By Cory Doctorow (GPG 0xBF3D9110957E5F4C) @doctorow.pluralistic.net · 12/09/2026But sometimes, the NSA (and other "security" orgs, like the CIA) will discover a really *juicy* bug and then *keep it secret*, so that they can use it to attack their adversaries. 112710
By Cory Doctorow (GPG 0xBF3D9110957E5F4C) @doctorow.pluralistic.net · 12/09/2026This is a doctrine called "NOBUS," which stands for "No One But Us" - as in, "No one but us is smart enough to find this bug, so we can leave it unpatched without putting Americans in danger." 113410
By Cory Doctorow (GPG 0xBF3D9110957E5F4C) @doctorow.pluralistic.net · 12/09/2026NOBUS is a terrible idea. How terrible? Well, in 2017, the NSA lost track of a Microsoft Windows vulnerability that they'd discovered and hoarded, code-named "EternalBlue." 113110