Live data from Hacker News

Hacking Team, Computer Vulnerabilities, and the NSA

schneier.com

31–40 of 75 posts

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#31
post #25
post #13

There's a fourth reason NSA wouldn't have tipped off every vendor impacted by HT exploits: because they have no business breaking into commercial vulnerability research teams networks, grabbing their exploits, and burning them. It is in fact probably unlawful for them to do so (those actions having as they do an impact on US F-500 companies that use --- for better or worse --- tools from companies like HT to evaluate…

Is it still a reason when the NSA clearly don't care whether they break the law?

You're missing the point. Behind the scenes? Sure. But Schneier is asking why NSA didn't break into HT and then burn all their exploits with the vendors. That's not a behind- the- scenes hack.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#32

Earlier quoted context omitted.

Says "NullCharacter", the respected authority on all matters security. Teach us more.

I definitely never claimed to be anything more than someone who thinks making bullshit assumptions based on other bullshit assumptions is, well, bullshit.

Look, there is probably 500M "generalist thinkers" like you on the internet. The value of your opinion is zero - "0".

The value of the opinion of that other guy that you mentioned is way more than zero - he gets invited to conferences, publishes in peer-reviewed journals, publishes free security software etc. So, people actually listen to what he says.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#33

Earlier quoted context omitted.

I definitely never claimed to be anything more than someone who thinks making bullshit assumptions based on other bullshit assumptions is, well, bullshit.

Look, there is probably 500M "generalist thinkers" like you on the internet. The value of your opinion is zero - "0". The value of the opinion of that other guy that you mentioned is way more than zero - he gets invited to conferences, publishes in peer-reviewed journals, publishes free security software etc. So, people actually listen to what he says.

Haha wow. Schneier fan, are we? Did I touch a nerve? The hilarious thing is you don't even know who I am or what I do. You have no fucking clue.

How dare someone think critically. Not on your watch.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#34
post #13

There's a fourth reason NSA wouldn't have tipped off every vendor impacted by HT exploits: because they have no business breaking into commercial vulnerability research teams networks, grabbing their exploits, and burning them. It is in fact probably unlawful for them to do so (those actions having as they do an impact on US F-500 companies that use --- for better or worse --- tools from companies like HT to evaluate…

Burning exploits is more or less directly industrial espionage/sabotage. The NSA seems to avoid engaging in economic battles unless it's a direct policy goal (stuxnet) or furthers their mission of gathering secrets.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#35

Earlier quoted context omitted.

Look, there is probably 500M "generalist thinkers" like you on the internet. The value of your opinion is zero - "0". The value of the opinion of that other guy that you mentioned is way more than zero - he gets invited to conferences, publishes in peer-reviewed journals, publishes free security software etc. So, people actually listen to what he says.

Haha wow. Schneier fan, are we? Did I touch a nerve? The hilarious thing is you don't even know who I am or what I do. You have no fucking clue. How dare someone think critically. Not on your watch.

No it's just funny when a random person on internet claims that they are better because they "think critically". My point is, you are not a special snowflake. You are one of 500M that think that they are smarter than others. You are not.

Basically, you are just like a 4-year old begging for attention. You will get some, but unlike 4-year old, it will wane quickly. All the best!

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#36

Earlier quoted context omitted.

Haha wow. Schneier fan, are we? Did I touch a nerve? The hilarious thing is you don't even know who I am or what I do. You have no fucking clue. How dare someone think critically. Not on your watch.

No it's just funny when a random person on internet claims that they are better because they "think critically". My point is, you are not a special snowflake. You are one of 500M that think that they are smarter than others. You are not. Basically, you are just like a 4-year old begging for attention. You will get some, but unlike 4-year old, it will wane quickly. All the best!

In the words of XCKD: The important thing is you've found a way to feel superior. Good for you!

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#37

Earlier quoted context omitted.

No it's just funny when a random person on internet claims that they are better because they "think critically". My point is, you are not a special snowflake. You are one of 500M that think that they are smarter than others. You are not. Basically, you are just like a 4-year old begging for attention. You will get some, but unlike 4-year old, it will wane quickly. All the best!

In the words of XCKD: The important thing is you've found a way to feel superior. Good for you!

If I were on Reddit, I would say something like "I feel massive now", but I am not, so I won't :) BTW no hard feelings, mate, all is good. I don't mean no harm to anyone.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#38
post #15
post #5

Earlier quoted context omitted.

I think it's a fairly safe bet that they did, and I'll explain why I believe this. 1. The NSA has access to more info on both good crypto and broken crypto 2. Hacking Team's software & infrastructure were clearly vulnerable, otherwise they wouldn't have been hacked 3. Leaked docs show that NSA hacks everyone they possibly can, to get as much information as they possibly can. It's really not a big leap to assume that…

For probably more than 95% of the Fortune 500, vulnerability intelligence that is years out of date is more than sufficient to own up those firms' entire enterprise networks. The half-life of most software vulnerabilities is long. Simple IT problems like inventory remain unsolved in the real world. So the same logic suggests that NSA has owned up every company of any real size in the world. Could NSA do that? Absolut…

I think this discussion could get convoluted really quickly, because I bet 100% of the companies in the Fortune 500 have a different definition of what their "enterprise" network consists of, and how it's organized.

I can say that I used to work for one, and our departments' network was literally air gapped (not joking). Internal systems could not reach out, and no one could reach in. It was impossible for us to work remotely, because even a VPN wasn't set up. There was no physical connectivity.

But there's a difference between Hacking Team and every company on the Fortune 500: Hacking Team was in the Exploit business, they literally made money selling weaponized exploits to US enemies, and possibly allies.

If anything, I think that's literally the NSA's directive in collecting foreign intelligence.

Meaning, I believe if there was one foreign business that the NSA would spy on (and lets face it, I don't know that many), I think Hacking Team would absolutely be at the top of their list, purely for logical reasons.

But.....I also completely admit that my statement was an assumption, a "bet". I'm not guaranteeing anything, and I really don't care. I'm just over here, arm-chair quarterbacking this shit, haha.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#39
post #5

Earlier quoted context omitted.

I think it's a fairly safe bet that they did, and I'll explain why I believe this. 1. The NSA has access to more info on both good crypto and broken crypto 2. Hacking Team's software & infrastructure were clearly vulnerable, otherwise they wouldn't have been hacked 3. Leaked docs show that NSA hacks everyone they possibly can, to get as much information as they possibly can. It's really not a big leap to assume that…

> But just so I can understand what you're saying, why do you think it's a big assumption? Are you serious? Because there's no proof or mention of it anywhere. You're making an assumption based on literally nothing more than "well obviously, based on what I've read on the Internet, they could have done it so they must have". You're bending facts to fit a worldview, something I'm sure you yourself detest elsewhere in…

It's an assumption, but I'm asking why it's a big assumption.

We know that the NSA spied on Google, Yahoo, and Microsoft, and those are our own (US) companies.

Hacking Team produced weaponized exploits/crypto/stuffs and sold it to US enemies and allies.

Having read through the documents, I assert that it's a small/likely/reasonable assumption.

It's literally the NSAs mission statement to defend the US against foreign intelligence.....how is Hacking Team not a perfect example of an appropriate target for them?

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#40
post #38
post #15

Earlier quoted context omitted.

For probably more than 95% of the Fortune 500, vulnerability intelligence that is years out of date is more than sufficient to own up those firms' entire enterprise networks. The half-life of most software vulnerabilities is long. Simple IT problems like inventory remain unsolved in the real world. So the same logic suggests that NSA has owned up every company of any real size in the world. Could NSA do that? Absolut…

I think this discussion could get convoluted really quickly, because I bet 100% of the companies in the Fortune 500 have a different definition of what their "enterprise" network consists of, and how it's organized. I can say that I used to work for one, and our departments' network was literally air gapped (not joking). Internal systems could not reach out, and no one could reach in. It was impossible for us to work…

I've done in the life immediately previous to my current one a fair bit of enterprise netpen work, and I have never seen a large enterprise network that had anything effectively airgapped. Getting onto a single desktop, in my experience, is virtually a gameover guarantee for any reasonable definition of "gameover".
Post reply on HN