← Back to context

Comment by VulgarExigency

3 days ago

The CIA ran one of the world's largest cryptography companies, for DECADES[1]. Are you truly so naive that you believe intelligence agencies that have more to gain from stifling the discovery of vulnerabilities they know of and use wouldn't do so?

[1] https://www.washingtonpost.com/graphics/2020/world/national-...

You should probably realise that the world has radically changed since then. This kind of thing works when you have a significant lead in the field that makes keeping vulnerabilities open sufficiently low risk for your own side. But if your adversaries have similar capabilities, then the calculation changes.

  • Has anything changed? Governments are hoarding undisclosed vulnerabilities, using them as they see fit instead of fixing. Every espionage, surveillance, or war campaign (see Russia v Ukraine, US/Israel v Iran etc) is followed by a ton of burned 0-days.

    >This kind of thing works when you have a significant lead in the field

    No? It works even if the adversary has the same capabilities. It only stops working when everything is fixed.

I believe it is unlikely. (Not because I do not believe NSA is hoarding 0-days, but for many other reasons.)

I'm curious: to any professional vulnerability researchers reading this, what do you think?