3 ms·
So, serious question: Why would they backdoor Windows, when apparently they could just buy an exploit for $X00k[1]? Its seems buying an exploit serves all thos
by skolor 12y ago
So, serious question:
Why would they backdoor Windows, when apparently they could just buy an exploit for $X00k[1]? Its seems buying an exploit serves all those same factors, at a similar price range, while making it much harder to point a finger at the NSA when it eventually gets discovered.
Its probably a safe assumption that if someone is found using a backdoor in Windows, its probably the US Government that put it there. If its an exploit, its a hell of a lot harder to point that finger at anyone in particular.
[1]: http://www.rand.org/pubs/research_reports/RR610.html http://www.rand.org/pubs/research_reports/RR610.html
- mynameisvlad 12y agoBingo, or even creating their own exploit and releasing it in a way that does not tie back to them. Realistically, a backdoor is the worst option for the NSA. A backdoor would be known by the people who implemented it, who, assuming it's a cooperative venture, would most likely be at the company itself. A backdoor would also be most likely living in the real codebase, able to be discovered by others, and, if somehow it leaks, it'll point directly at the NSA. An exploit does not live in the codebase, could be blamed on others, and will produce the same results.
- na85 12y agoExploits get fixed.
- philtar 12y agoYou talk like they're different things. This is something the Chinese do. Leave the backdoor as a vulnerability. Sure other people may find it, but that means they have access to it from the git-go (on another note, this should be how you initialize repos in git) That way when someone finds it, they could go "oops. thanks for pointing this vulnerability out for us. Will fix"
- skolor 12y agoThat gives you the worst of both worlds, though. You get the major developmental downside of a backdoor - making sure no one in the development pipeline finds and removes it - while still having to do the non-trivial work of actually exploiting the bug. Admittedly I don't have real experience with the 0-day black market, but the internet tells me I can just show up with $200k and buy a Chrome/Windows/iOS 0-day, if I know the right people. I find it hard to believe its actually cheaper or even easier to backdoor software than it is to just buy the exploits.