Live data from Hacker News

The Government Uses Zero Days for “Offense”

eff.org

11–20 of 111 posts

Re: The Government Uses Zero Days for “Offense”

#11
post #9

It's good news to me. The NSA's mission means they're going to have to get in somehow . FBI, too. Bulk collection and subversion have huge issues. Targeted collection with 0-days in endpoints that we know are insecure is much closer to Constitution than most of what they do. If people want that to go away, they could always apply methods for building secure systems from ground up. I've posted plenty here and elsewher…

And you're cool with them doing it to you ?

Yeah. If I used insecure crap, I've already decided that it will be destroyed by opponents. If I want something safe, I use very secure methods to protect it. That field is called high assurance or high robustness security. Quite a few things in it stopped NSA pentesters. Very few of us left in that field but one can learn from what's published as I did. Build your security strong, obfuscated, and with tamper detection to give them real headaches. Otherwise, you're enabling your enemy by your choice of systems, software, and methods. It's your own fault given what you know of the world you live in.

Examples of high assurance thinking another comment:

https://news.ycombinator.com/item?id=10529676

Have fun with that rabbit hole. :)

Re: The Government Uses Zero Days for “Offense”

#12
post #10

It's good news to me. The NSA's mission means they're going to have to get in somehow . FBI, too. Bulk collection and subversion have huge issues. Targeted collection with 0-days in endpoints that we know are insecure is much closer to Constitution than most of what they do. If people want that to go away, they could always apply methods for building secure systems from ground up. I've posted plenty here and elsewher…

US has the most to lose from having the NSA hoard vulnerabilities in popular software that itself uses. So by that logic, the NSA is actually harming national security. > Most users want the risk management paradigm where they buy insecure systems that are fast, pretty and cheap, then occasionally deal with a data loss or system fix I disagree. I think most people don't know what the hell they want or need in terms o…

"US has the most to lose from having the NSA hoard vulnerabilities in popular software that itself uses. So by that logic, the NSA is actually harming national security."

I totally agree. I've said the same and gone as far to say they're "aiding and abetting" the enemy. Not Manning, Snowden, etc. ;)

That said, NSA doesn't build these systems. NSA doesn't use insecure methods of software or system construction to keep their profit margin high on critical stuff. NSA... does... neglect contributions to critical protocols and stuff but so do everyone else. Most of the problems come from businesses, FOSS projects, and demand side all sticking with what produces the most 0-days.

There's no excuse as even the first mainframe was doing it better back in 1963:

http://www.smecc.org/The%20Architecture%20%20of%20the%20Burr...

Many did:

https://www.schneier.com/blog/archives/2014/04/dan_geer_on_h...

It's just everyone's choice to stick with the most risky approaches and tradeoffs. What follows is a consequence of that choice. Even when shown better way, they usually tell you to get lost or further justify bad choices. So, it's totally on the market itself. NSA could help and DOD did back with Computer Security Initiative but hard for me to blame NSA for intentional failure and pervasive insecurity of most of 300+ million people and millions of businesses. They're just predators exploiting a bad situation created by others.

"It's the job of system builders (and I think the government, too) to ensure people get a strong standard of security with their devices."

Ever hear of DiamonTEK? Gemini Computers? Secure Computing Corporation? They did highly secure stuff. They disappeared, were acquired, or withered away (eg Aesec). That's a false claim disproven by decades of buyers and management ignoring good security advice. No, producers only goal it to satisfy buyers and make money. Doing so means trading against security. Time after time.

Re: The Government Uses Zero Days for “Offense”

#14

It's good news to me. The NSA's mission means they're going to have to get in somehow . FBI, too. Bulk collection and subversion have huge issues. Targeted collection with 0-days in endpoints that we know are insecure is much closer to Constitution than most of what they do. If people want that to go away, they could always apply methods for building secure systems from ground up. I've posted plenty here and elsewher…

Nick, our programming ecosystem barely satisfies the basic principles of software fault tolerance, much less self-healing systems. High assurance? Multiple independent levels of security (MILS)? Covert channel resistance? Completely out of the question!

That said, it is somewhat true that when you reduce the intelligence agency activities to targeted surveillance with employment of 0-days, the onus falls more and more on industry adopting HA.

Yet one must not discount that how 0-days are even procured can involve questionable deeds.

Furthermore, when the NSA's offense model is targeted attacks with 0-day deployment, an incentive is created to pump these 0-days by subverting cryptographic standard bodies. The market for 0-days is a) adversary and b) contestable, which is a lethal combination that promulgates black bag and kleptographic techniques.

We must also be willing to assume that in any interventionist statist society, the property of domestic surveillance is not a unique event or something that can be eradicated, but a constant cyclical factor akin to a business cycle that may only be mitigated.

Re: The Government Uses Zero Days for “Offense”

#15

Does the EFF really expect the NSA to publicly detail every time they've used an exploit offensively?

Against Americans? Yes. The rule of law demands it.

I think you're misrepresenting what the rule of law means. The rule of law just means we follow codified rules, not the arbitrary whims of an individual. The NSA is, I'm sure, very scrupulous about following the law.

Re: The Government Uses Zero Days for “Offense”

#16

Does the EFF really expect the NSA to publicly detail every time they've used an exploit offensively?

Against Americans? Yes. The rule of law demands it.

That's great! Do you mean the law demands a reason to do it? (I.e. reasoning for a warrant?) I'm guessing here.

Re: The Government Uses Zero Days for “Offense”

#17

Does the EFF really expect the NSA to publicly detail every time they've used an exploit offensively?

Against Americans? Yes. The rule of law demands it.

That point is so important that I hesitated to add a distraction but I think it's also worth remembering that the NSA has a defensive role, too.

It's been much neglected in recent decades but the entire country would be better off if the NSA helped patch things. They're hoping some suspected bad guy doesn't get patched but odds are high that many Americans, particularly important IP-heavy businesses, are going to get exploited as well — and given all the reports about how e.g. bin Laden preferred to send messages using trusted couriers, that trade off doesn't seem very good.

Re: The Government Uses Zero Days for “Offense”

#18

It's good news to me. The NSA's mission means they're going to have to get in somehow . FBI, too. Bulk collection and subversion have huge issues. Targeted collection with 0-days in endpoints that we know are insecure is much closer to Constitution than most of what they do. If people want that to go away, they could always apply methods for building secure systems from ground up. I've posted plenty here and elsewher…

Nick, our programming ecosystem barely satisfies the basic principles of software fault tolerance, much less self-healing systems. High assurance? Multiple independent levels of security (MILS)? Covert channel resistance? Completely out of the question! That said, it is somewhat true that when you reduce the intelligence agency activities to targeted surveillance with employment of 0-days, the onus falls more and mor…

"Nick, our programming ecosystem barely satisfies the basic principles of software fault tolerance, much less self-healing systems. High assurance? Multiple independent levels of security (MILS)? Covert channel resistance? Completely out of the question!"

Original high assurance systems were done with Pascal, etc. Not much required in terms of programming past type and memory safety, esp strong interface checks. Plus easily understanding how that language becomes code with ability of compilers to transform it (eg auto-insertion of checks). More about a clear description of how it works, clear security policy, evidence they correspond, and implementation that maintains the same. As in another comment in this thread, small changes in hardware or OS's alone would create great increases in security.

Far as the other requirements, software MILS just takes a microkernel with capabilities, periods processing, virtualizable hardware, and the right scheduler. A covert channel analysis via Kemmerer's Shared Resource Matrix can be done by a junior staffer with guidance and little time. That usable, prototypes of secure systems were done by small academic teams with 1990's and early 2000's tech shows it's well within reach of today's programmers. There's just an issue of willingness. Just look back at all the times I wrote up a secure-by-design system and how many people jumped on bandwagon to try to build their own. I can count them on my hands.

"Yet one must not discount that how 0-days are even procured can involve questionable deeds."

That's the subversion risk. The EAL6-7 development processes going back to Orange Book are designed to partly counter that. I add certified compilation, mutually suspicious parties doing analysis, diverse hardware, and so on in my requirements. Gotta address it all. Teams with little resources should focus on ability to detect, trace, and recover rather than prevent. Prevent what they can but only so much staff and time...

"the property of domestic surveillance is not a unique event or something that can be eradicated, but a constant cyclical factor akin to a business cycle that may only be mitigated."

That's an interesting thought. There have been cycles in my country. What worries me is the cyclical nature seems to be ending. We haven't seen the mass protests of police state activity that we wanted. The abuses revealed by Manning and Snowden led to griping followed largely by inaction. We've only seen American power increase even after the parties changed. The 180 of Obama administration on the key issues further suggests strong, covert influence that exists across parties and time. I wished we got something like Iceland in 2008 but America is a fake democracy: people did nothing, are mostly doing nothing, and TPP situation is set to confirm that trend. It's the new cycle.

Re: The Government Uses Zero Days for “Offense”

#19

Does the EFF really expect the NSA to publicly detail every time they've used an exploit offensively?

Against Americans? Yes. The rule of law demands it.

Can you provide some links to docs discussing NSA 0days against Americans? I can't seem to find 'em.

Re: The Government Uses Zero Days for “Offense”

#20
post #15

Earlier quoted context omitted.

Against Americans? Yes. The rule of law demands it.

I think you're misrepresenting what the rule of law means. The rule of law just means we follow codified rules, not the arbitrary whims of an individual. The NSA is, I'm sure, very scrupulous about following the law.

We have repeated proof of the opposite – Congress had to rush to retroactively legalize the mass surveillance programs, and much of what's been disclosed since is clearly unconstitutional.

What they are extremely good at is using security claims to avoid ever having to see a real court. Most of the cases have been thrown out for lack of standing because it's hard to prove that you've been spied on when all of the details are classified.

Post reply on HN