Live data from Hacker News

NSA Director Says Agency Shares Vast Majority of Bugs It Finds

threatpost.com

31–40 of 62 posts

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#31
post #30

Earlier quoted context omitted.

Yes. The market for 0days has been cooling off in recent years, but for a good decade there you could sell 0days, even mediocre ones for six digits. Nowdays you'll need a pretty good vuln for six digits, and something pretty stellar for seven (this isn't unheard of). ZDI, frsirt and others got into the game as middlemen. They allow(ed) you to not know who the final purchaser is and would allow you to sell 0days that…

What is the least interesting vulnerability whose sale you have firsthand knowledge of that fetched more than $20,000? Have you personally ever sold a vulnerability?

I've contacted independent brokers before, many of whom allegedly resell primarily to "the US government". When asked about hypothetical Tor 0day, they quoted a price of $150,000 before their 20% broker fee. So I'm not sure that 6 figures for most trivial vulnerabilities fits the market.

(And obviously, I don't have such a 0day to sell, so I can't prove that they would actually pay up.)

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#32
post #30

Earlier quoted context omitted.

What is the least interesting vulnerability whose sale you have firsthand knowledge of that fetched more than $20,000? Have you personally ever sold a vulnerability?

I've contacted independent brokers before, many of whom allegedly resell primarily to "the US government". When asked about hypothetical Tor 0day, they quoted a price of $150,000 before their 20% broker fee. So I'm not sure that 6 figures for most trivial vulnerabilities fits the market. (And obviously, I don't have such a 0day to sell, so I can't prove that they would actually pay up.)

People believe a lot of weird stuff about vulnerability prices. For instance, any time a post hits HN about someone getting a $500 bounty for an XSS, there's always a post or two saying that's a rip-off compared to the tens of thousands of dollars it would fetch on the black market --- as if single-site XSS vulnerabilities with a half-life measured in minutes were worth huge amounts of money.

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#33
post #30

Earlier quoted context omitted.

Yes. The market for 0days has been cooling off in recent years, but for a good decade there you could sell 0days, even mediocre ones for six digits. Nowdays you'll need a pretty good vuln for six digits, and something pretty stellar for seven (this isn't unheard of). ZDI, frsirt and others got into the game as middlemen. They allow(ed) you to not know who the final purchaser is and would allow you to sell 0days that…

What is the least interesting vulnerability whose sale you have firsthand knowledge of that fetched more than $20,000? Have you personally ever sold a vulnerability?

FWIW I don't agree with the assessment of the OP. While there are some security firms that do have contracts, the vast majority of NSA capability is internally developed (or developed under contract by defence contractors).

As for the "market assessment" I find it implausible. It seems to be based on the assumption that the demand for capabilities has decreased over time while the availability of good bugs has increased. This is at odds with reality.

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#34
post #33
post #30

Earlier quoted context omitted.

What is the least interesting vulnerability whose sale you have firsthand knowledge of that fetched more than $20,000? Have you personally ever sold a vulnerability?

FWIW I don't agree with the assessment of the OP. While there are some security firms that do have contracts, the vast majority of NSA capability is internally developed (or developed under contract by defence contractors). As for the "market assessment" I find it implausible. It seems to be based on the assumption that the demand for capabilities has decreased over time while the availability of good bugs has increa…

I believe you on this a lot more than I believe anonymous employees of a firm known principally for giving a brand name to an Admin->Root privilege escalation bug.

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#35
post #34
post #33

Earlier quoted context omitted.

FWIW I don't agree with the assessment of the OP. While there are some security firms that do have contracts, the vast majority of NSA capability is internally developed (or developed under contract by defence contractors). As for the "market assessment" I find it implausible. It seems to be based on the assumption that the demand for capabilities has decreased over time while the availability of good bugs has increa…

I believe you on this a lot more than I believe anonymous employees of a firm known principally for giving a brand name to an Admin->Root privilege escalation bug.

[deleted]

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#36
post #32

Earlier quoted context omitted.

I've contacted independent brokers before, many of whom allegedly resell primarily to "the US government". When asked about hypothetical Tor 0day, they quoted a price of $150,000 before their 20% broker fee. So I'm not sure that 6 figures for most trivial vulnerabilities fits the market. (And obviously, I don't have such a 0day to sell, so I can't prove that they would actually pay up.)

People believe a lot of weird stuff about vulnerability prices. For instance, any time a post hits HN about someone getting a $500 bounty for an XSS, there's always a post or two saying that's a rip-off compared to the tens of thousands of dollars it would fetch on the black market --- as if single-site XSS vulnerabilities with a half-life measured in minutes were worth huge amounts of money.

I commented on this back when Facebook paid out $30k for that RCE. I know the Facebook security team points to this comment all the time. Maybe more people should read it:

https://news.ycombinator.com/item?id=7106953

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#37
post #2

In the video of that discussion[1] he also says that NSA developed the Heartbleed patch after hearing about the vulnerability on April 7 and shared with the private sector on April 8. Interesting to compare with timeline: http://www.smh.com.au/it-pro/security-it/heartbleed-disclosu... [1] https://www.youtube.com/watch?v=yhwy2ZWi_y8

So, this is going to sound like I'm determined to find a reason to hate the NSA, but.. this doesn't make them look good either. It's the most accessible and widely-deployed memory disclosure bug of recent years, if not ever. Surely there are at least 1000 vulnerable (at the time) servers they'd specifically love to have this window into, for intelligence on the "bad guys." Surely they know the "bad guys" would love t…

So your argument is "If the NSA is any good, they must know about every vulnerability in the world before the private sector- otherwise they are incompetent"?

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#39
post #29

I've talked to some employees of TrueSec (the firm that just discovered the Yosemite "rootpipe" exploit) and they told me that many security research firms are "on retainer" with intelligence agencies. They didn't share specifics but they said that they have friends who are paid to share exploits with, say, British Intelligence and to not report it to the vendor with the exploit in it. I assume this is why Stuxnet ha…

Most security research firms have no links whatsoever to intelligence agencies, but every security researcher in the world gossips about those links. Clearly some do, though. I have no firsthand knowledge of how these connections work (the gossip I hear tends to involve firms proffering vulnerabilities to middleman "commercial" firms --- not ZDI, by the way --- but who knows?). But I'm skeptical of the idea that secu…

But isn't that exactly what a security researcher with links to intelligence agencies _would_ say ;)

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#40
I assume they do share the majority of vulnerabilities they find, but keep the top 2% for their own use. By top 2% I mean the vulnerabilities that are highly unlikely to be discovered by other nations.

The other 98% of zero days that are easy enough to stumble upon by foreign cyber units might be better to disclose and get fixed.

If the NSA can find a bug relatively easy, then we can assume China(example) might be able to as well. Getting those bugs fixed is a big gain for national security. Although, it will boost security of all nations.

Post reply on HN