6 ms·
I hope this signals a turning point and lessons learned from the historic practice of hoarding exploits in the hopes they can be weaponized. when you disclose
by nimbius 2y ago
I hope this signals a turning point and lessons learned from the historic practice of hoarding exploits in the hopes they can be weaponized.
when you disclose vulnerabilities and exploits, you effectively take cannons off both sides of the metaphorical battle field. it actively makes society safer.
- toomuchtodo 2y agoGovernments who want power will hoard the knowledge, which is power. Other governments will share. This is perpetual tension: we collectively receive utility when good policy is active (rapid dissemination of vuln info), but we need third parties to seek these exploits out when government cannot be relied on. Very similar to the concept of journalism being the Fourth Estate imho. (vuln mgmt in finance is a component of my day gig)
- tptacek 2y agoThis is a little bit like talking about why they hoard the guns. The reason governments have caches of exploit chains is not hard to understand.
- toomuchtodo 2y agoYou're the expert, and certainly not wrong, I wrote my comment because I have had to explain this to folks in a professional capacity and thought it might be helpful.
- tptacek 2y agoIt's just a rhetoric thing. We're talking about the USG "hoarding" stuff, but, in a sense, the government has a conceptual monopoly on this kind of coercive capability. Anybody can find vulnerabilities and write exploits, but using them in anger and without mutual consent is an authority exclusively granted to law enforcement and intelligence agencies. This is just an extension of the "monopoly on violence". The longstanding objection to this is that secretly holding a gun doesn't intrinsically make everyone less safe, and there's a sense in which not disclosing a vulnerability does. That argument made more sense back in and before 2010; it doesn't make much sense now.
- DoctorOetker 2y agoIt is substantially different from hoarding guns: not hoarding exploits takes away those exploits from adversaries. If an important factor is the ratio of exploits A and B have, then publishing their hidden but common exploits the ratio does not remain the same. The ratio is interesting because potential exploitation rate is proportional zero days (once used, the "zero" day is revealed and remediated after a certain time span).
- thomastjeffery 2y agoYou can't hoard knowledge, just like you can't take it away.
- Xen9 2y agoOnly predictive capabilities & AI trained on data can be more valuable than having perfect profile of the person who turns out to be an enemy of your nation in whatever sense. Taking a person down once you know everyone they have ever talked, been interested about, or thought, is trivial. This can only be acheived by mass surveillance & hoarding. Arguably US as a nation state has the very best LLMs in the world, which is why I personally think they have been running weak AGI for few years, e.g. for autonomous malware analysis, reverse-engineering, and tailored malware generation & testing capability. Because they can actually store the personal data long term, without habing to delete it, this may be of gigantic strategic advantage due web being highly "polluted" after 2020-2021. I would from this guess US has bet on AI research since end of WWII, and especially within last 30 years, noting the rather highly remarkable possibility that Surveillance Capitalism is actually part of the nation's security effforts. The warehouses of data they have built are warehouses of gold, or rather, gold mixed in sand since of course lots of it is also garbage.
- Eisenstein 2y agoHas the US done anything that huge and kept it secret? The Manhattan project is the only one I can think of, and that involved sequestering the entirety of the nations top physicists, chemists, and metallurgists in the desert and employed 130,000 people. This was before the internet and during a time when Americans were unified in a war effort in a way that hasn't existed before or since.
- boringg 2y agoHuh? You absolutely can hoard knowledge and you can most certainly purge knowledge as well.
- axegon_ 2y agoI doubt it. Historically, most government agencies around the world have had appalling security and each iteration is just as bad as the previous with a few half-assed patches on top to cover the known holes.
- lenerdenator 2y agoI'd be surprised if the policy continues. Or if the people who worked at the agency are still there.
- burkaman 2y agoThey are not: https://techcrunch.com/2025/01/22/trump-administration-fires-members-of-cybersecurity-review-board-in-horribly-shortsighted-decision/ https://techcrunch.com/2025/01/22/trump-administration-fires... Also, not a joke, this program contains the word "equity" ("the Director of National Intelligence is required to annually report data related to the Vulnerabilities Equities Process") so it will probably be frozen or cancelled.
- vaccineai 2y ago[dead]
- dang 2y agoWe've banned this account for using HN primarily (exclusively?) for political/ideological/national battle. That's not allowed here, regardless of what you're battling for or against. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- spacephysics 2y agoMost likely these vulnerabilities were known by adversaries and they decided to report these to make it more difficult for those adversaries to attack. I’m sure the really juicy zero days they’ve discovered in-house are kept out of reports like these
- thewebguyd 2y agoThis is the most likely scenario. Its not like the government has decided they no longer need to hang on to zero days to use against adversaries. They've just determined these ones are either no longer useful to them, or adversaries have discovered and began using them.
- tptacek 2y agoIt literally is the scenario, as really the only outcome of the VEP (for serious, "marketable" vulnerabilities) is "disclose once burned".
- kevin_thibedeau 2y agoThe US depends on exploits being available for the companies it uses to circumvent the 4th amendment.
- stephen_g 2y agoThe problem is when they don't know that their adversaries know about those exploits... There's a lot of arrogance and hubris with the idea of NOBUS, and they often make things worse assuming only they know...
- downrightmike 2y agoProbably not, trump's first term he was all for allowing ransomware. And the only reason we started seeing a strategy for mitigating was because of Biden. Since trump is all in on crypto and the fact that russia is the main beneficiary of ransomware, I highly expect cybercrime to ramp up as the current admin is positioned to benefit directly.
- meowface 2y agoI might be a contrarian, but I think it makes sense for the NSA to hoard 0-days. They should disclose only after they burn them.
- thomastjeffery 2y agoYou can't actually hoard them, though. They aren't objects, they are knowledge. A 0-day is present in every instance of the software it can exploit.
- bluefirebrand 2y agoThis is a meaningless distinction imo You hoard knowledge by writing it down somewhere and then hoarding the places it's written down. Whether that's books, microfilm, hard drives, what have you
- thomastjeffery 2y agoYou can't stop someone else from writing it down. When you hoard something, your possession of that thing effectively takes access to that thing away from everyone else. You can't keep access to a vulnerability away from anyone!
- rozab 2y agoGreat, fantastic, awesome plan. https://en.wikipedia.org/wiki/The_Shadow_Brokers https://en.wikipedia.org/wiki/The_Shadow_Brokers
- honzaik 2y agoOK, hoarding discovered zero-days might not be the best strategy, BUT if we actually create a backdoor and don't tell anyone about it, then this should be safer right? right? /s https://www.wired.com/2015/12/researchers-solve-the-juniper-mystery-and-they-say-its-partially-the-nsas-fault/ https://www.wired.com/2015/12/researchers-solve-the-juniper-... https://en.wikipedia.org/wiki/Dual_EC_DRBG https://en.wikipedia.org/wiki/Dual_EC_DRBG https://en.wikipedia.org/wiki/Juniper_Networks#ScreenOS_Backdoor https://en.wikipedia.org/wiki/Juniper_Networks#ScreenOS_Back...
- edm0nd 2y agoAint no way. All major governments hoard 0days or buy them to use for espionage. I dont see this being some kind of "turning point" and more of a feel good easy PR win for the US gov but really they are still using many 0days to spy.
- thewebguyd 2y agoYeah, this is more like "these vulnerabilities are no longer useful to us" or "adversaries have discovered these and began using them, so here you go."
- ggernov 2y ago[flagged]
- tptacek 2y agoIt is not that turning point. These are VEP vulnerabilities. Like every major government, the US will continue to do online SIGINT.
- timewizard 2y agoThe lesson is not in vulnerability management. The lesson is that our desktop software is garbage and the vendors are not properly held to account.
- JumpCrisscross 2y ago> when you disclose vulnerabilities and exploits, you effectively take cannons off both sides of the metaphorical battle field. it actively makes society safer If I know you always disclose, and I find something you haven't disclosed, I know I have an edge. That incentivises using it because I know you can't retaliate in kind. The hoarding of vulns is a stability-instability paradox.
- Retr0id 2y agoHow would you ever know that someone always discloses, if you can't know what they don't disclose?
- JumpCrisscross 2y ago> How would you ever know that someone always discloses Same way you know if they don't have nukes. Based on what they say and your best guess.
- krisoft 2y agoYou can’t know (in the mathematical certainty sense) that they always disclose. But you can know if some entity has the policy of always disclosing. Those are two different things. A policy is about the intentions and the structure of the organisation. How they think about themselves, how they train their recruits and how they structure their operations. The first hint would be the agency stating that they have a policy of always disclosing. You would of course not believe that because you are a spy with trust issues. But then you would check and hear from all kind of projects and companies that they are receiving a steady stream of vulnerability reports from the agency. You could detect this by compromising the communications or individuals in the projects receiving the reports, or through simple industrial rumours. That would be the second hint. Then you would compromise people in the agency for further verification. (Because you are a spy agency. It is your job to have plants everywhere.) You would ask these people “so what do you do when you find a vulnerability?” And if the answer is “oh, we write a report to command and we sometimes never hear about it again” then you know that the stated policy is a lie. If they tell you “we are expected to email the vulnerable vendor as soon as possible, and then work with them to help them fix it, and we are often asked to verify that the fix is good” then you will start to think that the policy is actually genuine.