Live data from Hacker News

Thousands of computers now compromised with leaked NSA tools, researchers say

cyberscoop.com

11–20 of 173 posts

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#11

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

You haven't been a crazy cookoo conspiracy theorists since the Snowden dropped his info. Unless you've got conspiracies on other topics, then maybe.

I think it's fairly common for even someone with a cursory knowledge of security to know that backdoors are a bad idea.

The triple letters don't get their power from poor products. Those are going to be around no matter what. I'd rather this just drive a push toward more open source products throughout the network stack. The triple letters get their power, not from poor products, but because of existing oversight of the agencies has been lax in the name of fightin' terror.

When it is legal for gobs of data to be vacuumed up without any court order then they will have power, no matter how much poor software is in the wild.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#13

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it. That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary. That doesn't solve the fact that NSA's competitors could find a…

> The NSA needs to exploit flaws

In the current doctrine, it apparently does.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#14

shower thought: have them been infected now, or now are known to be infected?

I was about to comment something similar , but then I saw your post. Btw I don't know why people are down voting it.

This is an important point. This research comes after 10 days of the leak. I have been following the leak closely, I've even compiled a list with all the analysis and resources on a gist.

Good guys, bad guys, kids, bored Blackhats, had enough time to practically follow the step by step instructions in order to implant the backdoor. It doesn't take more than 30-40 mins for the first read till a successful exploit.

The short answer is that we have no idea of knowing how many of those were backdoored by the NSA.

Also worth noting is that the leak happened 3-4 months ago. A lot of people had access to this privately.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#15
post #8
post #6

Earlier quoted context omitted.

If the 0 day is in an open source project this seems doable but I don't know if the NSA has access to the Microsoft or Cisco source code.

They very likely do have access to the Windows source code. Microsoft does share that with certain governments & educational institutions. I think the Chinese government also has access, FWIW, but it's been a long time since I looked into this.

I got personal access to the Windows source along with many others via the MS MVP program.

And it's unlikely that even if MS was secretive that the USG cannot get multiple people working at MS with access.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#16

shower thought: have them been infected now, or now are known to be infected?

I was about to comment something similar , but then I saw your post. Btw I don't know why people are down voting it. This is an important point. This research comes after 10 days of the leak. I have been following the leak closely, I've even compiled a list with all the analysis and resources on a gist. Good guys, bad guys, kids, bored Blackhats, had enough time to practically follow the step by step instructions in…

I was thinking this created great plausible deniability for the NSA.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#17

Earlier quoted context omitted.

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it. That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary. That doesn't solve the fact that NSA's competitors could find a…

> If it ever leaks We have evidence that the NSA has no idea from where or through whom it's leaking. My impulse is to say "you get so many years to use an exploit, maybe more with higher-up approval, and then you must disclose it." Unfortunately, with virtually zero independent oversight of these agencies, I have no faith such rules would be followed.

We have evidence that the NSA has no idea from where or through whom it's leaking.

The general consensus seems to be that Russia was the source of the leaks. The US government knows this, and everyone involved knows who is leaking what, and why. If so, then this is a political move. Is there evidence to contradict this?

https://www.nytimes.com/2016/08/17/us/shadow-brokers-leak-ra...

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#19

Earlier quoted context omitted.

> If it ever leaks We have evidence that the NSA has no idea from where or through whom it's leaking. My impulse is to say "you get so many years to use an exploit, maybe more with higher-up approval, and then you must disclose it." Unfortunately, with virtually zero independent oversight of these agencies, I have no faith such rules would be followed.

We have evidence that the NSA has no idea from where or through whom it's leaking. The general consensus seems to be that Russia was the source of the leaks. The US government knows this, and everyone involved knows who is leaking what, and why. If so, then this is a political move. Is there evidence to contradict this? https://www.nytimes.com/2016/08/17/us/shadow-brokers-leak-ra...

The current enemy is always the source of the leaks. A few months back it was china. The political move is just the finger pointing.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#20
post #6

Earlier quoted context omitted.

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it. That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary. That doesn't solve the fact that NSA's competitors could find a…

If the 0 day is in an open source project this seems doable but I don't know if the NSA has access to the Microsoft or Cisco source code.

MS has a code sharing program. Large government contracts almost always have a code transfer clause in them if nothing else than if the company goes bust or no longer wants to support the product.
Post reply on HN