Pretty Complex

The Hacker's Business Model

The hacker's business may have become a lot harder. A former hacker noted that his "last full weaponized exploit took eight months to create; today you need a full chain from remote to kernel, and not every stack overflow is exploitable anymore – it's not like in the 90s. In '98, all we needed to create an exploit was a crate of Mate, a weekend, some computers, and no sleep." Technologies like address space layout randomization (ASLR), code fuzzing, and the extended use of canaries make it harder today to exploit software bugs, he further explains. "Someone at Pwn2Own had to chain 17 bugs to finally get code execution." Even though the prize money awarded at Pwn2Own 2018 [26] decreased, the work quality increased in skill level. Today, exploit programmers have to know more about operating systems, platforms, and software and invest more time and qualification in their work. Very likely that is also a reason for price increases.

If not for all the taxpayer money being wasted, the whole development could be seen as very positive: "If I find a bug, I can choose to get the $10 - 20K from Google – not too bad for a few days, maybe weeks of work – or invest months just to find the bug being closed or discovered by someone else in the meantime." With more and more open source, this scenario becomes more and more likely. It seems to be a business decision for a hacker as well.

Ethics

So what about the malware industry? On the one hand, they have enough money to have lots of skilled developers code exploits, even if it takes longer. The large amount of money spent should even make up for occasional losses due to the "death" of a bug before an exploit is finished.

When you talk to these companies' representatives, they usually don't want to talk about this. However, there's one topic they do like to talk about: lack of experts. Both the military and its affiliated businesses can't find experts with skill levels as high as they need. In addition, the ethical differences between the hacker culture and the military's goals pose another problem. Ethical hacking is a big thing; there are even certifications available now. In the meantime, Western military leaders and politicians alike wonder how the Russians motivate their hackers. Although patriotism might have some influence with Russian hackers, ideology is rare – most are more interested in cleaning out other people's bank accounts [27].

Infos

  1. Tim Cook on Google and Facebook: http://time.com/5433499/tim-cook-apple-data-privacy/
  2. Eisenhower's farewell address: https://en.wikipedia.org/wiki/Eisenhower%27s_farewell_address
  3. Data is the new oil: https://www.economist.com/leaders/2017/05/06/the-worlds-most-valuable-resource-is-no-longer-oil-but-data
  4. German IT Security 2017: https://www.bsi.bund.de/EN/Publications/SecuritySituation/SecuritySituation_node.html
  5. Windows zero-day exploit: https://thehackernews.com/2018/10/windows-zero-day-exploit.html
  6. Bleedingbit: https://www.zdnet.com/article/new-bleedingbit-zero-day-vulnerabilities-impact-majority-of-enterprises-at-the-chip-level/
  7. Motherboard article: https://motherboard.vice.com/en_us/article/neqkgm/israel-zero-days-letter-to-american-hackers
  8. Israeli Ministry of Defense letter: https://www.documentcloud.org/documents/4389584-Israel-MoD-Zero-Days-Letter.html
  9. VEP: https://en.wikipedia.org/wiki/Vulnerabilities_Equities_Process
  10. EFF VEP FOIA request: https://www.eff.org/files/2016/01/18/37-3_vep_2016.pdf
  11. New US policy regarding VEP: https://www.theregister.co.uk/2017/11/15/us_governments_vulnerability_disclosure_policy/
  12. "Old Trick Threatens the Newest Weapons" by John Markoff, The New York Times, October 26, 2009: https://www.nytimes.com/2009/10/27/science/27trojan.html
  13. Stuxnet: https://www.businessinsider.com/stuxnet-was-far-more-dangerous-than-previous-thought-2013-11
  14. US cyberwarfare: https://en.wikipedia.org/wiki/Cyberwarfare_in_the_United_States
  15. National Cyber Strategy: https://www.whitehouse.gov/wp-content/uploads/2018/09/National-Cyber-Strategy.pdf
  16. USCYBERCOM: https://www.cybercom.mil/About/Mission-and-Vision/
  17. Zero Days: http://www.zerodaysfilm.com/
  18. Stuxnet II: https://www.bleepingcomputer.com/news/security/new-stuxnet-variant-allegedly-struck-iran/
  19. DoD Cyber Strategy 2018: https://media.defense.gov/2018/Sep/18/2002041658/-1/-1/1/CYBER_STRATEGY_SUMMARY_FINAL.PDF
  20. Kurz, Constanze, and Frank Rieger. Cyberwar – Die Gefahr aus dem Netz, C. Bertelsmann Verlag, 2018: https://netzpolitik.org/2018/cyberwar-der-endlose-krieg/ [in German]
  21. FinFisher: https://en.wikipedia.org/wiki/FinFisher
  22. Adriel Desautels at BDF 2015: https://www.youtube.com/watch?v=VkembqnbNUQ
  23. Zerodium: https://zerodium.com
  24. Rand exploit study: https://www.rand.org/content/dam/rand/pubs/research_reports/RR1700/RR1751/RAND_RR1751.pdf
  25. Google's bug bounty program: https://techcrunch.com/2018/02/07/googles-bug-bounty-programs-paid-out-almost-3m-n-2017/
  26. Pwn2Own 2018: https://securityaffairs.co/wordpress/70358/hacking/pwn2own-2018.html
  27. Russian hackers: https://www.calvertjournal.com/features/show/3781/

Buy this article as PDF

Express-Checkout as PDF
Price $2.95
(incl. VAT)

Buy Linux Magazine

SINGLE ISSUES
 
SUBSCRIPTIONS
 
TABLET & SMARTPHONE APPS
Get it on Google Play

US / Canada

Get it on Google Play

UK / Australia

Related content

  • News

    In the news: Linux Mint Dropping Blueberry Bluetooth Configuration Tool; Fedora 36 Beta Now Has a Release Date; AV Linux MX-21 Released for All Your Audio/Video Production Needs; Slax Proves You Can't Keep a Good Linux Distribution Down; Dirty Pipe Might Be the Most Severe Vulnerability to Hit Linux in Years; and A Decades-Old Linux Backdoor Has Been Discovered.

  • Old Vulnerabilities Are Kept Alive Through Bad Configuration

    HP's annual Cyber Risk report offers a bleak look at the state of IT.

  • Zero Day Exploits Target Flash

    Adobe scrambles to release patches for vulnerable Flash Player.

  • Zero Trust Security

    Some old-school admins are still philosophizing about secure internal networks, but the experts have already moved on: Zero trust architectures use a reliable but complex strategy to protect the network from all threats – inside and outside.

  • New Point-and-Click Exploit Kit Appears in the Wild

    3ROS attack tool lowers the technical bar so anyone can be an intruder.

comments powered by Disqus