Kevin Mitnick Now Selling Zero-Day Exploits
wired.com
wired.com
1) It would result in more vulnerabilities found
This is fairly axiomatic. An open market increases the price of vulnerabilities which in turn increases the number of vulnerabilities found (unless you want to argue the ability to find vulnerabilities is inelastic for some reason).
2) It would result in more vulnerabilities being disclosed to the proper authorities rather than malicious parties
This is more debatable, but since there should always be significantly more incentive on good actors to prevent the exploit (i.e. the software creators and/or community) than bad actors, the good actors should always win the bid. Indeed, one could argue that it is only the prevention of free negotiation in the sale of vulnerabilities is the reason an exploit is ever sold to bad actors (e.g. if I found a Windows vulnerability and told Microsoft $10m or else, I'm a criminal).
3) It would ultimately increase the quality of software
Given more vulnerabilities are found and more vulnerabilities would be disclosed to good actors, the quality of software increases.
I believe that 2) is essentially the Coase theorem (http://en.wikipedia.org/wiki/Coase_theorem), but I am only an arm-chair economist. Also, I'm not sure that what Mitnick is doing actually is a free and open market for vulnerabilities.
Imagine he had said: I believe a free and open market for weapons would be a good thing, because it would reduce the number of defenseless people, would result in a power imbalance that puts generally-okay actors at an advantage (say what you will, but the mob doesn't have 1% of the resources the US government does), and would therefore reduce crime.
I do not personally find that argument compelling (and it is of identical structure to the above), but me disagreeing with it does not mean it isn't of sufficient quality for Hacker News.
Perhaps restricting the analogy to nuclear weapons would make sense. Only nation states (software companies) and terrorists (malicious hackers... and perhaps intelligence agencies) would be interested in purchasing such weapons.
My thought is: if one argument is good and another is bad, clearly the reason for the difference does not exist within the properties they share. It must exist where the arguments are different, or more likely in this case (as what the poster said and what I said are so similar), in the outside world of facts and understanding.
But if the shape of the argument allows for things that may successfully convince you, then clearly that information is not enough to dismiss it outright. It should be the start of a dialog with the parent comment.
Now, for something completely different:
If, for some reason, you want to actually engage _me_ on this particular policy issue, angle your thought at this: my understanding is that it's 2014, and if you want to regulate the information people share or sell over the internet you've accepted a challenge I do not envy.
I would be particularly skeptical you could do this without building a comprehensive computer spying system and perhaps outlawing crypto (it's been tried), as you're trying to read communications of highly security-conscious people.
As for if Mitnick is a good person (or similar things under discussion here), I have not met him.
Replacing "vulnerabilities" with "firearms" while retaining the same argument structure does not mean that both arguments are logically identical (a false equivalency). The implications of a free market for information security and a free market for firearms are totally different.
If you cared a lot about Internet Points, I'm betting keeping a sockpuppet acccount just to post "why was [master]'s post downvoted?" comments would be one of the highest-ROI things you could do to get more of them.
I should also note that I've seen a lot of early-greyed posts come back from the dead after 30 minutes or so even without the "omgwtfisgoingon" posts underneath them as well. Sometimes even becoming clear winners on their strata of the post's comments.
You prompt a fascinating hypothetical: suppose all the world's atomic weapons were put up in a free, transparent auction? (i.e. bidders and bids are disclosed)
I'd argue that most would end up in the hands of good actors (e.g. the world bands behind the Dalai Lama to buy and destroy them all), but who knows? Good debate topic for happy hour, though.
[1] As a case in point, I showed the headline of the email for the bash vulnerability to a coworker today on the commute and he instantly described in accurate detail how it probably works. Not that this was a particularly difficult case, but I think the principle holds.
Wait a second...won't increasing the number of vulnerabilities found push prices down? If I'm looking to penetrate a system I only need to buy one vulnerability, so in effect different vulnerabilities are somewhat fungible and so should compete on price. Hence, if more vulnerabilities are being found and coming to market, prices should be going down.
On the other hand, with a free and open market for vulnerabilities there would likely be people who would NOT have bought vulnerabilities on the black market buying vulnerabilities on the safer, easier to use free and open market, so demand could go up, raising prices.
That's impossible to tell. You could just as easily say that the price will crash when you take away all the costs and risk of running a black market and give buyers a place to compare multiple "products." The demand side could just as easily be inelastic (or at least saturated) as the supply.
> the good actors should always win the bid
This works if you're talking about Microsoft, but not if you're talking about smaller companies or open source products. Maybe a Google or a Facebook would step up and pay off the market for things that they use, but "the rich people will take care of us" is not a setup that I'm comfortable with.
In the complaints about auctioning off vulnerabilities it's hard to avoid hearing companies bitching that they may have to pay security researchers, and it will be harder to intimidate them with law enforcement.
Our only proper response is secure software development practices, employment of security reseachers, and adoption of security-centric practices in critical systems... such as the Linux kernel. Which is embarassingly not the case at the moment. For ex: http://unix.stackexchange.com/questions/59020/why-are-the-gr...
Especially if we think of small software companies or open-source projects (like OpenSSL) who cant afford to pay hundreds of thousands of dollars to secure their own exploit.
On your overall point... I think this issue of selling 0days is more a debate of ethics, and I don't think economics can solve a problem of ethics.
What's your logic behind this? I believe this to be false. To my knowledge the black market commands artificially high prices on illicit goods as a rule, except when the good is available on the open market. See:
1) The goods are stolen and need to be unloaded quickly.
2) Open market prices are artificially high thanks to things like taxes (example: alcohol, cigarettes)
Mitnick served five years in prison—four and a half years pre-trial and
eight months in solitary confinement—because, according to Mitnick, law
enforcement officials convinced a judge that he had the ability to "start a
nuclear war by whistling into a pay phone", meaning that law enforcement
told the judge that he could somehow dial into the NORAD modem via a
payphone from prison and communicate with the modem by whistling to launch
nuclear missiles. He was released on January 21, 2000. During his
supervised release, which ended on January 21, 2003, he was initially
forbidden to use any communications technology other than a landline
telephone. [1]
He committed a series of crimes, and prison was appropriate. Solitary confinement, however, was not.The comment section of this post has an underlying anger towards the hi-jacking of the word 'hacker' as it was and is applied to kevin mitnik and thus misunderstood by the public waaaaay too often.
For what it's worth, I really enjoyed Zalewski's book. He seems like a really smart guy.
[0] http://www.amazon.com/The-Art-Deception-Controlling-Security...
Calling them a criminal does not necessarily invoke [2]
[1] a person charged with and convicted of crime
[2] a person who commits crimes for a living
Lawyers have power, Doctors have power, Hackers have power.
There is nothing libertarian about the defense industry or their actors. Unless you mistake neo-liberalism as libertarianism as far too many people do.
(Legitimate) governments generally are the only legitimate users of 0-days. Governments can legitimately and legally hack into your computer; nobody else can. Governments can legitimately and legally shoot you, but generally nobody else can.
One definition of government is that they have a monopoly on violence.
(I say "generally" above because there are exceptions, of course.)
The alternative to free markets isn't "no markets" or some flowery hippie ideal world. It's mafia and black/dark markets operating in complete or partial secrecy.
The Finnish software house Reaktor recently invited Mr. Mitnick as a "keynote speaker" into their popular event for software developers:
To be honest, I didn't understand the relevance at all. The idolization seemed quite childish.
and
> The rise of libertarianism in geekdom seems to fall under the same dynamic.
I can agree to the first, the second can be simply attributed to an understanding of the first. It is unfortunate that you don't see the connection.
The corruption of traditional causes and activism is what leads people toward libertarianism.
Wow, he hacked into some corporation's computers, that's just so awful. Pacific Bell - a shady monopoly who is granted a monopoly by the government, and in return showers politicians with bribes, I mean donations, and sends our calls and web history off to the NSA for monitoring and permanent storage.
> in reality, the rebels and the intellectually vain are easily co-opted politically
In reality, he has been doing security consultations for corporations, so he has already been co-opted. "The service has offered to sell corporate and government clients high-end 'zero-day' exploits". That doesn't really smell of rebel. Of course, everyone has to grow up and make a living.
I can think of a number of IT companies that were founded in the past 20 years, sold for billions of dollars, or worth billions or even hundreds of billions of dollars, that were founded by ex-hackers, or at least people very associated with the hacker scene and whose first technical hires were ex-hackers. It's mentioned in the tech press, in interviews, in blogs etc. It's easy enough to look up if you want to. I mean, one of YC's founders is rtm, and he was around back in Viaweb days.
It's difficult for me to perceive of a modern working class kid interested in technology today, it seems he has more resources at his disposable (although not many - a dinky Vic 20 booted people right into a programming environment, whereas a kid with an iPad and iPhone today would find it very difficult to program his own device - it is pretty much that definition of an embedded system of a device that can't program itself). Back in the 1980's a working class kid with a Vic 20 and 300 baud modem could only call people locally, call local BBS's, and be stuck with poor computing power.
If he hacked and phreaked, he could call around the country, access teleconferences, call BBS's around the country, access powerful Unix, Vax/VMS etc. systems, access the Internet, access x.25 networks and x.25 chat networks in Europe etc. He could follow the law and accept his straitjacket of being designated by the Relations of Production to be one who works a menial job, and for the privilege of being allowed to work he can kick up his expropriated surplus labor work time to the idle class job creator heirs who own his company. Or he can bend the rules, see new vistas, and somewhere down the line maybe co-found a billion dollar company, or a hundred billion dollar company. Then he, or his apologists like you, can then go around complaining about the kids hacking into his company's computers.
I wonder if money could be made selling 'Fuck Kevin' shirts and bumper stickers now.
Incidentally, Fuck Kevin.
*consensually.
Wow what a first class dick. He's implying that he will be glad to sell zero days to the government to illegally monitor ACLU activities (e.g. free speech, etc.)?
A glorified reseller and scumbag. Pathetic.
In the case of patent trolls, they're leveraging asymmetries in the legal system and flaws in intellectual property laws to profit from non-meritorious lawsuits.
To the extent that a market in zero-day vulnerabilities is something you want to have (I'm not sure where I stand on this, exactly), a firm with a reputation to maintain does have a role to play. They sell the exploit to Mitnick, who has an idea of which ones he'll be able to sell, and the companies buying them are able to avoid the transaction costs and risks associated with buying and then testing potential zero-day vulnerabilities submitted by arbitrary hackers and counterparties. He's playing a valuable role by mitigating risk for both the companies he approaches and the random hackers. Consider also that it's hit-or-miss when you try to contact a company about zero-day vulnerabilities whether or not they are going to pay you, ignore you or, worse, sue you. Knowing Mitnick doesn't sue people who submit bugs to him, and presumably he has lawyers vetting this operation carefully, is a significant benefit for bug-finders.
I don't agree with the attitude and sale of vulnerabilities, but if someone approaches the vendor and get the responses "this is not a vulnerability" or "why are you hacking our software, we're calling the authorities" this is where it ends up...
I don't know what to do about it, either.
About the best I can come up with is to support software that I feel makes the best effort they can to defend against exploits.
/smirk
"Researchers find them, they sell them to us for X, we sell them to clients for Y and make the margin in between."
Can anyone shed light on these "researchers" and how they sell their exploits now? Or is this just a friendly way of saying "we pay hackers for exploits and then blackmail vendors"?
I can't say I like the money-for-exploits thing, but one good thing is that it's made most companies be very nice to people to want to voluntarily report bugs. Silver lining and all that.
Either way, an exploit market is a grimy business, basically war profiteering. I wonder who is off-limits to sell to - certainly the Iranians, but who else, and who decides who is evil and who is good? People will die from some of these sales.
I think we'll see pervasive encryption and P2P (blockchain-based) applications that will push back tyranny a bit. There will be technological solutions to things like secret legal proceedings and warrantless wiretaps. And by pushing computation back out to decentralized nodes, there won't be such juicy targets to attack.
Governments define legality, and governments are likely to be some of Mitnick's best clients. Funny thing is, if I were Iran's government I would be concerned about buying exploits there because for all I know Mitnick has double-crossed me and given the US government info on the exploit and how to neutralize or detect it.
Pervasive encryption only helps if the endpoints doing the encryption aren't compromised, and this type of service is aimed at those endpoints.
* We need less endpoints in general. You can imagine a blockchain-based encrypted email system, which could not be tapped, pen-registered, and the government would have to issue a subpoena to actual users to see data.
EDIT: I realize he's been trading on his name for a while now but I was cool with it when he was a "white hat".
Who says it's the same people? Because it's people on the same site?
If you treat the commenters here as a single entity you'll really hurt your head trying to make sense of the HN consensus. There often isn't one because so much of this boils down to opinions about and attitudes towards governments, economics, personal responsibility, corporate responsibility, and laws.
The difference is that most of those people are not calling for any government interference. Otherwise that would be humorous given that governments and their no-trace-back shell companies are the largest clients. They simply disagree ethically through free speech.
I know he didn't find them himself. The boy can't code.
Sounds like Mitnick is well ahead of Gonzalez, there.
It's going to bring way way way more detriment than it is benefit, especially if his clients start looking at using semi-legal tactics to protect their investments.
"Pay us for all your secret vulnerabilities or we'll sell them to the highest bidder".
Don't get me wrong, im sure hes a nice guy. But he hasn't demonstrated anything useful for 20+ years and it seems he is mainly making a living writing vague non-technical h4ax0r books and giving interviews. Hell, i think he cant even code.
I wonder if maybe that has occurred to anyone.
Is the ACLU of all groups really interested in stopping/censoring people from sharing ideas?
To respond to your point more broadly, the ACLU has done excellent work on many Internet issues, and has represented me in court on multiple occasions. But it is not a monolithic entity, its board members do not always make the decisions you and I might prefer, and it does not always come down on the free speech side of an issue: http://www.volokh.com/2011/04/27/harvey-silverglate-on-the-a...
There are plenty of things in business that can be seen as unconscionable from the outside. I find more business practices disgusting than the general consensus of Hacker News threads, I'm kind of amused that selling exploits is one of the places where a line seems to be forming.
The relaxed ethics of the general consensus of the Hacker News threads is probably due to the lack of information rather than people here having questionable morals, or so I'd like to believe :).
We shall have wait and see how that works out for him.
All of you who don't produce 0 day: You don't get to have a say. Your opinion doesn't matter and you don't get a seat at the table, not even as an observer.
And now back to telling other people what to do with their work product...