Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…
The battle for the world’s most powerful cyberweapon
21–30 of 87 posts
Re: The battle for the world’s most powerful cyberweapon
#22How is it that we can't have an OS that stops such things? I'm of the opinion that the NSA must have a long running covert program to discourage the adoption of secure operating systems. Multilevel Secure Operating Systems have existed since the 1980s, yet most people haven't even heard of them.
Immunity can't prevent disease from entering your body either; They can only make it harder and actively respond to intrusion.
Re: The battle for the world’s most powerful cyberweapon
#23Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…
Paying is the key. NSA doing it for FBI would generate no profit for anyone. Given various loopholes exploiting arrangements between allied security services, I'd not be surprised if NSA were a source of 0days for NSO.
Not directly, NSA requests tech companies to slow down 0day research so they and others can exploid them.
Re: The battle for the world’s most powerful cyberweapon
#24Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…
Re: The battle for the world’s most powerful cyberweapon
#25How is it that we can't have an OS that stops such things? I'm of the opinion that the NSA must have a long running covert program to discourage the adoption of secure operating systems. Multilevel Secure Operating Systems have existed since the 1980s, yet most people haven't even heard of them.
Except for the Xbox. Someone hacking an Xbox would lose _Microsoft_ money through piracy, which hurts their bottom line!
As a result, the Xbox runs a type 1 hypervisor with various compiler hardening options like Control Flow Integrity enabled, and are generally some of the most locked down consumer devices sold today.
What's Apple's motivation beyond bad press? iMessage was parsing media sent to it with a pdf parser. Sure, some activists in repressive regimes will get spied on and executed, but it's just so much effort to invest dev effort on rewrites for security when you could find new ways to send cute animated gifs to each other.
Re: The battle for the world’s most powerful cyberweapon
#26The most powerful cyberweapon is making sure every human understands an inkling of number theory
So everyone's invented their own cryptography. Great! I'll just buffer-overflow the TCP stack and let myself in; then I can read all their messages after they've decrypted them. Rock, meet paper.
Re: The battle for the world’s most powerful cyberweapon
#27How is it that we can't have an OS that stops such things? I'm of the opinion that the NSA must have a long running covert program to discourage the adoption of secure operating systems. Multilevel Secure Operating Systems have existed since the 1980s, yet most people haven't even heard of them.
There's insufficient motivation for OS creators. It's possible to compile C code with various hardening options and pay a few percent overhead for it, but it remains almost entirely in the realm of academia... Except for the Xbox. Someone hacking an Xbox would lose _Microsoft_ money through piracy, which hurts their bottom line! As a result, the Xbox runs a type 1 hypervisor with various compiler hardening options li…
From what I can tell all NSO's rigmarole of making a virtual machine in the PDF parser is to work around the existing mitigations.
I guess they could also turn on asan etc in production but that's more than a few percent slowdown.
Re: The battle for the world’s most powerful cyberweapon
#28Earlier quoted context omitted.
So everyone's invented their own cryptography. Great! I'll just buffer-overflow the TCP stack and let myself in; then I can read all their messages after they've decrypted them. Rock, meet paper.
So we have evolved best practice in secure commumication using the most rigorous scientific review methods available to math. We just need to help each other understand how we're modelling this stuff.
RSA is based on the assumptions that factoring prime numbers and finding discrete logarithms are both hard. ECC is based on the assumption that the subtraction analogue of that weird additiony thingy is hard. Afaik, neither of these things has been proven.
Re: The battle for the world’s most powerful cyberweapon
#29Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…
The most likely reasons the FBI paid for access to Pegasus are: 1. It is another tool that frankly does not cost very much if you are the FBI. 2. The part of the FBI that bought it likely does not have authorization or possibly even knowledge of the other tools and contracted with NSO to gain those capabilities at the cost of just some money. This is like how a developer team in large stodgy old mega corporation might not be able to get IT to setup their servers so they just get a budget that they spend on AWS to do an end-run around their own IT organization.
The zero days are likely occasionally being discovered and fixed, but buying a zero-click zero day for Android/iPhone on the black market only costs on the order of $1-2M at retail. If you have your own competent team you can reasonably expect to find a zero-click zero day with only a few person-months of effort which, even at US wages, is only a few 100k per zero day. At those prices, you could keep a dozen or so stockpiled for less than the cost of starting a McDonalds franchise, so they likely did maintain a dozen or so at any one time, so if one was discovered they could just switch over to a different one and write off the old one as a cost of doing business.
They absolutely do have competition. One high profile example is Hacking Team. In terms of overall competition, I do not have any hard information, but given the size of the vulnerability markets there are probably at least a couple dozen to a few hundred organizations similar in scope to the NSO group. We do not hear about them because they mostly sell to governments.