I assume this is why Stuxnet had so many zero-day exploits in it. The agencies behind it had security firms feeding them.
NSA Director Says Agency Shares Vast Majority of Bugs It Finds
21–30 of 62 posts
Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds
#22Earlier quoted context omitted.
How come that MS runs Linux on some Azure serves?
MS's customers can run Linux on Azure. Although I'm sure somewhere out there MS must have had a Linux server affected by this..
Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds
#23Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds
#24I've talked to some employees of TrueSec (the firm that just discovered the Yosemite "rootpipe" exploit) and they told me that many security research firms are "on retainer" with intelligence agencies. They didn't share specifics but they said that they have friends who are paid to share exploits with, say, British Intelligence and to not report it to the vendor with the exploit in it. I assume this is why Stuxnet ha…
The market for 0days has been cooling off in recent years, but for a good decade there you could sell 0days, even mediocre ones for six digits. Nowdays you'll need a pretty good vuln for six digits, and something pretty stellar for seven (this isn't unheard of). ZDI, frsirt and others got into the game as middlemen. They allow(ed) you to not know who the final purchaser is and would allow you to sell 0days that may or may not be interesting to a government entity - in this case ZDI, etc would swallow the cost.
Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds
#25I've talked to some employees of TrueSec (the firm that just discovered the Yosemite "rootpipe" exploit) and they told me that many security research firms are "on retainer" with intelligence agencies. They didn't share specifics but they said that they have friends who are paid to share exploits with, say, British Intelligence and to not report it to the vendor with the exploit in it. I assume this is why Stuxnet ha…
Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds
#26Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds
#27So, the NSA are, to a person, lying sacks of shit. After their director's performance in front on congress -- the "least untruthful answer possible" -- don't trust a damn word. So when they say they share, with whom? And what priority? Ooh, you found a documentation bug; is that the one you chose to share? The more severe a bug is, the more useful to them. There's a million ways to parse this bullshit that come down…
There are two uses of "sharing" in the response. One was sharing of vulnerabilities. It was never clear who it was shared with. It could be with the DoD, with GCHQ, with private contractors under contract with the NSA, etc. and still be counted as "sharing."
The other is an example of sharing one patch, for the Bash vulnerability, with the private sector.
I think we are supposed to connect those two pieces of data, but there's no reason to do so.
Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds
#28I've talked to some employees of TrueSec (the firm that just discovered the Yosemite "rootpipe" exploit) and they told me that many security research firms are "on retainer" with intelligence agencies. They didn't share specifics but they said that they have friends who are paid to share exploits with, say, British Intelligence and to not report it to the vendor with the exploit in it. I assume this is why Stuxnet ha…
Yes. The market for 0days has been cooling off in recent years, but for a good decade there you could sell 0days, even mediocre ones for six digits. Nowdays you'll need a pretty good vuln for six digits, and something pretty stellar for seven (this isn't unheard of). ZDI, frsirt and others got into the game as middlemen. They allow(ed) you to not know who the final purchaser is and would allow you to sell 0days that…
Sorry for the questions, no contact info in your profile. Answers from anyone would also be appreciated.
Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds
#29I've talked to some employees of TrueSec (the firm that just discovered the Yosemite "rootpipe" exploit) and they told me that many security research firms are "on retainer" with intelligence agencies. They didn't share specifics but they said that they have friends who are paid to share exploits with, say, British Intelligence and to not report it to the vendor with the exploit in it. I assume this is why Stuxnet ha…
I have no firsthand knowledge of how these connections work (the gossip I hear tends to involve firms proffering vulnerabilities to middleman "commercial" firms --- not ZDI, by the way --- but who knows?). But I'm skeptical of the idea that security research firms are a real feeder for vulnerability intel to NSA, because based on the people NSA spits back out into commercial industry, they appear to have a very, very capable internal research staff.
Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds
#30I've talked to some employees of TrueSec (the firm that just discovered the Yosemite "rootpipe" exploit) and they told me that many security research firms are "on retainer" with intelligence agencies. They didn't share specifics but they said that they have friends who are paid to share exploits with, say, British Intelligence and to not report it to the vendor with the exploit in it. I assume this is why Stuxnet ha…
Yes. The market for 0days has been cooling off in recent years, but for a good decade there you could sell 0days, even mediocre ones for six digits. Nowdays you'll need a pretty good vuln for six digits, and something pretty stellar for seven (this isn't unheard of). ZDI, frsirt and others got into the game as middlemen. They allow(ed) you to not know who the final purchaser is and would allow you to sell 0days that…
Have you personally ever sold a vulnerability?