4 ms·
I've seen the invite-only marketplaces where these exploits are sold. You can buy an exploit to compromise any piece of software or hardware that you can imagin
by joshfraser 2y ago
I've seen the invite-only marketplaces where these exploits are sold. You can buy an exploit to compromise any piece of software or hardware that you can imagine. Many of them go for millions of dollars.
There are known exploits to get root access to every phone or laptop in the world. But researchers won't disclose these to the manufacturers when they can make millions of dollars selling them to governments. Governments won't disclose them because they want to use them to spy on their citizens and foreign adversaries.
The manufacturers prefer to fix these bugs, but aren't usually willing to pay as much as the nation states that are bidding. All they do is drive up the price. Worse, intelligence agencies like the NSA often pressure or incentivize major tech companies to keep zero-days unpatched for exploitation.
It's a really hard problem. There are a bunch of perverse incentives that are putting us all at risk.
- timewizard 2y ago> It's a really hard problem. Classify them as weapons of mass destruction. That's what they are. That's how they should be managed in a legal framework and how you completely remove any incentives around their sale and use.
- joshfraser 2y agoYes. Except our government is the largest buyer.
- Symbiote 2y agoThe USA has 5044 nuclear missiles, so that shouldn't be a problem.
- kingaillas 2y agoHow about some penalties for their creation? If NSA is discovering or buying, someone else is creating them (even if unintentionally). Otherwise corporations will be incentivized (even more than they are now) to pay minimal lip service to security - why bother investing beyond a token amount, enough to make PR claims when security inevitably fails - if there is effectively no penalty and secure programming eats into profits? Just shove all risk onto the legal system and government for investigation and clean up.
- tptacek 2y agoThat is never, ever going to happen, and they are nothing at all like NBC weapons.
- JumpCrisscross 2y ago> weapons of mass destruction. That's what they are Seriously HN? Your Netflix password being compromised is equivalent to thermonuclear war?
- aczerepinski 2y agoThink more along the lines of exploits that allow turning off a power grid, spinning a centrifuge too fast, or releasing a dam.
- JumpCrisscross 2y ago> exploits that allow turning off a power grid, spinning a centrifuge too fast, or releasing a dam By this definition trucks are WMDs because they, too, can blow up a dam. Hyperbolic comparisons undermine the speaker’s authority. Zero Days aren’t WMDs.
- Henchman21 2y agoSuddenly I felt like re-reading Ken Thompson’s essay Reflections on Trusting Trust. We’ve created such a house of cards. I hope when it all comes crashing down that the species survives.
- davisr 2y agoInstead of hoping, you can do a lot just by ditching your cell phone and using Debian stable.
- Henchman21 2y agoAh yes, switching from an iPhone to Debian is sure to… checks notes save the species from extinction. Apologies for the dismissive snark; perhaps you could provide me some examples of how this would help?
- tptacek 2y agoThe markets here are complicated and the terms on "million dollar" vulnerabilities are complicated and a lot of intuitive things, like the incentives for actors to "hoard" vulnerabilities, are complicated. We got Mark Dowd to record an episode with us to talk through a lot of this stuff (he had given a talk whose slides you can find floating around, long before) and I'd recommend it for people who are interested in how grey-market exploit chain acquisition actually works. https://securitycryptographywhatever.com/2024/06/24/mdowd/ https://securitycryptographywhatever.com/2024/06/24/mdowd/
- JumpCrisscross 2y ago> It's a really hard problem Hard problems are usually collective-action problems. This isn't one. It's a tragedy of the commons [1], the commons being our digital security. The simplest solution is a public body that buys and releases exploits. For a variety of reasons, this is a bad idea. The less-simple but, in my opinion, better model is an insurance model. Think: FDIC. Large device and software makers have to buy a policy, whose rate is based on number of devices or users in America multiplied by a fixed risk premium. The body is tasked with (a) paying out damages to cybersecurity victims, up to a cap and (b) buying exploits in a cost-sharing model, where the company for whom the exploit is being bought pays a flat co-pay and the fund pays the rest. Importantly, the companies don't decide which exploits get bought--the fund does. Throw in a border-adjustment tax for foreign devices and software and call it a tariff for MAGA points. [1] https://en.wikipedia.org/wiki/Tragedy_of_the_commons https://en.wikipedia.org/wiki/Tragedy_of_the_commons
- fluoridation 2y agoA tragedy of the commons occurs when multiple independent agents exploit a freely available but finite resource until it's completely depleted. Security isn't a resource that's consumed when a given action is performed, and you can never run out of security.
- JumpCrisscross 2y ago> Security isn't a resource that's consumed when a given action is performed, and you can never run out of security Security is in general non-excludable (vendors typically patch for everyone, not just the discoverer) and non-rival (me using a patch doesn't prevent you from using the patch): that makes it a public good [1]. Whether it can be depleted is irrelevant. (One can "run out" of security inasmuch as a stack becomes practically useless.) [1] http://www.econport.org/content/handbook/commonpool/cprtable.html http://www.econport.org/content/handbook/commonpool/cprtable...
- fluoridation 2y ago>Security is [...] a public good Yeah, sure. But that doesn't make it a resource. It's an abstract idea that we can have more or less of, not a raw physical quantity that can utilize directly, like space or fuel. And yes, it is relevant that it can't be depleted, because that's what the term "tragedy of the commons" refers to.
- westoque 2y agoreminds me of the anthropic claude jailbreak challenge which only pays around $10,000. if you drive the price up, i'm pretty sure you'll get some takers. incentives are not aligned.
- deleted 2y ago[deleted]
- Melatonic 2y agoMakes me wonder if there are engineers on the inside of some of these manufacturers intentionally hiding 0 days so that they can then go and sell them (or engineers placed there by companies who design 0 days)
- tptacek 2y agoPeople have been worrying about this for 15 years now, but there's not much evidence of it actually happening. One possible reason: knowing about a vulnerability is a relatively small amount of the work in providing customers with a working exploit chain, and an even smaller amount of the economically valuable labor. When you read about the prices "vulnerabilities" get on the grey market, you're really seeing an all-in price that includes value generated over time. Being an insider with source code access might get you a (diminishing, in 2025) edge on initial vulnerability discovery, but it's not helping you that much on actually building a reliable exploit, and it doesn't help you at all in maintaining that exploit.
- Edman274 2y agoAre we just straight up ignoring the Jia Tan xz exploit that happened 10 months ago that would've granted ssh access to the majority of servers running OpenSSH?, or does that not count for the purposes of this question, because that was an open source library rather than a hardware manufacturer?
- pvg 2y agoIs there any evidence the author of this backdoor was able to sell it to anyone, for any kind of money?
- skirge 2y agogood vulnerability / backdoor should be indistinguishable from programming mistake. Indirect call. Missing check on some bytes of encrypted material. Add some validation and you will have good item to sell no one else can find.