Just imagine if we had a key escrow or other backdoor like FBI asked for. If governments were made up of 99.9% very honest people, hundreds of untrustworthy individuals would still have enormous power ready to be abused.
The battle for the world’s most powerful cyberweapon
31–40 of 87 posts
Re: The battle for the world’s most powerful cyberweapon
#32How is it that we can't have an OS that stops such things? I'm of the opinion that the NSA must have a long running covert program to discourage the adoption of secure operating systems. Multilevel Secure Operating Systems have existed since the 1980s, yet most people haven't even heard of them.
In contrast, until a few years ago, it was official government policy that EAL4 certification (i.e. "demonstrating resistance to penetration attackers with an Enhanced-Basic attack potential"[5]) was adequate for government systems. This likely corresponds to Class C2 under the old Orange Book standard. This standard was chosen in the interest of allowing standard IT commercial vendors, such as Microsoft and Unix vendors, to submit competitive bids because it was deemed economically and technically infeasible for those systems to be retrofitted with adequate security to achieve a higher standard[6]. So, they instead set the standard to a level achievable by standard commercial IT vendors. They have since reduced it to EAL2 because they determined that requiring a EAL4 certification was too onerous, disqualified large vendors such as FireEye, and was unnecessary as the layering of enough EAL2 systems, each like a piece of swiss cheese, would result in systems comparable to EAL4 systems.
[1] https://www.commoncriteriaportal.org/files/ccfiles/CCPART3V3... Page 34
[2] https://www.niap-ccevs.org/profile/Info.cfm?PPID=65&id=65
[3] https://www.niap-ccevs.org/MMO/PP/pp_skpp_hr_v1.03.pdf Page 84
[4] https://www.commoncriteriaportal.org/files/ccfiles/CCPART3V3... Page 42
[5] https://www.commoncriteriaportal.org/files/ccfiles/CCPART3V3... Page 38
[6] https://www.commoncriteriaportal.org/files/ccfiles/CCPART3V3... Page 38
Re: The battle for the world’s most powerful cyberweapon
#33Earlier quoted context omitted.
So we have evolved best practice in secure commumication using the most rigorous scientific review methods available to math. We just need to help each other understand how we're modelling this stuff.
All cryptography is based on the assumption that the inverse of some operation is hard to compute, because nobody's found an easy way to do it (yet). RSA is based on the assumptions that factoring prime numbers and finding discrete logarithms are both hard. ECC is based on the assumption that the subtraction analogue of that weird additiony thingy is hard. Afaik, neither of these things has been proven.
It's not even clear (at least to me) what a proof of "difficulty" would look like. You would have to prove that no mathematical process could exist that was capable of (for example) factoring a composite number N in less than M steps (where M is a function of N), and prove that each step has some minimum energy or time requirement, to ground the "difficulty" in terms of things that we can use our current understanding of physics to reason about.
Re: The battle for the world’s most powerful cyberweapon
#34Re: The battle for the world’s most powerful cyberweapon
#35Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…
The NSA does have an organization devoted to developing these sorts of attacks that make the NSO group look like a bunch of kindergarteners as evidenced by the Snowden leaks. The CIA also, independently of the NSA, has an organization that develops these sorts of attacks that make the NSO group also look like a bunch of kindergarteners as evidenced by the Vault 7 leaks. Almost without a doubt, the FBI, DHS, US Navy,…
""" The zero days are likely occasionally being discovered and fixed, but buying a zero-click zero day for Android/iPhone on the black market only costs on the order of $1-2M at retail """
In reality the final packaged product is worth exponentially more.
Also, Israel produces some of the best security research talent on the planet due to their national focus on cybersecurity, and funneling some of the most talented students in the country directly to 8200 starting in high school, and some of them end up going to NSO group after. None of the vulnerabilities/exploits in the Vault 7 leaks come close to the sophistication of the FORCEDENTRY exploit. I'm not saying the US doesn't have better capabilities and the NSA most certainly does because they have suppliers like Azimuth, but a lot of what you've stated is based in fantasy.
Re: The battle for the world’s most powerful cyberweapon
#36Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…
Because NSO is on a different level completely. Google engineers who analyzed NSA hacks found it to be "terrifying". See https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
> JBIG2 doesn't have scripting capabilities, but when combined with a vulnerability, it does have the ability to emulate circuits of arbitrary logic gates operating on arbitrary memory. So why not just use that to build your own computer architecture and script that!? That's exactly what this exploit does. Using over 70,000 segment commands defining logical bit operations, they define a small computer architecture with features such as registers and a full 64-bit adder and comparator which they use to search memory and perform arithmetic operations. It's not as fast as Javascript, but it's fundamentally computationally equivalent.
Re: The battle for the world’s most powerful cyberweapon
#37Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…
The NSA does have an organization devoted to developing these sorts of attacks that make the NSO group look like a bunch of kindergarteners as evidenced by the Snowden leaks. The CIA also, independently of the NSA, has an organization that develops these sorts of attacks that make the NSO group also look like a bunch of kindergarteners as evidenced by the Vault 7 leaks. Almost without a doubt, the FBI, DHS, US Navy,…
Anyone even vaguely familiar with the Vault 7 leaks knows that they made the CIA look like a bunch of kindergarteners.
There’s no doubt about the NSAs capabilities, but the Vault 7 crowd was clearly playing in the same league as most NSO group customers.
Re: The battle for the world’s most powerful cyberweapon
#38Re: The battle for the world’s most powerful cyberweapon
#39Earlier quoted context omitted.
The NSA does have an organization devoted to developing these sorts of attacks that make the NSO group look like a bunch of kindergarteners as evidenced by the Snowden leaks. The CIA also, independently of the NSA, has an organization that develops these sorts of attacks that make the NSO group also look like a bunch of kindergarteners as evidenced by the Vault 7 leaks. Almost without a doubt, the FBI, DHS, US Navy,…
As someone who has worked Vulnerability Research/Exploit Dev for US based companies I'd consider this a bit misguided and is likely coming from someone not in the Vulnerability Research/Exploit Dev industry. I'm guessing you're getting these numbers from just reading Zerodium: """ The zero days are likely occasionally being discovered and fixed, but buying a zero-click zero day for Android/iPhone on the black market…
You are correct, I do not work in exploit development. My numbers are based on quotes vulnerability brokers have given for their inventory of zero-click iOS vulnerabilities (and other OS and application vulnerabilities) to some of my coworkers over the years. I have heard they have increased in price recently, though due to increased demand rather than increased difficulty of discovery, but I doubt the price of a raw exploit has breached the $10M mark yet. I have no knowledge as to the pricing on a final packaged consumer-friendly UI product.