Week 8 Discussion 1

profilemid908
u.s._government_use_of_zero-day.docx

U.S. Government use of zero-day exploits

Early in the textbook reading for this week there is a discussion of how the government has some inherent conflicts among its role in cybersecurity. In particular, the conflict between its offensive and defensive missions.

 

This conflict is probably most obvious in the government's use of zero-day exploits, which was illustrated very clearly by Stuxnet.

 

Even though there hasn't been any official acknowledgment, it's pretty clear that the U.S. had at least a supporting role in the creation of Stuxnet. And Stuxnet exploited four different zero-day vulnerabilities in Windows.

 

That means that the U.S. government was aware of four vulnerabilities in Windows for which there was no patch available. Every similar Windows computer in the United States, including the government and the military, were vulnerable. Someone in the government made the decision that the ability to exploit those vulnerabilities in an offensive operation was more important than the threat that someone else might exploit those vulnerabilities against any other computer in the United States.

 

In fact, the discovery of the details of Stuxnet was the first time that this conflict between offensive and defensive missions was really brought to the attention of the public. But now it get raised fairly often, usually as the result of some news story.

 

One such event happened in the summer of 2015, when the Italian company Hacking Team was itself hacked. Hacking Team is one of many companies who sell zero-day exploits, perfectly legally. Sometimes they sell the exploits by themselves, but just as often, they sell the exploits as part of software packages that simplify other hacking activities. For instance, Hacking Team includes zero-day exploits as part of surveillance software that they sell to some less-than-friendly governments, and likely other organizations even less friendly.

 

Interestingly, like the cybersecurity firm HBGary Federal, Hacking Team was itself hacked by hacktivists using not particularly sophisticated exploits of their own. And the result was the release of something like 400GB of data, including multiple zero-day exploits.

 

How does this tie back to the U.S. Government?

 

In two ways. First of all, the U.S. Government is generally considered to be one of the biggest purchasers of zero-day exploits, though that is not officially acknowledged. Now I doubt that the U.S. Government purchased Hacking Team's software, they have their own capabilities. But they may have purchased other zero-day exploits from them.

 

The other way this ties back to the U.S. Government is speculation that if hacktivists were able to hack into Hacking Team, then surely the U.S. could have. And if they had, then they would have known about those zero-day exploits.

 

And unlike Stuxnet, where the U.S. government could at least have argued that it was likely that no one else knows about those exploits, in this case, there's no doubt that others know about the exploits, and yet the U.S. government still keeps them secret.

 

Anyway, that's a long introduction to this article by Bruce Schneier:

 

http://journal.georgetown.edu/hacking-team-and-the-nsa/

 (Links to an external site.)