CIA’s venture firm security chief: US should buy zero-days, reveal them

From: ars technica

In-Q-Tel CISO tells Black Hat: end cyber arms race by “clearing the market.”

by

LAS VEGAS—In a wide-ranging keynote speech at the Black Hat information security conference today, computer security icon Dan Geer gave attendees a sort of personal top 10 list of things that could be done to make the Internet more secure, more resilient, and less of a threat to personal privacy. Among his top policy picks: the US government should move to “corner the market” on security vulnerabilities by paying top dollar for them and then publish them to the world.

***

“Net neutrality is not a panacea,” he said, adding that Internet providers’ ability to claim the protections of being a common telecommunications carrier while avoiding liability for what passes over them allowed them to duck any responsibility for security.

He declared that ISPs needed to be “restricted to a constrained set of choices. You can charge whatever you want, but you are responsible for what you carry; or you can be a common carrier and not monitor traffic. You get one or the other, but you don’t get both.” 

Read Complete Article

Facebooktwittergoogle_plusredditpinterestlinkedinmail

Leave a Reply

Your email address will not be published.

Please Answer: *