4 ms·
This is a great question. Surely they look for vulnerabilities also in their own systems but then what do they do when they find them? Is there some special set
by DickingAround 10y ago
This is a great question. Surely they look for vulnerabilities also in their own systems but then what do they do when they find them? Is there some special set of software that always gets patched because the CIA uses it?
- LyndsySimon 10y ago> Is there some special set of software that always gets patched because the CIA uses it? If so, a diff between the "CIA version" and the "civilian version" would be highly instructive.
- Godel_unicode 10y agoPresumably the same thing others do when they know about 0-days? Signatures.
- redblacktree 10y agoCould you explain a bit more? I'm not sure what you mean.
- Godel_unicode 10y agoSure, this is essentially the argument for disclosure of bugs before they've been patched. If I had known about e.g. shellshock before the patch was out, I could have written a Snort signature looking for it in network traffic and have my IPS drop the packets. I do this on my network with bugs I find before the vendor patches them. This is an example of security through defense in depth; patching is one layer of defense, but if you can't patch there are other mitigating actions you can take to protect against (especially) known threats. It allows someone with an offensive and defensive mission to simultaneously use exploits while not being vulnerable to them.