Live data from Hacker News

Thousands of computers now compromised with leaked NSA tools, researchers say

cyberscoop.com

1–10 of 173 posts

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#2
Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently.

Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massively weakened infrastructure, corporate, and government security... basically all the things important to national security in general. So while I don't disagree that triple letters need some cool tools to get shit done, I think this function needs some technocratic oversight specifically for this issue.

It's time for a new Church committee.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#5

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it.

That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary.

That doesn't solve the fact that NSA's competitors could find and exploit the same flaws, or that sometimes it's hard to tell whether any leaks have happened, but it's an improvement.

At the end of it, it's hard to seriously argue that the NSA should stop exploiting computers. It's their role. We need them, just like we need a military. But we can think of ways to reduce the impact without getting in the way of their job.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#6

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it. That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary. That doesn't solve the fact that NSA's competitors could find a…

If the 0 day is in an open source project this seems doable but I don't know if the NSA has access to the Microsoft or Cisco source code.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#8
post #6

Earlier quoted context omitted.

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it. That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary. That doesn't solve the fact that NSA's competitors could find a…

If the 0 day is in an open source project this seems doable but I don't know if the NSA has access to the Microsoft or Cisco source code.

They very likely do have access to the Windows source code. Microsoft does share that with certain governments & educational institutions. I think the Chinese government also has access, FWIW, but it's been a long time since I looked into this.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#9
post #6

Earlier quoted context omitted.

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it. That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary. That doesn't solve the fact that NSA's competitors could find a…

If the 0 day is in an open source project this seems doable but I don't know if the NSA has access to the Microsoft or Cisco source code.

True, but blackbox pentesting is pretty common. If a company is informed of a flaw in their XYZ service with details of how the flaw operates, it would probably be enough.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#10

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it. That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary. That doesn't solve the fact that NSA's competitors could find a…

> If it ever leaks

We have evidence that the NSA has no idea from where or through whom it's leaking. My impulse is to say "you get so many years to use an exploit, maybe more with higher-up approval, and then you must disclose it." Unfortunately, with virtually zero independent oversight of these agencies, I have no faith such rules would be followed.

Post reply on HN