> In addition, if Russia had stolen the hacking tools, it would be senseless to publicize the theft, let alone put them up for sale. It would be like a safecracker stealing the combination to a bank vault and putting it on Facebook. Once revealed, companies and governments would patch their firewalls, just as the bank would change its combination.
Why would this be bad for Russians (if this was indeed the Russians)? We can/should assume that Russia has it's own methods of infiltrating systems. The value of this data to them would be knowledge of how it's done, not necessarily hoarding and replicating how the NSA does it. If anything, having vendor's patch exploits that they're not using, but their enemy is, would be a great chess move.
The longer the russian's know or have the exploits without the NSA knowing they've been compromised, the longer they can hold it against them. -- Imagine you've hacked a bank network vs robbing a single bank, and every week you take 1 penny from all users without anyone knowing, and do this for 3+ years... you'd get a lot more than a one-off bank robbery... That's the long game that Russia would play - milk it for every ounce of use, and keep it totally secret.
They get nothing from exposing it, hacktivists on the other hand get a lot more, and are more boastful about their exploits.
Hold what against them? The exploit? That makes no sense.
The Russians do not use the exact same set of tools that the NSA does. Sure, they may have discovered some of the same exploits, but the two do not have the same "toolbox" strictly speaking. Releasing a set of tools used by the NSA doesn't mean that Russia loses access to the systems that they have compromised...
To be honest, it's very difficult to have a clear view on whether is makes sense to call the Russians on this or not. We know too little and we speculate to much :-)
Plus, for a USA agency, it goes without saying that when shit hits the fan it's either Russians, Chinese or Aliens not necessarily in that order.
Yes, this Bamford argument doesn't make much sense either. It seems to imply that the Russians and Americans are working from the same set of vulnerabilities. I don't know anyone who does this work professionally who thinks that's likely to be true.
Why would this be bad for Russians (if this was indeed the Russians)? We can/should assume that Russia has it's own methods of infiltrating systems. The value of this data to them would be knowledge of how it's done, not necessarily hoarding and replicating how the NSA does it. If anything, having vendor's patch exploits that they're not using, but their enemy is, would be a great chess move.