NSA Bought Exploit Service From VUPEN
New submitter Reverand Dave writes "The U.S. government – particularly the National Security Agency – is often regarded as having advanced offensive cybersecurity capabilities. But that doesn't mean that they're above bringing in a little outside help when it's needed. A newly public contract shows that the NSA last year bought a subscription to the zero-day service sold by French security firm VUPEN. The contract, made public through a Freedom of Information Act request by MuckRock, an open government project that publishes a variety of such documents, shows that the NSA bought VUPEN's services on Sept. 14, 2012. The NSA contract is for a one-year subscription to the company's 'binary analysis and exploits service.'"
It's not as conspiracy-theory cool as magical backdoors implanted in every piece of hardware, but this is how the NSA actually breaks into systems... they do it the same way everyone else does, just on a much larger scale and with even less fear of legal repercussions that the cyber criminals.
AntiFA: An abbreviation for Anti First Amendment.
I paid a visit to Northern Va a few weeks ago. The place was crawling with construction projects and high end malls.
That I am paying for.
Using Vupen actually sounds like a fairly efficient use of taxpayer money.
for the life of me I don't know why Cisco, Microsoft and other big players just don't pay up to get at least some insight into how these guys are finding exposures in their systems
I would assume that VUPEN would refuse to sell to Microsoft and Cisco on account of it diminishing the value of the zero-days they're holding.
Or at least not sell them the best stuff.
Obviously, if Cisco, Microsoft, etc. were going to buy this service, they wouldn't do it (only) as themselves, acting directly. They'd do it through a front, to insure they got the same things the bad guys were getting.
Just as a startup did, about a decade ago, when I was designing a next-generation routing chip, and we needed to obtain equipment from Cisco for testing it for function and compatibility.
It took two half-rack, 3/4 megabuck, top-of-the-line Cisco routers to drive it properly. We bought them through another company on a very hush-hush basis, just to be sure Cisco wouldn't be tempted to send us defective or gimmicked equipment, not support it properly, or hold up shipment and slip our schedule.
Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way