Live data from Hacker News

The Government Uses Zero Days for “Offense”

eff.org

41–50 of 111 posts

Re: The Government Uses Zero Days for “Offense”

#41

Earlier quoted context omitted.

Okay, so let's say American businesses can't get hacked so easily by nationstates and have their secrets stolen. Also, Iran has successfully tested a nuclear bomb. Is that the world you'd prefer?

This is such a laughably typical strawman excuse that is used to shut down all discussion on this topic.

Typical of what? Obviosity? We've got a poster here claiming that business are "going to" get exploited, and in the meantime, non-theoretically (consider reading the Wikipedia [1] article on "strawman"), the U.S. Govt is making productive use of exploits today.

You're the one trying to shut down discussion.

[1] https://en.wikipedia.org/wiki/Wikipedia

Re: The Government Uses Zero Days for “Offense”

#43

Earlier quoted context omitted.

Okay, so let's say American businesses can't get hacked so easily by nationstates and have their secrets stolen. Also, Iran has successfully tested a nuclear bomb. Is that the world you'd prefer?

This is such a laughably typical strawman excuse that is used to shut down all discussion on this topic.

I believe the parent may have been referring to Stuxnet. https://en.wikipedia.org/wiki/Stuxnet

It is indeed possible that if the NSA used a very different strategy with vulnerabilities, Iran might be further along with its nuclear weapons development.

Re: The Government Uses Zero Days for “Offense”

#45
post #17

Earlier quoted context omitted.

That point is so important that I hesitated to add a distraction but I think it's also worth remembering that the NSA has a defensive role, too. It's been much neglected in recent decades but the entire country would be better off if the NSA helped patch things. They're hoping some suspected bad guy doesn't get patched but odds are high that many Americans, particularly important IP-heavy businesses, are going to get…

Why do you think the two are mutually exclusive? I was under the impression that the NSA publishes security advisories all the time?

For the most part, any party the NSA might be interested into is going to be running an OS and an application suite that will also be used by Americans a whole lot. Probably even other government agencies.

So, every zero day they find and weaponize, is a zero day that they don't tell the vendor about. So to be able to be aggressive with exploits, they have to leave American computers exposed too, and hope nobody else has found the exploit. So even with the same budget looking for vulnerabilities, doing the right thing for one of their roles makes them worse for the other.

It's a bit like the encryption problem: An encryption system with a backdoor that the NSA has weakens American security too, because the backdoor itself is a valid intelligence target: Infiltrate the NSA, take the backdoor key, and anything the NSA can snoop into, someone else can too.

So doing both defense and offense without major tradeoffs requires having some kind of edge that nobody else can ever have: For instance, the rumored gigantic cluster that can crack specific SSH communications, which they expect nobody else to be able to replicate, just due to the cost of the hardware. That's a far more limited offense than what we know the NSA had at the time of the Snowden leaks.

So my guess, based on public information, is that they do trade-offs, and disclose the issues that they think are easier to find, while keeping around enough ammunition to have something against pretty much every target.

Re: The Government Uses Zero Days for “Offense”

#46
post #17

Earlier quoted context omitted.

Against Americans? Yes. The rule of law demands it.

That point is so important that I hesitated to add a distraction but I think it's also worth remembering that the NSA has a defensive role, too. It's been much neglected in recent decades but the entire country would be better off if the NSA helped patch things. They're hoping some suspected bad guy doesn't get patched but odds are high that many Americans, particularly important IP-heavy businesses, are going to get…

Are you seriously suggesting you don't think the security services have decades of experience in weighing the pros and cons of information release?

Re: The Government Uses Zero Days for “Offense”

#47
post #17

Earlier quoted context omitted.

That point is so important that I hesitated to add a distraction but I think it's also worth remembering that the NSA has a defensive role, too. It's been much neglected in recent decades but the entire country would be better off if the NSA helped patch things. They're hoping some suspected bad guy doesn't get patched but odds are high that many Americans, particularly important IP-heavy businesses, are going to get…

Are you seriously suggesting you don't think the security services have decades of experience in weighing the pros and cons of information release?

Whats good for one agency may be bad for another, for example the State Department might like Tor because it facilitates anonymous informants while the NSA might not like it because they can't read your email.

I am not even sure if the NSA's mission extends to defending civilians.

Re: The Government Uses Zero Days for “Offense”

#48
Now the question is, are vendors deliberately putting in security flaws at NSA's instigation?

Intel's "system management mode" and code need to be viewed with extreme suspicion. So do network controllers which accept management commands from the network side. It would be so easy to add some system management passwords to a network controller that don't show up when you list them. (In fact, if you're willing to have them show up in a list that nobody ever checks, you can insert a backdoor in a motherboard if you can get hold of it anywhere in the supply chain, hook it up to power and Ethernet, and talk to it briefly.)[1]

[1] https://en.wikipedia.org/wiki/Intel_AMT_versions

Re: The Government Uses Zero Days for “Offense”

#50
post #40

Earlier quoted context omitted.

Why do you think the two are mutually exclusive? I was under the impression that the NSA publishes security advisories all the time?

At least one issue is perception of the NSA by the talented people that the NSA needs to recruit. At the time I graduated CS undergrad in 2010, the NSA was still seen as "Sketchy, but good (and reliable) on the balance." Post-Snowden, views have changed. If the NSA can't do a better job of public relations, nobody is going to want to work for them, and then this defensive work won't be done as well.

Conscription neatly solves that problem...

Given the proper motivation (neé, "a carrot-shaped stick"), a potential prospect will be inclined to accept the offer of employment.

Post reply on HN