Live data from Hacker News

Thousands of computers now compromised with leaked NSA tools, researchers say

cyberscoop.com

51–60 of 173 posts

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#51

Earlier quoted context omitted.

> It's their job to exploit computers the same way it's the job of the military to apply force. That's one half of their job, the other half is to secure government infrastructure from exactly the type of attacks they use on other countries. The problem there is that it sets up an incredible tension since how do you get the message out about a 0-day in windows to protect your 'own' side without your opponents getting…

> how do you get the message out about a 0-day in windows American companies get disclosures, foreign companies do not.

What's an 'American' company these days?

US companies like Oracle, MS, Google, etc. have offices all over the world.

They also tend to use various visas to import 10% of their own US based staff (probably a much higher ratio of engineers) from foreign nations.

The US has gotten very wealthy from offshoring, foreign talent, and technical exports, but it causes a massive problem when keeping secrets locally.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#52

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it. That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary. That doesn't solve the fact that NSA's competitors could find a…

Would it be possible to scan for infected systems if you know the 0-day?

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#53

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it. That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary. That doesn't solve the fact that NSA's competitors could find a…

Would it be possible to scan for infected systems if you know the 0-day?

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#54
post #11

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

You haven't been a crazy cookoo conspiracy theorists since the Snowden dropped his info. Unless you've got conspiracies on other topics, then maybe. I think it's fairly common for even someone with a cursory knowledge of security to know that backdoors are a bad idea. The triple letters don't get their power from poor products. Those are going to be around no matter what. I'd rather this just drive a push toward more…

It was before Snowden. We have had hard facts since the 90's that mass wiretapping and exploitation has been going on thru vehicles like AT&T and Verizon.

And we knew about PRISM for a good two years before its public disclosure. Sudden black square over a remote area in Utah in satellite imagery. Pictures of a massive contruct. Coupled with the fact that we knew they needed a place to centralize all of this collected information, it was plainly public how the NSA was operating. No one just wanted to frigging listen until they had a celebrity icon like Snowden to interest them, because we operate on a system of identity politics.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#55

Earlier quoted context omitted.

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it. That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary. That doesn't solve the fact that NSA's competitors could find a…

Would it be possible to scan for infected systems if you know the 0-day?

If I recall correctly from some of the Snowden docs, they do have their passive internet taps watch for exploit signatures of foreign adversaries. I don't see why they would not do the same with their own.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#57

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

> If you put backdoors in, or exploit 0days for your own

This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea.

However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day exploits (Which are the issue at hand).

0-days are going to be in code regardless of who finds them. It would be great to get some clarification on this from the government, but I would be pretty OK if the process looked anything like this:

1. Discover 0-day exploit relevant to mission.

2. Build modular tools to utilize the 0-day.

3. Create detection signatures for the exploit to run against Upstream collected internet communications.

4. If another party is seen using the same 0-day (doesn't matter if it was via leak or independent discovery), have a cutout such as FBI or DHS contact vendor with details to get it patched ASAP.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#58

Earlier quoted context omitted.

We have evidence that the NSA has no idea from where or through whom it's leaking. The general consensus seems to be that Russia was the source of the leaks. The US government knows this, and everyone involved knows who is leaking what, and why. If so, then this is a political move. Is there evidence to contradict this? https://www.nytimes.com/2016/08/17/us/shadow-brokers-leak-ra...

Its impossible now. Wikileaks showed the the cia goes into incredible detail to frame other countries. https://www.wired.com/2017/03/wikileaks-cia-dump-gives-russi... http://thehackernews.com/2017/03/cia-marble-framework.html I also bet that other countries do the exact same thing, probably even more likely considering the "marble project" source code is leaked. http://www.dailymail.co.uk/news/article-4427452/CIA-lau…

Wikileaks has not shown this, although it seems to be the narrative which some wanted to push regarding the Marble leak.

> We do still have to deal with the content of the leaks.

Check out the actual content of the Marble leak. You will find that there is no evidence of your claim. It has been mentioned countless times that the foreign languages seen in the code are gibberish when translated, and are evidently there for testing purposes.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#59

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it. That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary. That doesn't solve the fact that NSA's competitors could find a…

> it's hard to seriously argue that the NSA should stop exploiting computers. It's their role. We need them, just like we need a military.

Would you say the same of Chinese government hackers and Syran military? If yes, OK. I understand you accept the need for competition in arms. If not, can you explain why?

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#60

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…

That's the exact process I'd like to see, but what really happens is more like:

1. Discover 0-day exploits relevant to mission

2. Build modular tools to utilize the 0-day

3. Do nothing

4. Lose control of 0days, or allow other actors to discover them.

It seems like the NSA is trying to avoid perceptions that they're scanning domestic internet traffic, but that leaves us in the vulnerable position of hacking everyone while leaving our own doors wide open.

Post reply on HN