Earlier quoted context omitted.
All cryptography is based on the assumption that the inverse of some operation is hard to compute, because nobody's found an easy way to do it (yet). RSA is based on the assumptions that factoring prime numbers and finding discrete logarithms are both hard. ECC is based on the assumption that the subtraction analogue of that weird additiony thingy is hard. Afaik, neither of these things has been proven.
> Afaik, neither of these things has been proven. It's not even clear (at least to me) what a proof of "difficulty" would look like. You would have to prove that no mathematical process could exist that was capable of (for example) factoring a composite number N in less than M steps (where M is a function of N), and prove that each step has some minimum energy or time requirement, to ground the "difficulty" in terms…
The battle for the world’s most powerful cyberweapon
41–50 of 87 posts
Re: The battle for the world’s most powerful cyberweapon
#42Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how…
Because NSO is on a different level completely. Google engineers who analyzed NSA hacks found it to be "terrifying". See https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
Re: The battle for the world’s most powerful cyberweapon
#43Earlier quoted context omitted.
The NSA does have an organization devoted to developing these sorts of attacks that make the NSO group look like a bunch of kindergarteners as evidenced by the Snowden leaks. The CIA also, independently of the NSA, has an organization that develops these sorts of attacks that make the NSO group also look like a bunch of kindergarteners as evidenced by the Vault 7 leaks. Almost without a doubt, the FBI, DHS, US Navy,…
As someone who has worked Vulnerability Research/Exploit Dev for US based companies I'd consider this a bit misguided and is likely coming from someone not in the Vulnerability Research/Exploit Dev industry. I'm guessing you're getting these numbers from just reading Zerodium: """ The zero days are likely occasionally being discovered and fixed, but buying a zero-click zero day for Android/iPhone on the black market…
I dont see why the FBI wouldn't buy Pegasus. Does the above poster think the FBI can just call the NSA and tell it to decrypt a bunch of stuff? The NSA has its own mission and its based on national security interests, not solving the everyday crime the FBI works on. The government isn't just one big club. I'm guessing its likely the NSA isn't going to offer up its best tools to catch someone providing abortion access in Texas or "stealing" academic papers from JSTOR or "pirating" comic book movies. Not only is it a waste of their resources but every time a tool like this is used, the detection of that tool is possible, and with that detection Apple or whomever would figure out what the exploit is doing and patch against it. Now that tool is wasted because some FBI boss wanted a promotion thinking if he impersonated an Associated Press journalist to hack a teenager again like they did in 2007 it would impress some authoritarian higher up.
They can't waste these precious exploits on some culture war, IP enforcement thuggery, leftist organizers, unions, and mid-range drug dealers the FBI regularly beats up, murders (think Filiberto Ojeda Rios), harasses, and spies on. Even the NSA is low-key ACAB. So they just say no and tell the FBI to just let NSO potentially burn their exploits. The NSA and military intelligence has better things to spend it on (think Stuxnet-like scenarios).
tldr; the FBI operates on a level far below these other organizations and are far less important than any of them in the grand scheme of things. They're just well funded cops with all the problems cops bring. They're not getting NSA tools because they don't need them the same way your county sheriff doesn't need MRAPs to drive around in.
Re: The battle for the world’s most powerful cyberweapon
#44Earlier quoted context omitted.
All cryptography is based on the assumption that the inverse of some operation is hard to compute, because nobody's found an easy way to do it (yet). RSA is based on the assumptions that factoring prime numbers and finding discrete logarithms are both hard. ECC is based on the assumption that the subtraction analogue of that weird additiony thingy is hard. Afaik, neither of these things has been proven.
> Afaik, neither of these things has been proven. It's not even clear (at least to me) what a proof of "difficulty" would look like. You would have to prove that no mathematical process could exist that was capable of (for example) factoring a composite number N in less than M steps (where M is a function of N), and prove that each step has some minimum energy or time requirement, to ground the "difficulty" in terms…
Re: The battle for the world’s most powerful cyberweapon
#45Earlier quoted context omitted.
As someone who has worked Vulnerability Research/Exploit Dev for US based companies I'd consider this a bit misguided and is likely coming from someone not in the Vulnerability Research/Exploit Dev industry. I'm guessing you're getting these numbers from just reading Zerodium: """ The zero days are likely occasionally being discovered and fixed, but buying a zero-click zero day for Android/iPhone on the black market…
The sophistication of individual exploits is largely uninteresting, a bullet and a cruise missile both go through a piece of cardboard. Even quantity per target is largely uninteresting past the first couple in much the same way that having 23 snipers trained on a person is not so different than 8. It is the breadth of attacks in the Vault 7 leak that make the NSO group look like nothing. Maybe the NSO group could re…
Re: The battle for the world’s most powerful cyberweapon
#46Earlier quoted context omitted.
As someone who has worked Vulnerability Research/Exploit Dev for US based companies I'd consider this a bit misguided and is likely coming from someone not in the Vulnerability Research/Exploit Dev industry. I'm guessing you're getting these numbers from just reading Zerodium: """ The zero days are likely occasionally being discovered and fixed, but buying a zero-click zero day for Android/iPhone on the black market…
The sophistication of individual exploits is largely uninteresting, a bullet and a cruise missile both go through a piece of cardboard. Even quantity per target is largely uninteresting past the first couple in much the same way that having 23 snipers trained on a person is not so different than 8. It is the breadth of attacks in the Vault 7 leak that make the NSO group look like nothing. Maybe the NSO group could re…
Re: The battle for the world’s most powerful cyberweapon
#47Earlier quoted context omitted.
The sophistication of individual exploits is largely uninteresting, a bullet and a cruise missile both go through a piece of cardboard. Even quantity per target is largely uninteresting past the first couple in much the same way that having 23 snipers trained on a person is not so different than 8. It is the breadth of attacks in the Vault 7 leak that make the NSO group look like nothing. Maybe the NSO group could re…
.
Reasonable forms for a sufficiently quantified answer include, but are not limited to:
1. A numerical value to purchase from a broker.
2. A numerical value for the budget a competent organization (such as NSO) might allocate to a team to restock their hoard at a profitable return.
3. The number, skill, likely salary, and time/person-months a competent organization might allocate to restock their hoard at a profitable return.
4. The estimated return on a vulnerability. Giving an estimate of the expenditure bound to maintain profitability.
5. The estimated number of vulnerabilities NSO is finding per year given their budget.
6. The estimated number of vulnerabilities NSO has currently hoarded given their budget. Giving an estimate of the embodied expenditures to date.
7. The estimated amount of time for a NSO vulnerability to be burned allowing the estimation of required replenishment rate.
This is not an exhaustive list of reasonable quantifications, but I think at least something along these lines should provide an adequate quantification to demonstrate the degree to which I am underestimating the state of affairs.
Re: The battle for the world’s most powerful cyberweapon
#48Earlier quoted context omitted.
.
Okay. Since you say I am underestimating according to your experience can you supply a, in your opinion, 68% confidence interval estimate for the cost or effort required to purchase or develop a zero click iOS exploit (i.e. give a general range for the median case). Reasonable forms for a sufficiently quantified answer include, but are not limited to: 1. A numerical value to purchase from a broker. 2. A numerical val…
Re: The battle for the world’s most powerful cyberweapon
#49How about we do a YC startup and buy a few RCEs for android and iphone from zerodium and do this? (Just kidding to undermine the "most powerful" exaggeration in the title)
Re: The battle for the world’s most powerful cyberweapon
#50Earlier quoted context omitted.
Okay. Since you say I am underestimating according to your experience can you supply a, in your opinion, 68% confidence interval estimate for the cost or effort required to purchase or develop a zero click iOS exploit (i.e. give a general range for the median case). Reasonable forms for a sufficiently quantified answer include, but are not limited to: 1. A numerical value to purchase from a broker. 2. A numerical val…
.
Just for clarification, am I correctly understanding your answer to 1b as the price of a zero-click iOS exploit being ~$4M in contrast to my stated $1-2M? If so, I will not openly contest that claim here and thank you for your time. Anybody reading to this point can substitute my earlier claims for $4M if so.