{"id":2060,"date":"2017-01-18T04:17:58","date_gmt":"2017-01-18T04:17:58","guid":{"rendered":"https:\/\/joeuchill.org\/?p=2060"},"modified":"2017-01-18T04:17:58","modified_gmt":"2017-01-18T04:17:58","slug":"u-s-cyber-arsenal-is-smaller-than-imagined-on-purpose-the-hill-august-9-2016","status":"publish","type":"post","link":"https:\/\/joeuchill.org\/?p=2060","title":{"rendered":"U.S. cyber arsenal is smaller than imagined \u2014 on purpose \/ The Hill, August 9, 2016"},"content":{"rendered":"<p>The United States government may be stockpiling far fewer digital arms than anyone expected, according to new research.<\/p>\n<p>The study centers around \u201czero day\u201d exploits, which are soft spots in product security that companies are not aware of or have not patched. Depending on the severity of a vulnerability, zero days sell on the slightly-more-legal-than-black market known as a gray market for tens of thousands to more than a million dollars a piece.<\/p>\n<p>Governments are the primary buyers of zero days and spend vast resources researching them. Since the U.S. is not short on capital and invests heavily into its offensive cyber warfare positions, even people in the zero day business assumed it held a few hundreds of these vulnerabilities.<\/p>\n<p>\u201cToday, the best, surest 0-days acquirer is the [National Security Agency], in truth a really insatiable one,\u201d David Vincenzetti, founder and CEO of the military spyware contractor Hacking Team, wrote in one his company\u2019s emails leaked last year.<\/p>\n<p>\u201cToday, the largest 0-days producers are U.S. companies, possibly large U.S. defense contractors, selling their stuff directly and possibly exclusively to the NSA.\u201d<\/p>\n<p>But new research shows that might not be the case.<\/p>\n<p>Jason Healey, a senior researcher at Columbia University, says the number of vulnerabilities held by the government is closer to 50.<\/p>\n<p>\u201cI don&#8217;t think this is just a surprise to the DEFCON community, however, it was a surprise to me, and other policymakers as well,\u201d said Healey.<\/p>\n<p><!--more-->Healey, a former director of cyber infrastructure protection for the George W. Bush administration, believes that the rapid pace of obsolescence of zero days, paired with an aggressive policy of notifying manufacturers of vulnerabilities rather than keeping them and using them, means the government keeps far fewer on hand than imagined.<\/p>\n<p>Healey notes it would be extremely difficult to keep a large arsenal of zero days on hand, as computer vulnerabilities spoil on the vine if they are not used quickly.<\/p>\n<p>The government is racing vendors and researchers constantly discovering and patching new vulnerabilities, nation states that also use zero days \u2014 once one is used in the wild, it only stays secret for an average of 300 more days \u2014 and people who are constantly upgrading equipment.<\/p>\n<p>The longer the NSA sits on a bug, the less likely it is the agency can ever use it. At the same time, the longer the NSA sits on a bug, the more likely it is that someone will use it against the U.S., its companies or its interests.<\/p>\n<p>Healey estimates that over a year, half the stockpile will become obsolete. Even without using any zero days, maintaining a stockpile of 100 means discovering or purchasing 50.<\/p>\n<p>This year, the Electronic Frontier Foundation successfully sued the government to release its policies for keeping a vulnerability. From that, and from news reports, Healey has pieced together that since 2014 \u2014 around the time the NSA had to deny reports it had been using the infamous Heartbleed bug \u2014 the Obama administration has been strictly enforcing a policy that forces agencies wishing to keep a zero day to justify the reason to review board.<\/p>\n<p>To keep a vulnerability, according to a 2014 list of criteria, the board weights its intelligence value against the security risk of not reporting the problem. Otherwise, the default is for an agency to notify vendors of any vulnerabilities it discovers.<\/p>\n<p>Confirming public information with private interviews, Healey said the United States does not end up reviewing many of the zero days it finds. Of those it reviews, it keeps extremely few.<\/p>\n<p>By an NSA estimate, it reports more than 90 percent of the bugs it has ever found. That estimate is likely weighted heavily to one side.<\/p>\n<p>In autumn 2014, two sources told Healey that no requests had been accepted so far that year.<\/p>\n<p>Combining the low number of zero days the U.S. keeps with the supply lost to use or obsolescence and the likely numbers the U.S. had on hand before 2014, Healey calculated that there are likely no more than 50 or 60 vulnerabilities in the arsenal at any given time.<\/p>\n<p>It is a good system, he said, but one with a few quirks.<\/p>\n<p>For example, when the FBI purchased a vulnerability to unlock a cellphone belonging to one of the San Bernardino, Calif., shooters, Healey thought it should have been required to report by the governing criteria.<\/p>\n<p>The FBI did not do so.<\/p>\n<p>Healey said methods to circumvent being required to report still need to be ironed out \u2014 even though it does not appear any are widely used.<\/p>\n<p>\u201cIt\u2019s not really clear whether or not you can use the vulnerability while it goes through the process,\u201d he said.<\/p>\n<p>And nothing specifically prevents someone from hiring third parties to break into devices without disclosing methods to the U.S. government or to operate under non-disclosure agreements.<\/p>\n<p>The Vulnerabilities Equity Process ends with the Obama administration \u2014 it\u2019s a directive, not a legality.<\/p>\n<p>Healey hopes it will be taken up as legislation. But he cautions that it only works if agencies are funded in a way that makes vulnerabilities replicable enough to abide by the rules.<\/p>\n<p>\u201cI get the sense that we are not funding properly,\u201d he said. \u201cThe executive branch is still getting its act fully together. Maybe some funding can help them out.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The United States government may be stockpiling far fewer digital arms than anyone expected, according to new research. The study centers around \u201czero day\u201d exploits, which are soft spots in product security that companies are not aware of or have not patched. Depending on the severity of a vulnerability, zero days sell on the slightly-more-legal-than-black [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_exactmetrics_skip_tracking":false,"_exactmetrics_sitenote_active":false,"_exactmetrics_sitenote_note":"","_exactmetrics_sitenote_category":0},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/joeuchill.org\/index.php?rest_route=\/wp\/v2\/posts\/2060"}],"collection":[{"href":"https:\/\/joeuchill.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/joeuchill.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/joeuchill.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/joeuchill.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2060"}],"version-history":[{"count":1,"href":"https:\/\/joeuchill.org\/index.php?rest_route=\/wp\/v2\/posts\/2060\/revisions"}],"predecessor-version":[{"id":2061,"href":"https:\/\/joeuchill.org\/index.php?rest_route=\/wp\/v2\/posts\/2060\/revisions\/2061"}],"wp:attachment":[{"href":"https:\/\/joeuchill.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2060"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/joeuchill.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2060"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/joeuchill.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2060"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}