Live data from Hacker News

NSA Director Says Agency Shares Vast Majority of Bugs It Finds

threatpost.com

61–62 of 62 posts

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#61
post #33
post #30

Earlier quoted context omitted.

What is the least interesting vulnerability whose sale you have firsthand knowledge of that fetched more than $20,000? Have you personally ever sold a vulnerability?

FWIW I don't agree with the assessment of the OP. While there are some security firms that do have contracts, the vast majority of NSA capability is internally developed (or developed under contract by defence contractors). As for the "market assessment" I find it implausible. It seems to be based on the assumption that the demand for capabilities has decreased over time while the availability of good bugs has increa…

More defence contractors than internal, I'd understood?

Re: NSA Director Says Agency Shares Vast Majority of Bugs It Finds

#62
post #45
post #44

Then where are the fixes? They spend untold billions per year... their visible bugfix output is very low, including in low level cryptographic domains that you might expect them to be power-houses. The claim makes me think either that they're lying about sharing what they find (either intentionally or via institutional stupidity); or they're really inept and not finding much at all compared to much less well funded O…

Bug volume in crypto is also very low, and the "fixes" to major crypto bugs tend to take the form of entirely new constructions... which users are not happy to get from NSA (this was a problem even in the 1970s!) So I'm not sure this is a valid critique.

It's not the NSA that is publishing cryptanalysis of proposed constructions with any frequency compared to industry/academia. Considering the number of mathematicians they employ and their focus on cryptography this is more than a little surprising.

But I did also mean that more broader than just construct attacks..., implementations of cryptosystems are often flawed in low level ways which people without special expertise are unlikely to notice... both from a design perspective (any of the great many protocol design flaws in TLS that have turned around an bitten us), or straight forward coding (e.g. it wasn't the NSA that reported reference implementations of Curve25519 had broken carry propagation).

Post reply on HN