Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

In this case, the FBI and SEC may need to investigate precisely what is going on. If Intel is doing partial fixes it knows of other things that aren’t being disclosed there could be criminal activity occurring.

Additionally, this had big implications for cloud providers. If additional liabilities of data leaks are foisted on companies, insurance companies and corporate counsel may just say no more using amazon, google cloud, azure, etc.



> here could be criminal activity occurring.

More likely some agencies don't want their exploits to stop working.


Which is sad... It wouldn't bug me nearly as much if they (NSA etc) had a sunset/disclosure policy of a reasonably short timeframe (say 60 days or so) for disclosure to the org that makes the software/hardware.

I can understand a state agency keeping a security flaw a secret to exploit in the near term... but stockpiling for years only to let stuff leak eventually is just irresponsible.

Note: I'm not saying that I like state sponsored hacking, only that I understand it being a reality and pragmatically wish they struck a better balance.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: