EFF Pries More Information on Zero Days from the Government
eff.org
eff.org
It's a much bigger problem for Fight For The Future, which seems to be fueled entirely by melodrama.
Part of the reason, I think, is that EFF has much better on-staff technical (in the conventional sense and the legal sense) expertise than FFTF does.
EFF does get really dodgy in their pure advocacy pieces (these are the "Your Rights Online" stories where EFF doesn't have much to do with the story). They're better in stories where they have a direct role.
Also, at some point, I think integrity demands reasonable language even if hyperbole is effective. It ends up being a variation on clickbait.
Even the tiniest improvement is always hailed as this massive victory.
In fairness, this is something many political groups are prone to.
We must operate under the assumption that if "a good guy" has discovered a vulnerability in a product then "a bad guy" will also find it before long. That "before long" part is really just an assumption based on the best-case scenario: No one else has discovered the vulnerability yet.
Even if the vendor has no fix available disclosure is still of the utmost importance because it gives the public at large a fighting chance at remediating the problem; whether the vendor is ready or not!
Example: If a critical vulnerability is discovered in Nginx and the developers can't put out a release any time soon I can always switch to Apache or some other web server. How "entrenched" or "locked in" you are with a product is neither here nor there. That's your own damned fault if you can't swap it out with something else. Especially if you knew you were locked in ahead of time and have yet to do anything about it.
Today, we have to operate under the assumption that if a good guy has discovered a vulnerability, a bad guy is probably already exploiting it.
Full, immediate, public disclosure is also reasonable.
Switching Nginx out in your infrastructure (for instance) isn't a simple trick at scale when you have a heavily customized install. (e.g. OpenResty with routing code)
That is exactly what the newly unredacted VEP the EFF is writing about says: agencies discover vulnerabilities and report them to an internal clearinghouse. That may or may not result in alerts to vendors.
Reporting to vendors remains a solid way of killing vulnerabilities, so long as researchers are aggressive about it (the 60-90 day open publication window seems to do the trick).
(This is my field).
I'd be surprised if USG didn't have access to pretty much every important feed like that. This gives every notified party at least a few days to act. (defence or otherwise)
Right, and what little it has to do with reporting to vendors is this: If you want to throw a wrench in the surveillance apparatus, instead of selling privately, disclose to the vendor to spite the government.
But that's not to say that reporting a vulnerability to MITRE/CERT is going to land a 0day in the hands of the NSA. (But on the other hand, if you're lucky, you might kill a vector they were already using.)
Knowing what we do just from the Snowden disclosures, monitoring those aliases is exactly the type of thing I would expect them to do. Even if they only get 60-90 days before a vulnerability is "killed", that still leaves them a fair amount of time to utilize them against their targets.
I super-duper don't care if you alert vendors before telling the public about a vulnerability. I think "responsible disclosure" is doublespeak, and I've generally supported direct- to- the- public disclosures for my whole career; I've written some articles justifying it (for instance: even if there's no patch, people can simply stop using the vulnerable software).
But giving vendors a heads-up is at least neighborly (to the vendor) and, increasingly, a sign of professionalism, and "the NSA will get my bugs" is not a good reason not to do it.