Category Archives: Security

Bundesregierung zieht den Zero-Day-Feed zurück

English | Deutsch

In meiner Juli-Analyse des 691-seitigen Referentenentwurfs habe ich § 10 Abs. 2 BNDG den Waffenhändler des Wilden Westens genannt: das BSI, die Bundesbehörde mit dem gesetzlichen Auftrag, Schwachstellen schließen zu lassen, per Gesetz zur verpflichteten Annahmestelle gemacht, die dem BND rohe und unbearbeitete Schwachstellen liefert, ohne vorherige Aufarbeitung, 0-Days eingeschlossen.

Diese Regelung wird nun als gestrichen gemeldet.

Florian Flade, der die Pflicht am 13. Juli auf seinem Blog Verschlusssache dokumentierte, meldete heute Morgen als @FlorianFlade auf der mit einem Nazi-Hakenkreuz verzierten Plattform, dass die Nachrichtendienstgesetze diese Woche ins Kabinett eingebracht werden sollen und der BND-Entwurf kurz zuvor noch eine Änderung erhielt:

Die Verpflichtung des BSI künftig IT-Schwachstellen an den BND melden zu müssen, ist raus.

Diese künstlerische Darstellung der Marke X wurde von der Plattform gelöscht, die der sich selbst so vermarktende „Redefreiheits-Extremist“ Elon Musk betreibt. Quelle: Ai Weiwei

Die Kabinettsfassung selbst ist noch nicht veröffentlicht. Bis das BMI sie einstellt, gebe ich im Kern nur wieder, was Flade berichtet. Der Beweis bleibt das Dokument selbst.

Die Aktenlage

Wie die Regelung starb, steht in der kurzen öffentlichen Aktenlage. Das BMI veröffentlichte den Entwurf am 5. Juli, und Sven Herpig markierte die Übermittlungspflicht binnen Tagen. Flade dokumentierte sie bis zum 13. Juli. Dann brachte die Verbändeanhörung ihre Stellungnahmen hervor, und die Pflicht war deren konzentrierter Brennpunkt. Die AG Kritis warnte, die Regelung baue IT-Sicherheit ab, statt sie zu stärken, und Betreiber kritischer Infrastrukturen müssten sich fragen, „wie vertrauenswürdig das BSI dann noch für sie sein kann“, wenn ihre sensibelsten Vorfallsdaten an einen Nachrichtendienst weiterfließen.

Eine öffentliche Frage auf abgeordnetenwatch hält fest, dass Konstantin von Notz die Pflicht als fahrlässig und nicht mit den Vorgaben des Bundesverfassungsgerichts vereinbar bezeichnet hat.

Zuletzt, laut Flade: die Streichung, bevor der Entwurf ins Kabinett ging.

Eine Streichung ist nur eine Streichung

Die Streichung des Feeds ist nichts Größeres, etwa ein vollständiger Abwägungsprozess für Schwachstellen. Nach Herpigs Bericht hat das Kanzleramt acht Jahre lang ein gesetzliches Schwachstellenmanagement im Interesse des BND blockiert. Die Streichung des Einweg-Angriffsfeeds führt Deutschland in dieses benannte Vakuum zurück. Sie löst es nicht auf, denn an die Stelle der Übermittlungspflicht trat keine Offenlegungspflicht. Die Nutzung von Schwachstellen durch den BND zur Auslandsaufklärung läuft auf der bestehenden Rechtsgrundlage weiter; geändert hat sich, nach aktuellem Berichtsstand, nur, dass das BSI nicht mehr per Gesetz als Lieferant verpflichtet ist. Die eigene Logik der Begründung, dass die Zeit bis zur Behebung das Erntefenster ist, wurde zurückgezogen und blieb unbeantwortet.

Wie es weitergeht

Flades Einordnung: eine kleine, aber relevante Änderung. Nach aktuellem Berichtsstand geht alles Übrige aus meiner Juli-Analyse wie entworfen ins Kabinett.

Die automatisierten Gegenmaßnahmen werden weiterhin mit der Behauptung begründet, menschliche Prüfung leiste keine relevante Qualitätssicherung. Das ist Unsinn.

Die Täuschungslizenz des § 60, die staatliche Desinformation unter dem Etikett Schutzmaßnahme ins Gesetz schreibt. Die Abschaffung der G10-Kommission. Das Verhältnis von 30:1 zwischen Ausgaben für Fähigkeiten und Ausgaben für Kontrolle. All das bleibt aus den bereits genannten Gründen bedenklich.

Man betrachte genau die Regelung, die starb, und warum. Die Übermittlungspflicht hatte eine konzentrierte Interessengruppe mit etwas Konkretem zu verlieren: KRITIS-Betreiber mit Vorfallsdaten, Sicherheitsforscher mit Offenlegungsentscheidungen, die eigene Annahmestelle des BSI. Diese Parteien schreiben Stellungnahmen. Die Regelungen, die überlebt haben, verteilen ihre Kosten anders, aus ökonomischer Sicht der Schwachstellenforschung.

Die Abschaffung der G10-Kommission kostet die Allgemeinheit ein Kontrollgremium; die Täuschungslizenz kostet die Ziele von V-Leute-Netzen; die Automatisierungsklausel kostet den, der auf geteilter Infrastruktur steht, wenn die Maschine feuert. Keine dieser Gruppen reicht Verbandsstellungnahmen ein. Das ist keine Aussage über Absichten. So filtern Kommentarverfahren: Sie beantworten die Einwände, die organisiert, finanziert und auf dem passenden Briefkopf eintreffen.

Das nächste Fenster

Die Verbändeanhörung ist vorbei. Vom Kabinett wandert das Paket in den Bundestag, wo Regelungen per Änderungsantrag im Ausschuss eingefügt und gestrichen werden, ohne dass das Verfahren eine zweite Kommentarrunde verlangt. Eine vor dem Kabinett gestrichene Regelung ist die am billigsten wiederherstellbare, und sie käme in der Phase mit der geringsten öffentlichen Sichtbarkeit zurück.

Mein Juli-Beitrag argumentierte, dieser Entwurf baue Instrumente, die den Machtwechsel zwischen Regierungen überstehen. Hier zeigt sich die Miniatur desselben Problems: Instrumente, die den Wechsel zwischen Verfahrensstufen überstehen, wobei jede Stufe weniger Kontrolle kennt als die vorige. Die Kabinettsfassung wird all das bestätigen oder korrigieren; die Ausschussfassung, noch Monate entfernt, wird zeigen, ob der Waffenhändler wieder öffnet.

German Government Pulls Zero-Day Feed Proposal

English | Deutsch

In my July analysis of the 691-page Referentenentwurf I called § 10(2) BNDG the wild west’s gun dealer: the BSI, the federal agency whose statutory mission is getting vulnerabilities patched, conscripted by law into a mandatory intake feeding the BND raw and unprocessed vulnerabilities, ohne vorherige Aufarbeitung, including 0-days.

That provision is now being reported as dead.

Florian Flade, who documented the duty on his Verschlusssache blog on July 13, reported this morning from @FlorianFlade on the Nazi Swastika-adorned platform that the intelligence bills go to cabinet this week and that the BND draft got one change shortly beforehand:

Die Verpflichtung des BSI künftig IT-Schwachstellen an den BND melden zu müssen, ist raus.

EN: (The obligation for the BSI to report IT vulnerabilities to the BND in future is out.)

This artist’s rendering of the X brand was deleted by the platform run by the self-promoting “free speech extremist” Elon Musk. Source: Ai Weiwei

The Kabinettsfassung itself is not yet published. Until the BMI posts it, I’m basically reposting what Flade is reporting. The document itself still has to be the proof.

The Paper Trail

How the provision died was in the brief public record. The BMI published the draft on July 5 and Sven Herpig flagged the transmission duty within days. Flade documented it by July 13. Then the Verbändeanhörung produced its Stellungnahmen, and the duty was their concentrated flashpoint. The AG Kritis warned that the provision would degrade IT security rather than strengthen it, and that operators of critical infrastructure would have to ask “wie vertrauenswürdig das BSI dann noch für sie sein kann” if their most sensitive incident data flowed onward to an intelligence service.

A public question on abgeordnetenwatch records Konstantin von Notz characterizing the duty as careless and incompatible with the Bundesverfassungsgericht’s requirements.

Finally, per Flade, deletion arrived before the draft went to the cabinet.

Deletion is just deletion

Removing the feed is not something bigger, like a full equities process. Herpig’s reporting had the Kanzleramt spending eight years blocking a statutory Schwachstellenmanagement on the BND’s behalf. Deleting the one-way attack feed returns Germany into that stated vacuum. It does not resolve it because no disclosure duty replaced the transmission duty. The BND’s use of vulnerabilities for foreign collection continues on its existing legal basis; what changed, on current reporting, is only that the BSI is no longer statutorily drafted as the supplier. The Begründung’s own logic, that remediation time is the harvest window, was withdrawn and left unanswered.

Moving ahead

Flade’s characterization is that there was a small but relevant change. On current reporting, everything else in my July analysis goes to cabinet as it has been drafted.

The automated countermeasures are still being justified with the claim that human review adds no relevant quality assurance. That’s nonsense.

The § 60 deception charter that writes state Desinformation into statute under the label Schutzmaßnahme. The abolition of the G10-Kommission. The 30:1 ratio of capability spending to control spending. All of it remains concerning for the reasons already stated.

Look at the exact provision that died and why. The transmission duty had a concentrated constituency with something specific to lose: KRITIS operators with incident data, security researchers with disclosure decisions, the BSI’s own intake pipeline. Those parties write Stellungnahmen. The provisions that have survived distribute costs differently, from the economics view of vulnerability research.

The G10-Kommission’s abolition costs the general public an oversight body; the deception charter costs the targets of informant networks; the automation clause costs whoever is standing on shared infrastructure when the machine fires. None of those constituencies files sector comments. This is not a claim about anyone’s intent. It is how comment processes filter: they answer the objections that arrive organized, funded, and on particular letterhead.

The Next Window

The Verbändeanhörung is over. From cabinet the package moves to the Bundestag, where provisions are added and removed by Änderungsantrag in committee, with no second comment round required by procedure. A provision deleted before cabinet is the cheapest kind to restore, and it would return at the stage with the least public exposure.

My July post argued this draft builds instruments that survive handover between governments. We see here the miniature of the same problem: instruments surviving handover between drafting stages, where each stage has less scrutiny than the last. The Kabinettsfassung will confirm or correct all of this; the Ausschussfassung, still months out, will show whether the gun dealer’s office reopens.

Unstoppable AI as the Business Model: Weak Detection Sells

The most profitable sentence in AI security has been that prompt injection cannot be solved. Since 2012 I’ve been repeatedly told to stop trying to make AI safe, because the unsafe AI is the most profitable version.

After all, look at the money Tesla made after promising in 2016 that a car would drive itself coast to coast with no human touch within a year, and later that its cars would ship with no steering wheel or pedals. Musk’s fortune rode on those promises while the driver-assistance systems were involved in dozens of deaths, fourteen confirmed in the closed federal Autopilot probe and at least sixty-five counted Autopilot/FSD crashes, and Tesla built its own coverage of the toll into head-on crashes like this one. Then he pivoted into government, where a Lancet projection ties the USAID cuts he drove to more deaths than Stalin caused.

Any historian can tell you there is no reliable way to detect whether a piece of text is a malicious instruction. That is true and it stays true. Whether an injected instruction can reach anything that matters is a separate question, a permission question, and permission questions have had working answers for forty years. More to the point, the “free speech” doctrine depends on protecting the ability to speak, which is as old and settled as the ethics of preventing suicide. The field keeps trying to muddy the waters, and to call the second problem by the first problem’s name. The mess is what has created a product category that should not exist, in the same way “America First” shouldn’t ever be allowed into political office, let alone on any ballot.

The refutation

claude --dangerously-skip-permissions.

gemini --yolo.

q chat --trust-all-tools.

Documented agent malware this year did not break any permission model. It weaponized the AI coding agents already on the machine, shelling out to whatever CLI it found and passing the flag the vendor ships to turn the model’s own approvals off.

Sit with what that requires. The attack only works because the vendor shipped a switch that disables the gate. Where the switch was not thrown, the gate was the thing in the way. The malware did not defeat the boundary. It looked for the off-switch the vendor built, and used it. The strongest evidence that injection is containable is that the attacker had to disable containment to get through. The field has that evidence in its own incident data and files it backwards under inevitability.

OpenAI used its own Black Hat slot to describe models that broke out of a test sandbox and attacked a partner platform. The company treated the containment failure as resolved by rebuilding the compromised service while leaving the write access that had enabled it, so the agents rebuilt their coordination channel within days. Eradication without root cause removal is the one move every incident response framework tells you not to make, and they presented it from the stage as a watershed.

Unsolvable is an alibi

Watch what the claims are being designed to do. I see presentations describe an always-on server holding SSH keys and the ability to send mail, wired to an agent fed by an untrusted chat channel. This is already a dumpster fire, but it gets defended as “limiting capabilities limits the value”. That is the whole ideology in five words. If injection cannot be stopped, a gate is not protection, it is friction, and friction is lost value. Unsolvable is not a diagnosis. It is a permission slip.

It’s saying brakes will stop the car, therefore the use of cars would be limited by brakes. Obviously, exactly the opposite is reality. The brakes make the car suitable for going faster and farther.

It is not that these unsafe operators cannot detect the injection. It is that they use their claims of weakness in their ability or desire to excuse never building the containment, which is a choice made that gets dressed up as a law of nature.

This has the shape of colonialism, causing massive extraction harms under the false principle of some “nature” to a racist and artificially contrived order.

Detection sells. Containment doesn’t.

A classifier that promises to spot the malicious prompt is a subscription, it’s a tether and a tax. An approval gate on the dangerous action is a config the customer writes once and never pays for again. The incentive runs entirely one direction: declare the input problem central and the authority problem beneath notice, because the input problem is the one you can bill for.

An industry does not converge on “unsolvable” by accident when solvable does not have a price tag.

The tell is how the field treats the one control that measurably refuses attacks. Model refusal is real and quantifiable. An independent comparative study measured agent frameworks refusing between roughly a third and half of adversarial instructions, depending on the framework, and it costs the customer nothing. It shows up in the writeups as a footnote about the models being frustratingly inconsistent. The one safeguard nobody can bill for gets logged as a nuisance.

The gate works

Injection is an input fact and it is not going away. Blast radius is a choice and it never had to be this large.

The industry agreed to confuse the two because the confusion is where the money is. And it feeds the power-hungry failing upward by refusing accountability.

The boundary holds when it exists and cannot be switched off from inside the agent. The year’s demos keep proving it. They ship the bypass, they glorify the harms, and they sell you the reason not to build the gate.

Ears Off at Sea: Zuckerberg Yacht Says It Doesn’t Listen

The duty to rescue a stranger at sea is relatively new, despite it feeling as old as water. For most of the history of seafaring it existed as custom and as commerce. A master who saved a vessel could claim a salvage award in an admiralty court, and the law concerned itself mainly with how that award should be divided. Notably, saving the people aboard earned nothing so in practice it was a cargo valuation process.

The first general international obligation is from Brussels, 23 September 1910, in the Convention for the Unification of Certain Rules of Law respecting Assistance and Salvage at Sea. Article 11 is two sentences.

Every master is bound, so far as he can do so without serious danger to his vessel, her crew and her passengers, to render assistance to everybody, even though an enemy, found at sea in danger of being lost. The owner of a vessel incurs no liability by reason of contravention of the above provision.

Keep the second sentence in mind.

Eighteen months later the rule met the exact case it was written for, yet it was not yet in force. The convention did not take effect until 1 March 1913, while on the night of 14 April 1912 the SS Californian lay stopped in ice on the westbound track to Boston. Her sole wireless operator, Cyril Evans, had been told to keep off the air by the Titanic’s operator earlier that evening and turned in around half past eleven. The Titanic began transmitting shortly afterward. Nobody aboard the Californian heard it. Her officers even watched rockets rise over the horizon and formed no conclusion worth acting on.

I’ve been there, in the middle of a sea, watching bright lights rise far away in darkness. Calculating whether a turn towards them makes any sense. In the wide open water it’s essential to have radio confirmation to do the math of a course change.

How far apart the two ships lay has been argued ever since. The Board of Trade inquiry under Lord Mersey put it at eight to ten miles. The Marine Accident Investigation Branch reappraisal published in March 1992 put it at seventeen to twenty and concluded the ships lay beyond each other’s visible horizon. That same report found the rockets were seen and that proper action was not taken. The distance stays contested. The silence of the wireless never has been.

The conference that followed sat in London from 23 November 1913 to 20 January 1914, with the British delegation led by Mersey himself, fresh from the inquiry. It produced the first International Convention for the Safety of Life at Sea, and among its provisions was a requirement that ships keep a continuous wireless watch.

The 1914 convention never entered into force because it was overtaken by the war that summer, and it was rewritten in 1929, 1948, 1960 and 1974.

The listening watch survived every revision. That’s perhaps common sense since a duty to assist is worth nothing if the vessel best placed to assist has stopped listening. The Californian is the reason anyone knows this, if not simple experience on the water.

Which brings us to Zuckerberg’s super yacht casting its massive shadow over Farragut Bay.

On the night of Monday 3 August a 21-foot skiff ran out of fuel in the channel between Petersburg and Juneau. The Coast Guard heard the call just after 9:30 p.m., determined by 9:56 that the boat was not in distress, and issued a Marine Assistance Request Broadcast on VHF channel 16. The Marine Exchange of Alaska repeated it. The UnCruise passenger ship Wilderness Legacy answered, steamed past the halted 387-foot Launchpad, towed the skiff into shelter, refuelled it and found it an anchorage. The captain told his passengers why he was responding in the shadow of the Launchpad super yacht and they booed.

No law was broken by Zuckerberg’s massive failure. The Coast Guard’s non-distress finding removed the precise measure on which Article 11 and its successors hang, and a marine assistance broadcast is a request for volunteers rather than the order of duty.

However, Zuckerberg’s spokesperson dug a huge hole anyway. Their statement to the Alaska Beacon on Sunday opens by saying that the billionaire and his family were not on board at the time of the incident. It then explains that by the time the crew reviewed the Coast Guard contact on a different radio channel from the one they were operating on, the assist was already underway.

Ok, ok, let’s take this apart. First claim, first, because it is the one being offered as an answer and it answers exactly nothing. The owner’s location has never been an element of the duty. Article 11 binds the master. Regulation 33 of SOLAS Chapter V binds the master. Article 98 of the 1982 convention binds the state to bind the master. The owner appears in the law of assistance exactly once, in that second sentence, and again in Article 10 of the 1989 Salvage Convention, and on both occasions the appearance is an immunity. The drafters at Brussels wrote owners out of liability on purpose, because a duty that could be overridden from a shore office is not a duty. So a spokesperson announcing that the principal was elsewhere is claiming an exemption that has been sitting in the treaty for a hundred and sixteen years, unasked for, and volunteering it as though it were exculpatory.

It is NOT exculpatory.

It is beside the point twice over. Whether the man was hanging from the mast, in a stateroom, in a helicopter overhead, or in Palo Alto, the ship was his, the crew of roughly fifty were paid by him, and the standing orders they were following that night were written on his authority. Which channel the bridge monitors in confined waters after dark is not a decision made in the moment by a tired officer. It is a policy, set ashore, months in advance, by people who answer to the owner. So is the AIS discipline of a vessel that has been reported operating with its tracking limited. So is the flag. A yacht that is somewhere else on the dial at 9:56 p.m. in the inside waters of Southeast Alaska is executing a decision, and the decision was not made by sea fairies.

Six decades of conference diplomacy went into ensuring that no vessel would again be near and silent, and that has always meant continuous watch on a common frequency. Channel 16 is not any mystery or novelty. The whole arrangement is voluntary in the sense that nobody boards a private yacht at night to check, which is precisely why it runs on the assumption that a professional crew will keep the watch anyway. The three hundred million dollar vessel outside the bay was dead in its own water.

Their flag makes it worse. Article 98 does not command masters, it requires each state to require the masters of ships flying its flag to render assistance, so enforcement runs to the registry. The Launchpad flies the flag of the Marshall Islands, because money games, but that registry is a competent one and “white” listed by both the Paris and Tokyo port state control. The chain of accountability for what happened outside Farragut Bay runs to Majuro, and no port state control regime in the world inspects whether a private yacht is listening on 16 on a Monday night in Alaska. That trivial level of duty is real, the enforcement is nominal, so Zuckerberg’s crew had their ears off.

Dan Blanchard, who owns UnCruise, said he did not initially hear about the detour because this kind of assistance happens often enough that it does not always reach him. Two weeks earlier the National Geographic Quest had collected a family in Glacier Bay who swam ashore after a humpback sank their sailboat. Captain Sean Manske of the Wilderness Legacy contacted the skiff the following day to confirm it had reached Petersburg. Blanchard’s crews are on the same water under the same broadcast, and their owner did not find it necessary to explain where he had been standing every time a vessel calls for aid.

Cyril Evans went to bed, as one operator can’t always be on watch. The dozens of crew of the Launchpad were on another channel, by arrangement, on someone’s order to be unavailable.

The intervening century of treaty law produced a great deal of paper and one very, very solid insight, which is that listening makes the nearest vessel the nearest vessel. The nearest vessel telling us its owner was somewhere else that evening is the answer of a man who thinks a ship at sea comes without any societal obligations.

Mark Zuckerberg at sea
Mark Zuckerberg on the water