10 ms·
So it seems the dump contains at least one legit 0-day, and it's been in use for 3 years.
by salem 10y ago
So it seems the dump contains at least one legit 0-day, and it's been in use for 3 years.
- jonknee 10y ago> and it's been in use for 3 years. At least 3 years.
- ktRolster 10y agoThis is why "responsible disclosure" is a joke. The flaws put in by these companies are not responsible. (Sometimes people make mistakes, but we're at the point of carelessness).
- tptacek 10y agoThat may feel good to say, but as someone whose job it was to find these kinds of bugs in software from companies ranging from tiny startups to financial exchanges to major tech vendors, this is a kind of carelessness shared by virtually everyone shipping any kind of software anywhere. That said, the term "responsible disclosure" is Orwellian, and you should very much avoid using it.
- cdubzzz 10y agoHow is "responsible disclosure" Orwellian?
- tptacek 10y agoIt's coercive. It redefines language to make any handling of vulnerabilities not condoned by the vendors who shipped those vulnerabilities "irresponsible", despite the fact that third parties who discover vulnerabilities have no formal duty to cooperate with those vendors whatsoever. The better term is "coordinated disclosure". But uncoordinated disclosure is not intrinsically irresponsible. For instance: if you know there's an exploit in the wild for something, perhaps go ahead and tweet the vulnerability without notice!
- deleted 10y ago[deleted]
- gcr 10y agoDo you think there's a moral imperative for researchers to responsibly disclose discovered vulnerabilities? I see it as a kind of Hippocratic Oath in the field.
- tptacek 10y agoNo.
- openasocket 10y agoMaybe I don't understand you. Are you suggesting that, if you find a vulnerability in a piece of software, you aren't ethically obligated to confidentially disclose the vulnerability to the maintainer so it can be patched before the vulnerability becomes publicly known? If so, why? What is a person who found a vulnerability ethically obligated to do?
- tptacek 10y agoNo, of course you aren't. Why would you be?
- openasocket 10y ago... because if you don't and someone malicious also discovers this vulnerability they can use it to do bad things? If I can get a vulnerability patched before it can be exploited, I can potentially prevent a hacker from stealing people's identity, credit card numbers, private data, etc. To have that opportunity and not act seems irresponsible. I must be misunderstanding. Would you mind expanding on this more?
- tptacek 10y agoYou are not misunderstanding. I do not in the general case have a duty to correct other people's mistakes. The people deploying broken software have a duty to do whatever they can not to allow its flaws to compromise their users and customers. Merely learning something new about the software they use does not transfer that obligation onto me. I would personally in almost every case report vulnerabilities I discovered. But not in every case (for instance: I refused to report the last CryptoCat flaw I discovered, though I did publicly and repeatedly warn that I'd found something grave). More importantly: my own inclination to report doesn't bind on every other vulnerability researcher.
- rdtsc 10y agoSomeone mentioned selling vulnerabilities on the black market as a better alternative than doing these "responsible disclosure" and bug bounties. What's your take on that? Is it a better route to take?
- tptacek 10y agoFor the most part I think selling vulnerabilities on an actual "black market" is intrinsically unethical, and makes you a party to the bad things people who buy exploits on an actual black market do with them. Thankfully, the black market doesn't want 99.99999% of the vulnerabilities people find. I have friends who have sold vulnerabilities to people other than vendors. I do not think they're unethical people, and I don't know enough about those transactions to really judge them. So, it really depends, I guess. But if it were me, I'd be very careful.
- ktRolster 10y agoIt's dangerous, and might be illegal, so be careful if you decide to do that.
- ktRolster 10y agothis is a kind of carelessness shared by virtually everyone shipping any kind of software anywhere. I don't feel wrong saying that all of those are irresponsible. There are some people who write good code, who at least make an effort to avoid vulnerabilities, and those are the responsible ones.
- tptacek 10y agoIf you find one of them in the wild, take a picture, so we can have some evidence they exist.
- ktRolster 10y agoThey exist all over the place. OpenBSD, DJB, Knuth, at companies I've worked for, you'll find people who care, and code responsibly. The rest of you need to get your act together.
- Someone1234 10y agoWhich does at least HINT that it might be what it claims to be. That's a pretty impressive 0-day which they just gave away as a freebie, who knows what they didn't give away. I will say we'll never get real confirmation if this was actually stolen from the NSA, but if the other bundle contains a bunch of nice original vulnerabilities people will presume it was.
- salem 10y agoMakes you wonder if they could have made more money by pretending to find them and reporting them to the respective bug bounty programs.
- deleted 10y ago[deleted]
- wcummings 10y agoBug bounties almost never pay market value for exploits. Only reason to participate in them is charity.
- kbenson 10y agoAnd legality. I'm not sure why people seem to entirely discount that portion. There's more reward by selling on the black market, but there's also more risk associated with that.
- MichaelGG 10y agoYeah. Homeowners don't pay market value for me not robbing them, either. After all, think how much that jewellery is worth. And the damage of ID cards and passports. A laptop alone could get me $250, but no one wants to give me even $10 for telling them their door is unlocked.
- peterbotond 10y agoMost people only care about tangibles. When i politely advised about security holes, i was told that "we don't need people like you' or just called the police. I understand.