Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Because deniability is valuable in international relations? If a government can't prove something they aren't forced to act.

If it was obvious the Chinese government did this, then other world governments would have to respond with sanctions and import bans.



Why would anyone want a LPE backdoor like this? You would need another backdoor to achieve RCE in an order to make use of your silly LPE backdoor.


I personally of the opinion that this is just a bug, and not an intentional bug

That being said, there is value in a LPE as a part of a bigger exploit chain. There's all sorts of exploits that'll give you relatively unprivileged code execution, and you'd want to silently elevate in order to make yourself persistent for instance.


Windows LPE bugs tend to be quite cheap and plentiful, I just can't see much value in inserting a bug like this to possibly make it slightly cheaper on a few specific machines.


Windows LPEs are still up to $80k on zerodium, instead of the up to $50k for Linux, Mac, and BSD. Yes those numbers are funny money, and you're more likely to see a third of that, but they're still useful numbers in a relative sense.

Like I said, I think this is just a bug, but Windows LPEs do have value.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: