9 ms·
The NSA Is Hoarding Vulnerabilities
- deleted 10y ago[deleted]
- anexprogrammer 10y agoHere's what I've never understood despite following security for a number of years. How on earth can the NSA ever conclude "nobody but us" short of silicon level exploits at manufacturing? Do they really think they can do things that the Chinese or other governments with significant agencies and supercomputers can't?
- Kenji 10y agoThe assumption of NOBUS is equivalent to security through obscurity.
- tptacek 10y agoNo, it's not. I believe Schneier is simply abusing the term. As I've seen it deployed, "NOBUS" usually refers to capabilities protected cryptographically, not by kernel reference monitors that hide keys, but by actual secret keys. I don't believe zero-day vulnerabilities are considered "NOBUS" by NSA. That would be silly, because every time they're used on public-sector IP networks (which is usually where they're used!), they're disclosed.
- AnimalMuppet 10y ago> ... every time they're used on public-sector IP networks (which is usually where they're used!), they're disclosed. Could you explain what you mean by that? Do you mean that NSA discloses everything they use on public IP networks? If so, can you provide some references, because I have never heard of them doing so. Or do you mean that every time the NSA does so, they get caught and exposed? That seems to be based on the idea that we never hear of them using exploits on public IP networks without getting caught, which, if you think for a second, you realize is a completely silly argument. Or did you mean something else? If so, what?
- tptacek 10y agoI mean that running the exploit discloses it to anyone who's doing full packet captures on the protocol the exploit uses.
- AnimalMuppet 10y agoOK, so they're "disclosed" in the sense that "the information (in packet form) is released onto a public network". But that's potential discovery if someone is paying very close attention. And the point of a zero-day is that nobody's paying attention to that specifically, because nobody knows to do so yet. So, yes, somebody could have a packet capture of it, along with a billion other packets. So you're using "disclosure" here in a very restricted sense. It more normally means something more like "sending an email to the vendor" or "making a press release".
- tptacek 10y agoTo paraphrase someone smarter on these issues than I am: NSA's adversaries spend more on coffee than Cisco does on product security. When vulns like the ones we've seen are used on public networks, they are disclosed. The question isn't whether they're disclosed to vendors. It's whether they're NOBUS flaws. Schneier is suggesting NSA views them as NOBUS. They do not.
- srtjstjsj 10y agoyou mean the NSA staff spends more on coffee than Cisco does on product security? otherwise, the claim makes no sense. the NSA's adversaries include huge swaths of non-security-conscious users, and includes Cisco.
- tptacek 10y agoThe NSA's adversaries include the rest of the world's largest SIGINT agencies.
- woliveirajr 10y agoIMHO, they can't be sure but it's possible to estimate in the following scenario. NSA finds some 0-day vulnerability in some router. To use it someone must send some specific data to a specific port, so that it causes some buffer overflow and leaks information. NSA also might have all the traffic that is exchanged by some key points of the USA sites. They can monitor from now on, and also look the stored traffic, and try to find if that packed (attack) was ever used, is being used, or even activate some trigger if it shows up. So, if others used it, warn the manufacturer. Not seen in the wild, save it in the "only ours" folder and use at will.
- AnimalMuppet 10y agoThat's a very plausible bit of paranoia. And to add my paranoia to the mix: Then the "auction" of Equation Group stuff could be a way for the NSA to expose the vulnerabilities that others are starting to exploit.
- balabaster 10y agoJust because you're paranoid doesn't mean that's not exactly what they're doing ;) Given what is becoming more apparent about the NSA on a day by day basis, anything you can think might be being done but write it off as needless paranoia is probably exactly what's being done... because "you're just being paranoid, we'd never do that to millions of innocent Americans." Yet somehow...
- tptacek 10y agoThat's an understandable feeling to have, but you see how it sort of sucks all the oxygen out of any discussion you might have about issues or policy.
- balabaster 10y agoSure... the underlying cause though isn't because of policy or issues though, it's trust in the agencies creating the policies, mandating them and enforcing them. If we trusted them to adequately safeguard our information, and not to misuse it, then none of this would be an issue. But they've broken trust many times over and once that horse has bolted, you can't just close the stable door and expect people to just trust you again - especially not when you keep getting caught with your hand in the cookie jar, get caught lying about it or using smoke and mirrors to sidestep the consequences and then coming back and saying don't worry, not only can we be trusted with the cookie jar, but we must be the ones safeguarding you from the cookies because they make you fat. So it's for the good of everyone. Meanwhile, they're just sitting their eating the cookies. It's always a land grab for more cookies. You wouldn't trust your six year old with that kind of behavior, you certainly shouldn't trust a Government agency that acts the same way.
- fweespeech 10y ago> Here's what I've never understood despite following security for a number of years. How on earth can the NSA ever conclude "nobody but us" short of silicon level exploits at manufacturing? Do they really think they can do things that the Chinese or other governments with significant agencies and supercomputers can't? They have a dual mandate and vast surveillance capabilities. I'm honestly not surprise at all by the behavior. I think the horrifying thing is people don't seem to care that this makes Government & Criminals equally dangerous to the security of our infrastructure. I'm just waiting for some massive, systemic compromise of a major bank from a combination of "NSA thinks they are the only ones with them" exploits as it seems like the only thing that would wake people up to the danger. Those two mandates are in conflict so they are playing the logic of: 1) We have vast surveillance capabilities, so we would be able to detect 0-days sent over a network we have visibility into. 2) We don't care if non-US assets get cracked and we have near perfect visibility into US assets. 3) We have a duty to perform offensive operations. So we should retain any weapon we believe our enemies are unaware of.
- tptacek 10y agoI don't think Schneier established that NSA does consider zero-days NOBUS. I think he's conflating things like Dual_EC, which are cryptographically protected NOBUS capabilities, with zero-day vulnerabilities.
- ryao 10y agoI do not understand this "they're making us less secure" argument. The only way that the NSA could be actively making systems less secure would be if they were putting vulnerabilities into the source code or silicon. The reality is that the NSA need not do that because these systems were already insecure and the NSA just had to figure out how they were insecure. They would have been insecure, even if the NSA had never scrutinized them. The affected systems are ones that I had told others were likely insecure (by virtue of being closed source), but no one listened to me. If you care about network security, then you should use a properly configured software firewall/router running Linux or *BSD. This Cisco/Juniper/etcetera equipment is closed source, hard to scrutinize and almost certainly has horrible flaws that would never be allowed into a serious OSS project. Of course, things like pfSense are not "enterprise grade", so people will continue to ignore advice to use them, put these vulnerable systems into production and then be surprised when it comes out that the security was terrible.
- JustSomeNobody 10y agoHe says, "Hoarding zero-day vulnerabilities is a bad idea. It means that we're all less secure." I take this to mean we are less secure than we would be if we could fix the issues (obviously). I don't think this means the same thing as saying it "makes us less secure".
- ryao 10y agoBruce Schneier is well documented to equate failing to disclose vulnerabilities with making systems less secure, or as he put it in this interview, less safe: https://www.technologyreview.com/s/519336/bruce-schneier-nsa-spying-is-making-us-less-safe/ https://www.technologyreview.com/s/519336/bruce-schneier-nsa... To his credit, he was talking about weakening encryption standards, but then elaborated that simply looking for security vulnerabilities and not telling anyone what they found was also doing that. I find that latter position ridiculous. It would be like saying studying malaria and not reporting your findings makes people less healthy.
- pdkl95 10y ago
- wyldfire 10y ago> If there are any vulnerabilities that according to the standards established by the White House and the NSA should have been disclosed and fixed, it's these. It's too bad -- there's really just no accountability for these espionage organizations. And it seems like it will never change.
- tptacek 10y agoA bunch of thoughts: 1. It's not true that there's broad agreement among experts about how the government ought to handle vulnerabilities. In fact, that's close to the opposite of the truth. On the question of regulation, the field is riven over Wassenaar and the prospect of vuln research regulation. It's also divided between people with operational knowledge of how zero-day is used by the IC and people looking from the outside in, and also between privacy activists and security researchers, which is a Venn diagram with only partial overlap. 2. Schneier is showily beating up on the USG "vulnerability equities process", which supposedly determines whether or not the USG will publish vulnerabilities. It's fair game. But something that there is broad agreement on among practitioners is that the VEP is a PR farce. Nobody needed "Shadow Brokers" to confirm this; you can't have been paying attention over the last 10 years and not see that SIGINT roflstomps IAD. Read between the lines: even without specific NSA disclosures, to believe that NSA was serious about VEP, you'd have to believe that NSA is unique among all global intelligence agencies about protecting industry from vulnerabilities. 3. Schneier's perspective on whether, why, and how vulnerabilities should be disclosed is probably naive. The best account I've read on this so far is Aitel's Vulnerability Equities post on Lawfare. For a simple example: NSA SIGINT cannot necessarily disclose old vulnerabilities, even for products that have been discontinued, without revealing to its opponents a catalog of every machine they've compromised over the lifespan of the vulnerability. Take for instance the Cisco SNMP vulnerability: SNMP is so low-volume that even mid-sized US corporations maintain full packet logs of every SNMP request sent on their network. To premise operation decisions on the idea that FSB doesn't do that would be extremely poor tradecraft. That's not dispositive! It could be the case that the USG should simply give up on computer-based SIGINT, unilaterally disarming and working instead to help industry defend against foreign SIGINT. That would be a radical change and it would come with tradeoffs, but it's a coherent position. A far more straightforward argument to make is that NSA SIGINT should be entirely exempt from any equities process, but that NSA should be stripped of its IAD mission, and a separately funded and operated IAD capability should be spun up under DHS, with clear directives to disclose immediately to vendors. 4. I'm a little biased on this, not because I'm a vuln researcher (I am, but I don't do the kind of work that gets marketed to government, nor have I or will I ever work with governments) but because I think Bruce Schneier's track record on this subject is both bad and inconsistent, dating back to his use of his popular newsletter to vilify eEye for disclosing to the public vulnerabilities later used to build worms.
- Johnny555 10y agoThe government already admitted that they are hoarding vulnerabilities: ...the Obama administration announced, in early 2014, that the NSA must disclose flaws in common software so they can be patched (unless there is "a clear national security or law enforcement" use)... Obviously any valuable zero-day flaw has clear national security use to a national security agency that's tasked with breaking into "enemy" systems.
- tptacek 10y agoWhy the scare quotes around "enemy"?
- CDRdude 10y agoBecause the NSA breaks into US-based companies too.
- tptacek 10y agoI'm sure that's happened, but there's a reason the EQ dump included lots of vulnerabilities for Chinese products nobody in the US deploys. "Enemy" is a weird word ("adversary" is probably better), but however you slice it: NSA's mission includes real ones.
- nitrogen 10y agoThat is entirely irrelevant to people who are still getting hacked because of these hoarded vulnerabilities.
- tptacek 10y agoI don't follow. Could you make this argument more specific? Who's doing this attacking? What kinds of vulnerabilities? Stated as vaguely as you have, that's a hard argument to rebut. I tend to agree: the world would be a safer place if everything was publicly disclosed immediately. But even NSA's opponents tend not to support that as a policy objective.
- jokoon 10y agoI think that as long as the NSA can estimate they do have more of those cyber weapons, they won't push for patching them, and it makes sense. The day the chinese of the russians are able to discover more of those vulnerabilities, they will all get fixed. It's a simple arms race. Simple as that.
- upofadown 10y agoNow that the code makers have run far beyond the code breakers, hacking is all entities like the NSA have left. So of course they are hording vulnerabilities. That's all they can do. Cracking systems probably isn't going to lead to anything worthwhile. It isn't targeted enough. The thing that the NSA fears the most is the perception that they are not worth the money. It's a legitimate fear.
- tptacek 10y agoFirst, I think there's a lot of truth to the idea that NSA's primary motivation is headcount. I think that's an important and significant point that isn't raised often enough in these discussions. It has implications beyond vulnerability disclosure! (For instance: it's a very good reason to be wary of things like DNSSEC, that make it expensive but not intractable to attack Internet trust at its core). But I don't know what you mean by your first paragraph, or by the notion that "cracking systems isn't going to lead to anything worthwhile".
- nickthemagicman 10y agoWhats the distinction between hacking and cracking?
- mastax 10y agoSome would like to promote 'hacking' as screwing around with things for fun/learning and 'hacking' as digital breaking and entering. Seems like an uphill battle to me but its probsbly useful to have a distinction.
- doggydogs94 10y agoI think what would work best is the following. NSA alerts US companies of the vulnerabilities in their products with the understanding that the companies will not publicize that the vulnerability was fixed. This will let the NSA continue to exploit the vulnerabilities; most customers never update things like routers and other obscure pieces of the infrastructure.