Everything is about to 'go dark'

2026-08-14 20:53

A vendor offering exceptional-access capability should not be assessed only on whether the mechanism works under authorised conditions, but on whether it creates a new privileged attack path, who can activate it, how activation is authenticated and audited, whether the capability can be disabled, and whether foreign authorities can compel its use. Singapore agencies that depend heavily on overseas SaaS, cloud platforms, mobile operating systems or communications products therefore need to treat jurisdictional control and vendor-administered access as part of the threat model, rather than as contractual details.