US Government Fears Another Explosion Of The Ransomware Plague It Helped Create
gizmodo.com
gizmodo.com
You can't just pour money in offensive capabilities of your intelligence agencies, as is currently done in most countries, and hope to "win". Your exploits and zero days will be stolen, your critical systems will be weaker (because you intentionally weakened them or didn't disclose vulnerabilities) and you simply can't control the weapons you created. Worst of all, the weapons developed by state actors will fall into the hands of ordinary criminals, which makes for an even more complicated world.
Lose one and you're SOL.
(https://boingboing.net/2017/05/13/heroism-through-domain-squ...)
If the NSA was actually forced to be liable for the damage of their hoarded 0-day's should they leak, that might have a bigger effect than any 'guidance' I would imagine politicians might pass in a law. I hate to suggest something that involves yet more lawyers, but its amazing how effective that can be to make people in charge do some serious risk-assessment analysis about what they hoard and for how long.
[1] https://www.congress.gov/bill/114th-congress/senate-bill/204...
I agree that this would definitely curb potential damage, but I'm not sure if this is exactly the right way to go about it. NSA is first and foremost an intelligence agency. What do you think the best policy is for maintaining an effective arsenal and maintaining "0day responsibility"?
Edit: I think I misread this and you're asking in the context of the NSA holding them. I still doubt there's a way to do it responsibly, so they probably shouldn't be doing it.
[2] https://www.mitnicksecurity.com/shopping/absolute-zero-day-e...
And some info on this market: https://en.wikipedia.org/wiki/Market_for_zero-day_exploits
I think the best policy is for them to not maintain an "effective arsenal" at all, the second they find a vulnerability they should report it.
Under centuries old law, all someone would have to prove to make the government liable is that the government (1) was the cause (2) of damage (3) that was the result of their negligence. The negligent part will be tricky, as the NSA was probably using the best tech available to protect their secrets. Also, proving #1 may be tricky as most of the information you would need to prove it is highly classified.
The NSA made the dangerous part of the weapon, and then they lost it. They knew they lost it, and didn't do enough to harden fed computers. The government isn't allowed to just randomly attack someone, but attacked my hypothetical person that can prove the attack vector anyway.
Of course, i'm not a lawyer.
Incorrect, with the exception of DOD (and even there it's shared with DISA).
> didn't do enough to harden fed computers.
Interesting statement considering there have so far been 0 cases of fed computers being exploited. That figure is from US-CERT, the entity actually responsible for defending Federal systems.
2) Indeed, my entire argument depends critically on the existence of a .gov propagating the worm.
I mean these things are pretty much why the NSA exists, it's kind of its mandate. It's not like their employees don't know they're really, really, really, really not supposed to leak their whole horde of zero days, or protect it to the utmost. these things weren't in a dropbox with the password "password123" or something...
what do you expect greater "liability" to do exactly? (Of course this is assuming the agency continues to exists, which you're kind of presupposing when you write "if the NSA were actually forced to be liable")
Edit:
Don't know why I'm getting downvoted...could you explain what changes to their operating procedured you would expect them to make, if they had greater liability?
We need the NSA just like we need a military. As an offensive cyberweapon, this exploit was operationally one of the most effective weapons that the NSA had at its disposal. Most of the world runs unpatched Windows systems, as Stuxnet showed us. This would've been the perfect tool for a similar operation.
Unless your stance is that computers should never be used by a state actor to intentionally cause harm, like the military, then you can't logically also hold the position that the NSA should voluntarily neuter its own arsenal.
I don't like it either. But the alternatives seem objectively worse.
That way of thinking is whats making us need cyber weapons. Not to mention it shapes foriegn policy.
CIA is attempting to clean up their mess
I think that it's unreasonable to expect there not to be some sort of acting technology strike force within the US government, on the sole basis that they wouldn't let themselves fall behind as a super power in this manner. For the sake of one-upmanship alone I imagine this is happening. But as to what it should be doing? That needs to be reviewed.
Cyber weapons aren't traditional weapons - cyber weapons are nigh-infinitely replicable, easier to lose control over, fast and easy to redistribute, and they're just as harmful to US civilian targets as they are to political/miiltary targets. They're unconventional warfare in that once you let it go, it's almost impossible to reel it back in, and the current state of technology just lends itself to so much collateral damage by the nature of software dependencies. A lot of places have no control over the dependencies for their mission critical software, and either no money for better alternatives or legitimately no alternative.
Cyber weapons are going to be a weird thing for a very long time, since they have the same uncontrollable nature that a lot of banned weapons have, but they don't have the same immediate impact or lasting effect [1] that munitions, chemicals, and so on have. The lack of an immediate real world impact (read: a 'boom' or something toxic) is going to make it a challenge for people to see how damaging this an really be.
[1] - I mark this because I think it's arguable how lasting the impact for any given bit of malware can be. There can be a lot of long-lasting damage if major infrastructure pieces are targeted, or downing entire networks, ruining small to medium businesses, and so on.
I wonder how the dialectic will play out in a worst-case scenario if we get to that point.
Does the NSA literally report to no one?
If the NSA didn't discover it, the world would be equally insecure. The fact that they weaponized it and then lost control of it is a secondary effect at best.
That we know of, it's entirely possible that other governments have been using the same exploit and that this could have been prevented with NSA disclosure.
It's been an escalating war of intrusion capabilities among nation-states for the past 20 years, and when some of those weapons are released into the wild, this is sometimes the result.
Do you think this president would? I don't think it terribly likely, and if I heard that he was about to, I'd probably start booting Linux for a few months, because I would wholeheartedly suspect that it did more than just patch effected systems.
The researchers involved are @zerosum0x0 and @JennaMagius on twitter. Their work has been impressive (including eliminating a 10 second delay in some of the exploit chain iirc) if you ask me.
Of course I don't disagree with the content of your post - it does appear that the release of a working exploit has driven the release of this malware, rather than the release of the MS patch, or a description of the vulnerability in general (such as within the CVE).
The Metasploit eternalblue module simply runs an interpreter for a long set of commands that send massive binary blobs over the wire in a particular sequence. To me this looks like a cleaned up WireShark trace rather than anything based on true understanding of what it really does. As far as I can tell the only people who understand what these packets are doing to Windows are TAO and probably one or two developers at Microsoft.
Smokescreen for your $N if you're a rogue agent selling your exploits to another organization - or simply claiming some part of the ransomware pie? Just because the NSA as an organization is paying the price, doesn't mean you as an individual agent are.
Of course, this requires the gumption to think you'll get away with it.