{"id":12350,"date":"2016-04-15T11:54:54","date_gmt":"2016-04-15T15:54:54","guid":{"rendered":"http:\/\/www.megalextoria.com\/wordpress\/?p=12350"},"modified":"2016-04-15T11:54:54","modified_gmt":"2016-04-15T15:54:54","slug":"faq-apple-the-fbi-and-zero-days","status":"publish","type":"post","link":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/2016\/04\/15\/faq-apple-the-fbi-and-zero-days\/","title":{"rendered":"FAQ: Apple, the FBI, and Zero Days"},"content":{"rendered":"<h2 class=\"p1\"><span class=\"s1\">What We Know about the Vulnerabilities Equities Process and Government Hacking<\/span><\/h2>\n<p>Since the FBI\u2019s <a href=\"https:\/\/www.eff.org\/deeplinks\/2016\/03\/fbi-breaks-iphone-and-we-have-some-questions\">announcement<\/a> last month that it had successfully accessed data on a locked iPhone used in the San Bernardino shootings, there has been intense speculation about exactly how the Bureau got in. If you had \u201ciOS zero day\u201d in the office pool, you\u2019re a winner. According to a <a href=\"https:\/\/www.washingtonpost.com\/world\/national-security\/fbi-paid-professional-hackers-one-time-fee-to-crack-san-bernardino-iphone\/2016\/04\/12\/5397814a-00de-11e6-9d36-33d198ea26c5_story.html\">new report<\/a> in the Washington Post, the FBI paid \u201cprofessional hackers\u201d for information about a \u201cpreviously unknown software flaw\u201d in Apple\u2019s iOS operating system, which allowed the FBI to disable security features and then brute-force the passcode on the phone. As a result of this outside help, the Justice Department dropped its attempt to compel Apple to assist in accessing the phone, despite previously arguing that Apple\u2019s assistance was essential.<\/p>\n<p>For many, the FBI\u2019s sudden change in tactics, abandoning its legal case in favor of a technical solution, has raised <a href=\"https:\/\/www.washingtonpost.com\/posteverything\/wp\/2016\/03\/29\/your-iphone-just-got-a-lot-less-secure-and-the-fbi-is-to-blame\/\">questions<\/a> about whether there are any practical limits on the government\u2019s use of flaws to \u201chack\u201d devices and software. It also raises questions about whether it ever has to tell\u2014or voluntarily tells\u2014companies about these vulnerabilities. This post attempts to answer some of these frequently asked questions.<\/p>\n<p><b><a id=\"does-gov-use-vulns-often\"><\/a>Does the government often use vulnerabilities to \u201chack\u201d or exploit the software and devices we all use?<\/b><\/p>\n<p>Yes. The Apple case was especially high profile, but the FBI and other agencies exploit software flaws all the time. While we don\u2019t know of any comprehensive list, it happens in a wide variety of cases. The government has admitted it uses vulnerabilities for \u201coffensive purposes\u201d in \u201ccyber operations,\u201d law enforcement operations, and counterintelligence. Cyber operations might include <a href=\"https:\/\/en.wikipedia.org\/wiki\/Stuxnet\">Stuxnet<\/a>, in which the government reportedly used previously unknown vulnerabilities or \u201czero days\u201d in Microsoft Windows to sabotage the Iranian nuclear program by destroying centrifuges. In the law enforcement context, the government routinely exploits vulnerabilities to install malware, also called <a href=\"https:\/\/www.justsecurity.org\/15018\/justice-department-proposal-massive-expand-fbi-extraterritorial-surveillance\/\">\u201cnetwork investigative techniques\u201d<\/a> or NITs, to identify suspects and conduct remote surveillance. Some of the agencies that have admitted or been shown using vulnerabilities to engage in hacking include the FBI, DEA, NSA, and CIA.<\/p>\n<p><b><a id=\"how-does-gov-find-flaws\"><\/a>How does the government find out about these flaws?<\/b><\/p>\n<p>As with the Apple case, the government has admitted it purchases information about flaws in commonly used software and devices, sometimes reportedly <a href=\"http:\/\/www.nytimes.com\/2013\/07\/14\/world\/europe\/nations-buying-as-hackers-sell-computer-flaws.html?_r=0\">paying large sums<\/a>. Some agencies like the FBI have <a href=\"https:\/\/www.washingtonpost.com\/world\/national-security\/meet-the-woman-in-charge-of-the-fbis-most-contentious-high-tech-tools\/2015\/12\/08\/15adb35e-9860-11e5-8917-653b65c809eb_story.html\">in-house units that actively exploit flaws<\/a>.<\/p>\n<p><b><a id=\"stockpile\"><\/a>Does the government \u201choard\u201d or \u201cstockpile\u201d vulnerabilities in order to hack users?<\/b><\/p>\n<p>It\u2019s unclear. The White House Cybersecurity Coordinator Michael Daniel <a href=\"http:\/\/www.wired.com\/2014\/11\/michael-daniel-no-zero-day-stockpile\/\">denied<\/a> that the government has a \u201cRaiders of the Lost Ark style\u201d stockpile of vulnerabilities, while the NSA\u00a0<a href=\"https:\/\/www.nsa.gov\/public_info\/news_information\/2015\/ncsam\/discovering_solving_sharing_it_solutions.shtml\">claimed<\/a> that it has historically disclosed 91% of the vulnerabilities it discovers. But other evidence points toward agencies like CIA, FBI, and NSA holding on to at least some flaws for long periods. In one case involving a Network Investigative Technique, technologists have\u00a0<a href=\"https:\/\/motherboard.vice.com\/en_uk\/read\/the-fbi-may-be-sitting-on-a-firefox-vulnerability\">suggested the FBI may have withheld a previously unknown vulnerability in Firefox for more than a year.<\/a><\/p>\n<p><b><a id=\"what-is-vep\"><\/a>What is the Vulnerabilities Equities Process (\u201cVEP\u201d) and can I read it?<\/b><\/p>\n<p>The Vulnerabilities Equities Process is the policy the government uses to decide whether to disclose information about security vulnerabilities or instead withhold this information for its own purposes, including law enforcement, intelligence collection, and &#8220;offensive&#8221; exploitation.\u00a0<a href=\"http:\/\/www.wired.com\/2014\/11\/michael-daniel-no-zero-day-stockpile\/\">According to the White House<\/a>, the VEP has a \u201cstrong bias\u201d in favor of disclosure.<\/p>\n<p>Thanks to EFF\u2019s Freedom of Information Act <a href=\"https:\/\/www.eff.org\/cases\/eff-v-nsa-odni-vulnerabilities-foia\">lawsuit<\/a>, the government has publicly released the VEP (with some redactions). You can read it <a href=\"https:\/\/www.eff.org\/document\/vulnerabilities-equities-process-january-2016\">here<\/a>.<\/p>\n<p><b><a id=\"how-does-vep-work\"><\/a>How does the VEP work?<\/b><\/p>\n<p>According to the policy, when the government learns of a new flaw\u2014either by discovering it on its own or buying it from third parties\u2014it must submit the flaw to an interagency group. This group has officials from across the government representing various \u201cequities\u201d\u2014the competing interests in disclosing the flaw to strengthen security and exploiting it for offensive purposes.<\/p>\n<p><b><a id=\"iOS-vep\"><\/a>Has the VEP interagency group looked at the iOS flaw? How long does it take?<\/b><\/p>\n<p>We don\u2019t know. The Washington Post story suggests that it has not yet been submitted to the review group, although the policy states that discovery of a flaw, including by a contractor, should start the process.<\/p>\n<p><b><a id=\"will-fbi-share\"><\/a>Will the FBI have to share the iOS flaw with Apple? Does the VEP ever require the government to share vulnerabilities with the companies or the public?<\/b><\/p>\n<p>No. The VEP only requires that newly discovered flaws be considered for disclosure. Despite the \u201cstrong bias\u201d in favor of disclosure, there are exceptions for law enforcement and intelligence use. Reuters reports that in the San Bernardino case, the outside sellers retained\u00a0<a href=\"http:\/\/www.reuters.com\/article\/us-apple-encryption-whitehouse-idUSKCN0XB05D\">&#8220;sole legal ownership&#8221;<\/a>\u00a0of the iOS zero day, suggesting that it will not be disclosed under the VEP.<\/p>\n<p><b><a id=\"vep-effective\"><\/a>How effective is the VEP?<\/b><b>\u00a0<\/b><\/p>\n<p>We don\u2019t know, but the answer historically has been \u201cnot very effective.\u201d Although the VEP was adopted in 2010, reports indicate that it was not \u201cimplemented\u201d properly until April 2014. As further evidence, a panel of experts appointed by President Obama <a href=\"https:\/\/www.whitehouse.gov\/blog\/2013\/12\/18\/liberty-and-security-changing-world\">recommended<\/a> in December 2013 that vulnerabilities be disclosed in \u201calmost all cases.\u201d Meanwhile, the government has not released any information to back up its claims that it regularly discloses vulnerabilities to software vendors.<b>\u00a0<\/b><\/p>\n<p><b><a id=\"what-can-be-done\"><\/a>What can be done?<\/b><\/p>\n<p>EFF believes that much more oversight of the government\u2019s use of vulnerabilities is needed. As a first step, Congress could require that agencies report on the numbers of vulnerabilities the government has acquired and disclosed. It could also pass a law codifying the \u201cstrong bias\u201d in favor of disclosure.<\/p>\n<p>Meanwhile, at least in criminal cases, defendants who have been the target of exploits may be able to argue that they are entitled to information about the flaw if it is <a href=\"https:\/\/www.law.cornell.edu\/rules\/frcrmp\/rule_16\">\u201cmaterial\u201d<\/a> to their defense.<\/p>\n<p>Source: <em><a href=\"https:\/\/www.eff.org\/deeplinks\/2016\/04\/will-apple-ever-find-out-how-fbi-hacked-phone-faq\">FAQ: Apple, the FBI, and Zero Days | Electronic Frontier Foundation<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>What We Know about the Vulnerabilities Equities Process and Government Hacking Since the FBI\u2019s announcement last month that it had successfully accessed data on a locked iPhone used in the San Bernardino shootings, there has been intense speculation about exactly how the Bureau got in. If you had \u201ciOS zero day\u201d in the office pool, you\u2019re a winner. According to a new report in the Washington Post, the FBI paid \u201cprofessional hackers\u201d for information about a \u201cpreviously unknown software flaw\u201d in Apple\u2019s iOS operating system, which allowed the FBI to disable security features and then brute-force the passcode on the phone. As a result of this outside help, the Justice Department dropped its attempt to compel Apple to assist in accessing the phone, despite previously arguing that Apple\u2019s assistance was essential. For many, the FBI\u2019s sudden change in tactics, abandoning its legal case in favor of a technical solution, has raised questions about whether there are any practical limits on the government\u2019s use of flaws to \u201chack\u201d devices and software. It also raises questions about whether it ever has to tell\u2014or voluntarily tells\u2014companies about these vulnerabilities. This post attempts to answer some of these frequently asked questions. Does the government [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15],"tags":[194,687,1979],"class_list":["post-12350","post","type-post","status-publish","format-standard","hentry","category-news-and-politics","tag-apple","tag-fbi","tag-zero-days"],"_links":{"self":[{"href":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/wp-json\/wp\/v2\/posts\/12350","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/wp-json\/wp\/v2\/comments?post=12350"}],"version-history":[{"count":0,"href":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/wp-json\/wp\/v2\/posts\/12350\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/wp-json\/wp\/v2\/media?parent=12350"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/wp-json\/wp\/v2\/categories?post=12350"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.megalextoria.com\/wordpress\/index.php\/wp-json\/wp\/v2\/tags?post=12350"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}