Live data from Hacker News

NSA Director Says Agency Shares Vast Majority of Bugs It Finds

threatpost.com

21–30 of 62 posts

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#21
I've talked to some employees of TrueSec (the firm that just discovered the Yosemite "rootpipe" exploit) and they told me that many security research firms are "on retainer" with intelligence agencies. They didn't share specifics but they said that they have friends who are paid to share exploits with, say, British Intelligence and to not report it to the vendor with the exploit in it.

I assume this is why Stuxnet had so many zero-day exploits in it. The agencies behind it had security firms feeding them.

http://www.wired.com/2014/11/countdown-to-zero-day-stuxnet/

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#22
post #13

Earlier quoted context omitted.

How come that MS runs Linux on some Azure serves?

MS's customers can run Linux on Azure. Although I'm sure somewhere out there MS must have had a Linux server affected by this..

This is correct. The number of Linux machines, even counting firmware and other devices, is extremely low.

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#23
They've been lying so much at this point I don't know what it matters what they say. They were so caught up in seizing power with no regard to the consequences that they forgot that Trust is most precious and fleeting and far more valuable than lying about your law-breaking.

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#24

I've talked to some employees of TrueSec (the firm that just discovered the Yosemite "rootpipe" exploit) and they told me that many security research firms are "on retainer" with intelligence agencies. They didn't share specifics but they said that they have friends who are paid to share exploits with, say, British Intelligence and to not report it to the vendor with the exploit in it. I assume this is why Stuxnet ha…

Yes.

The market for 0days has been cooling off in recent years, but for a good decade there you could sell 0days, even mediocre ones for six digits. Nowdays you'll need a pretty good vuln for six digits, and something pretty stellar for seven (this isn't unheard of). ZDI, frsirt and others got into the game as middlemen. They allow(ed) you to not know who the final purchaser is and would allow you to sell 0days that may or may not be interesting to a government entity - in this case ZDI, etc would swallow the cost.

Edit: http://www.vupen.com/english/services/lea-index.php

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#25

I've talked to some employees of TrueSec (the firm that just discovered the Yosemite "rootpipe" exploit) and they told me that many security research firms are "on retainer" with intelligence agencies. They didn't share specifics but they said that they have friends who are paid to share exploits with, say, British Intelligence and to not report it to the vendor with the exploit in it. I assume this is why Stuxnet ha…

[deleted]

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#27
post #9

So, the NSA are, to a person, lying sacks of shit. After their director's performance in front on congress -- the "least untruthful answer possible" -- don't trust a damn word. So when they say they share, with whom? And what priority? Ooh, you found a documentation bug; is that the one you chose to share? The more severe a bug is, the more useful to them. There's a million ways to parse this bullshit that come down…

I want to be more specific about the concept of sharing.

There are two uses of "sharing" in the response. One was sharing of vulnerabilities. It was never clear who it was shared with. It could be with the DoD, with GCHQ, with private contractors under contract with the NSA, etc. and still be counted as "sharing."

The other is an example of sharing one patch, for the Bash vulnerability, with the private sector.

I think we are supposed to connect those two pieces of data, but there's no reason to do so.

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#28

I've talked to some employees of TrueSec (the firm that just discovered the Yosemite "rootpipe" exploit) and they told me that many security research firms are "on retainer" with intelligence agencies. They didn't share specifics but they said that they have friends who are paid to share exploits with, say, British Intelligence and to not report it to the vendor with the exploit in it. I assume this is why Stuxnet ha…

Yes. The market for 0days has been cooling off in recent years, but for a good decade there you could sell 0days, even mediocre ones for six digits. Nowdays you'll need a pretty good vuln for six digits, and something pretty stellar for seven (this isn't unheard of). ZDI, frsirt and others got into the game as middlemen. They allow(ed) you to not know who the final purchaser is and would allow you to sell 0days that…

I'm not sure if I agree with the ethics of selling security exploits, but it's a world I know very little about. You seem knowledgeable, is there any more information you could share about the business and culture of selling 0days? Like, how many people are doing that full time now (dozens or thousands?). Why do you think that the market slowed down, and do you think that most of the security hackers are trying to sell exploits to the responsible parties or do they expect most of them to go to government and other black hats?

Sorry for the questions, no contact info in your profile. Answers from anyone would also be appreciated.

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#29

I've talked to some employees of TrueSec (the firm that just discovered the Yosemite "rootpipe" exploit) and they told me that many security research firms are "on retainer" with intelligence agencies. They didn't share specifics but they said that they have friends who are paid to share exploits with, say, British Intelligence and to not report it to the vendor with the exploit in it. I assume this is why Stuxnet ha…

Most security research firms have no links whatsoever to intelligence agencies, but every security researcher in the world gossips about those links. Clearly some do, though.

I have no firsthand knowledge of how these connections work (the gossip I hear tends to involve firms proffering vulnerabilities to middleman "commercial" firms --- not ZDI, by the way --- but who knows?). But I'm skeptical of the idea that security research firms are a real feeder for vulnerability intel to NSA, because based on the people NSA spits back out into commercial industry, they appear to have a very, very capable internal research staff.

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#30

I've talked to some employees of TrueSec (the firm that just discovered the Yosemite "rootpipe" exploit) and they told me that many security research firms are "on retainer" with intelligence agencies. They didn't share specifics but they said that they have friends who are paid to share exploits with, say, British Intelligence and to not report it to the vendor with the exploit in it. I assume this is why Stuxnet ha…

Yes. The market for 0days has been cooling off in recent years, but for a good decade there you could sell 0days, even mediocre ones for six digits. Nowdays you'll need a pretty good vuln for six digits, and something pretty stellar for seven (this isn't unheard of). ZDI, frsirt and others got into the game as middlemen. They allow(ed) you to not know who the final purchaser is and would allow you to sell 0days that…

What is the least interesting vulnerability whose sale you have firsthand knowledge of that fetched more than $20,000?

Have you personally ever sold a vulnerability?

Post reply on HN