7 ms·
From Krebs tweets: The NSA's Neuberger said this wasn't the first vulnerability the agency has reported to Microsoft, but it was the first one for which they a
by kornholi 7y ago
From Krebs tweets:
The NSA's Neuberger said this wasn't the first vulnerability the agency has reported to Microsoft, but it was the first one for which they accepted credit/attribution when MS asked.
Sources say this disclosure from NSA is planned to be the first of many as part of a new initiative at NSA dubbed "Turn a New Leaf," aimed at making more of the agency's vulnerability research available to major software vendors and ultimately to the public.
- mrguyorama 7y ago>a new initiative at NSA dubbed "Turn a New Leaf," More like "do the actual job they are paid to do"
- eyegor 7y agoThey are paid to collect intelligence for the benefit of the american people, not american companies. Luckily citizens united hasn't stretched that far.
- monoideism 7y agoTheir mission also explicitly includes information assurance: Mission Statement The National Security Agency/Central Security Service (NSA/CSS) leads the U.S. Government in cryptology that encompasses both signals intelligence (SIGINT) and information assurance (now referred to as cybersecurity) products and services, and enables computer network operations (CNO) in order to gain a decision advantage for the Nation and our allies under all circumstances.
- Seenso 7y agoThey've got to balance both roles. IIRC, in earlier times the government didn't use as much COTS stuff, and civilian computer systems weren't so critical, so the roles were easier to separate. The NSA developed whole series of secret encryption algorithms for the exclusive use of the government/military, and civilian algorithms weren't approved to secure classified communications. https://en.wikipedia.org/wiki/NSA_cryptography https://en.wikipedia.org/wiki/NSA_cryptography
- A4ET8a8uTh0 7y agoI always wondered why Barr, Comey and basically every AG I paid attention to, consistently want to break encryption for the populace. I guess it makes sense proponents of those changes would be ok of breaking it for the proles of they thought their secrets are protected.
- thfuran 7y agoYou don't see how a lack of critical vulnerabilities is software infrastructure is of benefit to citizens?
- diffeomorphism 7y agoNo, I don't see how this is part of foreign intelligence/surveillance/espionage work. It is good that these vulnerabilities are fixed, of course. But shouldn't that be at least a separate partially independent branch of the NSA? Otherwise you get a large conflict of interest.
- xrayzerone 7y agoTheir job is to collect signals intelligence and execute cyber warfare operations. Not whatever you think it is.
- mrchucklepants 7y agoTheir job is more than that. "The National Security Agency/Central Security Service (NSA/CSS) leads the U.S. Government in cryptology that encompasses both signals intelligence (SIGINT) and information assurance (now referred to as cybersecurity) products and services, and enables computer network operations (CNO) in order to gain a decision advantage for the Nation and our allies under all circumstances." [1] https://www.nsa.gov/about/mission-values/ https://www.nsa.gov/about/mission-values/
- xrayzerone 7y agoSo...SIGINT and CNO. Exactly as I stated.
- toomuchtodo 7y agoSecurity assurance isn’t necessarily cyber warfare. To have the high ground is not the same as using it offensively, hence the expectation of defensive posture as part of the NSA’s mission (although admittedly some offensive activities are to be expected, depending on the situation, such as Stuxnet and Iran).
- ericmason 7y agoNot sure if you’re just being snarky, but the NSA’s stated mission includes helping with cyber security: https://www.nsa.gov/about/mission-values/ https://www.nsa.gov/about/mission-values/
- xrayzerone 7y agoAnd what do you think the end state of all that cybersecurity research is?
- ct520 7y agomore like someone with some commonsense decided to capitalize on disclosing issues when other countries get zero days. Oh well, guess we can't use this anymore Bob, china has been exploiting it over the past week. Call Microsoft lets at least get some free PR in exchange of having to give this up.
- reaperducer 7y agoYou write that like it's a bad thing.
- SlowRobotAhead 7y agoYou can do the right thing for the wrong reasons.
- toyg 7y agoThey have probably done that for a while (this is the first public attribution, not the first disclosure); but they are now blowing their trumpet because they need some good PR. Why? Snowden.
- idlewords 7y agoMuch more likely the bad reaction to Eternal Blue.
- toyg 7y agoEternalBlue would have not received that much coverage had it not happened after Snowden proved that the American public cannot trust the agency. They had been dragged to the foreground before without repercussions, because reactions were limited to the IT world. Snowden made it a general-public issue, and now they are forced to to shape up.
- jka 7y agoAn alternative angle that could make sense is that it shows that they're not purely intent on hoarding exploits (particularly dangerous ones) and are willing to report them to software vendors in order to reduce everyone's risk profile. That'd be more of a communal-good, de-escalation approach. There's certainly something to be said for the fact that it displays the talent and expertise available too though (i.e. helping for recruitment).
- mzs 7y agoThe tweet* from the call with reporters - a cynical person might think instead that NSA thought that with the similarity to the LE and FF flaws it was not much longer before a hostile actor would find this crypt.dll flaw so it was time to notify MS. * https://twitter.com/briankrebs/status/1217125030452256768 https://twitter.com/briankrebs/status/1217125030452256768
- blaser-waffle 7y agoDidn't the FBI or NSA push for flawed Elliptical Curve Crypto in the past? Could be the knew about it for a while and had milked it hard until they caught someone else using it. Or like the parent said, previously discovered flaws meant that someone might catch this one, too.
- mzs 7y agoThere is no evidence that US push flawed curves.
- alasdair_ 7y ago>There is no evidence that US push flawed curves. "Reuters reported in December that the NSA had paid RSA $10 million to make a now-discredited cryptography system the default in software used by a wide range of Internet and computer security programs. The system, called Dual Elliptic Curve, was a random number generator, but it had a deliberate flaw - or “back door” - that allowed the NSA to crack the encryption." https://www.reuters.com/article/us-usa-security-nsa-rsa/exclusive-nsa-infiltrated-rsa-security-more-deeply-than-thought-study-idUSBREA2U0TY20140331 https://www.reuters.com/article/us-usa-security-nsa-rsa/excl...
- mzs 7y ago"random number generator"
- tptacek 7y ago"Dual Elliptic Curve" is an RNG, a PKRNG, that works by using a public key to encrypt its state, which is then directly revealed (as public key ciphertext) to callers (for instance: in the TLS random blob). The problem with PKRNGs has nothing to do with elliptic curves; you could design one with RSA as well. The problem is that for a given public key, there's also a private key, and if you have that private key you can "decrypt" the random value to reveal the RNG's state. That's not a flawed curve that NSA pushed; it's a much more straightforward cryptographic backdoor.
- cafxx 7y ago> Sources say this disclosure from NSA is planned to be the first of many as part of a new initiative at NSA dubbed "Turn a New Leaf," aimed at making more of the agency's vulnerability research available to major software vendors and ultimately to the public. Sounds like "we find so many critical bugs... we don't need all of them to achieve our goals, so let's blow some of them for PR"
- chance_state 7y agoI think it's more like, "We find so many critical bugs, let's blow some of them for PR once we discover that adversaries are using them too."
- swarnie_ 7y agoBull.... A more likely scenario is they've been sat on this for years and finally saw another actor using it in the wild.
- chance_state 7y agoSo... exactly what I said?
- Havoc 7y agoI like NSA being more active, but the concept of trusting NSA on crypto is just never gonna happen. Their core mandate is being able to break it so the whole concept is a non-starter
- tptacek 7y agoThis kind of logic is attractive on message boards but makes little sense in the real world. What NSA needs are NOBUS ("nobody but us") backdoors. Dual_EC is a NOBUS backdoor because it relies on public key encryption, using a key that presumably only NSA possesses. Any of NSA's adversaries, in Russia or Israel or China or France, would have to fundamentally break ECDLP crypto to exploit the Dual_EC backdoor themselves. Weak curves are not NOBUS backdoors. The "secret" is a scientific discovery, and every industrialized country has the resources needed to fund new cryptographic discoveries (and, of course, the more widely used a piece of weak cryptography is, the more likely it is that people will discover its weaknesses). This is why Menezes and Koblitz ruled out secret weaknesses in the NIST P-curves, despite the fact that their generation relies on a random number that we have to trust NSA about being truly random: if there was a vulnerability in specific curves NSA could roll the dice to generate, it would be prevalent enough to have been discovered by now. Clearly, no implementation flaw in Windows could qualify as a NOBUS backdoor; many thousands of people can read the underlying code in Ghidra or IDA and find the bug, once they're motivated to look for it.