Tech●●●●●Difficulty 5 of 5

Should governments tell vendors about the flaws they find, or keep them for spying?

The NSA held a Windows flaw for more than five years; when it leaked, it powered WannaCry.

▶ Start the story

Every government that finds a serious software flaw faces a choice: tell the vendor so it gets fixed, or keep it secret to use against adversaries. The United States has a process for it, the Vulnerabilities Equities Process, which decides case by case whether to disclose a zero-day to the public to improve general computer security, or to keep it secret for offensive use. It was developed in 2008-2009 and became public in 2016, after a freedom-of-information request by the Electronic Frontier Foundation.

The case for keeping secrets is intelligence. Reasons states keep a vulnerability secret include wanting to use it offensively. Zero-day exploits grew in importance once big companies encrypted their servers and messages, because the easiest way to a user's data became intercepting it before it was encrypted. The case for disclosure is that disclosing the vulnerability reduces the risk that consumers and all users of the software will be victimized by malware or data breaches.

The best-known test case is EternalBlue, an NSA exploit built on a zero-day flaw in Windows. The NSA did not tell Microsoft for several years, holding onto it for more than five years before the breach forced its hand. When a group called the Shadow Brokers stole it and it was released publicly in 2017, WannaCry used it to attack computers around the world, with over $8 billion in damages estimated across 150 countries.

EternalBlue: from secret to worldwide worm
  1. Before 2017

    The NSA holds the flaw for more than five years without telling Microsoft

  2. March 2017

    Microsoft issues a patch after the NSA warns it

  3. 14 April 2017

    The Shadow Brokers release EternalBlue publicly

  4. 12 May 2017

    WannaCry spreads using it

Following public pressure for greater transparency in the wake of the Shadow Brokers affair, the US government published more about the process in November 2017.

Quiz me

0/3

  1. 1.Why do states sometimes keep a zero-day secret?
  2. 2.What does the EternalBlue case suggest about stockpiling flaws?
  3. 3.Which fact makes stockpiling riskier, according to the research cited?

Recap

Every secret zero-day is a bet that nobody else will find or steal it.

💡 A trick to remember it · A secret crack in a shared lock: a tool for spies while it stays secret, a danger to everyone once someone else finds it.

Surprising fact · EternalBlue was kept secret for years, then leaked and used by WannaCry.

Sources (6)

No source, no claim. Every fact in this lesson (16 claims) cites at least one of these.

  1. [1]Vulnerabilities Equities Process · Wikipedia
  2. [2]EternalBlue · Wikipedia
  3. [3]Zero-day vulnerability · Wikipedia
  4. [4]Heartbleed · Wikipedia
  5. [5]Crypto Wars · Wikipedia
  6. [6]Coordinated vulnerability disclosure · Wikipedia
More lessons in 💻 Tech (3) See all tech lessons →

One more light on your map.

Get one lesson like this every day, about the things you love. Free, in two or five minutes.

Get the share card for this lesson ↗