3 ms·
> [1]: https://opzero.ru/en/prices/ https://opzero.ru/en/prices/ Those are the prices that they are buying for, they do not indicate at all that these are comm
by SahAssar 11mo ago
> [1]: https://opzero.ru/en/prices/ https://opzero.ru/en/prices/
Those are the prices that they are buying for, they do not indicate at all that these are common or how large the market is for RCE on any OS.
> [2]: https://arstechnica.com/gadgets/2025/10/leaker-reveals-which-pixels-are-vulnerable-to-cellebrite-phone-hacking/ https://arstechnica.com/gadgets/2025/10/leaker-reveals-which...
Those are (mostly) not RCE, and are for consumer devices configured in a default way.
---
The parent stated that "Any government can get RCE on any OS with the change in their couch."
That implies that Kiribati currently could easily buy RCE on for example hardened Linux or OpenBSD running the most sensitive infra in the world. I just don't buy that, since if it was true any current conflict would look much different.
Of course there are security holes and major fuckups do happen, but not at the scale the parent implied.
- indolering 11mo agoThese prices are consistent (actually more costly) than public bounties by (now defunct) western based exploit brokers and manufacturer bounties. > Those are (mostly) not RCE, and are for consumer devices configured in a default way. I'm more worried about activists and journalists in developing counties without the financial means to afford flagship phones. But even Google can't manage to keep out a pedestrian mid sized security outfit selling to the cops and the FBI. When activists lobbying for a fucking sugar tax in Mexico get hacked, then the bar is too fucking low. Let's not talk about the nightmare that is old networking equipment or IoT devices.
- SahAssar 11mo agoCome on, you said: > Any government can get RCE on any OS with the change in their couch If you were extremely hyperbolic for effect that's fine, that's why I asked if you actually believed that, but what you are saying now is not at all arguing the same point.
- DANmode 11mo ago“Extremely hyperbolic”, or relative? $50k-$150k+ is a low-to-medium cost case to carry out for US law enforcement. or military. Much like the $3 in change you could dig out of your couch or car to get a small drink or sandwich.
- SahAssar 11mo agoNobody in this thread has provided anything that would lead me to believe that any government can easily buy RCE on any OS. Read the quote again: > Any government can get RCE on any OS with the change in their couch
- Veserv 11mo agoThat is inanely pedantic. The municipal government of Monowi, Nebraska probably can not buy a RCE in any OS as they only govern a single person. That is also utterly meaningless to argue as it bears no effect on the core thrust of the argument that COTS operating systems in use by military and critical infrastructure are easily and cheaply hackable by potential adversaries. They are demonstrably grossly inadequate for purpose.
- SahAssar 11mo agoAll my questions where with the assumption of a country-level government. I asked why, if this is so cheap, common and easy we do not see it used more. Even if we said that we restrict it to for example the G20 I still don't think they can easily and cheaply "RCE any OS".
- indolering 11mo agoWe do see it! Do you not remember the Snowden leaks? Shit hasn't changed much. We still have monolithic kernels written in portable assembly. Linus still doesn't tag bug fixes with potential security impacts as such because he is more worried about unpatched consumer garbage (which compromise all low end phones). When your mitigation for such problems is to not make it obvious, then your OS is not safe enough in safety critical settings (which includes consumer devices). Process isolation would downgrade the vast majority of critical Linux CVEs to availability bugs (crash a server but not compromise it). Just because governments don't need to reach for RCE everytime doesn't mean that it is safe. Th fact that such bugs are so cheap is an indication that your safety margin is too thin.
- indolering 11mo agoI was not being hyperbolic: a couple million dollars is very cheap for virtually any military. Both exploit broker bounties and corporate bug bounties are in that range. What is your objection?
- lossolo 11mo agoThis shouldn't be downvoted because it's stating facts. RCEs for critical infrastructure/OSes are very rare, they don't just grow on trees. I agree that OP exaggerated by saying that any government can buy whatever RCE they want and get access to any system they want, like buying candy in a candy shop. That's not reality.
- indolering 11mo agoThankfully, there are regulatory regimes that require physically segregated systems for most cars, airplanes, power stations, etc However, safety critical is not limited to cars: it also includes the phones of activities and journalists living under authoritarian regimes. Monolithic kernels written in portable assembly mean that such bugs DO grow on trees [1] and the lack backporting means they just drop to the ground: the poor are sold phones that may never receive a security update. So even sugar tax activists in Mexico are the target of spyware! We have seen the sophistication of these attacks ramp up as cryptocurrency has made them profitable and the North Koreans have made a killing exploiting these bugs. Maybe you are right and it is very difficult to find these bugs but that just means low demand is what is keeping the price down. But that's probably because there enough LPEs and known RCEs that they are not needed most of the time. [1]: https://www.cvedetails.com/vulnerability-list/vendor_id-33/Linux.html?page=1&cvssscoremin=9&order=1 https://www.cvedetails.com/vulnerability-list/vendor_id-33/L...