Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

While it may be true that in this particular instance the FBI might act benevolently, the idea was that it would be nice if there was an organization you could go to with any zero day bug. Even if the FBI is not mismanaged and always tries to protect Americans, you could easily imagine a scenario where someone reports an exploit to an OS where anyone can remotely install a key logger. The FBI wouldn't be a good organization to report this to because they may want to use this to track down criminals which, they would no doubt feel, would greatly outweigh the cost to Americans that the zero day represents.

The EFF seems like a good choice. In general you would need to pick an organization that does not have a vested interest in using exploits.



> While it may be true that in this particular instance the FBI might act benevolently

Indeed. Didn't the FBI effectively purchase a zero day to break into the iPhone of the San Bernardino shooter? Didn't they also then not disclose said zero day to Apple?

There's no way that any LE agency can be trusted with this responsibility; I'm not convinced that it can be done by the federal government at all. EFF seems like a reasonable choice, but even non-profits have the potential to be corrupted/subverted (and operating as a dump for zero days has the power to corrupt, for sure, regardless of how moral your organization claims to be on its website).

This definitely falls under the umbrella of hard-problems-in-politics-that-will-not-be-solved-any-time-soon


What if there were multiple non-profits that can keep each other honest?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: