has both attack and defense mandates and organizations. Currently, the attack org has priority, but it's not like the defense org does nothing. So if the attack org doesn't want a vuln, they can let the defense org reveal it for PR points.
- monoideism 7y agoNSA has long had an explicit offensive and defensive mandate. They even recently created a cyber defense directorate: https://www.washingtonpost.com/national-security/nsa-launches-new-cyber-defense-directorate/2019/09/30/c18585f6-e219-11e9-be96-6adb81821e90_story.html https://www.washingtonpost.com/national-security/nsa-launche...
- Ajedi32 7y agoIt also involves breaking enemy cyber security (signals intelligence). It's actually a rather fascinating incongruity, since we live in a world where "the enemy" is more likely than not to be using the same software systems that the NSA themselves are, and that therefore any exploitable flaws they find in enemy systems are pretty likely to be just as exploitable in their own. (And that similarly, disclosing the flaw in order to fix the issue in their own systems is very likely to result in "the enemy" fixing the flaw as well.) A couple years ago the White House released a document explaining the process they use for deciding what vulnerabilities they keep secret: https://www.cnet.com/news/white-house-trump-administration-hacking-security-flaws-vulnerabilities/ https://www.cnet.com/news/white-house-trump-administration-h... noting that "In the vast majority of cases, responsibly disclosing a newly discovered vulnerability is clearly in the national interest". Though from what we've seen in past leaks, it's pretty obvious they don't reach that conclusion for all vulnerabilities they find.