1. Strong encryption works and data in transit and at rest can be secured.
2. Node security doesn't work, and state actors are behaving irresponsibly by creating a market in insecurity by buying zero-day attacks. This is analogous to buying bioweapons from freelance laboratories and hoping nothing really bad happens. How do you "govern" a dangerous practice like that?
The article appears to assume that all nations will accept a subservient role in a monitored world. Nobody will want actual confidentiality for their government and industry. That doesn't seem plausible.
Hey, if we can capture the packets today, it's only a matter of time until quantum computers are brought online and AES256 is rendered as strong as wet paper.
(Or so the gamble might go)
Well, aint that just the question. If you're not working on world-changing technologies (~= morally defensible alternatives to today's centralized technologies) then quit your job and get with the program.
Sounds a lot like the Central Intelligence Corporation from Snowcrash. Presumably Google glass owners are going to become the gargoyles.
I keep expecting the first publicly known example to be conspiracy nutcases deploying drones into Area 51 or similar... We've already seen what the semi-anonymity of hacking over the network leads to.
Over the next few years, we're likely to see the next step: With robotic delivery platforms becoming small enough and cheap enough to be hard to stop/track (either because they're hard to spot, or simply because they're cheap enough that there can be ridiculous numbers of them), and sensors and networking lets "anyone" capture high quality images etc., while gaining some chance at evading capture by being physically detached from an intrusion.
On one hand there's plenty of potential for abuse against individuals, and for corporate espionage and organized crime. On the other hand, it seems like we're at a stage where it may become incredibly hard for state intelligence and military actors to prevent individual civilians, political groups or organized crime from carrying out intrusions of an unprecedented level.
And here's the thing; it's a tool that's most effective against the midlist, the strivers, the up and coming execs and entrepreneurs who can't afford a real security detail yet. If you start hearing a lot of stories about promising young execs dying by weird household and office mishaps that could involve automated machinery ( like burned to death by scalding water from a dishwasher, electrocutions, garage doors closing at inopportune moments or such.)... you might be seeing traces of an organized campaign.
Just something to think about next time you step into a hotel elevator...
I'm reminded of the EE-vs-CS joke about how to design a toaster[1]. Engineering-major rivalries aside, I've always liked it for its caution against over-engineering. For some things - such as elevators - we hit "good enough" a long time ago.
I wonder if "non-programmability" will become a popular feature in the future, specifically to avoid these risks. Using non-Turing Complete "Little Languages"[2] or hardware that's fixed to a single circuit could help. Unfortunately, it's probably too late; we spent the last few decades putting CPUs into everything, and now we get to slowly find out how many security holes that additional complexity left us with.
Isn't it called Google?
Tell your less technical friends not to post shit to the internet.
Last I checked, Russia was not shoveling many billions in aid to Pakistan along with F16s & other weapons systems with the misguided hope that engagement is better than outright confrontation of a failed state with Nukes.
So India "sharing intelligence with NSA vs FSB" as proof of some Network effect is bogus. NSA spies on Pakistan extensively via direct & indirect methods, FSB does not (that we know of).
Blog posts consisting of nothing but an excerpt from someone else's work generally don't count as good links for HN.