7 ms·
NSO is clearly in the business of selling surveillance to foreign entities, and saying they vet people is nothing but smoke as there is zero actual evidence oth
by coldcode 5y ago
NSO is clearly in the business of selling surveillance to foreign entities, and saying they vet people is nothing but smoke as there is zero actual evidence other than their blanket statements. If some government or other customer tells them they only attack terrorists, it's clearly easy to target anyone; how would NSO even know.
Also rather stupid was Apple's statement about their phones being secure, when its obvious there are zero days being sold to NSO instead of telling Apple. Everything is insecure these days, at some level.
If NSO paid people $1M for a zero day (I bet they don't say), and Apple/Google/etc paid $10K, who do you think gets the info.
- netsec_burn 5y agoIt's not that cut and dry, ethics and legality are a concern for a lot of researchers such as myself that sell zerodays. In my experience the actual price difference between unethical and ethical outlets is up to 4x, not two orders of magnitude (10K vs 1M?). I can't speak for everyone of course, but even the other researchers I know refuse to sell to unethical buyers, money isn't a factor.
- fossuser 5y agoThanks for being one of the good guys.
- deleted 5y ago[deleted]
- zrth 5y agoCan you give me a feeling for wat ethical buyers would be. I'd assume bug bounties and ZDI and similar. What else?
- netsec_burn 5y agoFirst and foremost, the original vendor is always the most ethical place to sell it. That's where you stand the best chance of having it fixed for affected users. Second to the vendor are third parties that report vulnerabilities to the vendor by selling early warnings as a service. I don't know if I would recommend ZDI, they provide zero guidance for what their payout ranges are. There are security companies that purchase zerodays to write about them for PR, which also fixes the issue. And finally there's selling it to branches of the US government with license restrictions and a blanket exclusion for the NSA. Beyond those buyers, the lines start to blur (defense contractors, companies in countries allied with the US e.g. FVEY). I would not recommend it either. Unethical buyers have completely different interests. I know Zerodium for one is a terrible place to sell to (you may be a target), and anything that is sold to Crowdfense is likely to be used against American interests. My take away advice is, you can choose between painting a target on your front or one on your back.
- Aulig 5y agoWho do companies like ZDI sell early warnings to? I don't quite understand how a vulnerability could be worth more to them than the vendor who could fix it (assuming they don't somehow abuse the vulnerability).
- dannyw 5y agoBecause ZDI negotiate. As a bug bounty participant in the official programs, you aren't allowed to negotiate. ZDI, on the other hand can say: "We want $10M for this iOS zero day, or we don't report it to you." And the process of negotiation goes back and forth, but the end result is, Apple will pay considerably more to ZDI than through the direct program.
- zrth 5y agoCorrect me if i am wrong. I think another reason why ZDI maybe could pay more is because they also have other paying customers that pay for IDS/IPS subscription.
- zrth 5y agoWhen you say "one could be targeted/painting an target on one self" what does this imply? Basically that some group, most likely a nation state actor might hack my systems in the hope to see what else i have and who i am selling to? Or rather that when i cross the wrong broader in to the wrong country that i might disappear?
- sudosysgen 5y agoYou can almost assuredly sell exploits illegally/unethically for a serious amount if you have the right connections. We know that iOS zerodays have sold north of 2 million $.
- edoceo 5y agoI don't know that. I can't find anything on G or DDG - can you point me towards some data/links?
- sudosysgen 5y agohttps://www.wired.com/2015/11/hackers-claim-million-dollar-bounty-for-ios-attack/ https://www.wired.com/2015/11/hackers-claim-million-dollar-b... https://arstechnica.com/information-technology/2019/01/zeroday-exploit-prices-continue-to-soar-especially-for-ios-and-messaging-apps/ https://arstechnica.com/information-technology/2019/01/zerod... https://zerodium.com/program.html https://zerodium.com/program.html [see iOS 0-click FCP]
- edoceo 5y agoThank you! Summary: Wired report is a $1M and Ars reports three, one at $2.5M - all paid by Zerodium. Wow.
- dannyw 5y agoIf you have a iOS/iCloud/Google 0day, you will absolutely fetch tens of millions from it assuming it's the real deal (reliable, etc). Google, on the other hand, regularly pays white-hats something like $100k for "arbitrary access to contents of any Gmail content".
- zepto 5y ago> Also rather stupid was Apple's statement about their phones being secure Apple has never made such a statement.
- commoner 5y ago> Apple has never made such a statement. From the article: > Apple said: “Security researchers agree iPhone is the safest, most secure consumer mobile device on the market.”
- zepto 5y agoExactly. It says nothing about their phones being secure. Only that they are more secure than their competitors.
- commoner 5y agoThat's a stretch.
- zepto 5y agoNo, it’s what they said. Saying they claimed their phones to be secure is just a lie.
- commoner 5y agoIt's a stretch to argue that "safest, most secure consumer mobile device on the market" is not a claim of security. The average reader would not interpret that statement as you did, which makes the statement misleading.
- zepto 5y ago> is not a claim of security. It is a claim of relative security but it is a lie to say that Apple claimed their device is secure. >The average reader would not interpret that statement as you did I think most people can read the statement for what it is - a comparison to other devices on the market.
- cblconfederate 5y agoPart of their vetted list: Azerbaijan, Bahrain, Kazakhstan, Morocco, Rwanda, Saudi Arabia, United Arab Emirates It's as if they are vetting for the most authoritarian, human-rights-abusing, anti-free-press countries in the list. A peculiar vetting process indeed
- Leparamour 5y agoTheir vetting process probably goes like this: Question: How would you solve the Trolley problem? Answer: By using more trolleys.
- pessimizer 5y agoThose are US and UK allies you're talking about.
- cblconfederate 5y agoKazakhstan? Also, why does that matter
- NMDaniel 5y agoThis isn't very different from the West selling guns, tanks and police equipment to allied 3rd world countries. You hope they'll be used for good causes(preventing crime and terrorism) but knowing that these governments tend to be corrupt, you acknowledge the risk that these weapons will be used by bad elements too.