NSA Paid French Hacker Company For Software Exploits, Contract Reveals

Future Tense
The Citizen's Guide to the Future
Sept. 17 2013 4:56 PM

NSA Paid French Hacker Company For Software Exploits, Contract Reveals

1024px-Marietje_Schaake_-_State_of_Social_Media_Summit_1
Member of European Parliament Marietje Schaake

Photo byy Sebastiaan ter Burg via Wikimedia Commons

France is one of several countries in Europe whose people have been outraged by revelations about the National Security Agency’s surveillance programs. But it turns out that a French company has quietly bolstered the NSA’s capabilities.

Ryan Gallagher Ryan Gallagher

Ryan Gallagher is a journalist who reports on surveillance, security, and civil liberties.

According to a contract newly released in response to a Freedom of Information request, last year the NSA purchased a 12-month subscription to a “binary analysis and exploits service” sold by Vupen, a company based in Montpelier, France. These exploits, sometimes described as “zero days,” are complex codes custom-written by hackers to target undisclosed security weaknesses in widely used operating systems like Windows and software programs like Google Chrome, Internet Explorer, Java, and Flash. A spy agency can use exploits to help infiltrate targets’ computers in espionage operations or to strengthen its own computer networks as part of cybersecurity efforts.

It is unclear how much money the NSA spent on the Vupen exploits package because the cost has been redacted in the released contract. Vupen CEO Chaouki Bekrar declined to answer questions about his deal with the NSA, but told me in an emailed statement that his company’s binary analysis and exploits service includes “highly technical documentation and private exploits written by Vupen’s team of researchers for critical vulnerabilities affecting major software and operating systems.” Bekrar added that the aim of the service was to “to allow customers protect their systems against sophisticated attacks.”

Advertisement

It seems possible that the NSA purchased the Vupen service for defensive reasons, with the purpose being to secure U.S. government infrastructure from adversaries. However, the NSA is believed to use zero days in offensive hacking operations, too. A Washington Post scoop in August detailed how the NSA has apparently turned to exploits as part of its covert attempts to spy on foreign computer networks. The Post reported that the NSA designs most of its own “implants” used for this purpose, but set aside $25.1 million in 2013 for “additional covert purchases of software vulnerabilities” from private providers.

Internationally, the zero-day marketplace is growing and largely unregulated. Many of the larger sellers are based in the United States, and reportedly include companies such as Raytheon, Endgame Systems, Harris Corp., and Northrop Grumman. But the market is also burgeoning in Europe, with Vupen leading the field. As I reported here back in January, Vupen’s latest financial accounts show that it generated revenue of about $1.2 million in 2011, 86 percent of which was earned from exports outside France.

Lawmakers in Europe, concerned about how the technology could be abused if in the wrong hands, are pushing for the introduction of new restrictions that would limit sales. Last week, Dutch Member of the European Parliament Marietje Schaake argued that Europe should take the lead in reining in the industry.  “We must end the export and proliferation of digital arms now,” Schaake said. “We have to close the regulatory vacuum, and that includes curbing the trade in zero-day exploits.”

Future Tense is a partnership of SlateNew America, and Arizona State University.

TODAY IN SLATE

Politics

The Irritating Confidante

John Dickerson on Ben Bradlee’s fascinating relationship with John F. Kennedy.

My Father Invented Social Networking at a Girls’ Reform School in the 1930s

Renée Zellweger’s New Face Is Too Real

Sleater-Kinney Was Once America’s Best Rock Band

Can it be again?

The All The President’s Men Scene That Captured Ben Bradlee

Medical Examiner

Is It Better to Be a Hero Like Batman?

Or an altruist like Bruce Wayne?

Technology

Driving in Circles

The autonomous Google car may never actually happen.

The World’s Human Rights Violators Are Signatories on the World’s Human Rights Treaties

How Punctual Are Germans?

  News & Politics
The World
Oct. 21 2014 11:40 AM The U.S. Has Spent $7 Billion Fighting the War on Drugs in Afghanistan. It Hasn’t Worked. 
  Business
Moneybox
Oct. 21 2014 5:57 PM Soda and Fries Have Lost Their Charm for Both Consumers and Investors
  Life
The Vault
Oct. 21 2014 2:23 PM A Data-Packed Map of American Immigration in 1903
  Double X
The XX Factor
Oct. 21 2014 1:12 PM George Tiller’s Murderer Threatens Another Abortion Provider, Claims Right of Free Speech
  Slate Plus
Behind the Scenes
Oct. 21 2014 1:02 PM Where Are Slate Plus Members From? This Weird Cartogram Explains. A weird-looking cartogram of Slate Plus memberships by state.
  Arts
Behold
Oct. 21 2014 12:05 PM Same-Sex Couples at Home With Themselves in 1980s America
  Technology
Future Tense
Oct. 21 2014 4:14 PM Planet Money Uncovers One Surprising Reason the Internet Is Sexist
  Health & Science
Climate Desk
Oct. 21 2014 11:53 AM Taking Research for Granted Texas Republican Lamar Smith continues his crusade against independence in science.
  Sports
Sports Nut
Oct. 20 2014 5:09 PM Keepaway, on Three. Ready—Break! On his record-breaking touchdown pass, Peyton Manning couldn’t even leave the celebration to chance.