Slashdot Mirror


NSA Uses Vulnerabilities Before It Discloses Them, Keeps Some To Itself (reuters.com)

An anonymous reader writes: The NSA, perhaps seeking to repair its reputation, has started talking about how it handles vulnerabilities in computer software. But in doing so, they've only confirmed their own questionable behavior. The agency says it discloses zero-day flaws about 91% of the time. This means, of course, that they hold back about 9% of the flaws for their own use. They also don't mention when they disclose these flaws — which is damning, given statements from several current and former government officials indicating the NSA frequently waits and takes advantage of the vulnerabilities before notifying the companies who make the compromised software. This is the NSA's argument: "[T]here are legitimate pros and cons to the decision to disclose vulnerabilities, and the trade-offs between prompt disclosure and withholding knowledge of some vulnerabilities for a limited time can have significant consequences. Disclosing a vulnerability can mean that we forgo an opportunity to collect crucial foreign intelligence that could thwart a terrorist attack, stop the theft of our nation's intellectual property, or discover even more dangerous vulnerabilities that are being used to exploit our networks."

121 comments

  1. Same as Jailbreaking iPhones by sanf780 · · Score: 2

    You want to keep some vulnerabilities for yourself just in case. You never know what will happen in the future.

    1. Re: Same as Jailbreaking iPhones by ememisya · · Score: 0

      They're not so bad, once you get to know them.

    2. Re: Same as Jailbreaking iPhones by mrclevesque · · Score: 1

      : )

    3. Re: Same as Jailbreaking iPhones by davester666 · · Score: 1

      It's just a little anal probing. You probably won't even notice...much.

      --
      Sleep your way to a whiter smile...date a dentist!
    4. Re: Same as Jailbreaking iPhones by JustAnotherOldGuy · · Score: 1

      It's just a little anal probing.

      As long as it's just a little. Because after what the IRS has done to me, "just a little" sounds downright neighborly.

      --
      Just cruising through this digital world at 33 1/3 rpm...
    5. Re: Same as Jailbreaking iPhones by ememisya · · Score: 1

      Troll? Funny, sure, but I think it's trolling to consider my comment trolling.

  2. Biased summary by GlobalEcho · · Score: 3, Insightful

    ...confirmed their own questionable behavior...

    I am a US citizen as frustrated about unauthorized domestic surveillance as anyone. But this summary goes too far. Finding, keeping and using vulnerabilities is exactly what the NSA is supposed to do, and there is nothing questionable about that behavior.
    If the submitter wants the government to have a group that finds and discloses vulnerabilities as part of its remit, then make a case for creating such a group. Don't saddle the NSA with the job.

    1. Re:Biased summary by Anonymous Coward · · Score: 2, Insightful

      Wrong the NSA's goal is surveillance, the DISA (Defense Information Systems Agency) is digital security. That the NSA can assist the DISA is only a second thought.

    2. Re:Biased summary by Anonymous Coward · · Score: 5, Interesting

      i don't agree that we should be funding an agency to spy on our own citizens and undermine
      our digital security.

      so if you agree that thats part of the role of government, for the children, then sure, nothing wrong
      with what the NSA is doing

      however, a lot of us disagree, and furthermore, we never had an opportunity to express our
      opinion as to whether or not we wanted to live in a police state.

      so this is us weakly trying to say no. try to pretend we have a right to our opinon so your
      mind doesn't collapse from all the cognitive dissonance from supporting a 'police state democracy'

    3. Re:Biased summary by Anonymous Coward · · Score: 0

      i don't agree that we should be funding an agency to spy on our own citizens and undermine our digital security.

      I agree. What does that have to do with TFA? For its foreign spy operations, the NSA should find vulnerabilities to spy on foreigners, and not disclose those vulnerabilities publicly.

    4. Re:Biased summary by TWX · · Score: 4, Insightful

      The foreigners use the same technologies as the citizens, and are thus vulnerable to the same sort of exploits.

      I guess I feel much the same way as GlobalEcho does. I actually do not have a problem, in of itself, with the concept of attempting to discover the real criminal plots that are used to attack people. What I have a problem with is when the number of persons being subject to scrutiny is far too many generations removed from the original subject, when the scrutiny is applied to things that aren't criminal acts or should otherwise be protected-speech (ie, counter-political groups, peaceful civil rights groups, and other such organizations that did not advocate violence or even equip themselves with the tools for violence), and when the checks and balances to ensure that overzealous application of the surveillance is curtailed are ignored or violated (ie, warrantless).

      My problem with the idea is that there currently is no line between surveillance target and everyone else. If surveillance target == enemy, then that means everyone == enemy, or at least potential enemy. It leads to an us-versus-them mentality that is now prevalent in law enforcement at all levels of government. It works to destabilize the nature of our government being by us, for us, and starts resembling something out of 1984 or out of East Germany during its Stasi period. That is not healthy.

      There need to be real rules covering investigation of people. There needs to be justification. There needs to be oversight. There needs to be the occasional criminal prosecution of a law enforcement official when they blatantly overstep their authority, and dismissal of charges from time to time through fruit-of-the-poisonous-tree legal concept, to remind law enforcement that if they ignore the law, those they attempt to prosecute can also ignore the law, and the only way to prosecute is to remain within its bounds.

      It's not too far yet, but we need to continue to push for it to be corrected.

      --
      Do not look into laser with remaining eye.
    5. Re:Biased summary by Anonymous Coward · · Score: 0

      That depends. If they're using them against Americans, then it's not what the NSA is supposed to do. The NSA has been caught spying on Americans before, so skepticism is IMO warranted.

    6. Re:Biased summary by Anonymous Coward · · Score: 1

      The NSA, and ultimately the US, re the enemies of the rest of the world.

      Yeah, because you would fare much better under Vladimir Putin or perhaps you would prefer the Iranian mullahs or the hard-core Sunnis of ISIS? Take your head out of your hindquarters, grow a brain and come back when you have something to say that isn't completely ignorant and stupid.

    7. Re:Biased summary by MyAlternateID · · Score: 2

      That depends. If they're using them against Americans, then it's not what the NSA is supposed to do. The NSA has been caught spying on Americans before, so skepticism is IMO warranted.

      Skepticism was warranted long before that happened because those in positions of power are never to be trusted.

    8. Re:Biased summary by Anonymous Coward · · Score: 2, Insightful

      after everything thats happened these past 14 years, you really believe
      there is a hard bright line between domestic and foreign operations?

      do you even think it would be possible to define such a line?

    9. Re: Biased summary by Anonymous Coward · · Score: 0

      You haven't been paying attention to what the NSA is actually doing, have you?

    10. Re:Biased summary by Anonymous Coward · · Score: 1, Insightful

      You pick examples from the middle east when every US intervention there turns the place into even more of a clusterfuck?

    11. Re:Biased summary by soap_and_dish · · Score: 2

      This is the same logic that's applied to any military secrets - keeping information out of the hands of the enemy means also keeping it out of the hands of citizens. That sometimes makes sense. Sometimes. But it fails when withholding this information makes the country and its residents less safe.

      The trouble is that we tend to forget that these organizations do not exist to attack, they exist to protect. Just as our penal system has gone over almost wholly to revenge and punishment rather than rehabilitation, our "defense" agencies have gotten far more aggressive. This seems to be a pretty consistent failure of logic which we are collectively suffering through. From militarization of police to projection of military power to the fucking article - in which we are making ourselves more vulnerable in the name of also making other entities ("the enemy") more vulnerable.

    12. Re:Biased summary by Anonymous Coward · · Score: 0

      http://www.maxkeiser.com/2013/06/first-time-since-1948-propaganda-is-now-legal-in-the-u-s/

    13. Re:Biased summary by Anonymous Coward · · Score: 0

      Actually, the NSA has a dual purpose. One in surveillance, but the other is keeping our infrastructure secure.

      Disclosing vulnerabilities to be repaired, is part of their purpose.

    14. Re:Biased summary by Peter+H.S. · · Score: 1

      I am a US citizen as frustrated about unauthorized domestic surveillance as anyone. But this summary goes too far. Finding, keeping and using vulnerabilities is exactly what the NSA is supposed to do, and there is nothing questionable about that behavior.
      If the submitter wants the government to have a group that finds and discloses vulnerabilities as part of its remit, then make a case for creating such a group. Don't saddle the NSA with the job.

      Well, you are wrong in thinking that it isn't the job of NSA to disclose at least certain vulnerabilities.

      NSA's job description also include counter intelligence. That means it should also do its best to protect US government servers, including the US military and potentially too, civilian US military contractors, who may have highly valuable knowledge on their servers.

      So certain vulnerabilities affecting software that the US government uses, are circulated back into the software community, it is simply in the interest of NSA as a counter intelligence agency to do so.

    15. Re:Biased summary by Anonymous Coward · · Score: 0

      And I as a non-US citizen and frusted that some US citizens seem to think the NSA have a right to engage in mass surveillance against a global population.

      I can understand targeted lawful surveillance against a foreign. Not this anything goes fishing expedition against all of humanity.

    16. Re:Biased summary by penguinoid · · Score: 1

      Much as I like to dump on the NSA, in this case they're doing things exactly right. If I were in their position, I'd use the zero day exploits against my targets, ensure we have a defense against it, maybe prepare a patch or workaround for publication, keep watch for others using that exploit. At some point I'd disclose the exploit to the developers, starting with the most obvious ones or the those which are already being exploited by others.

      Much as it would be nice for all exploits to be disclosed immediately, doing so unilaterally would leave our cyberespionage people weaponless (but other countries wouldn't be).

      The only problem I see in this situation is that apparently the target is "everyone".

      --
      Don't waste your vote! Vote for whoever you want, unless you live in a swing state it won't matter anyways
    17. Re:Biased summary by Anonymous Coward · · Score: 0

      The NSA, and ultimately the US, re the enemies of the rest of the world.

      Yeah, because you would fare much better under Vladimir Putin or perhaps you would prefer the Iranian mullahs or the hard-core Sunnis of ISIS? Take your head out of your hindquarters, grow a brain and come back when you have something to say that isn't completely ignorant and stupid.

      The point retards like you miss is we shouldn't have to make such a choice in the 21st century.

    18. Re:Biased summary by Anonymous Coward · · Score: 0

      You pick examples from the middle east when every US intervention there turns the place into even more of a clusterfuck?

      It is more funny to pick examples from the last few Republican presidential and congressional campaigns where they try to turn the US and the public opinion poll about what we should be doing into to even more of a clusterfuck. There you go.. go and play somewhere else than my lawn.

    19. Re:Biased summary by phil.swansborough · · Score: 1

      Yes, because the NSA is really ever going to be about protecting citizens. How can people still believe that any "security" agency ever has the interests of the majority of citizens at heart is beyond me. They are there to protect the wealthy and powerful, not you. They will never ever be there for you.

    20. Re:Biased summary by Anonymous Coward · · Score: 0

      I don't understand this focus on "criminal acts" and "terrorism". Sure, thats been a headline (and funding) getter for 15 years, but the goals of intelligence agencies are to gather intelligence to inform policy makers.

      Should the NSA be spying on US Citizens? Probably not, not without procedures and policies to keep it from being abused. But do I believe that this is a regular practice? No, I think its been blown out of proportion by headline-seeking media companies and an ill-informed social media 'blogosphere' that tends to have a mob mentality.

      Things that are not terrorism related, and the concept of "enemy" isn't really appropriate either.

      - Finding out that Country A's leaders are going to invoke martial law on their citizens? The president and Secretary of State might want to know before it happens. Maybe the US Embassy there can prepare for stranded US Citizens pleading for help.
      - Finding out that Countrys B,C, D and E are colluding to raise the price on a global resource? Might be useful to know.
      - Determining what the internal impact of US policy X might be if its carried out?
      - Knowing what's going on behind the scenes of deliberations of a peace treaty, or an economic treaty? Also helpful for informed policy making.
      - Knowing that country F, with unpredictable leadership, will be launching missiles purely as saber-rattling and not as a precursor to war, is vital in keeping responses reasonable and measured

      That's the point of intelligence. None of this is US specific. (3rd party nations might be interested in how another country might react to a US policy). None of this is "evil". It helps inform decisions that impacts millions of people.

      Should the NSA keep its own exploitable vulnerabilities? Absolutely, based on the premise that their very reach and capabilities that everyone is so scared of,, they're in a fantastic position to judge whether a vulnerability is truly unknown, or whether criminals are starting to use it, and can then inform vendors to get things fixed. Is that a popular position in the infosec world? Absolutely not, but I think its a somewhat reasonable balance between their intelligence mandate and responsible disclosure (as part of their information assurance mission.)

    21. Re:Biased summary by TWX · · Score: 1

      I was referring to within the borders of the United States predominately. Internationally, nations, even friends, have spied on each other since the concept of the nation first formed.

      --
      Do not look into laser with remaining eye.
    22. Re:Biased summary by Anonymous Coward · · Score: 0

      I mean... technically the NSA's primary mission is to protect the warfighter (it's a DoD organization unlike the rest of the intelligence agencies).

    23. Re:Biased summary by Rujiel · · Score: 1

      "There need to be real rules covering investigation of people. There needs to be justification. There needs to be oversight. "

      There are effectively none of these, and you're still satisfied with the NSA anyway. Very telling about your priorities. Also almost no one on here lauds another user by name, let alone bolds it--comes off as sockpuppety.

    24. Re:Biased summary by Anonymous Coward · · Score: 0

      Also almost no one on here lauds another user by name, let alone bolds it--comes off as sockpuppety.

      Well Rujiel , methinks thou doth protest too much.

    25. Re:Biased summary by dunkindave · · Score: 1

      You pick examples from the middle east

      I don't think Putin would consider Russia part of the Middle East. And to add to the anonymous coward's list, try living in North Korea, or in Somalia, or Sudan if you aren't Muslim, or Zimbabwe, or Burma, or Eritrea, or China if you are not wealthy or like to speak your mind, or ...

    26. Re:Biased summary by Anonymous Coward · · Score: 0
      Can you show evidence that the 91% the summary says they pass on do not contain the vulnerabilities that directly effect the security of government systems? Or could they make sure those are addressed and only keep the ones not in that group, which would defeat your argument?

      NSA's job description also include counter intelligence.

      Is that some sort of smart kitchen food preparation area, or did you mean counterintelligence? All razzing aside, you need to look up what counterintelligence means, since it deals with detecting spying by an adversary, not implementing security protocols, and the detecting can include hacking back to identify the actor(s).

    27. Re:Biased summary by dunkindave · · Score: 1

      I mean... technically the NSA's primary mission is to protect the warfighter (it's a DoD organization unlike the rest of the intelligence agencies).

      I think DIA, ONI, NGA, AFISRA, Military Intelligence Corps, MCIA, a a couple others would disagree with the latter part of that statement.

    28. Re:Biased summary by Anonymous Coward · · Score: 0

      I completely agree with Rujiel , who certainly isn't a paid shill. Rujiel never sockpuppets, and all his comments should be modded up.

  3. Don't criminals do similar things? by Anonymous Coward · · Score: 0, Troll

    This is definitively criminal thinking and behavior.

    1. Re: Don't criminals do similar things? by Anonymous Coward · · Score: 0, Insightful

      Criminals also eat and drink and breathe air. Wait... Don't you do that too?!

    2. Re: Don't criminals do similar things? by Anonymous Coward · · Score: 0

      Criminals also eat and drink and breathe air. Wait... Don't you do that too?!

      You know Adolph Hitler and the KKK and the Republicans breathe air too you insensitive clod!

  4. Surprise! by Anonymous Coward · · Score: 0

    I don't think it exists in this context.

  5. Iran by ultranova · · Score: 2, Interesting

    The NSA, perhaps seeking to repair its reputation, has started talking about how it handles vulnerabilities in computer software. But in doing so, they've only confirmed their own questionable behavior.

    Questionable perhaps, but the article also provides a pretty good answer by mentioning Stuxnet, which was used to halt Iran's enrichment of uranium. Surely being able to stop what's at best an oppressive theocracy from obtaining nuclear weapons with no casualties or collateral damage has some value?

    --

    Forget magic. Any technology distinguishable from divine power is insufficiently advanced.

    1. Re:Iran by Anonymous Coward · · Score: 4, Funny

      That's what happens when you allow religious nut jobs to roam free...

      Please leave Texas out of this.

    2. Re: Iran by Anonymous Coward · · Score: 0, Informative

      Hahaha you assume we will hold true to our word. We are one elected official away from collapsing the whole agreement.

    3. Re: Iran by Anonymous Coward · · Score: 0

      Obama is a lame duck, he has no need for political points. Try again.

    4. Re: Iran by 31415926535897 · · Score: 2

      Right, legacy means nothing to him. Nor does party momentum. Obama does everything from righteousness and virtue now.

    5. Re:Iran by chipschap · · Score: 2

      The NSA retains some offensive weapons. This is wrong?

      You can answer that question as per your beliefs, and you're fully entitled to do that. But I could argue that if the NSA shouldn't have offensive weapons, neither should the Army or any other government entity. Again, you may be a pacifist and agree with that, too.

      But there's practical reality at play here. Pacifism doesn't always work in the face of aggression.

    6. Re:Iran by Anonymous Coward · · Score: 1

      There was a lot a collateral damage: a dramatic boost in the private zero-day industry. The NSA is boosting a cyber cold war, instead of shutting it down as much as possible. Now the country with the most to lose will lose, and that is the US. Remember, other countries now have access to the same information, meaning they could do the same thing to our infrastructure, and they already have: the stolen personnel files. Remember that the same argument against nuclear proliferation applies to zero-day proliferation. Better that the NSA focus on securing infrastructure. One of the best tools to end the cold war was the star wars missile defense system, and that is the strategy we need today: kill the demand, don't grow the supply. Same issue with the drug war.

    7. Re: Iran by AK+Marc · · Score: 1

      The Republicans paid the Iranians to commit acts of war in 1980 to sway the election to the warmonger party, why would this time be any different? If Iran attacks, it's probably as paid stooges for the Republicans.

    8. Re:Iran by Anonymous Coward · · Score: 0

      Surely being able to stop

      It didn't stop them, just cost them some money and a few months of time. It would have been cheaper to bomb the place instead. The Iranians are already killing and have killed our soldiers, civilians and operatives and they're actively working against our interests in Iraq, Syria, Lebanon and throughout the Middle East. The Iranians are the enemies of the United States and although or current President is too squeamish to admit it, we're already at war with Iran, if not de-jure then de-facto. The stakes are much higher than a few dead Iranian scientists. We should be ready to bomb their facilities when (not if) it becomes clear that they aren't holding up their end of the nuclear deal. The foreign policy of the United States should be muscular, as befits a great power, but we elected a wimp to lead us and the Iranians can hardly believe their luck as they take over the Middle East. It's disgusting. Maybe if the Iranians hit us here in the United States, the left will finally wake up to the threat posed by the Iranians and their goal of world Shia domination.

    9. Re: Iran by Anonymous Coward · · Score: 0

      I see crazy conspiracy theories are in full swing by liberals / progressives.

    10. Re: Iran by Anonymous Coward · · Score: 0

      We are one elected official away from collapsing the whole agreement.

      Good. It should collapse because it's a rotten and worthless deal. It hinders us and does nothing to prevent an Iranian bomb. The Iranian government lies, cheats and kills as a matter of doing business and openly promotes terrorism and targeting of civilians to get its way. We ought to be fighting them, not talking to them.

    11. Re:Iran by radarskiy · · Score: 1

      "what's at best an oppressive theocracy from obtaining nuclear weapons"

      The Guardian Council is opposed to nuclear weapons. It was the secular authorities that were pursuing their development.

      The only value nuclear weapons have for Iran are a) to prevent the USA from pre-emptively invading, and b) to trade away in a diplomatic deal. The latter did not even require actual weapons to have been developed.

      There is no plausible way in which Iran represents a threat to the USA. The only people that the post-revolutionary Iran has used their military offensively against are the Taliban (remember them?), and defensively they fought against the USA-backed Iraq.

    12. Re:Iran by Chaos+Incarnate · · Score: 2

      The problem isn't the NSA having offensive weapons. The problem is the NSA knowing that some installations are built on quicksand but not informing the owners.

      That's not helping national security, that's degrading it.

      --
      Benford's Corollary to Clarke's Law: "Any technology distinguishable from magic is insufficiently advanced."
    13. Re: Iran by AK+Marc · · Score: 1

      For 1980? That was admitted by the Republicans and Iranians. No conspiracy needed, just read the confessions. Why do you think that Ollie North went to jail? To protect The Party from the fallout of the illegal payments to Iran. Not only was the deal treason in 1980, but they followed through with the payment as a second treason. Just like G Gordon took one for the team for Watergate, the investigations into treason stop when someone goes to jail for a much lesser crime.

    14. Re:Iran by Anonymous Coward · · Score: 0

      And funded radical extremist to attack and kill their most hated, Israel (Jews).

    15. Re:Iran by Anonymous Coward · · Score: 1

      But I could argue that if the NSA shouldn't have offensive weapons, neither should the Army or any other government entity.

      And if the NSA shouldn't have nuclear bombs, neither should the Army or any other government entity. Oh, right, that's absurd. Honestly, the fact is the NSA has two very contradictory goals: the protection of government systems against penetration and network warfare and the collection of foreign communications by both passive and clandestine means. This story isn't really news precisely because to do the latter almost inherently means interfering with the former. It's the same reason why [insert company]'s security team wants to push out details to mitigate attacks and release patches as soon as reasonable possible but [insert company] wants to delay patches into bundles and minimize the level of details to the public for PR purposes. Those very contradictory goals hurt everyone. It's only made worse when it's made clear just how much the NSA has defined "foreign" in such loose terms that often they'll still collect information on people non-foreign. Add to that the whole data swapping with other countries...

      But there's practical reality at play here. Pacifism doesn't always work in the face of aggression.

      Long-term pacifism is the foundation of what civilization is: non-force behavior that organizes towards a collective structure. Yes, civilizations can be destroyed. That doesn't carte blanche justify aggression or genocide on one's own end. And honestly, this whole discussion would be radically different if the NSA actually stuck to its job and there wasn't a very clear issue that other agencies couldn't subvert the NSA's information to bypass the intentions of limiting the scope of surveillance to actual foreign powers that are a real threat to people of the US. Instead, it's more in line with political tyranny.

      PS - Yes, leaping to nuclear bombs seems like a strawman, but then your own discussion is very much strawman too. The NSA could be a passive-only surveillance and it could be left up to the CIA to do clandestine surveillance so the NSA could effectively undermine the CIA's efforts for the good of the American people. The whole step towards offensive acts can fundamentally undermine an agency in ways that, well, are obviously currently being undermined now. Besides, we don't per se give the Army nukes nor simply hand over weapons to the Army per se to do as they please. They're invariably under orders from the civilian government (President and under Acts of war) in a more direct way than the NSA seems to be. Perhaps if the NSA were less autonomous it'd be less of an issue, but then the NSA would have even more political tyranny in its actions.

    16. Re: Iran by Anonymous Coward · · Score: 0

      Obama is a DUMB fuck. Try again.

      FTFY!

    17. Re: Iran by Anonymous Coward · · Score: 0

      The American government lies, cheats and kills as a matter of doing business and openly promotes terrorism and targeting of civilians to get its way. We ought to be fighting them, not voting for them.

      FTFY.

    18. Re: Iran by Anonymous Coward · · Score: 0

      Americans are such posturing wankers. I can't believe there actually are people who think that the world needs a brute squad with aircraft carriers to smack everyone into shape.

      You and your idiot compatriots are the REASON the world is fucked up.

    19. Re: Iran by Anonymous Coward · · Score: 0

      (Citation needed.)

      Also Iran has and promotes Jewish representation in its government. Where are the Arabs of Israel represented in the Israeli government? Which one is the Looney one sided theocracy again?

    20. Re:Iran by Anonymous Coward · · Score: 0

      and Yakima, WA.

    21. Re: Iran by Anonymous Coward · · Score: 0

      Obama is a DUMB fuck. Try again.

      FTFY!

      Negros are apes who are not human and we need to keep the white species pure!

      FTFY!

    22. Re:Iran by Anonymous Coward · · Score: 0

      It bought a temporary reprieve for something the government decided to let them have anyways.
      The cost was that the United States will forever be known as the first country to use a cyber weapon in a deliberate act of aggression on a country that they never declared war on. The resulting damage to the USA's reputation will linger for decades.
      Was it worth it?

  6. We just snort a little of this cocaine before.... by Anonymous Coward · · Score: 0, Insightful

    ...disposing of it. After all we need our men to stay alert in-case there's a terrorist attack. MURICA!

  7. NSA missions are often in conflict by Anonymous Coward · · Score: 0

    The NSA has an Information Assurance mission and a Signals Intelligence mission. If the Information Assurance mission is secondary, which seems to be the case, then it should be offloaded to independent agency whose only goal is to assist keeping vital US interests secure from cyber attacks. Let the NSA focus on external threats.

  8. Water is wet by gurps_npc · · Score: 2
    Ice is cold. Lava is hot.

    Spies use privacy vulnerabilities

    Are we going to publicly announce that soldiers kill people next? Perhaps someone thinks it is noteworthy that a bank charges interest on loans! Or that boxers HIT each other.

    --
    excitingthingstodo.blogspot.com
    1. Re:Water is wet by Anonymous Coward · · Score: 0

      Let's dismantle the army, all they do is kill people.

    2. Re:Water is wet by Anonymous Coward · · Score: 0

      Ice is cold. Lava is hot.

      Spies use privacy vulnerabilities

      Are we going to publicly announce that soldiers kill people next? Perhaps someone thinks it is noteworthy that a bank charges interest on loans! Or that boxers HIT each other.

      Or that people say stupid things online?

    3. Re:Water is wet by Anonymous Coward · · Score: 0

      Ice is cold. Lava is hot.

      Spies use privacy vulnerabilities

      Are we going to publicly announce that soldiers kill people next? Perhaps someone thinks it is noteworthy that a bank charges interest on loans! Or that boxers HIT each other.

      Murderers murder people. Thieves steal from people. Stupid people do stupid things. People in power end up abusing it. What's your point?

    4. Re:Water is wet by athe!st · · Score: 1

      I've also heard scurrilous rumours the pope is a catholic

  9. Deconstructing BS by Anonymous Coward · · Score: 1

    Here is the NSA's claim.

    "Disclosing a vulnerability can mean that we forgo an opportunity to collect crucial foreign intelligence that could thwart a terrorist attack, stop the theft of our nation's intellectual property, or discover even more dangerous vulnerabilities that are being used to exploit our networks."

    a. The Terrorists. The Terrorists. Terrorism has been used by thugs throughout history to justify violations of rights. The TARGETED and use Intelligence in self-defense, on case-by-case basis lawfully approved, is justified and important to security. Even police sometimes need to do this to catch criminals. Mass indiscriminate surveillance of the global population, including violating personal data stores that are supposed to be our private property, is a violation of human rights. The number one violators of the right to privacy in world today seems to be the NSA.

    b. How NSA ""Stop the theft of intellectual property" by not disclosing vulnerability? If follows if the NSA finds one so can someone else!

    c. What good is the NSA's claim they "discover even more dangerous vulnerabilities that are being used to exploit our networks" when they don't disclose some of them? This is like arguing I disclosed an SQL injection vulnerability but didn't disclose an XSS one. Do hackers and those with malicious intent care what specific vulnterabilities they use to get into systems or is the objective getting into the system?

    The fundamental problem though isn't the NSA. The real problem is the megalomaniacs that have encouraging and funding the anything-goes culture of the NSA. This would include both Bush AND Obama.. both Democrats and Republicans. This is one of those rare situations where the issue isn't partisan. Both members of the left and right have been supporting this overarching spying.

    Thus those that claim to care about freedom, need to start calling out not only the other guys politicians but their own over this issue too.

    Many feel a sense of hostility for the NSA out of control snoopying but the reality

    1. Re:Deconstructing BS by Anonymous Coward · · Score: 0

      Edit. Pardon for the typos and grammar errors. Accidentally pressed submit before reviewing. Please don't let my Engrish interfere with the substance of what I am arguing.

    2. Re: Deconstructing BS by Anonymous Coward · · Score: 0

      Fuck the nsa bunch of faggots. They can stick their vulnerabilities back in their collective assholes.

    3. Re:Deconstructing BS by Anonymous Coward · · Score: 0

      Terrorism has been used by thugs throughout history to justify violations of rights.

      "Better that ten guilty persons go free than one innocent suffer." -- Sir William Blackstone

      "It is better that ten innocent men suffer than one guilty man escape." -- Pol Pot, Dick Cheney and others.

    4. Re:Deconstructing BS by Opportunist · · Score: 1

      The main problem here is that the NSA went away from a defensive position and is more and more used as an offensive tool in international (and domestic) espionage. Which by itself isn't so bad a thing, but using it indiscriminately not only on allies but on the own, domestic population without impunity is clearly stepping over the line.

      Personally, I dare say international surveillance of alleged allies already does this. It damages the US' credibility far more than anything gained that way could compensate.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    5. Re:Deconstructing BS by Anonymous Coward · · Score: 0

      (warning: graphic language)

      You make a good point but I think what is far more likely to happen is a case of selective enforcement of the law. For example...

      Lets suppose we are in a position of influence. Your a good guy that means well but you also enjoy having bandcamp with yourself so you regularly surfs the internets for the porns. (highly hypothetical because as we know very few males would ever do such a thing) Does anyone actually validate the age of "teen cheerleader gives BJ's" page? How about age of the girls on the "tight shaved pussy fucked" link? The Asian bondage page? Maybe even hit a page that's borderline so you take a few peeks in the heat of the moment?

      Now here is the NSA. They not only see every page we surf (and no VPNs won't protect us) but they keep that data probably indefinitely. . Someone with powerful links in the government doesn't like you. BAM. FBI slams down your door and you are nailed as a pedo. Finished politically, economically, and even socially a cancer.

      Meanwhile there is someone in that very same government likes -- like say a President that's committing war crimes by signing off on state sponsored torture. Hey we will all just look the other way and forget about it because he's one of us. One of the good guys.

      (Not that any of this would ever happen. Just saying)

  10. First Priority is to Protect the Innocent by physicsphairy · · Score: 1

    If the police failed to act on information a rape or murder was planned because they wanted to catch the perpetrator in the act, there would be outcry. You don't jeopardize the safety of the innocent to assail the (potentially) guilty. Collecting foreign intelligence is not more important than heading off immediate threats to domestic citizens. Clearly the NSA views it as all about "catching the bad guy" and has forgotten the reason the bad guys are considered bad. It's like SWAT leaving a bomb in a public building because, "Hey, maybe we could trip it when the bad guys get back."

    1. Re:First Priority is to Protect the Innocent by Opportunist · · Score: 1

      Well, there is the "need of the many" counter argument. If you can catch a serial killer by sacrificing one target and ensure that way that he is being stopped and cannot kill dozen others, is it justified?

      Is it justified to allow a terrorist plot to go ahead if that means the heads behind it have to expose themselves in a way that you can cut them off?

      This game is rarely one painted in just black and white.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  11. And this is a surprise? by QuietLagoon · · Score: 1

    If so, why?

    1. Re:And this is a surprise? by Anonymous Coward · · Score: 0

      Yeah, you're the obligatory wisecrack who somehow knew all details beforehand.

  12. They have no duty to disclose by cfalcon · · Score: 3, Insightful

    They are an intelligence agency. You'd EXPECT that they would hold onto some method to do their job, which absolutely involves electronic infiltration. This is neither controversial nor unexpected.

    Don't mistake the fact that they reach out to industry to improve everyone's (worldwide) security most of the time, for that being their primary mission or charge. That's a nice bonus.

    If you want to get worked up, get angry about the same shit Snowden did- the possible indiscriminate spying against US citizens, and the idea that they only way that the government can do its job is by casting a worldwide net that monitors everyone everewhere all the time. Not that they can hack systems, which is a huge part of why they fucking exist.

    1. Re:They have no duty to disclose by Anonymous Coward · · Score: 0

      If you want to get worked up, get angry about the same shit Snowden did

      What shit did Snowden do?

      the possible indiscriminate spying against US citizens, and ... casting a worldwide net that monitors everyone everewhere(sic) all the time.

      So, Snowden is bad because he spied on protected communications and documents, and he hacked into systems to steal information which he then sent to foreign entities with the intention of disrupting US intelligence gathering operations. OK, got it.

  13. NSA? by Dan+East · · Score: 1

    What do you think the NSA is for??? Free government funded penetration testing and reporting service? Sheesh.

    --
    Better known as 318230.
    1. Re:NSA? by warm_warmer · · Score: 1

      Free government funded...

      Just to clarify, did you mean free or did you mean government-funded?

  14. Nothing wrong with it per se by Opportunist · · Score: 2, Insightful

    The NSA is a security service. Having tools to break and enter into the communication and data storage of potential enemies of the state is their business. That's what they do. Their whole reason to exist, to be blunt. If they can't do that, well, they can as well not exist at all. Which would not be beneficial for the US, in general, because, well, their enemies sure as fuck won't do away their version of the NSA. You'd deprive yourself of a valuable tool in international espionage.

    What something like this needs, and what is sorely lacking today, is oversight. You needn't take away such powerful tools. You need to ensure they are not being abused. That's the real problem here.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    1. Re:Nothing wrong with it per se by Anonymous Coward · · Score: 0

      What something like this needs, and what is sorely lacking today, is oversight. You needn't take away such powerful tools. You need to ensure they are not being abused.

      Honestly, that's bullshit. The problem isn't a lack of oversight per se. It's precisely oversight by people who view use of such powerful tools on the American people as not abuse that allows abuse to continue. It's no different than why so much regulation is ignored. It's not that we need more regulation. It's not that we need more oversight. What we do need is enough autonomy of agencies to do their job and for it to not be in conflict with their other jobs. That's where, I think, the NSA has failed.

      In my view, the NSA should be split up into three parts (with one part probably merged with the CIA). Part one's job should be solely in passive monitoring of foreign communications (although being passive, it's possible they'll also pick up American broadcasts as well). Part two's job should be solely in finding, reporting, and working with vendors/companies/people in finding vulnerabilities in hardware, software, etc that would allow for intrusion by others, domestic or foreign; this could even include things like testing real physical locks, so it wouldn't necessarily all be computer related. Part three's job would be to find and exploit vulnerabilities, plant bugs, etc to monitor foreign threats but for that information to be limited to internal to the US government and really to only a very small section of the government (part of Congress, part of the Executive, and part of the Judiciary) on a need/oversight basis. Part three could likely be merged into the CIA and be under the same umbrella of need/oversight.

      In the end, the problem today isn't oversight. It's that the oversight is corrupt. It's what turn the system into a corrupt one that further oversight won't intrinsically help. Restructuring is only part of the solution. The other part is replacing the oversight committee who desires such abuses. Too bad the American people apparently WANT this abuse to continue. But, then, that's democracy for you. You get the abuse you vote for.

  15. Uhh... what? by BronsCon · · Score: 0

    If this is what passes for news in this crowd, I've been here too long and must be moving on.

    --
    APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
    1. Re:Uhh... what? by BronsCon · · Score: 1

      And if that depressing insight is moderated as flamebait rather than insightful, perhaps I should consider that as confirmation. It's been a good run and my karma indicates that I will be missed; perhaps more than some of you realize.

      --
      APK quotes people (including myself) without context and should not be trusted. Just thought you should know.
  16. Does NSA buy exploits? by Anonymous Coward · · Score: 0

    Asking for a friend.

    1. Re:Does NSA buy exploits? by Anonymous Coward · · Score: 0

      Does NSA buy exploits?
      Asking for a friend.

      "If you'd like NSA to make an offer, call your friend up and ask how he did it!"

  17. National Security Agency by GoodNewsJimDotCom · · Score: 0

    Security Agency, completely against computer security. You know vulnerabilities can be used against US targets too right? Backdoors can be used by criminals.

    1. Re: National Security Agency by GoodNewsJimDotCom · · Score: 1

      I love the USA. I just wish we didn't feel the need to promote malware vectors instead of patch them. I try and keep my Windows computers off the Internet anymore since there are so many viruses you can get just by clicking a wrong link. You don't even need to run a file anymore to get a virus. Things are pretty bad now. I wonder if things will get worse or better for computer security.

  18. It goes without saying by dhaen · · Score: 1

    The surprise is that they disclose so many. Invasion into personal privacy is only collateral damage at the moment, whilst there are relatively sane governments in power. Things might change in the future.

  19. File under: by Anonymous Coward · · Score: 0

    No shit, Sherlock.

  20. Kerfuffle by Dunbal · · Score: 1

    [T]here are legitimate pros and cons to the decision

    No there are not. There is only the LAW. The decision has already been made, ratified and written down. It's not up to some bureaucrat to make things up as he goes along. Governments are compelled to act within the bounds set by law. When they stop doing this, they are no longer law abiding nations and lose the right to enforce law on the people.

    --
    Seven puppies were harmed during the making of this post.
    1. Re:Kerfuffle by Anonymous Coward · · Score: 0

      Interpretation of the law, all the way down into the details, is handled by an entire top tier segment of the US government. -1 for trolling

    2. Re:Kerfuffle by Anonymous Coward · · Score: 0

      enjoy your police state

  21. To be fair, I do the same by niks42 · · Score: 2

    Many, many times in my career I have found some vunerability and delayed disclosing it while enjoying it myself. I found a wonderful way of spiriting - nay, liberating - electronic components out of work that would have found their way into a dumpster. I found a way of accessing peoples' accounts on TSO and VM; I found ways of resetting the prepayment cards for lunch at work. I've keylogged PCs; I have tcpdumped and etherealed to find passwords to gain access to systems. I used I don't know how many exploits to get free Sky TV. I installed an FM transmitter in my manager's office about that time of year when salary plans were being discussed. I've picked many locks. I've used Apache and other exploits to break into systems where admins had long before forgotten root passwords. Not everything I have done has been legal. It's all contributed to me being who I am today, and having the skill set that I rely on to do my job.

    If I think about it, I can't expect any different from the NSA. If they are going to learn the skills that they need to do their jobs, they do need to flex their muscles. We do need to have some level of trust in the agencies that have been put into place to protect our citizens.

  22. People are not gambling tokens by Anonymous Coward · · Score: 0

    Well, there is the "need of the many" counter argument. If you can catch a serial killer by sacrificing one target and ensure that way that he is being stopped and cannot kill dozen others, is it justified?

    It is never ethically justifiable to knowingly sacrifice one person to save a million. It is merely efficient, and that is entirely different. You still have to live with the fact that you took an innocent life, and saving many other lives will never undo that.

    When the saving of millions is merely speculative though, even "needs of the many" arguments for efficiency have no rational justification whatsoever, since you may be sacrificing one and saving none.

    People are not tokens at the gambling table, to be sacrificed on a whim as if they were spare cash.

    1. Re:People are not gambling tokens by Opportunist · · Score: 1

      Such entities are not running on morality. By definition no group of people, unless governed explicitly by some moral codex, will waste a nanosecond pondering the moral implications.

      For reference, see corporation.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    2. Re: People are not gambling tokens by Anonymous Coward · · Score: 0

      By YOUR ethical standards. Why do you think yours are better than anyone else's?

    3. Re: People are not gambling tokens by Anonymous Coward · · Score: 0

      By YOUR ethical standards. Why do you think yours are better than anyone else's?

      "Your freedom ends where that of another person begins." Alas, you may not see the truth of that until later years.

      It's the only social premise which provides a balance in rights, ethics, morality, and all other group virtues. Every other form gives rise to one person coercing others to their detriment and is inherently flawed as a social construct that doesn't lead to barbarism.

      I don't have a distinct personal ethic --- the above is certainly not my own invention, it's been handed down through the ages and is reinforced every time one barbaric dictator or another delivers their evil under the pretext that overriding the rights of other is better.

  23. Not news unless you're naive by matbury · · Score: 1

    A secretive, clandestine spy agency does secretive, clandestine things and has no scruples. Mmm... what a surprise! The thing we should really be complaining about is that they claim to have effective oversight and act within the law.

  24. Lol by Anonymous Coward · · Score: 0

    Keep America Safe by spending their tax dollars to make computers less secure... Wtf

  25. Two-edged sword by Anonymous Coward · · Score: 0

    Each one of their arguments can be used in reverse.

    Holding back vulnerabilities means US companies continue to use compromised software. Foreign actors could use information gained by exploiting those vulnerabilities to plan a terrorist attack, steal our nation's intellectual property, or discover even more dangerous vulnerabilities that could be used to exploit our networks.

    They themselves (and any government agencies they choose to share the vulnerabilities with) are no longer at risk - but that's it.

  26. "the theft of our nation's intellectual property" by Anonymous Coward · · Score: 0

    The NSA is involved in large-scale theft of other nations' intellectual property. These people are really disgusting.

  27. In other words, they're script kiddie wannabes. by Chas · · Score: 1

    This reminds me of an idiot who went on a zero day, full disclosure forum, advocating that they should "hold the best stuff back" so that they "look like gods" to the next, upcoming generation of hackers.

    Let's just say that this silly jackass was laughed off the board, and is now enjoying his second stint in FPMITAP for unoriginal idiocy with a computer.

    So the NSA is at the same basic intellectual (for lack of a better term) level...

    Sigh.

    --


    Chas - The one, the only.
    THANK GOD!!!
  28. An article with the proper use of zero-day? by thogard · · Score: 1

    I didn't think I would ever see another article with the proper use of the term zero-day. I expect when the NSA talks about zero-day they get the terminology right. An exploit the NSA discovers and doesn't use isn't a zero day until someone else start using it. Exploits they buy are most likely zero-day. Bugs found and reported to vendors but not used aren't zero-day if a patch arrives before an exploit. A real trick is knowing if a new exploit is being used and I think it is clear that the spooks might have an advantage in detecting that sort of thing.

  29. How are these things threats to national security? by Anonymous Coward · · Score: 0

    Has anybody noticed how they love to include things like: terrorism, child porn, drug trafficking, copyright infringement, and "intellectual property" as threats to our national security? None of these things or like-things have *any* serious consequence to the existence of the United States, its government, or its people as a whole. There aren't enough drug traffickers or paedophiles in the world to overthrow the US government and I'd be totally lost as to how intellectual property issues are a threat to the people or government. No- these things are not threats to the government or people. They are at best ordinary criminal activity of which largely has no harmful effect except in and of itself (to a large degree). What we have done by passing laws is created an opportunity for some people to justify there use of violence (ie law enforcement, judges, military, etc) against people we may not care for and are or may be perceived to be dangerous to us or some of those around us. However if you put people into a corner by making something a crime they *will* use violence in self-defence. Totally predictable and much more defensible than the position of the government. The one is on the attack and the other is defending ones interests.

  30. NSA speak translated to English by Required+Snark · · Score: 1
    NSA speak: Disclosing a vulnerability can mean that we forgo an opportunity to collect crucial foreign intelligence that could thwart a terrorist attack, stop the theft of our nation's intellectual property, or discover even more dangerous vulnerabilities that are being used to exploit our networks.

    English: Disclosing a vulnerability can mean we forgo an opportunity to use the power of the state to spy on innocent people for no reason, crush legitimate political dissent, blackmail political figures to make them our puppets, engage in economic espionage that puts vast sums in the coffers of political insiders, interfere with foreign governments both friend and foe, cover up our vast incompetence, avoid the consequence of our bad decisions, and interferes with our degenerate addiction to unencumbered personal power that makes use feel superior to everyone else on the planet.

    --
    Why is Snark Required?
  31. 91% fake by Anonymous Coward · · Score: 0

    I bet that 9% that they released are all the exploits they could find, where the "intentional" delay is just the time they needed to find them. the other 91% is just made up.

  32. "Data and Goliath" by Bruce Schneier by eric_harris_76 · · Score: 1

    Golly. I could have not read "Data and Goliath" and learned *one* of the appalling truths in it from Slashdot only a few wees later.

    --
    There's no time like the present. Well, the past used to be.
  33. NSA -- No Sales for America by Anonymous Coward · · Score: 0

    NSA -- No Sales for America -- Would you buy something that possibly would have embedded surveillance equipment?

    NSA -- Not Safe for America

    NSA -- Not Sensible to Anyone

    When people criticize the NSA, they assume the NSA is well-managed, and doing something wrong. It is NOT well-managed. Management problems can be hidden. One example that was not hidden, Edward Snowden, an employee of a sub-contractor, could take huge amounts of data.

  34. Surprise! by Another+Mouse+Coward · · Score: 1

    The only surprising thing about this would be if anyone were surprised!

  35. If the NSA ever provided a benefit... by Anonymous Coward · · Score: 0

    ...none of us would have a problem with what they claim to do. (only the sheep think the nsa is telling any truths)
    But since the three-letter agencies of our oligarchical police-state have yet to FIND or PREVENT any attack of any kind, ever, then we should assume the following:
    - They are lying.
    - They cannot protect anyone from anything.
    - They have no value to We The People.
    - They have no justification for even 10% of their budget.
    - Their main threat is We The People, and that is how they run their 'business'.
    - If they were gone tomorrow, nothing would get worse and a lot of things would improve.