Since Dell holds a ton of government contracts and a good amount of government computers are Dell, you can guarantee they most DEFINITELY "give a shit" about this.
This is why I have an issue with Project Zero. You will NEVER patch all the 0days. There are only a few bugs that I've seen that were so impactful (Heartbleed for example) that it made a massive impact to release and patch it. And as you implied, patching an 0day often publicizes a new vulnerable attack surface with new bugs to follow.
The real way to fix security issues isn't to find new exploits and expose them. It's to architect new ways to prevent whole families of exploits from being possible. I've only really seen Project Zero do one sort of recommendation in this way. Outside of that, I don't feel that them finding 0days and releasing them is actually a significant improvement on security because they aren't even close to plugging all of the holes (or even enough to really make a difference).
You're stating that the organization "as a whole" is "blatantly" violating the Constitution. Don't you see why your statement is being challenged? It's largely baseless. At most, a small number of programs that the NSA has used have been shown to maybe be unconstitutional.
The documents regarding that incident were pulled from an Inspector General's folder regarding an open investigation. That hadn't shown themselves to be anything. They were actively looking in to the incident. If anything Manning tainted the investigation and may have even prevented justice from being served.
There is a difference between releasing data that is strictly related to the public interest and taking massive amounts of data, including information about very sensitive operations and diplomatic discussions and releasing them without regards to the damage they may cause. It's reckless.
Fox? He used the Constitution to definite the terms. Are you arguing against the Constitutional definition of what a traitor is? What definition would you want him tried on in court if not the Constitutional one?
VMWare. It takes advantage of the fact that VMWare links guest VMs to the host's printers by default and takes advantage of that link. The patch from VMWare even applied to VMWare Fusion even though there hasn't been anything published on getting this to work in OSX.
Wait... you believe that the NSA is easier to compromise than the computers of reporters from multiple international news agencies with various levels of computer security policies and knowledge?
Here's the problem with the Boston Marathon attack; it was planned and conducted by US citizens in the USA without any planning with any foreigners.
When someone says "the NSA couldn't even stop the Boston Marathon bombing", they are implying that the NSA SHOULD have been able to. But for the NSA to be able to stop it, they would have to be collecting data on US citizens inside the USA.
You can't have it both ways. You can't blast the NSA for not being able to stop Boston but then also be against them doing domestic collection. The fact that they couldn't stop Boston shows that they weren't spying on Americans (even though one was on watchlists).
My point is that you were arguing against targeted collection. Going after individual devices is a scoped and precision form of intelligence collection. You were saying that this type of intelligence isn't targeted and was instead insisting they should have to get a warrant.
The point the original commentor was trying to make is that this type of work is much more preferable to the mass collection that you're referring to from the Snowden documents.
The USA has never needed a search warrant to conduct foreign intelligence. A search warrant requirement is a 4th amendment protection afforded to US citizens. Foreign intelligence does not require courts unless you're trying to get foreign information from US companies (like the PRISM program and the FISA courts).
The FBI (who is responsible for all intelligence conducted in the USA, against foreigners or Americans) is absolutely required to get a search warrant.
The iPhone is one of the most popular phones in the world. Is it that crazy that the CIA is interested in them for intelligence gathering purposes?
Your example isn't a particular good one. Huawei has been accused of backdooring their products for the Chinese government on numerous occasions, including presentations at DEFCON exposing those backdoors. There are also numerous cases of backdoors in Chinese cell phones.
"I did not break the official algorithm. I do not know the secret value used to compute the Q constant, and thus cannot break the default implementation. Only NSA (and people with access to the key) can exploit the PRNG weakness."
I found this note interesting. How big is the secret value used to compute the Q constant? Is it a single static value or does it vary? Would it be possible to brute force this? I'm not a crypto expert and want to understand this a bit better.
One of the big arguments about the NSA introducing weaknesses into these algorithms is "this makes them insecure for everyone and flaws exploited by the government could be exploited by anyone", but this makes it sound like ONLY the NSA could exploit this.
I'm not saying this is better. I just think, if true, it's an interesting discussion point in the debate.