So this weekend a group calling themselves "the Shadow Brokers" posted a bunch of files online claiming they'd broken into the outfit security researchers call the Equation Group, which is basically the polite industry euphemism for "probably the NSA." They dumped a batch of exploit code for free as a teaser and then said the rest was going up for auction, starting bid one million bitcoin. At Saturday's exchange rate that's something like half a billion dollars, which is such a cartoonishly large number that I don't think anyone believes they expect to actually collect it. Feels more like a flare gun than a business plan.
I spent a chunk of Saturday night reading through the leaked file listing instead of doing literally anything else I was supposed to be doing, because a handful of the tool names referenced firewall products I actually run. Cisco ASA stuff, some Fortinet gear, a few things aimed at Juniper. By Sunday morning Cisco had put out an advisory confirming at least one of the bugs was real and gave it a name (extrabacon, if you're keeping score, which is a genuinely funny thing to call a piece of NSA malware). Fortinet said something similar not long after. So this isn't some larp, at least not entirely — real vendors are patching real holes because of it.
I run a little ASA at the place I do IT consulting for on the side, and I'll be honest, I hadn't logged into it in probably four months before Saturday. Nobody logs into their firewall for fun. That's the thing nobody says out loud about network security — most of it isn't clever attacks, it's just gear sitting untouched behind a rack somewhere until something like this forces you to go check the version number. I patched it around midnight, mostly out of guilt, and found it was running a firmware build from early last year. Not because anyone was lazy exactly, just because "it's working" is a very effective argument against touching anything.
What I keep turning over is less the exploits themselves and more the fact that whoever these people are apparently just had this stuff sitting around and decided posting it publicly, for money, was the move. If it really did come out of the NSA's toolkit, that's a pretty remarkable leak on top of everything else that's leaked out of federal agencies the last couple years. Nobody official has confirmed anything, obviously, and I doubt they will anytime soon, but there's a lot of quiet speculation floating around about who'd have the access and the motive to pull something like this off and time it the way they did, especially with everything else going on in the news cycle around Russia and hacking this summer. I'm not going to pretend I know the answer. I just think it's worth sitting with how weird it is that a random public auction listing is the thing making intelligence agencies patch their own tools.
Small unrelated complaint while I'm here: I also spent part of the weekend trying to watch Olympics coverage and NBC's stream buffered so badly during the swimming that I gave up and just refreshed a results page instead, which honestly might be the more reliable tech story of the week for most people reading this. Half the country is dealing with garbage geo-locked video and the other half is reading about nation-state firewall exploits, and somehow both feel equally 2016.
Anyway. If you're running any Cisco ASA, PIX, or Fortinet gear at home or at work, go check your firmware version tonight instead of tomorrow. I know "go patch your router" is not a thrilling call to action, but half the reason these things work at all is that everyone assumes someone else already did it. I assumed that for four months. Don't be me.
I'll probably write more on this once there's an actual patch timeline instead of a Saturday night advisory and a vague auction page, because right now most of what's out there is speculation dressed up as analysis, myself very much included.