Live data from Hacker News

Thousands of computers now compromised with leaked NSA tools, researchers say

cyberscoop.com

31–40 of 173 posts

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#31

Earlier quoted context omitted.

Who cares what nation state actor alledgedly moved the exploits from an NSA employee to WikiLeaks? Why would the medium matter in the least, in the case of hoarding 0days?

I agree with this and want to further add to it. Firstly by saying: isn't it interesting that, if it is Russia who moved the exploits from the NSA employee / contractor to WikiLeaks then they (the Russians) have acted in the service of the global public. But let's not get distracted. The source of all NSA leaks is never some rogue employee, or contractor. It's never "The Russians"™ or "The Chinese"™ . The source of N…

We probably need the NSA. It's their job to exploit computers the same way it's the job of the military to apply force. It's difficult to say that we can do without the NSA any more than we can do without a military.

In that light, the context is to reduce the impact of the NSA's necessary goals.

Higher up in the thread, it was claimed that one of the most feared branches of the intelligence arm of the most powerful government in the world was so incompetent that they had no idea who was behind these leaks, and that there was evidence to support this assertion. I have an open mind, so I was hoping to see this evidence.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#32

Earlier quoted context omitted.

> If it ever leaks We have evidence that the NSA has no idea from where or through whom it's leaking. My impulse is to say "you get so many years to use an exploit, maybe more with higher-up approval, and then you must disclose it." Unfortunately, with virtually zero independent oversight of these agencies, I have no faith such rules would be followed.

We have evidence that the NSA has no idea from where or through whom it's leaking. The general consensus seems to be that Russia was the source of the leaks. The US government knows this, and everyone involved knows who is leaking what, and why. If so, then this is a political move. Is there evidence to contradict this? https://www.nytimes.com/2016/08/17/us/shadow-brokers-leak-ra...

Its impossible now. Wikileaks showed the the cia goes into incredible detail to frame other countries.

https://www.wired.com/2017/03/wikileaks-cia-dump-gives-russi... http://thehackernews.com/2017/03/cia-marble-framework.html

I also bet that other countries do the exact same thing, probably even more likely considering the "marble project" source code is leaked.

http://www.dailymail.co.uk/news/article-4427452/CIA-launches... Also it looks like a hunt for the internal leaker has begun.

Whatever the source, We do still have to deal with the content of the leaks.

The content is what we need to take a very close look at begin to increase and harden our security. Especially senior developers and software architects.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#33

Earlier quoted context omitted.

Poetic, but you shot yourself in the foot in the first paragraph. "That we have centralized global social networks carries risks that the majority of people are not able to experience" If the majority of people do not experience the consequences of the risks of whatever-it-is-your-railing-against, if those risks are never realised by the majority, your argument evaporates.

Point taken. The majority are not able to experience it because it has not happened for the majority, yet. The data is there, the technology to use that data in the future has not been employed.

I used to be right in to the impending doom of the techno-dystopia, but I've stopped worrying about it. Predicting the future is hard.

We don't need a future info-technologically induced dystopia to commit atrocities. A shibboleth[1] will suffice.

From modern times to way back.

Then said they unto him, Say now Shibboleth: and he said Sibboleth: for he could not frame to pronounce it right. Then they took him, and slew him at the passages of Jordan: and there fell at that time of the Ephraimites forty and two thousand. Judges 12:6

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#34

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

>Which is exactly what we crazy cookoo conspiracy theorists have been warning about.

Which is what exactly? That a spy agency is spying?

>If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massively weakened infrastructure, corporate, and government security

I don't agree with putting in backdoors, but I don't see how exploiting backdoors by your security agency is so nefarious. That is literally why they were created to do, and this is what every other foreign security agency is doing as well.

>So while I don't disagree that triple letters need some cool tools to get shit done

Sounds like you do.

>I think this function needs some technocratic oversight specifically for this issue.

How about congressional, judicial and executive oversight? Because that's what we have now.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#35

Earlier quoted context omitted.

I agree with this and want to further add to it. Firstly by saying: isn't it interesting that, if it is Russia who moved the exploits from the NSA employee / contractor to WikiLeaks then they (the Russians) have acted in the service of the global public. But let's not get distracted. The source of all NSA leaks is never some rogue employee, or contractor. It's never "The Russians"™ or "The Chinese"™ . The source of N…

We probably need the NSA. It's their job to exploit computers the same way it's the job of the military to apply force. It's difficult to say that we can do without the NSA any more than we can do without a military. In that light, the context is to reduce the impact of the NSA's necessary goals. Higher up in the thread, it was claimed that one of the most feared branches of the intelligence arm of the most powerful…

> It's their job to exploit computers the same way it's the job of the military to apply force.

That's one half of their job, the other half is to secure government infrastructure from exactly the type of attacks they use on other countries.

The problem there is that it sets up an incredible tension since how do you get the message out about a 0-day in windows to protect your 'own' side without your opponents getting the same message.

I've thought for years that the NSA doing both jobs is silly since one side will inevitably win that argument (as seems to be the case).

It needs to be a separate agency concerned purely with securing government and infrastructure from external threats with a decent firewall between the two sides (and possibly an oversight clearing committee to keep an eye on what both sides are up to).

Over here in the UK we have largely the same problem with GCHQ having a dual mandate.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#36

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

SV doesn't get amnesia, it gets younger people reinventing the wheel to "disrupt".

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#37

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it. That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary. That doesn't solve the fact that NSA's competitors could find a…

    > If it ever leaks, they can send the target
    > company the report.
Any usage of the exploit by the NSA constitutes leaking it.

You can't treat cyberweapons like normal weapons.

The analogy is not that you come up with a secret bomb design and drop it on the target, but that to use your bomb you must send the full Top Secret designs for the bomb to every target, hoping that they voluntarily use it to blow themselves up instead of writing the design down & using it against you.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#39

"Once installed, DOUBLEPULSAR is a stealthy backdoor that’s difficult to detect and continuously relays new information back to its controller." Seems to contradict itself? If it's continuously relaying information, wouldn't that make it easy to detect?

I think what that means is that it's difficult to detect on the infected host machine. It's easy to detect at the network level, however.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#40

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

>Which is exactly what we crazy cookoo conspiracy theorists have been warning about. Which is what exactly? That a spy agency is spying? >If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massively weakened infrastructure, corporate, and government security I don't agree with putting in backdoors, but I don't see how exploiting backdoors by your se…

The NSA leverages these exploits to spy on foreign nations. That's fine, spies should spy...

But it does beg the question: who's protecting our information from foreign intrusions?

Post reply on HN