#vendorrisk — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #vendorrisk, aggregated by home.social.
-
With the new hack-back memo, the US has shot itself in the foot again. And most of the initial online discussions miss how far the damage reaches. For the US.
Quick summary. On August 12 the President signed a memorandum letting vetted American companies break into foreign systems used by criminal groups and disrupt or destroy them. It is not vigilantism: the companies act under federal direction, and two officials approve every operation in writing.
Americans lost more than $20 billion to this fraud last year, so the motivation is real. I am not against acting. I am against this approach, and I know the arguments because I spent years making them to governments that wanted the same thing.
The debate so far has been about whether private firms should do this, and whether innocent foreigners get hurt. However I analyze it, the first casualty is American:
- Why would anyone share threat intel with Americans, when it could now be used to attack infrastructure in their own country?
- Why would a non-US CISO keep American EDR and XDR agents deep in their stack, when nobody can tell them whether that vendor also runs surveillance and offensive operations for the state?
- Why would anyone outside the US let an American vendor build the map of their weakest cryptography, in the PQC discovery and inventory work their own regulator is forcing them to do?
- Why would a European buyer accept "we cannot comment" as a tender answer?
- Why would an American firm disclose the flaw it just found, when its other contract values that flaw unpatched?
- Why would a sovereign wealth fund hold a listed US security vendor it has no way to assess?
- Why would an allied service share access with a partner whose contractors may be on the same box?
- How does a US prosecutor explain the next indictment of a Chinese contractor hacker?
- What does Washington say when Beijing runs the same program and calls it law enforcement?
Procedures are due October 11 and need not be published. Which means these questions may never get a public answer, and every one of them will get answered by assumption instead. None of those assumptions will favor the American cybersecurity industry.
https://postquantum.com/cyber-kinetic-security/cyber-privateers-what-breaks/
#Cybersecurity #CISO #CyberPolicy #ThreatIntel #NationalSecurity #InfoSec #VendorRisk #PQC