3 ms·
A unreported zero day is a de facto backdoor. The chain you mentioned has similar flaws as the current strategy. Step 3 would be incredibly difficult. It would
by lazy_gator 9y ago
A unreported zero day is a de facto backdoor. The chain you mentioned has similar flaws as the current strategy. Step 3 would be incredibly difficult. It would be similar to detecting a virus signature, which are easily circumvented. The second party can use trivial techniques to change the signature in a way that makes it incredibly difficult to detect.
Many 0-days are built of of multiple bugs. A triple letter may use bug #1 and bug #2 to get a result, but another party will use bug #1 and bug #3 to get a similar result. Back to square one with corporate/government/personal equipment getting hacked reducing overall security.
- acdha 9y ago> A unreported zero day is a de facto backdoor Traditionally the meaning of “backdoor” has involved intent as well as access. Unlike a basic bug, the system is working as designed but the designer wasn't trustworthy.
- willstrafach 9y ago> A unreported zero day is a de facto backdoor. This is not true. A backdoor indicates that Microsoft is aware of it (and/or colluded to put it in), but there is no evidence of that. I respect your disagreement with my thoughts on how they should handle 0-days, but re-defining "backdoor" does not seem helpful.
- lazy_gator 9y agoWe can debate the meaning of words, but the goal of a backdoor from the perspective of the government is to gain access to a system. The effect of a backdoor is accomplished through a literal backdoor or a figurative backdoor by hoarding exploits, which both are a detriment of security. By de facto, I was implying that they both accomplish the same things with almost the same list of pros and cons.
- willstrafach 9y agoWhen I worked on jailbreaking tools for iOS devices, we routinely held onto multiple 0-days, waiting for a major iOS release to ensure compatibility. While I know there may be reasons to disagree with that practice, I think it would be a major stretch to say that it meant iOS suddenly had a backdoor.
- lazy_gator 9y agoI agree that it is not a true backdoor, but I am simply pointing out that the goal is accomplished by hoarding 0-days or creating an actual backdoor. The 0-day you were not reporting gave you escalated access to iOS devices. If Apple had given you a backdoor, you would have had the exact same access to the device. Not saying its the same thing, which is why I used "de facto". The government just wants the access. Regardless the hole is intentional or unintentional, if a hole exists, then overall security is weakened