5 ms·
Anyone else notice this: "We realized there was another actor [South Korea] that was also going against them [North Korea] and having great success because of
by sandworm 12y ago
Anyone else notice this:
"We realized there was another actor [South Korea] that was also going against them [North Korea] and having great success because of a 0 day they wrote. We got the 0 day out of passive and were able to re-purpose it. Big win."
NSA learned of a 0-day exploit being used by South Korea (not five eyes) and re-purposed it. They had knowledge of an exploit in the wild. Did they share this with anyone in order to close this security flaw? They exploited it. This is not a case of the NSA developing an exploit in house. They took this from the wild. This would seem to confirm suspicions that NSA is/was willing to allow active 0-days to fester, leaving the general public exposed.
- redstripe 12y agoAre you suggesting the NSA should be a government funded QA department for large corps and open source? For commercial software the companies who are not finding these bugs on their own are to blame. For open source, the cheapskates who mooch free software without contributing are too blame.
- sandworm 12y agoYes and no. They are tasked with protecting national security assets within the US, most of which rely on commercial systems. When they find a dangerous flaw in those systems, especially one loose in the wild, they are to help fix it. To not fix it is to leave US systems at risk. "in almost all instances, for widely used code, it is in the national interest to eliminate software vulnerabilities rather than to use them for US intelligence collection" ( quote from the 2013 panel report, not wired.) http://www.wired.com/wp-content/uploads/2014/04/White-House-NSA-Panel-Report-2013.pdf http://www.wired.com/wp-content/uploads/2014/04/White-House-...
- csandreasen 12y agoNot all 0-days affect national security assets. Heck, I'm sure there's plenty of software out in the world that isn't even used in the US at all.
- higherpurpose 12y agoNSA, no. But a non-NSA influenced USG, or some other new agency that should be in charge of cyber-security and not cyber-war (like NSA is) should be responsible for that. Developing strong security policies, finding about loopholes, and then nagging companies and government about fixing those loopholes and implementing those strong security policies (such as: "Go enable HTTPS for your site already god damn it, EPA!!"). NSA doesnt do anything like that right now, yet they keep yelling from the rooftops about "cyber security". The NSA should have absolutely no relationship with this agency. If NSA finds out about some "catastrophic" loophole, then they should disclose it to multiple agencies at the same time, including this new cybersecurity agency, and should have no "special" relationship with it. Also this new agency should be a civil agency, not a military or a spy one. NSA is and has always been a "war-time" agency, even if it has been used for non-war purposes (in my opinion wrongfully). Security is in most cases not about war. So why do we let a war-time agency try to militarize the Internet and treat it as a battleground, with everyone's computers as collateral damage, even if there's no immediate danger of "war"?
- cyphunk 12y agoNo, except the NSA/WhiteHouse has themselves said they would be the QA dept for corps. http://icontherecord.tumblr.com/post/82416436703/statement-on-bloomberg-news-story-that-nsa-knew http://icontherecord.tumblr.com/post/82416436703/statement-o...
- meowface 12y agoWell, it depends on how the exploit was being used and who was being targeted. If SK was only using it to target, say, Iran and NK, then it would not be in the NSA's interest to disclose the exploit to anyone. Only if they had reason to believe it could be targeting Five Eyes governments or corporations would they feel any need to.