Live data from Hacker News

Hacking Team, Computer Vulnerabilities, and the NSA

schneier.com

11–20 of 75 posts

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#11
Schneier didn't discuss what is IMO the biggest reason for NSA not to report vulnerabilities: it's "pissing into the wind", it's futile. When 10 vulnerabilities are reported and fixed, 11 new ones are quickly found. The vulnerabilities are overwhelming us.

Back around the year 2000 Microsoft was being beaten up for all the vulnerabilities in their software. So in 2002 Bill Gates announced "Trustworthy Computing".[1][2]

   Microsoft Chairman Bill Gates announced a
   major strategy shift across all its products,
   including its flagship Windows software,
   to emphasize security and privacy over new
   capabilities. 
In 2014 Microsoft finally threw in the last towel, folding the group they formed into other units. They gave up. Microsoft lost not because they were incompetent, but because the problem is too big to attack in a conventional manner.

I don't know what the answer is, but we need to approach things very differently. To quote Dr. Peter Venkman: "the usual stuff isn't working".

[1] http://www.foxnews.com/story/2002/01/16/bill-gates-announces... [2] https://en.wikipedia.org/wiki/Trustworthy_computing

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#12
post #8
post #6

Earlier quoted context omitted.

Thanks for this, I agree it makes sense that they would have, I was just a bit disappointed that Bruce didn't enumerate any of this in his post. In fairness, all of this stuff is probably "duh" to him, and his normal audience, but it's not so obvious to everyone. Here's another thought: what if the NSA hacked Hacking Team, and they were also the ones to release all the data publicly. Re: #3 – do you have any links to…

I think it would be hard to go through everything, but off the top of my head: https://snowdenarchive.cjfe.org/greenstone/collect/snowden1/... Quote: For the past decade, NSA has lead an aggressive, multi-pronged effort to break widely used Internet encryption technologies Their Motto: "We penetrate targets' defences."

Thanks a bunch.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#13
There's a fourth reason NSA wouldn't have tipped off every vendor impacted by HT exploits: because they have no business breaking into commercial vulnerability research teams networks, grabbing their exploits, and burning them. It is in fact probably unlawful for them to do so (those actions having as they do an impact on US F-500 companies that use --- for better or worse --- tools from companies like HT to evaluate their own security).

This is a positive comment, not a normative one. I don't know how I feel about entities busting up companies like HT, but I do think I know that the world would be better off without companies like HT.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#14
post #5
post #3

While I wouldn't put it past the NSA – why would we assume the NSA had infiltrated Hacking Team?

I think it's a fairly safe bet that they did, and I'll explain why I believe this. 1. The NSA has access to more info on both good crypto and broken crypto 2. Hacking Team's software & infrastructure were clearly vulnerable, otherwise they wouldn't have been hacked 3. Leaked docs show that NSA hacks everyone they possibly can, to get as much information as they possibly can. It's really not a big leap to assume that…

It's an assumption to me, simply because there were no facts or evidence presented. This is purely speculation based on what Bruce thinks the NSA might have done. I wouldn't be surprised if it turns out the NSA had breached them prior to this, though.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#15
post #5
post #3

While I wouldn't put it past the NSA – why would we assume the NSA had infiltrated Hacking Team?

I think it's a fairly safe bet that they did, and I'll explain why I believe this. 1. The NSA has access to more info on both good crypto and broken crypto 2. Hacking Team's software & infrastructure were clearly vulnerable, otherwise they wouldn't have been hacked 3. Leaked docs show that NSA hacks everyone they possibly can, to get as much information as they possibly can. It's really not a big leap to assume that…

For probably more than 95% of the Fortune 500, vulnerability intelligence that is years out of date is more than sufficient to own up those firms' entire enterprise networks. The half-life of most software vulnerabilities is long. Simple IT problems like inventory remain unsolved in the real world.

So the same logic suggests that NSA has owned up every company of any real size in the world.

Could NSA do that? Absolutely yes. Did they? I doubt it. I do not see how NSA secures a single extra headcount by illicitly hacking every US and/or European company, and securing additional headcount is literally the core mission of NSA.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#16
post #6
post #5

Earlier quoted context omitted.

I think it's a fairly safe bet that they did, and I'll explain why I believe this. 1. The NSA has access to more info on both good crypto and broken crypto 2. Hacking Team's software & infrastructure were clearly vulnerable, otherwise they wouldn't have been hacked 3. Leaked docs show that NSA hacks everyone they possibly can, to get as much information as they possibly can. It's really not a big leap to assume that…

Thanks for this, I agree it makes sense that they would have, I was just a bit disappointed that Bruce didn't enumerate any of this in his post. In fairness, all of this stuff is probably "duh" to him, and his normal audience, but it's not so obvious to everyone. Here's another thought: what if the NSA hacked Hacking Team, and they were also the ones to release all the data publicly. Re: #3 – do you have any links to…

For whatever it's worth: I do not believe --- and this is an opinion I think is shared by lots of people in my field --- that Scheier has any special insight into the software and network exploitation capabilities of NSA. Schneier is a writer first, then a policy guy next, then an academic/standards-group cryptographer. Information security is a huge field with lots of subfields, and nobody specializes in all of them.

My take on this post on his blog is that it's probably a stretch for him to be analyzing the Hacking Team story in any depth.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#17
post #13

There's a fourth reason NSA wouldn't have tipped off every vendor impacted by HT exploits: because they have no business breaking into commercial vulnerability research teams networks, grabbing their exploits, and burning them. It is in fact probably unlawful for them to do so (those actions having as they do an impact on US F-500 companies that use --- for better or worse --- tools from companies like HT to evaluate…

I salute your sentiment: the world would be better off without companies like HT.

It is in fact probably unlawful for them to do so

I realize that the patriotic employees of the NSA work within a legal framework, and seemingly pride themselves on doing so. But they haven't bothered to share that framework with the rest of us. So my first response was to snicker to myself, and that's unfair to you.

Also, Hacking Team was Italian, not US, so would it really be illegal to slurp up all of HT's exploits? That is, if you want to stay within the bounds of the law, if not the bounds of ethical behavior.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#18
post #13

There's a fourth reason NSA wouldn't have tipped off every vendor impacted by HT exploits: because they have no business breaking into commercial vulnerability research teams networks, grabbing their exploits, and burning them. It is in fact probably unlawful for them to do so (those actions having as they do an impact on US F-500 companies that use --- for better or worse --- tools from companies like HT to evaluate…

I salute your sentiment: the world would be better off without companies like HT. It is in fact probably unlawful for them to do so I realize that the patriotic employees of the NSA work within a legal framework, and seemingly pride themselves on doing so. But they haven't bothered to share that framework with the rest of us. So my first response was to snicker to myself, and that's unfair to you. Also, Hacking Team…

I tried to acknowledge that HT is jurisdictionally complex; they are probably allowed, under the same charter that allows CIA to conduct HUMINT missions, to attack Italian security companies (modulo treaties, I guess). The issue though is that those attacks have direct impact on US companies, who (again) may rely on HT products for "zero day pentesting" (among other things).

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#19
Schneier apparently doesn't even know what the NSA stands for (National Security Administration?) and yet seems it's safe to assume that they had infiltrated Hacking Team, and then proceeds to make a whole bunch of judgements and follow-on assumptions based off that first baseless assumption all while pandering to his userbase.

Well done, Bruce.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#20
post #5
post #3

While I wouldn't put it past the NSA – why would we assume the NSA had infiltrated Hacking Team?

I think it's a fairly safe bet that they did, and I'll explain why I believe this. 1. The NSA has access to more info on both good crypto and broken crypto 2. Hacking Team's software & infrastructure were clearly vulnerable, otherwise they wouldn't have been hacked 3. Leaked docs show that NSA hacks everyone they possibly can, to get as much information as they possibly can. It's really not a big leap to assume that…

> But just so I can understand what you're saying, why do you think it's a big assumption?

Are you serious? Because there's no proof or mention of it anywhere. You're making an assumption based on literally nothing more than "well obviously, based on what I've read on the Internet, they could have done it so they must have". You're bending facts to fit a worldview, something I'm sure you yourself detest elsewhere in life.

This is like Russell's Teapot but for the NSA. You're shifting the burden of proof to someone who now has to prove a negative.

Post reply on HN