Written evidence submitted by Dr Christopher Soghoian (IPB0045)

  1. Introduction

 

The Investigatory Powers Bill would explicitly permit the government to hack into computers, through the use of targeted equipment interference warrants.[1] These warrants would not only permit the hacking of individual targets, but bulk hacking operations in which multiple devices, used or owned by multiple people, are hacked pursuant to a single order.[2]

 

Since at least 2001, law enforcement agencies in the United States have used hacking and sophisticated surveillance software (commonly referred to by technical experts as malware) as part of criminal and national security investigations.[3] As with many surveillance technologies used by the U.S. government, law enforcement agencies have intentionally kept the public in the dark regarding their use of this invasive technology.

 

In spite of the widespread secrecy regarding law enforcement hacking, enough information has come to light that I am able to describe a few specific public policy issues associated with, and in some cases, inherent in this use of this surveillance technology. If you do grant hacking powers to your law enforcement agencies, hopefully you will learn from our mistakes and include specific safeguards to protect the British public from the harms I describe in this document.

 

  1. The use of deception and impersonation to deliver malware

 

Often, the most difficult part of a law enforcement hacking operation is the task of getting their surveillance software onto the computer of the target. If law enforcement agencies control a website that the target regularly visits or have physical access to the target’s computer, malware delivery is relatively straightforward. Otherwise, they often have to try and trick the target into downloading a malicious email attachment or clicking on a malicious link in an email.

 

Just as most drug dealers are unlikely to sell drugs to a police officer dressed in uniform, online criminals are unlikely to download an attachment or click on a link in an email if the sender is the Federal Bureau of Investigations or the National Crime Agency. As such, just as the police go undercover to conduct drug busts, law enforcement agencies also resort to deception and impersonation in order to deliver malware.

 

Impersonation and deception certainly make it easier for law enforcement agencies to successfully infect the computers of targets with malware. There are, however, significant public policy concerns associated with the use of impersonation by the government, particularly if and when the police impersonate doctors, lawyers, journalists, and the clergy, who can only perform their vital roles in our society if they are trusted by the public.

 

One year ago, while researching the Federal Bureau of Investigation’s use of malware, I discovered that the agency had, in 2007, impersonated the Associated Press in an effort to trick a teenager into clicking on a malicious link in an email message.[4] Although FBI agents had first sought and obtained a search warrant, the warrant application did not reveal to the court the means they intended to employ to deliver their malware, nor did they reveal that they planned to impersonate a journalist.[5] Thus, the magistrate judge responsible for overseeing law enforcement’s use of invasive surveillance techniques was only able to evaluate the invasion of privacy by the government—which was relatively modest, as the software merely collected basic information from the computer of the target. The court was unable to oversee the far more problematic aspect of this operation—the impersonation by the government of a trusted news organization. Indeed, it is quite possible that had the FBI agents told the court what they planned to do, the magistrate might have refused to approve the warrant.

 

Although news articles at the time had revealed the FBI’s use of malware, the public remained in the dark regarding the agency’s impersonation of a journalist until I revealed it in 2014.[6]  Once the FBI’s use of this tactic was revealed, it was widely condemned by news organizations.[7] In contrast, FBI Director James Comey defended his agency’s impersonation of the Associated Press, calling it “proper and appropriate.” Comey later told journalists that he was unwilling to forswear the use of similar tactics in the future, stating that “I’m not willing to say never. Just as I wouldn’t say that we would never pose as an educator or a doctor.”[8]

 

The FBI’s impersonation of the Associated Press is the only example I know of where a law enforcement agency impersonated an innocent, trusted entity in an effort to deliver malware. There are, however, several examples of intelligence agencies engaging in similar tactics. For example, in 2012, researchers revealed that Flame, a sophisticated piece of malware, later revealed to be the work of the US and Israel,[9] had spread by impersonating the software update service built into Microsoft’s Windows operating system.[10] One expert described the ability to successfully impersonate Microsoft as the “Holy Grail of malware writers.”[11]

 

By impersonating a trusted software security update mechanism, these governments risked harming global Internet cybersecurity by giving users a reason to doubt the safety of automatic software updates.[12] There are strong parallels between the impersonation of a critical piece of cybersecurity infrastructure and the sham polio vaccination program established by the CIA in an attempt to locate Osama bin Laden.[13] Whatever the possible intelligence value of that operation was more than outweighed by the catastrophic impact it had on legitimate polio vaccination efforts.[14]

 

Recommendation: Government agencies engaged in hacking operations should be prohibited from impersonating trusted professions, including doctors, lawyers, journalists, and the clergy. They should also be prohibited from impersonating, via technical means, app stores and other critical cybersecurity infrastructure used by software companies to deliver security updates.

 

  1. Bulk hacking and general warrants

 

In addition to the targeted delivery of malware to specific targets, the FBI has, since at least 2013, engaged in bulk hacking. In a number of operations targeting users of so called Dark Web forums, the FBI has attempted to deliver malware to every computer that visited a particular website or server. This method of malware delivery, referred to as a watering hole attack by computer security experts, raises a number of troubling issues, in addition to the more general policy issues associated with the use of malware by law enforcement.

 

In February 2015, the FBI launched a watering hole attack targeting visitors to Playpen, a child pornography forum only accessible via Tor.[15] According to the FBI, the site had more than 214,000 registered users.[16] Although the search warrant in this case remains sealed, the FBI’s boilerplate warrant application for watering hole operations targeting Tor sites includes language requesting authority to deliver malware to “any user or administrator who logs into [the target website] by entering a username and password.”[17]

 

Even if the FBI was able to demonstrate probable cause that every single one of the 214,000 registered users of this website was violating the law, a single court order authorizing the government to hack into so many computers is no longer a search warrant, identifying places or persons to be searched, but a general warrant, authorizing the government to search the population of a decent sized city. Quite simply, there is no way for a single magistrate judge to engage in meaningful oversight of hacking at such scale, even more so when the computers of the targets are almost certainly located around the world.

 

That law enforcement officers can now hack 214,000 computers with the same effort as one or two computers is a testament to the power of modern technology and a stark reminder that the marginal cost of surveillance has plunged.[18] As Judge Richard Posner observed a few years ago, “technological progress poses a threat to privacy by enabling an extent of surveillance that in earlier times would have been prohibitively expensive.”[19] However, just because law enforcement agencies are now capable of hacking at scale, doesn’t automatically mean that they should be permitted to do so.

 

Recommendation: Bulk hacking operations and watering hole attacks should be prohibited.

 

  1. Bulk hacking and cloud computing

 

In August 2013, all of the websites hosted by Freedom Hosting—a service that hosted websites through the Tor network—began serving an error message to visitors with hidden code embedded in the web page.[20] That code was specifically designed to exploit a security flaw in a version of the Firefox web browser used to access Tor hidden servers.[21] According to an FBI agent who later testified in an Irish court, the Freedom Hosting service hosted at least 100 child pornography websites.[22] But the service also hosted a number of legitimate sites, including TorMail, a web-based email service that could only be accessed over the Tor network, and The Hidden Wiki, which one news site described as the “de facto encyclopedia of the Dark Net.” Even though these sites were serving lawful content, the FBI’s watering hole attack was performed in an overbroad manner, delivering malware to visitors to all of the Freedom Hosting

sites, not just to visitors to those sites that were engaged in the distribution of illegal content.

 

We are now firmly in the age of cloud computing, in which hundreds of websites may share resources provided by the same powerful servers. Law-abiding Internet users have no way of knowing if the sites that they are visiting are hosted on the same physical server as a site that facilitates illegal conduct. That websites with a potential connection to illegal conduct are hosted on the same server as legitimate websites is not sufficient reason to permit law enforcement agencies to hack into the computers of every person who interacts with a particular server.

 

The court order that the FBI presumably obtained before launching watering hole attacks targeting the visitors to the many Freedom Hosting websites is not public. As such, it is impossible to know what the FBI agents told the court, or what the court authorized. We do not know if the judge authorized the FBI to deliver malware to all visitors to all sites running on the server owned by Freedom Hosting, or if the FBI agents exceeded the scope of the warrant. In any event, this episode demonstrates one of the major risks of bulk hacking and of the importance of strict limits on the use of such capabilities, particularly when targeting visitors to sites that are hosted in the cloud.

 

Recommendation: If bulk hacking operations are permitted, government agencies should be required to narrowly target their use of malware so that innocent persons who are visiting lawful, legitimate content on sites hosted on the same servers (“in the cloud”) are not incidentally infected.

 

 

  1. Law enforcement will increasingly need zero-day exploits to hack targets

 

The successful execution or installation of malware will generally require law enforcement to exploit a security vulnerability in the software on a target’s computer. In order to do so, the target’s computer must either be running out-of-date software with a known software vulnerability, or law enforcement must know of a so-called “zero-day” vulnerability for which no update exists.[23]

 

Although some sophisticated targets may follow good information technology security practices by regularly updating their software, most people do not.[24] As such, law enforcement agencies have frequently been able to hack targets without needing zero-day security exploits.

 

Similarly, law enforcement agencies could, until recently, reliably hack large numbers of users visiting sites on the so-called Dark Web, without the aid of a zero-day exploit, because the Tor Browser did not include an automatic security update mechanism. For example, the FBI has on at least two occasions performed watering hole attacks which exploited flaws in the Tor Browser to identify visitors to child pornography sites.[25] The malware used by the FBI in these operations did not work against the latest version of the Tor Browser, but the operations were still successful, as many visitors to the sites were running out of date, vulnerable software.

 

In August of this year, the Tor Project introduced a mechanism to deliver automatic updates to the Tor Browser.[26] Over time, more and more users of Tor will be running a more recent version with automatic updates, which will mean that law enforcement operations against users of Tor will increasingly require a zero-day exploit. As such, if law enforcement agencies in the UK have not yet acquired and used zero-day exploits, I imagine that they will soon. 

 

  1. Policy concerns associated with law enforcement use of zero-day exploits

 

There is no doubt that zero-day exploits will enable law enforcement agencies to more reliably hack the computers of targets, just as there is no doubt that nuclear weapons enable the military to more effectively kill its enemies. But both technologies have significant collateral costs which should give policy makers reason to limit, if not prohibit their use.

 

When a government acquires a zero-day exploit and decides to use it rather than notifying the company or developers responsible for the software, the government is, in essence, leaving all of its own citizens who use that software vulnerable, so that it may exploit the flaw against a small number of them later. By choosing to use, rather than disclose that flaw, the government is also gambling that no other party will independently discover and exploit the flaw. This is a big gamble to make, as security researchers frequently discover the same security flaws. One recent example of a high-profile flaw independently discovered by multiple research teams was the HeartBleed flaw in 2014.[27]

 

Indeed, as ex-White House cyber czar Howard Schmidt observed in 2013, “It's pretty naïve to believe that with a newly discovered zero-day, you are the only one in the world that's discovered it...Whether it's another government, a researcher or someone else who sells exploits, you may have it by yourself for a few hours or for a few days, but you sure are not going to have it alone for long.”[28] In Schmidt’s view, when governments exploit zero-day vulnerabilities rather than report them, “we all fundamentally become less secure.’”

 

In addition to the risk that another government, a researcher or cyber-criminal will independently rediscover the same vulnerability, every time a government uses a zero-day exploit, that government risks discovery, reuse and or disclosure of the exploit by the target, security researchers, cyber-criminals, or another government. This is because governments have no ability to control the redistribution of malware or software exploits that they have transmitted over the Internet to targets. As a result, the U.S. Department of Justice cautions its attorneys and agents about these specific risks:

 

[O]nline undercover facilities that offer the public access to information or computer programs that may be used for illegal or harmful purposes may have greater capacity than similar physical-world undercover entities to cause unintended harm to unknown third parties. Because digital information can be easily copied and communicated, it is difficult to control distribution in an online operation and so limit the harm that may arise from the operation.[29] (emphasis added)

 

This scenario is by no means theoretical.

 

The FBI’s bulk hacking operation against visitors to Freedom Hosting in 2013, which I described earlier in this document, was quickly noticed by savvy users. Within days, the FBI’s malware had been reverse-engineered by security researchers and the IP address of the FBI’s server at a data center in Virginia had been identified.[30] Although, as I described earlier, the FBI did not use a zero-day exploit in this case, had the agency used one, it would almost certainly have been discovered. According to one ex-law enforcement official, the FBI is apparently “loath to use [malware] when investigating hackers, out of fear the suspect will discover and publicize the technique.[31]” The Freedom Hosting operation and the subsequent discovery and analysis of the FBI’s malware suggests that this fear is justified.

 

The Stuxnet worm, created by the United States and Israel, also serves as a good example that government malware and any associated zero-day vulnerabilities, may eventually be discovered. Although it took several years before Stuxnet was identified by security researchers, the Stuxnet code and the zero-day exploits it leveraged were extensively analyzed by a world-wide network of security experts.[32] Once notified by the research community, Microsoft rushed to develop and distribute patches for these vulnerabilities. However, criminals also took note, and exploited the same vulnerabilities for their own nefarious purposes.[33]

 

Recommendation: Law enforcement agency use of zero-day exploits should be prohibited. If the use of zero-days is permitted, a vulnerability equities process should be established to evaluate the risks associated with each particular vulnerability.[34] Preferably, this process should be more transparent than the largely-secret process in use by the U.S. government.[35]

 

  1. Conclusion

 

I appreciate the opportunity to present my views and policy recommendations on hacking by the government to this committee. Although my comments focus on this one topic, that I have not commented on the other parts of the Investigatory Powers Bill should in no way be interpreted as silent approval for the other surveillance powers that the government has sought. Given the extremely short window for public comments and the many problems associate with government hacking, I have not had the time to draft in-depth analysis and recommendations for the other parts of the bill. Should the committee have follow-up questions about government hacking or questions about any other part of the bill, please let me know, and I’d be happy to answer them.

 

November 2015


[1] UK law enforcement agencies already hack, although, this was not known to the public or acknowledged by the government until this month. See Joseph Cox, UK's National Crime Agency Revealed to Have Hacking Powers, Motherboard, 5 Nov 2015, http://motherboard.vice.com/read/uks-national-crime-agency-revealed-to-have-hacking-powers.

[2] See Draft Investigatory Powers Bill, Nov. 2015, Part 5, Equipment Interference, Section 83, Subject-matter of warrants, page 110 of https://www.gov.uk/government/uploads/system/uploads/attachment_data/file/473770/Draft_Investigatory_Powers_Bill.pdf (“A targeted equipment interference warrant may relate to…(c) equipment belonging to, used by or in the possession of more than one person or organisation, where the interference is for the purpose of the same investigation or operation...(e) equipment in more than one location, where the interference is for the purpose of the same investigation or operation.”)

[3] See FBI Sheds Light on 'Magic Lantern' PC Virus, Reuters, 13 Dec. 2001, http://usatoday30.usatoday.com/life/cyber/tech/2001/12/13/magic-lantern.htm

[4] See James B. Comey, To Catch a Crook: The F.B.I.’s Use of Deception, Letter to the Editor, New York Times, 6 Nov. 2014, www.nytimes.com/2014/11/07/opinion/to-catch-a-crook-the-fbis-use-of-deception.html (“[T]he online undercover officer portrayed himself as an employee of The Associated Press, and asked if the suspect would be willing to review a draft article about the threats and attacks, to be sure that the anonymous suspect was portrayed fairly. The suspect agreed and clicked on a link relating to the draft ‘story,’ which then deployed court-authorized tools to find him, and the case was solved.”)

[5] See Affidavit of Norman B Sanders Jr., Special Agent, Federal Bureau of Investigations, 12 June 2007, http://www.wired.com/images_blogs/threatlevel/files/timberline_affidavit.pdf.

[6] See Christopher Soghoian (@csoghoian), Tweet, 27 Oct. 2014, 19:18 UTC, ("In 2007, FBI sent malware via a link intended to look like a Seattle Times/AP story. https://twitter.com/csoghoian/status/526815317390266368 at pages 61-62.")

[7] See Chris Grygiel, FBI says it impersonated AP reporter in 2007 case, Associated Press, 7 Nov. 2014, http://www.chieftain.com/news/3043213-119/fbi-press-letter-comey.

[8] See Eric Tucker, FBI leaves door open on agents’ impersonating reporters, Associated Press, 9 Dec. 2014, http://www.seattletimes.com/seattle-news/fbi-leaves-door-open-on-agentsrsquo-impersonating-reporters/.

[9] See Ellen Nakashima,Greg Miller and Julie Tate, U.S., Israel developed Flame computer virus to slow Iranian nuclear efforts, officials say, Washington Post, 19 June 2012, https://www.washingtonpost.com/world/national-security/us-israel-developed-computer-virus-to-slow-iranian-nuclear-efforts-officials-say/2012/06/19/gJQA6xBPoV_story.html.

[10] See Dan Goodin, Flame malware hijacks Windows Update to spread from PC to PC, Ars Technica, 5 June 2012, http://arstechnica.com/security/2012/06/flame-malware-hijacks-windows-update-to-propogate/.

[11] See Mikko Hyppönen, Microsoft Update and The Nightmare Scenario, F-Secure Labs, 4 June 2012, http://www.f-secure.com/weblog/archives/00002377.html.

[12] See Christopher Soghoian, Lessons from the Bin Laden Raid and Cyberwar, Speech at Personal Democracy Forum, 11 June 2012, https://www.youtube.com/watch?v=swHkpHMVt3A.

[13] See Donald G. McNeil Jr, C.I.A. Vaccine Ruse May Have Harmed the War on Polio, New York TImes, 9 July 2012, http://www.nytimes.com/2012/07/10/health/cia-vaccine-ruse-in-pakistan-may-have-harmed-polio-fight.html. After the CIA was criticized by the public health community, the agency promised not to make ‘operational use’ of immunization programs in the future. See Letter from Lisa O. Monaco, Assistant to the President for Homeland Security and Counterterrorism, 16 May, 2014, http://apps.washingtonpost.com/g/page/national/letter-to-deans-of-public-health-institutions/1040/.

[14] Id.

[15] See Complaint in United States v. Luis Escobosa, Sept. 23 2015, page 6, https://regmedia.co.uk/2015/09/30/fbi_tor.pdf (revealing the website’s name to be “Playpen”)

[16] See John Robertston, Special Agent, Federal Bureau of Investigation, Affidavit In Support of Application For A Search Warrant, 10 June 2015, page 7,  https://assets.documentcloud.org/documents/2166606/ferrell-warrant-1.pdf

[17] See Affidavit In Support of Application for Search Warrant (sample), pages 189-210 of

http://www.uscourts.gov/file/15534/download at 200.

[18] See Kevin S. Bankston & Ashkan Soltani, Tiny Constables and the Cost of Surveillance: Making Cents Out of United States v. Jones, 123 Yale L.J. Online 335 (2014), http://www.yalelawjournal.org/pdf/1231_jjd1qz1e.pdf.

[19] See United States v. Garcia, 474 F.3d 994, 998 (7th Cir. 2007).

[20] See Kevin Poulsen, FBI Admits It Controlled Tor Servers Behind Mass Malware Attack, Wired, 13 Sept. 2013, http://www.wired.com/2013/09/freedom-hosting-fbi/.

[21] See Dan Goodin, Attackers Wield Firefox Exploit to Uncloak Anonymous Tor Users, Ars Technica, 5 Aug. 2013, http://arstechnica.com/security/2013/08/attackers-wield-firefox-exploit-to-uncloak-anonymous-tor-users/.

[22] Poulsen, FBI Admits It Controlled Tor Servers Behind Mass Malware Attack, supra.

[23] See Leyla Bilge & Tudor Dumitras, Before We Knew It: An Empirical Study of Zero-Day Attacks in the Real World, Proceedings of the 2012 ACM Conference on Computer and Communications Security, available at http://users.ece.cmu.edu/~tdumitra/public_documents/bilge12_zero_day.pdf (“A zero-day attack is a cyber attack exploiting a vulnerability that has not been disclosed publicly. There is almost no defense against a zero-day attack: while the vulnerability remains unknown, the software affected cannot be patched and anti-virus products cannot detect the attack through signature-based scanning.”).

[24] See Thu Pham, Detecting Out of Date and Vulnerable Flash Versions on Your Network, Duo Security, 8 Oct. 2015, https://www.duosecurity.com/blog/detecting-out-of-date-and-vulnerable-flash-versions-on-your-network (“[W]e found that on average, 46 percent of corporate PCs are running out of date versions of browsers, Flash and Java. Users browsing on Safari and Internet Explorer were running out of date browser versions, at 61 and 57 percent, respectively….Our data found that 30 percent of users are running an out of date version of Flash, while 50 percent of users are running an out of date version of Java.”)

[25] See Kevin Poulsen, The FBI Used the Web’s Favorite Hacking Tool to Unmask Tor Users, Wired, 16 Dec. 2014, http://www.wired.com/2014/12/fbi-metasploit-tor/ (“Only suspects using extremely old versions of Tor, or who took great pains to install the Flash plug-in against all advice, would have been vulnerable.”). See also Kevin Poulsen, FBI Admits It Controlled Tor Servers Behind Mass Malware Attack, Sept 13 2013, http://www.wired.com/2013/09/freedom-hosting-fbi/ (“On August 4, all the sites hosted by Freedom Hosting...began serving an error message with hidden code embedded in the page….the code exploited a critical memory management vulnerability in Firefox that was publicly reported on June 25, and is fixed in the latest version of the browser….Tor Browser Bundle users who installed or manually updated after June 26 were safe from the exploit.”).

[26] See Mike Perry, Tor Browser 5.0 is released, 11 Aug, 2015, https://blog.torproject.org/blog/tor-browser-50-released (“Starting with this release, Tor Browser will now also download and apply upgrades in the background, to ensure that users upgrade quicker and with less interaction.”). See also Tor Weekly News, 20 Aug. 2015, https://blog.torproject.org/blog/tor-weekly-news-%E2%80%94-august-20th-2015 (“The Tor Browser team put out a new stable version of the privacy-preserving browser….Thanks to the new automatic update mechanism in the Tor Browser 5.x series, you are probably already running the upgraded version!”).

[27] See Adriana Lee, How Codenomicon Found The Heartbleed Bug Now Plaguing The Internet, ReadWrite, 13 April 2014, http://readwrite.com/2014/04/13/heartbleed-security-codenomicon-discovery (“Discovered independently by Google engineer Neel Mehta and the Finnish security firm Codenomicon”).

[28] See Joseph Menn, U.S. Cyberwar Strategy Stokes Fear of Blowback, Reuters, 10 May 2013, http://www.reuters.com/article/2013/05/10/us-usa-cyberweapons-specialreport-idUSBRE9490EL20130510. See also Nicole Perlroth and David E. Sanger, Nations Buying as Hackers Sell Flaws in Computer Code, N.Y. Times, 13 July 2013, http://www.nytimes.com/2013/07/14/world/europe/nations-buying-as-hackers-sell-computerflaws.html.

[29] See U.S. Department Of Justice, Online Investigative Principles for Federal Law Enforcement Agents, Nov. 1999, at 44 (p. 57 of the PDF) https://info.publicintelligence.net/DoJ-OnlineInvestigations.pdf.

[30] See Vlad Tsyrklevich, untitled, Aug. 2013, https://tsyrklevich.net/tbb_payload.txt, (“this payload connects to 65.222.202.54:80 and sends it an HTTP request that includes the host name (via gethostname()) and the MAC address of the local host (via calling SendARP on gethostbyname()->h_addr_list). After that it cleans up the state and appears to deliberately crash.”)

[31] See Jennifer Valentino-DeVries and Danny Yadron, FBI Taps Hacker Tactics to Spy on Suspects, Wall Street Journal, 3 Aug. 2013, http://www.wsj.com/articles/SB10001424127887323997004578641993388259674.

[32] See David Kushner, The Real Story of Stuxnet, IEEE Spectrum, 26 Feb 2013, http://spectrum.ieee.org/telecom/security/the-real-story-of-stuxnet

[33] See Pierluigi Paganini, Kaspersky Revealed that Stuxnet Exploits Is Still Used Worldwide, Security Aff. 19 Aug. 2014, http://securityaffairs.co/wordpress/27633/cyber-crime/stuxnet-flaw-still-targeted.html.

[34] See Kim Zetter, See U.S. Gov Insists It Doesn’t Stockpile Zero-Day Exploits to Hack Enemies, Wired, 17 Nov. 2014, http://www.wired.com/2014/11/michael-daniel-no-zero-day-stockpile/ (“‘the agencies that you would expect’ use a ‘multi-factor test’ to examine vulnerabilities to determine how extensively the software is used in critical infrastructure and US government systems, and how likely it is that malicious actors have already got ahold of it or may get hold of it. ‘All of those questions that are laid out, we require that analysis and discuss each one of those points. Then groups of subject-matter experts across the government make a recommendation to this interagency group that I chair here on the National Security Council.’ The subject-matter experts provide ‘their best judgment about [a vulnerability’s] widespreadness or how likely it is that researchers are going to be able to discover it or how unlikely it is that a foreign adversary has it.’”)(Quoting White House “cyber czar” Michael Daniel, describing the White House Vulnerability Equities Process)

[35] See Andrew Crocker, The Government Says It Has a Policy on Disclosing Zero-Days, But Where Are the Documents to Prove It?, EFF Deep Link Blog, 30 Mar. 2015, https://www.eff.org/deeplinks/2015/03/government-says-it-has-policy-disclosing-zero-days-where-are-documents-prove-it. See also Andrew Crocker, It’s No Secret That the Government Uses Zero Days for “Offense”, EFF Deep Links Blog, 9 Nov. 2015, https://www.eff.org/deeplinks/2015/11/its-no-secret-government-uses-zero-days-offense.