Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

When it comes NSA pen testing, its not that some things are "impenetrable" its a question of how far they are willing to go, and who they are willing to p__ off to do it.

There are limits, both legal and political, that the NSA won't cross but a private contractor doing pen testing might try.

Rightly or wrongly, about the only way most US private companies can get a proper grasp of what the NSA is capable of is to hire a senior former NSA officer.

http://ironnetcyber.com/executive-team.html



This is possible. However, I read many of the papers and Final Evaluation Reports from this time period. They usually found the common and some uncommon flaws in systems with feedback to vendors. One of a UNIX aiming for higher assurance heavily criticized its lack of hardware-level enforcement and architectural issues. They also standardized on assurance and design techniques with similar re-applications to ensure what worked before would again. Evaluations were done by people from private labs and NSA's IAD hackers sometimes repeated by other groups.

So, altogether, they probably got plenty of review. They could still use more from independents with great skill. So far, though, solid in review and the field in high risk is saying something.

Re hiring a former NSA officer

Others and I have been telling all of you for years what they're capable of. You just look at each layer or compondnt to see what a subversion/breach would do. Then read years of papers showing how to avoid those. Then notice what each product is or isnt applying. Then you know they were breaking almost all of it. ;)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: