Live data from Hacker News

NSA Director Says Agency Shares Vast Majority of Bugs It Finds

threatpost.com

41–50 of 62 posts

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#41

Earlier quoted context omitted.

So, this is going to sound like I'm determined to find a reason to hate the NSA, but.. this doesn't make them look good either. It's the most accessible and widely-deployed memory disclosure bug of recent years, if not ever. Surely there are at least 1000 vulnerable (at the time) servers they'd specifically love to have this window into, for intelligence on the "bad guys." Surely they know the "bad guys" would love t…

So your argument is "If the NSA is any good, they must know about every vulnerability in the world before the private sector- otherwise they are incompetent"?

With the amount of money they spend, I would suggest that the US taxpayer should get some value out of it.

So while not every - at least a lot.

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#42
post #32

Earlier quoted context omitted.

I've contacted independent brokers before, many of whom allegedly resell primarily to "the US government". When asked about hypothetical Tor 0day, they quoted a price of $150,000 before their 20% broker fee. So I'm not sure that 6 figures for most trivial vulnerabilities fits the market. (And obviously, I don't have such a 0day to sell, so I can't prove that they would actually pay up.)

People believe a lot of weird stuff about vulnerability prices. For instance, any time a post hits HN about someone getting a $500 bounty for an XSS, there's always a post or two saying that's a rip-off compared to the tens of thousands of dollars it would fetch on the black market --- as if single-site XSS vulnerabilities with a half-life measured in minutes were worth huge amounts of money.

I would be quite happy with a $500 bounty for a trivial XSS bug. That pays for two days of work for me. :D

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#44
Then where are the fixes? They spend untold billions per year... their visible bugfix output is very low, including in low level cryptographic domains that you might expect them to be power-houses.

The claim makes me think either that they're lying about sharing what they find (either intentionally or via institutional stupidity); or they're really inept and not finding much at all compared to much less well funded OSS developers and participants in industry.

It would be interesting for someone to setup a scorecard site to document NSA's infosec contributions.

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#45
post #44

Then where are the fixes? They spend untold billions per year... their visible bugfix output is very low, including in low level cryptographic domains that you might expect them to be power-houses. The claim makes me think either that they're lying about sharing what they find (either intentionally or via institutional stupidity); or they're really inept and not finding much at all compared to much less well funded O…

Bug volume in crypto is also very low, and the "fixes" to major crypto bugs tend to take the form of entirely new constructions... which users are not happy to get from NSA (this was a problem even in the 1970s!)

So I'm not sure this is a valid critique.

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#46
post #45
post #44

Then where are the fixes? They spend untold billions per year... their visible bugfix output is very low, including in low level cryptographic domains that you might expect them to be power-houses. The claim makes me think either that they're lying about sharing what they find (either intentionally or via institutional stupidity); or they're really inept and not finding much at all compared to much less well funded O…

Bug volume in crypto is also very low, and the "fixes" to major crypto bugs tend to take the form of entirely new constructions... which users are not happy to get from NSA (this was a problem even in the 1970s!) So I'm not sure this is a valid critique.

There was the SHA0 -> SHA1 thing. Which mostly illustrates what you say here, of course, just seemed to deserve mention.

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#47
post #32

Earlier quoted context omitted.

I've contacted independent brokers before, many of whom allegedly resell primarily to "the US government". When asked about hypothetical Tor 0day, they quoted a price of $150,000 before their 20% broker fee. So I'm not sure that 6 figures for most trivial vulnerabilities fits the market. (And obviously, I don't have such a 0day to sell, so I can't prove that they would actually pay up.)

People believe a lot of weird stuff about vulnerability prices. For instance, any time a post hits HN about someone getting a $500 bounty for an XSS, there's always a post or two saying that's a rip-off compared to the tens of thousands of dollars it would fetch on the black market --- as if single-site XSS vulnerabilities with a half-life measured in minutes were worth huge amounts of money.

Oh we're not talking trivial bugs or single-site XSS.

Disappointed that 'mediocre' vulns got interpreted in this thread as 'trivial'.

Mediocre doesn't mean trivial, extremely scoped or useless. Mediocre means that it is for sensitive but not widely deployed software, for widely deployed software on default config but is post-auth or is not reliable, or it is reliable and yiels high auth but requires pairing with another vulns (i.e. memory disclosure) or extended recon (revision number, etc).

A MySQL bug affecting recent revisions that causes arbitrary file overwrites with semi-controlled content but that requires unprivileged (guest) auth would meet this criteria.

Apologies for the confusion with the word 'mediocre' - I figured people here would know.

In general organizations in the offensive world will pay more than those in the defensive world. This is not a hard and fast rule, but mostly it is the case that offensive network operations stand to gain more from the use of 0days than vendors stand to lose by not paying for the disclosure to patch them. It's not really a good calculus to use data from vendors sales to calculate the other.

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#48
post #30

Earlier quoted context omitted.

What is the least interesting vulnerability whose sale you have firsthand knowledge of that fetched more than $20,000? Have you personally ever sold a vulnerability?

I've contacted independent brokers before, many of whom allegedly resell primarily to "the US government". When asked about hypothetical Tor 0day, they quoted a price of $150,000 before their 20% broker fee. So I'm not sure that 6 figures for most trivial vulnerabilities fits the market. (And obviously, I don't have such a 0day to sell, so I can't prove that they would actually pay up.)

Six digits sounds about right for a Tor bug for one target depending on the specifics. The RCE bug used by the FBI recently against the Tor Firefox Bundle would have cost something similar, though the payload suspended the process where it could have resumed silently. It's not clear where that exploit was developed (my gut says in house but who knows?)

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#49
post #44

Then where are the fixes? They spend untold billions per year... their visible bugfix output is very low, including in low level cryptographic domains that you might expect them to be power-houses. The claim makes me think either that they're lying about sharing what they find (either intentionally or via institutional stupidity); or they're really inept and not finding much at all compared to much less well funded O…

Well, there was that time a tor developer claimed the NSA was leaking him fixes... https://news.ycombinator.com/item?id=8210319

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#50

Earlier quoted context omitted.

Yes. The market for 0days has been cooling off in recent years, but for a good decade there you could sell 0days, even mediocre ones for six digits. Nowdays you'll need a pretty good vuln for six digits, and something pretty stellar for seven (this isn't unheard of). ZDI, frsirt and others got into the game as middlemen. They allow(ed) you to not know who the final purchaser is and would allow you to sell 0days that…

I'm not sure if I agree with the ethics of selling security exploits, but it's a world I know very little about. You seem knowledgeable, is there any more information you could share about the business and culture of selling 0days? Like, how many people are doing that full time now (dozens or thousands?). Why do you think that the market slowed down, and do you think that most of the security hackers are trying to se…

The people who know don't talk and the people who talk don't know...
Post reply on HN