Live data from Hacker News

The Government Uses Zero Days for “Offense”

eff.org

1–10 of 111 posts

Re: The Government Uses Zero Days for “Offense”

#7
post #4

91% could also pretty misleading because not all vulnerabilities are equal. It's easy to let 9 potential segfaults or memory corruption issues get disclosed if you get to hold on to the 1 iOS Zero Day/Shellshock type attack/etc...

You beat me to it, haha. I was going to make the point that the vast majority of bugs found don't do anything significant for a hacker. A program crash or corruption at worst. It wouldn't surprise me if NSA just discloses the ones that hurt availability while weaponizing the few hitting confidentiality or integrity.

Re: The Government Uses Zero Days for “Offense”

#8
It's good news to me. The NSA's mission means they're going to have to get in somehow. FBI, too. Bulk collection and subversion have huge issues. Targeted collection with 0-days in endpoints that we know are insecure is much closer to Constitution than most of what they do. If people want that to go away, they could always apply methods for building secure systems from ground up. I've posted plenty here and elsewhere about high assurance security along with tons of Comp Sci and case studies existing.

If not, they've chosen to accept that risk from NSA and others hunting 0-days. Most choose that. Most platforms have tons of risk and attack surface. So, I'm all for them collecting 0-days for focused attacks and relying on it rather than pushing subversion or L.I. harder.

Anyone worrying about this should be focusing on the organizations creating 0-days with known-insecure development practices rather than those exploiting them. They're the problem and the demand side (users/customers) that doesn't give a shit. Excerpt from a counterpoint to Bruce Schneier on why users/customers, not manufacturers, were the problem in terms of security of our devices and services:

"Why does this problem (insecure everything) exist? Because manufacturers don't focus on building secure systems. Why don't they build secure systems? BECAUSE USERS DON'T BUY THEM!

Most users want the risk management paradigm where they buy insecure systems that are fast, pretty and cheap, then occasionally deal with a data loss or system fix. The segment of people willing to pay significantly more for quality is always very small and there are vendors that target that market (e.g. TIS, GD, Boeing and Integrity Global Security come to mind).

So, if users demand the opposite of security, aren't capitalist system producers supposed to give them what they want? It's basic economics Bruce. They do what's good for the bottom line. The only time they started building secure PC's en masse was when the government mandated them. Some corporations, part of the quality segment, even ordered them to protect I.P. at incubation firms and reduce insider risks at banks. When the government killed that & demand went low again, they all started producing insecure systems again. So, if user demand is required and they don't demand it, who is at fault again? The user. They always were and always will be.

On the bright side, those same users are the reason I can send photo's to friends on a thin, beautiful smartphone. They also gave us short-lived 1TB hard disks whose low cost made the short-lived part tolerable. They are also probably why I have a full-featured, fast, cheap wireless router at the home. So, at least some good comes from the users choices of demand. But, they definitely don't accept the tradeoffs of real security, they don't demand it, it doesn't pay to produce it, & that's why it's their fault. "

Re: The Government Uses Zero Days for “Offense”

#9

It's good news to me. The NSA's mission means they're going to have to get in somehow . FBI, too. Bulk collection and subversion have huge issues. Targeted collection with 0-days in endpoints that we know are insecure is much closer to Constitution than most of what they do. If people want that to go away, they could always apply methods for building secure systems from ground up. I've posted plenty here and elsewher…

And you're cool with them doing it to you?

Re: The Government Uses Zero Days for “Offense”

#10

It's good news to me. The NSA's mission means they're going to have to get in somehow . FBI, too. Bulk collection and subversion have huge issues. Targeted collection with 0-days in endpoints that we know are insecure is much closer to Constitution than most of what they do. If people want that to go away, they could always apply methods for building secure systems from ground up. I've posted plenty here and elsewher…

US has the most to lose from having the NSA hoard vulnerabilities in popular software that itself uses. So by that logic, the NSA is actually harming national security.

> Most users want the risk management paradigm where they buy insecure systems that are fast, pretty and cheap, then occasionally deal with a data loss or system fix

I disagree. I think most people don't know what the hell they want or need in terms on security, but they do want to be "safe". Nobody makes the choice "should I buy this phone for $600 or this one for $300 that is 10x less secure?" - People assume all of these devices have relatively the same security, and then they buy on price.

It's the job of system builders (and I think the government, too) to ensure people get a strong standard of security with their devices. Just like it's the government's job to ensure people don't get food poisoning from buying a random item from a store. You can't expect most people to actually know what they're buying in terms of food - but you expect them to know in terms of device security?

People think the $5 food item has the "same relative safety" as the $50 food item from the same category. Nobody expects to die from the $5 one, just like nobody expects to get hacked for buying a $100 unlocked phone at one of the four major (and let's say trusted) carriers. And by nobody I of course mean "normal people".

Post reply on HN