4 ms·
Here's what I've never understood despite following security for a number of years. How on earth can the NSA ever conclude "nobody but us" short of silicon lev
by anexprogrammer 10y ago
Here's what I've never understood despite following security for a number of years. How on earth can the NSA ever conclude "nobody but us" short of silicon level exploits at manufacturing? Do they really think they can do things that the Chinese or other governments with significant agencies and supercomputers can't?
- Kenji 10y agoThe assumption of NOBUS is equivalent to security through obscurity.
- tptacek 10y agoNo, it's not. I believe Schneier is simply abusing the term. As I've seen it deployed, "NOBUS" usually refers to capabilities protected cryptographically, not by kernel reference monitors that hide keys, but by actual secret keys. I don't believe zero-day vulnerabilities are considered "NOBUS" by NSA. That would be silly, because every time they're used on public-sector IP networks (which is usually where they're used!), they're disclosed.
- AnimalMuppet 10y ago> ... every time they're used on public-sector IP networks (which is usually where they're used!), they're disclosed. Could you explain what you mean by that? Do you mean that NSA discloses everything they use on public IP networks? If so, can you provide some references, because I have never heard of them doing so. Or do you mean that every time the NSA does so, they get caught and exposed? That seems to be based on the idea that we never hear of them using exploits on public IP networks without getting caught, which, if you think for a second, you realize is a completely silly argument. Or did you mean something else? If so, what?
- tptacek 10y agoI mean that running the exploit discloses it to anyone who's doing full packet captures on the protocol the exploit uses.
- AnimalMuppet 10y agoOK, so they're "disclosed" in the sense that "the information (in packet form) is released onto a public network". But that's potential discovery if someone is paying very close attention. And the point of a zero-day is that nobody's paying attention to that specifically, because nobody knows to do so yet. So, yes, somebody could have a packet capture of it, along with a billion other packets. So you're using "disclosure" here in a very restricted sense. It more normally means something more like "sending an email to the vendor" or "making a press release".
- tptacek 10y agoTo paraphrase someone smarter on these issues than I am: NSA's adversaries spend more on coffee than Cisco does on product security. When vulns like the ones we've seen are used on public networks, they are disclosed. The question isn't whether they're disclosed to vendors. It's whether they're NOBUS flaws. Schneier is suggesting NSA views them as NOBUS. They do not.
- srtjstjsj 10y agoyou mean the NSA staff spends more on coffee than Cisco does on product security? otherwise, the claim makes no sense. the NSA's adversaries include huge swaths of non-security-conscious users, and includes Cisco.
- tptacek 10y agoThe NSA's adversaries include the rest of the world's largest SIGINT agencies.
- woliveirajr 10y agoIMHO, they can't be sure but it's possible to estimate in the following scenario. NSA finds some 0-day vulnerability in some router. To use it someone must send some specific data to a specific port, so that it causes some buffer overflow and leaks information. NSA also might have all the traffic that is exchanged by some key points of the USA sites. They can monitor from now on, and also look the stored traffic, and try to find if that packed (attack) was ever used, is being used, or even activate some trigger if it shows up. So, if others used it, warn the manufacturer. Not seen in the wild, save it in the "only ours" folder and use at will.
- AnimalMuppet 10y agoThat's a very plausible bit of paranoia. And to add my paranoia to the mix: Then the "auction" of Equation Group stuff could be a way for the NSA to expose the vulnerabilities that others are starting to exploit.
- balabaster 10y agoJust because you're paranoid doesn't mean that's not exactly what they're doing ;) Given what is becoming more apparent about the NSA on a day by day basis, anything you can think might be being done but write it off as needless paranoia is probably exactly what's being done... because "you're just being paranoid, we'd never do that to millions of innocent Americans." Yet somehow...
- tptacek 10y agoThat's an understandable feeling to have, but you see how it sort of sucks all the oxygen out of any discussion you might have about issues or policy.
- balabaster 10y agoSure... the underlying cause though isn't because of policy or issues though, it's trust in the agencies creating the policies, mandating them and enforcing them. If we trusted them to adequately safeguard our information, and not to misuse it, then none of this would be an issue. But they've broken trust many times over and once that horse has bolted, you can't just close the stable door and expect people to just trust you again - especially not when you keep getting caught with your hand in the cookie jar, get caught lying about it or using smoke and mirrors to sidestep the consequences and then coming back and saying don't worry, not only can we be trusted with the cookie jar, but we must be the ones safeguarding you from the cookies because they make you fat. So it's for the good of everyone. Meanwhile, they're just sitting their eating the cookies. It's always a land grab for more cookies. You wouldn't trust your six year old with that kind of behavior, you certainly shouldn't trust a Government agency that acts the same way.
- fweespeech 10y ago> Here's what I've never understood despite following security for a number of years. How on earth can the NSA ever conclude "nobody but us" short of silicon level exploits at manufacturing? Do they really think they can do things that the Chinese or other governments with significant agencies and supercomputers can't? They have a dual mandate and vast surveillance capabilities. I'm honestly not surprise at all by the behavior. I think the horrifying thing is people don't seem to care that this makes Government & Criminals equally dangerous to the security of our infrastructure. I'm just waiting for some massive, systemic compromise of a major bank from a combination of "NSA thinks they are the only ones with them" exploits as it seems like the only thing that would wake people up to the danger. Those two mandates are in conflict so they are playing the logic of: 1) We have vast surveillance capabilities, so we would be able to detect 0-days sent over a network we have visibility into. 2) We don't care if non-US assets get cracked and we have near perfect visibility into US assets. 3) We have a duty to perform offensive operations. So we should retain any weapon we believe our enemies are unaware of.
- tptacek 10y agoI don't think Schneier established that NSA does consider zero-days NOBUS. I think he's conflating things like Dual_EC, which are cryptographically protected NOBUS capabilities, with zero-day vulnerabilities.