Friday, February 12, 2016

The value of an 0day stockpile to the country versus the value of feeling self-rightous



I wanted to follow on from yesterday by discussing Susan Hennessey's post on the NSA, in the sense that like a storybook character, "I Speak For The Trees". She's a former NSA lawyer and she quotes the current head of TAO and I find both those things funny, but there's some very clear misconceptions in industry and her post that I want to clear up.

I am quoting from https://www.lawfareblog.com/good-defense-good-offense-nsa-myths-and-merger below:
Second, there is a mistaken belief that it is not possible to both disclose and exploit a discovered vulnerability. Rob Joyce, head of NSA’s Tailored Access Operations, recently noted that, contrary to popular belief, it is generally more productive for NSA to exploit known vulnerabilities than zero-days.
Rob Joyce and Susan Hennessey are both wrong and if they disagree they are happy to come to INFILTRATE to point out why :). While yes, you don't need 0days to hack, there is a clear OPSEC advantage to having them, and once you have them, to not giving them up. Likewise, situations change and should modern defenses live up to their promise we will be ruing the day we decided to empty our "stockpiles" of vulnerabilities. Thirdly, it is obvious to the technical community (although not to lawyers and policy makers) that 0days are not a simple commodity like grain or oil, but often are highly correlated, composed of smaller parts and techniques, and uniquely non-fungible. Also, it is unproven in the public world whether our vulnerabilities have any significant overlap with Chinese and Russian stockpiles.

Based on all of these things, caution needs to be given to any claims that having the NSA "lean towards defense" in its handling of 0days would be beneficial even in the slightest.

This camo does not protect me from being found by Russian network analysts, but it does get me dates!


It is obvious to any experienced "operator" (as someone who hacks things for a living is known) that while a target may not be patched, when you use a known vulnerability, you are risking an IDS or AV or other defensive mechanism SILENTLY detecting you, and warning the target. The worst case scenario is not being blocked. The worse case scenario is being detected without knowing you are detected!

A brief understanding of how operations and defense play together is important. This is not NSA specific, but imagine you, as a nation-state attacker, use your shiny new IIS 0day against a Russian target. Russia keeps full packet logs of their entire countries network and has for many years. If you give that vulnerability to Microsoft, and fix it, Russia will then go backwards in time and look for all possible exploitation that would fit that pattern. Perhaps this is the goal of the next generation of EINSTEIN as well? ;>

Nation-grade hacking the way the US does it requires expensive implants, so if an implant (like FLAME) is discovered, not only will you lose access to that host, you may lose access to a thousand other hosts, and of course have to deploy an entirely new tool chain. You will, in a sense, have your entire tool-chain wrapped up in a destructive manner similar to having one of your spies discovered, and their case officer found and silently tracked for several years until all your other spies are found.

Because of this, even if you are no longer using an 0day, nation-state hackers are loath to give them to a vendor for fixes even if there may be some minor ancillary benefit. This case is completely lost, for whatever reason, to policy dialog at the moment.

The Chinese often do the opposite, having made a different OPSEC calculation. They use cheap implants that are highly replaceable, for the most part, and so when they realize they have been discovered, they release their exploits widely to avoid attribution. This is not the American way. We need the NSA to stockpile more 0day, not less, to accomplish our long term strategic goals.


Thursday, February 11, 2016

0days


Via Nicholas Weaver

From his latest post on "Trust and the NSA Reorganization":
Put simply, a zero-day is just more powerful than an older exploit. When the offense team knows the value is about to rapid diminish—and the time dimension means IA is more likely to bear a temporary risk—and it’s not difficult to imagine the efforts taken to exploit the vulnerability while it is still unpatchable. It is true that, in this scenario, the damage of early disclosure through offensive use is limited, because another attacker would need time to weaponize the exploit before a patch is released publically, and there is little such an attack could do to change the patch schedule.
So many over-simplifications in one paragraph, and normally I wouldn't care, but people keep doing it and so I want to move us forward a bit. (Excuse the pun :>)


0days, like atoms, are not simplistic and contain many mysterious and fun moving parts!

For anyone who has lived with 0days their whole adult life, listening to lawyers pontificate about them is painfully awkward, like a modern physicist trying to discuss wave-particle interactions with a Middle Ages alchemist.

Clearly 0days are an intoxicant of the highest order, but I'd like to demonstrate some quick subtleties that tie to their underlying wave-particle nature that the simplistic views of them cannot capture.

Let's play, like Einstein did, a quick mind game, that even lawyers can understand. :) I chose for this example the simplest thing I could imagine, but it still demonstrates the complexity of modern day 0day physics.

You have a piece of code with a null pointer deference in it. This code is in a library that handles images or some other common utility, and is widely shared.

The following things are all true:

  • When in the Kernel, this is a local privilege escalation (with a high criticality!)
  • But in modern Windows kernels, this may be entirely mitigated to a local crash (or not, hard to know without close investigation by a super-expert)
  • In a remote service, this vulnerability can only cause a crash
  • Except on certain architectures that sometimes map things at very low addresses (MIPS, for example), in which case it can allow remote code execution (very highest criticality!)
  • In userspace, this null pointer dereference is usually just a crash of the lowest criticality
In the same way that particles can decay into many different other particles and energies, we can track how that vulnerability changes over time. The most simplistic, and completely wrong, view is "Windows of Vulnerability". This the the one lawyers and defenders often cling to, as they don't know any better.

Let's say, for example, Microsoft fixes the null pointer dereference in their kernel, but that code is shared and continues to exist in a media player that many people use on Linux. In addition, they fix it, not with a security advisory, but in a service pack, while continuing to maintain and patch systems running under the older service pack, which is in common use.

Is that vulnerability an 0day, because on systems running the old service pack, it continues to be of high criticality? 

What if Microsoft, instead of fixing the null pointer dereference itself, removes the path of code that reaches that code from userland. Is that vulnerability fixed, or still an 0day? 

What if they DO issue an advisory for it, but Linus Torvalds completely ignores it, and continues to ship mainline kernels with the buggy code, which are exploitable but only on certain Linux kernel configurations? Is that still an "0day" in your terms? Did the bug "die"? 

What if they fix it on all versions of Windows, and issue an advisory, but completely fail to properly patch it? So it is known but unknown? Or is that a new vulnerability spawned out of the destruction of the old one?


What if no patch is ever issued, and nobody ever fixes it, but the product goes out of maintenance and is replaced by other products?

What if only the NSA and the Russians and Chinese know about this null pointer dereference, is it still an 0day?

What if I told you that 0day-reality was more complex and interesting than it first appeared?



Until you have asked all these questions in all their forms - crashed thousands of vulnerability-particles together to understand their underlying nature, it is impossible to make informed decisions as to what to do with them to protect yourself or build cool nano-machines out of them or even what words to use when talking about them. Basically, if you are still talking about archaic "Windows of vulnerability" or "Weaponization" you are wrong at the vocabulary and conceptual level, before you even reached the policy decisions you're trying to offer.

This is the metric you can use to see where you're at: Do you know what a write4 primitive is? Can you tell me how you would transform that into an information leak primitive?

The offensive community is happy to help, so come find us at INFILTRATE and we'll start the process. :)





Tuesday, January 26, 2016

The Elephant in the Room

This here is an elephant in the womb. So cute!

Wassenaar has been a learning experience for everyone involved. Everyone, that is, except the State Department. While Commerce has reached out and been quite open that they thought the initial rule was unlikely to be good, the State Department, which negotiated it in the first place, is as opaque as possible.

Look, there's three major companies in the States that sell penetration testing products. State called none of them before negotiating the rule, and I don't know why people think we can trust them to negotiate the next iteration, other than just ripping it up. 

Because any language that goes into this agreement is going to have subtle and complex issues that affect many segments of our industry. Do you trust State to understand the implications of them enough to allow them to negotiate in realtime on our behalf? Why would you?

I'll let you know when State finally makes an effort to reach out to those of us in the industry. Their claims of "We asked our technical advisory board" run very hollow. You can't help but assume they knew for a fact their technical advisers were not experts in this area and just didn't care.




Friday, January 15, 2016

Will there be a zombie Wassenaar Rule?

We know from the House Hearing this week on Wassenaar that the rule is dead in the United States. But will its zombie haunt us from Europe? That's the question. Because American companies also need their European offices to not be hamstrung, which is why State needs to go back and renegotiate this whole bad dream away.

If you haven't seen the hearing, it is here:



To give you some background: The State Department is playing massive amounts of defense. For example, they tried to pull Ann Ganzer out from the hearing the day before, and substitute her with Vann Van Diepen, who in theory outranks her, but would allow State to say they don't know the details on how this debacle came about, and otherwise obfuscate the issue.

Congressional Staffers immediately saw through that ruse and subpoenaed her. But even trying it makes State look bad.

Mr Van Diepen loves regulations. That's understating it a bit. His background is in Bio/Chem/Nuclear and he LOVES regulations like they are his grandchildren and thinks they can work everywhere, on everything. Nobody else in the room shared his opinions. It's also telling that while State ran their terrible ideas through their own technical advisory panel, they didn't stop to think that maybe calling a couple companies who would be affected would be a good idea. For some reason it's up to every company to be on every government board and advisory committee to keep them from making mistakes like this.

The fact is: I'm a highly public person in the community who runs one of the three companies most directly affected by this regulation, which State knows because THEY ARE A CUSTOMER. It is gross negligence for Ann Ganzer not to have reached out to me before the original language was finalized - and she has yet to do so even now. She claimed during the hearing that knowing what she knew then, she would have made the same choices, but if she knew then what she knew now, she would not. In other words: she didn't bother to learn enough about what she was regulating to make a wise choice.

So sensing this level of commitment to making a rule that works for industry and is rooted in reality, the House committee told her in no uncertain terms where she would be getting her next step from: Industry.

Her last argument is the same one we've covered before on this blog: "None of the other countries who have put this rule into place are having issues!" But of course, they also don't enforce their rules the way we do and we covered why this argument doesn't fly for many reasons in our previous blogpost here.


"I....have no excuses for what I did. It seemed like a good idea at the time."

"I'm not sure if you're going to be in that chair next year. To be blunt."

Wednesday, January 6, 2016

When your strategy fails!

Cyber Regulation Debate


The best regulatory effort...
I want to point out two interesting elements of the recent fronts in the ongoing Cyber Policy War. The first one, is the baffling Wassenaar support from various human rights groups upset at a tiny Italian company named "HackerTeam".

Someone, I'm sure not at all connected to any of these human rights groups, tried to buttress their argument that penetration testing software should be export controlled by uber-double-ironically hacking into HackerTeam and releasing all of their internal emails and documents.

At first, this worked well: HackerTeam had a number of contracts with people who they said they did not (Sudanese Govt, etc.).

However, it also demonstrated that HackerTeam had, in fact, gotten an export control license to do whatever they wanted, which completely undercut the whole rational for the Wassenaar cyber regulations, and in the end, helped cripple support for it. It also pointed out that of course HackerTeam's biggest customers were Western agencies - and if they really wanted to kill off HackerTeam, they could just close their pocket books.

Encryption Debate

Likewise, the crypto debate has always had a number of supporters of key escrow threatening loudly "When a terrorist attack happens, and the terrorists use crypto, this law is going to get shoved down your throat, so you better prepare a nicer version of the law for us and promise to self regulate!"

The FBI Director has been the head cheerleader on this, but everyone else on the key escrow side has parroted these remarks. And lo and behold, once a terrorist attack happened we saw a MASSIVE push to get the argument moved to pressure Apple and Google to change "Their business model" to allow for key escrow/crypto backdoors to happen.

But what also happened? JUNIPER. We still don't know how Juniper found the backdoor in their code. They claim "internal code review" which could very well be language that means "The NSA told us."

But what we do know is that they used the cryptographic primitive (DUAL_EC) that DOES provide for a "secure backdoor". It's the perfect key escrow!  This is what the FBI is asking for! But having a perfect mathematical primitive doesn't help the engineering side of things.

The weakness everyone is complaining about is not a mathematical weakness. It's an engineering weakness. And the Juniper hack completely demonstrated the fragility you introduce when you implement a "Cryptographic backdoor" in your system. Attackers then have a place to use to put implants into your network that are very hard to audit or control.

And, of course, China jumped the gun by requiring key disclosure from companies - the exact thing technology companies have been wanting the US Government to help prevent, which is why they were so angry the FBI was taking the opposite position in the first place.

So now the conversation has swung the other way, but with an EVEN MORE pissed off technology lobby, during an election year no less.

In summary: The crypto backdoor conversation is not one the government can win, in any likely scenario. It is time to move on and deal with the consequences.


Wednesday, December 9, 2015

The Force Awakens: Dec 8 Wassenaar Meeting Notes

I spent my day here so you didn't have to!

So one thing you might know about spooks is that they can "Talk Around" almost any subject. Essentially by using a complex dynamically generated shared key they can sit at a table in a crowded restaurant and converse about secret things in plaintext.

Commerce Dept officials have made an art of doing something similar but without the shared key.

Kevin Wolf (Asst Secretary of Commerce Dept) started off the meeting with a clear indicator that "intrusion software" was not going to get regulated any time soon. Here's how he did it: "As you know, we're coming up to a limit because of the election as to which regulations we can implement. I think we probably have three more slots left. Obviously the Rocket Engines one is almost done, and after that I think maybe we'll work on Night Vision Sensors and Lasers, always important. Lots of good work to do in that area before we're finished. Eventually I think Vehicle Ships and Armor." (Count them - that's three and "intrusion software" is not on that list.)

He also related a story about how in early 2014 they because anxious about the proposed scope of the cyber regulations, which is why it came out as a "proposed rule" and not a finalized rule, something they've not done before. He expected a response but not the "Rather Aggressive Response about the negative unintended consequences" he got. And of course, he mentioned that while various reports (leaked from State) have pointed towards some sort of resolution of this process by tweaking the implementation, the next step won't be a final rule. In fact, he hinted towards an opening for no rule at all by saying "I'm not sure what the next step is, because we're still talking with the US Gov Agencies, going through comments, getting industry input. When there is some sort of consensus, then we'll know what the next step is, but as the person who signs the rule, I can assure you that there are no positions other than the next step won't be a final rule."

Then he left. Randy Wheeler (of Commerce) pointed out that she's glad so many people from industry showed up to talk about cyber regulations and how they realized it was because there was continued "high interest" in the proposed regulation. The next hour was devoted to the proposed Wassenaar "Intrusion Software" rule.

"NAM is National Association of Manufacturers"
Dr. Sergey Bratus did an excellent job of looking at how there is NO WAY TO DEFINE THE STANDARD EXECUTION PATH OF A PROGRAM. This is key to the language of Wassenaar. It points to a need to go back and renegotiate and remove the whole thing. He was very clear and understandable even to a non-technical audience. The one telling question he got was "Is this something we can work around in our implementation?" (Which I assume was from State Dept representation). And also of course "What about the other clauses that relate to avoiding monitoring, exfilling data - do those help?" ("No.", said Sergey)

Afterwards the National Association of Manufacturers pointed out a couple key facts.

  1. Every single one of their members, no matter how small, is international
  2. And hires security researchers to find 0day in their equipment
  3. And thinks this issue is important enough to show up and is not ... in favor of crazy regulations
Just having them there at the table was a sign that this process of getting industry input could go on forever. FS-ISAC spoke briefly over the phone at the last meeting, and there are many more ISACs left to go!

Then (Tom Millar) DHS and (Allen Friedman) NTIA (another branch of Commerce) had their say. They're not allowed to say anything about the regulation in the open. Instead they said "We feel like there may be some <pregnant pause> detrimental impact on the sharing of information in this space with the proposed regulation. "


Afterwards FireEye and IONIC presented some information about how informing their customers about intrusions would be hamstrung.
"Dear State: Your idea is bad and you should feel bad."
Then it was question and answer time, and DHS and NTIA pointed out that not only would the costs of getting a license be passed directly to them and their programs, but also that there would be a "chilling effect" on beneficial information sharing, and that the President has made "information sharing" a clear priority.

One more question that keeps coming up (from State) is "Why are we having all these problems when other countries in the Agreement have implemented the rule and don't seem to be having any issues?" It's a major sticking point for them.

The answer is four-fold.

  1. There are no like-to-like comparisons for other country's industrial bases and the US industrial base. 
  2. Other countries don't enforce export control in the extremely rigorous way the US does. They have a "default we assume you are good unless you are clearly trying to be bad" policy. The US investigates any possible violation as a super-felony with massive liability.
  3. When export control becomes inconvenient, other countries just issue blanket exceptions to local companies (F.E. HackerTeam). 
  4. We have a large level of interest from "security researchers" and our industry is not just protecting their own interests, but looking out for broader principles of freedom.

That last point is the most important, and speaks to the long history of those who are non-lawyers but heavily involved in the resistance effort. In the US, researchers have been absorbed into Govt and Industry and are in positions to make this kind of regulation difficult - but of course, more hard work needs to be done to finally kill it forever.

Keep in mind, right now State's argument is not about how beneficial the rule is. It's about how much of a pain in the ass it would be for them to go back and renegotiate.

----------------------------------------
The comment section:


Sergey's paper:
http://www.cs.dartmouth.edu/~sergey/wassenaar/wa-intent-fallacy.pdf


Thursday, December 3, 2015

NTIA Vulnerability Disclosure Loya Jirga Part Deux

Here we are, gathered in a circle to talk about vulnerability. 


So the NTIA meeting was livestreamed yesterday (and livetweeted) and also you could physically attend! I had good luck with a combination of the conference-call and video system they had, but I know other people did not.

But some of you in our community don't want to sit through the entire day of action packed livestream, or read my twitter feed. So I'm going to provide some perspective below.

First of all, there were a few "moments" that caught my eye during the day.

Wendy Nather (who works in the retail industry space) started the day off by stating her group was interested in a way to tell extortionists, which they get a lot of, from normal vulnerability researchers. I'm not sure this is as hard a problem as it sounds, since extortion is already illegal? I also don't know the scope or scale of this problem in the real world. In the financial industry Immunity has, in the past, gotten requests to look at a potential issue reported from an outsider to validate it or find it if not enough information was given about it. In some cases the original reporter was looking for a gig of some type (aka, leading to money) but to be honest, these cases are not "extortion" and a "bug bounty" would have likely handled it better than any other solution for nominal cost.

Keep in mind, it is literally impossible to prevent full-disclosure on the Internet. There's a genuine Multiverse of vulnerability disclosure possibilities, one of which is tell a vendor about something and then forget about it forever, and the rest are going to make every vendor in the room uncomfortable in some way.

Nevertheless, she said one thing I thought was interesting: "Is there anyone in the room who thinks there are no situations where you should sue vulnerability reporters?" And nobody raised their hands. I would have raised my hand, and not because I'm naturally contrarian, but because it seems obvious and even in the past when someone has hacked into an Immunity server and then told me about how, my instinct was to thank them, not sue them (and then of course we removed that server from the Internet forever).

Some interesting statements were made towards the end of the day by Juniper's representative, who is much closer to the position of many big software houses than a lot of the other speakers (Oracle, for example). In particular, he stated that he would "personally rail against any document" that was a proponent of bug bounties or of an open vulnerability marketplace.

Toyota, at the end asked for a less publicly transparent forum, under Chatham house rules (which prohibit the attribution of statements made during a meeting). NTIA's process is fully transparent to the public, as they pointed out (to their credit), but DHS offered to host such a meeting.

And of course KatieM of Hacker0x1 (who is obviously a proponent of bug bounties) pointed out that in some cases, although a lot of thought goes into "how long before a fix is made available should be acceptable", there's often cases where no fix will ever be made available for various reasons. This was a theme of the day as pointed out by KatieM and Art from US-CERT: When the details of any particular issue were discussed, reasonable people disagreed widely. 

There's always a drumbeat theme from various parts of industry of "If only we could have Commerce sign off on what is GOOD and what is BAD behavior on the part of vulnerability disclosure" - and this, of course, is the clear and present danger I am hoping never happens.

Chances for it actually happening are low, despite a process in place to guide the "community" toward that point if it is at all possible. Most of the people are from West Coast software companies or the Government. There's the thought that "SOMETHING MUST BE DONE" which guides their actions but that said, even after two grueling meetings, there is still nothing even close to consensus what that thing might be.

Keep in mind that these people are all extremely well intentioned, but literally today I was proofreading a deliverable for a critical infrastructure company and I know that for all the noise about Internet of Things the way loss of life happens in the critical infrastructure space is probably SQL Injection, just like in any other space. Stuxnet is the perfect example of this, if you look closely enough.

In other words, the thought that the "safety" space is somehow magically different or more important  or more sensitive than say, the financial space, is more marketing than science. I say this as someone who has hacked all those things. Although, to be fair, this again is one of those issues with wide disagreement.

In summary, there may be massive ancillary benefits to having all these companies all together in one place. The companies clearly would prefer that place to be in Silicon Valley. But it is still highly unlikely a "statement of principles" will be the final result.

--------------------------------------------------------------------------------------------------------------------------

This area reserved for various quotes and resources (unsorted):

Blog from Space Rogue (of Tenable) (either optimistic or super pessimistic, depending on your worldview):
http://www.tenable.com/blog/the-vulnerability-disclosure-debate


Here you can see that Greg disagrees with me about the "Safety" industry being different.

Dino was basically the one "researcher" voice in the room, although obviously others have experience finding bugs.


The FDA is of course doing their thing. But this is pretty far out of range for their capability set (and in fact, maybe all roads lead to the NSA?)

There is palpable anger still for Charlie Miller and Chris for their car hack on a highway shenanigans.

The consequences most companies are worried about are "Their bottom line".

Important to note that FIRST was very active during this meeting and is of course doing a lot of work on vulnerability disclosure issues for multi-party - as are many other people and groups. This is something that keeps coming up - every group on Earth is working on making a methodology for disclosure.