Should governments tell vendors about the flaws they find, or keep them for spying?
The NSA held a Windows flaw for more than five years; when it leaked, it powered WannaCry.
▶ Start the storyEvery government that finds a serious software flaw faces a choice: tell the vendor so it gets fixed, or keep it secret to use against adversaries. The United States has a process for it, the Vulnerabilities Equities Process, which decides case by case whether to disclose a zero-day to the public to improve general computer security, or to keep it secret for offensive use. It was developed in 2008-2009 and became public in 2016, after a freedom-of-information request by the Electronic Frontier Foundation.
The case for keeping secrets is intelligence. Reasons states keep a vulnerability secret include wanting to use it offensively. Zero-day exploits grew in importance once big companies encrypted their servers and messages, because the easiest way to a user's data became intercepting it before it was encrypted. The case for disclosure is that disclosing the vulnerability reduces the risk that consumers and all users of the software will be victimized by malware or data breaches.
The best-known test case is EternalBlue, an NSA exploit built on a zero-day flaw in Windows. The NSA did not tell Microsoft for several years, holding onto it for more than five years before the breach forced its hand. When a group called the Shadow Brokers stole it and it was released publicly in 2017, WannaCry used it to attack computers around the world, with over $8 billion in damages estimated across 150 countries.
Before 2017
The NSA holds the flaw for more than five years without telling Microsoft
March 2017
Microsoft issues a patch after the NSA warns it
14 April 2017
The Shadow Brokers release EternalBlue publicly
12 May 2017
WannaCry spreads using it
Following public pressure for greater transparency in the wake of the Shadow Brokers affair, the US government published more about the process in November 2017.
Quiz me
0/3
Recap
Every secret zero-day is a bet that nobody else will find or steal it.
💡 A trick to remember it · A secret crack in a shared lock: a tool for spies while it stays secret, a danger to everyone once someone else finds it.
Surprising fact · EternalBlue was kept secret for years, then leaked and used by WannaCry.
Connects to
- ☢️ How did a computer worm wreck uranium centrifuges?
- 💔 How did one bug put much of the internet at risk, from Heartbleed to Log4Shell?
- 🔒 How did ransomware take hospitals and a fuel pipeline hostage?
- 🗝️ Should governments hold a key to every lock? The fight over encryption backdoors
- 🕳️ What is a zero-day, and why do companies pay hackers to find bugs?
- ✂️ Why is rock paper scissors a serious piece of mathematics?
- 🏭 Why do free markets make too much pollution, and can a price fix it?
Sources (6)
No source, no claim. Every fact in this lesson (16 claims) cites at least one of these.