3 ms·
Do you expect that Apple’s bigger security initiatives, like pointer authentication and writing the OS in a memory safe language, will improve the situation?
by meisel 2y ago
Do you expect that Apple’s bigger security initiatives, like pointer authentication and writing the OS in a memory safe language, will improve the situation?
- tptacek 2y agoAll these things increase attacker costs. In the current landscape, increasing attacker costs has the effect of shaking out some of the lower-rent players in the market, which may put some targets out of reach of lower-caliber threat actors. The problem you have over the medium term is that CNE is incredibly cost-effective, so much so that you need something like multiple-order-of-magnitude cost increases to materially change how often it's applied. The alternative to CNE is human intelligence; it competes with literal truck rolls. You can make exploits cost 10x as much and you're not even scraping the costs just in employee benefits for an alternate intelligence program. What that means is, unless you can foreclose on exploitation altogether, it's unlikely that you're going to disrupt the CNE supply chain for high-caliber state-level threat actors. Today, SOTA CNE stacks are probably available to the top IC/security agencies† of all of the top 100 GNP countries. It probably makes sense to think about countermeasures in terms of changing that to, like, the top 75 or 50 or something. I think we tend to overestimate how expensive it is for adversarial vendors to keep up with countermeasures. It's difficult at first, but everything is difficult at first; I vividly remember 20-30 extraordinarily smart people struggling back in 1995 to get a proof-of-concept x86 stack overflow working, and when I first saw a sneak preview of ROP exploitation I didn't really even believe it was plausible. As a general rule of thumb I think that by the time you've heard about an exploitation technique, it's broadly integrated into the toolchains of most CNE vendors. Further, remember that the exploit development techniques and people you've heard about are just the tip of the iceberg; you're mostly just hearing about work done by people who speak fluent English. † Reminder that customers for CNE vendors usually include many different agencies, invoiced separately, in the same governments.
- Jesus_piece 2y agoReminds me of the book “this is how they tell me the world ends” - a history on cyber weapons. It’s written from the perspective of a journalist without a comp sci background but delves deeply into the topic of how cyber weapons are procured, priced, and sold to multiple agencies in the same government. It’s unfortunate these are used for exploits and not for reporting bugs or vulnerabilities. Stockpiling exploits only makes everyone less safe
- tptacek 2y agoI mean, I agree, but also it doesn't matter than I agree, because wanting everyone to be altruistic --- no, to share the same notions of "altruism" that we do, since quite a few hypercapable exploit developers don't agree that their home states shouldn't have access to whatever signals intelligence they want --- won't make it so.