8 ms·
Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with
by DarkByte8 5y ago
Why is the FBI paying to get Pegasus? Doesn't the US have NSA to do this kind of hacks or find no click zero days in Android/iPhone and share the zero days with the FBI? Or why hasn't someone try to trick NSO to hack a monitored phone and find out the zero day? I am having these questions because every time I hear about NSO there is this question in my head "What is so special about NSO?". I see 2017, 2018, etc. how can someone have zero days for years and no one copy the zero day or fix the zero day? Why I don't hear about NSO competition? Does it have competition?
- trhway 5y agoPaying is the key. NSA doing it for FBI would generate no profit for anyone. Given various loopholes exploiting arrangements between allied security services, I'd not be surprised if NSA were a source of 0days for NSO.
- _kbh_ 5y agoI would 100% be surprised if NSO was being supplied with vulnerabilities from government agencies. If anything it is likely to be the other way around.
- ffhhj 5y ago> NSA were a source of 0days for NSO Not directly, NSA requests tech companies to slow down 0day research so they and others can exploid them.
- inter_netuser 5y agohow are you aware of that?
- 0a3feeb 5y agothe competition for NSO within the US would be traditional defense contractors: raytheon, l3harris, etc. One can make much more money with the DoD than the DoJ.
- JacobiX 5y agoI don’t think it’s a single or even a fixed collection of zero days, it’s an arms race that requires constant updates to the vulnerability catalog in order to be able to exploit the latest fully patched phones.
- petilon 5y agoBecause NSO is on a different level completely. Google engineers who analyzed NSA hacks found it to be "terrifying". See https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-into-nso-zero-click.html https://googleprojectzero.blogspot.com/2021/12/a-deep-dive-i...
- vsundar 5y agoWow, thanks for that link. That's incredible: > JBIG2 doesn't have scripting capabilities, but when combined with a vulnerability, it does have the ability to emulate circuits of arbitrary logic gates operating on arbitrary memory. So why not just use that to build your own computer architecture and script that!? That's exactly what this exploit does. Using over 70,000 segment commands defining logical bit operations, they define a small computer architecture with features such as registers and a full 64-bit adder and comparator which they use to search memory and perform arithmetic operations. It's not as fast as Javascript, but it's fundamentally computationally equivalent.
- astrange 5y agoThey say it's terrifying but this doesn't seem like an incredible advancement on any previous "weird machine" exploits. It's just nobody else has this problem to need to write a compiler like this.
- saagarjha 5y agoIndeed. It’s a fairly logical step in exploit development, and (while a significant amount of impressive work) not a particularly novel idea.
- Veserv 5y agoThe NSA does have an organization devoted to developing these sorts of attacks that make the NSO group look like a bunch of kindergarteners as evidenced by the Snowden leaks. The CIA also, independently of the NSA, has an organization that develops these sorts of attacks that make the NSO group also look like a bunch of kindergarteners as evidenced by the Vault 7 leaks. Almost without a doubt, the FBI, DHS, US Navy, US Army, and US Air Force all also have their own independent organizations that each make the NSO group looks like a bunch of kindergarteners given that developing a capability that makes NSO look like kindergarteners only costs on the order of ~$100M (i.e. less than a single jet fighter). There is absolutely nothing special about the NSO other than that they got caught and brought under the limelight. The most likely reasons the FBI paid for access to Pegasus are: 1. It is another tool that frankly does not cost very much if you are the FBI. 2. The part of the FBI that bought it likely does not have authorization or possibly even knowledge of the other tools and contracted with NSO to gain those capabilities at the cost of just some money. This is like how a developer team in large stodgy old mega corporation might not be able to get IT to setup their servers so they just get a budget that they spend on AWS to do an end-run around their own IT organization. The zero days are likely occasionally being discovered and fixed, but buying a zero-click zero day for Android/iPhone on the black market only costs on the order of $1-2M at retail. If you have your own competent team you can reasonably expect to find a zero-click zero day with only a few person-months of effort which, even at US wages, is only a few 100k per zero day. At those prices, you could keep a dozen or so stockpiled for less than the cost of starting a McDonalds franchise, so they likely did maintain a dozen or so at any one time, so if one was discovered they could just switch over to a different one and write off the old one as a cost of doing business. They absolutely do have competition. One high profile example is Hacking Team. In terms of overall competition, I do not have any hard information, but given the size of the vulnerability markets there are probably at least a couple dozen to a few hundred organizations similar in scope to the NSO group. We do not hear about them because they mostly sell to governments.
- rotrot 5y agoAs someone who has worked Vulnerability Research/Exploit Dev for US based companies I'd consider this a bit misguided and is likely coming from someone not in the Vulnerability Research/Exploit Dev industry. I'm guessing you're getting these numbers from just reading Zerodium: """ The zero days are likely occasionally being discovered and fixed, but buying a zero-click zero day for Android/iPhone on the black market only costs on the order of $1-2M at retail """ In reality the final packaged product is worth exponentially more. Also, Israel produces some of the best security research talent on the planet due to their national focus on cybersecurity, and funneling some of the most talented students in the country directly to 8200 starting in high school, and some of them end up going to NSO group after. None of the vulnerabilities/exploits in the Vault 7 leaks come close to the sophistication of the FORCEDENTRY exploit. I'm not saying the US doesn't have better capabilities and the NSA most certainly does because they have suppliers like Azimuth, but a lot of what you've stated is based in fantasy.
- upofadown 5y agoNSO doesn't ask to see your warrant...
- trasz 5y agoLaw enforcement is not NSA's job. They have no reason to help FBI here.