Live data from Hacker News

Thousands of computers now compromised with leaked NSA tools, researchers say

cyberscoop.com

71–80 of 173 posts

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#71

Earlier quoted context omitted.

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it. That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary. That doesn't solve the fact that NSA's competitors could find a…

> it's hard to seriously argue that the NSA should stop exploiting computers. It's their role. We need them, just like we need a military. Would you say the same of Chinese government hackers and Syran military? If yes, OK. I understand you accept the need for competition in arms. If not, can you explain why?

Exactly, if the US army starts raping ISIS females later it can't pretend its barbaric for other armies to do the same, incl. american females in the army.

Doing the least morally right thing always brings more problems than its worth, and that's exactly what NSA does every time it pokes holes into everyone's software.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#72

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

So the tool is getting used everywhere by "kiddies"?

I don't see any discussion about the fact that, if you were the NSA, you'd absolutely want this to happen to muddy the waters for attribution.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#73

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

Why do 3 letter agencies need special tools? Who will they be accountable to that these tools are being used ethically?

We already have a bunch of stories of crooked cops using databases to stalk love interests, etc. Then look at the Michael Hastings incident. Imagine how much abuse goes unreported.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#74

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…

>3. Create detection signatures for the exploit to run against Upstream collected internet communications.

Yes, it's a good thing that very illegal cyberattacks are never done over encrypted channels. To catch the once-in-a-blue-moon hacker who has their bots log in to the mothership with ssh or something, we could just go ahead and let the government write ring-0 antivirus for us.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#75

Earlier quoted context omitted.

We probably need the NSA. It's their job to exploit computers the same way it's the job of the military to apply force. It's difficult to say that we can do without the NSA any more than we can do without a military. In that light, the context is to reduce the impact of the NSA's necessary goals. Higher up in the thread, it was claimed that one of the most feared branches of the intelligence arm of the most powerful…

> It's their job to exploit computers the same way it's the job of the military to apply force. That's one half of their job, the other half is to secure government infrastructure from exactly the type of attacks they use on other countries. The problem there is that it sets up an incredible tension since how do you get the message out about a 0-day in windows to protect your 'own' side without your opponents getting…

I think the obvious answer here is to go full open-source on the infrastructure. if they can afford to pay engineers to craft exploits, the can afford to pay engineers to fix them.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#76

Earlier quoted context omitted.

> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…

> 3. Create detection signatures for the exploit to run against Upstream collected internet communications. Yes, it's a good thing that very illegal cyberattacks are never done over encrypted channels. To catch the once-in-a-blue-moon hacker who has their bots log in to the mothership with ssh or something, we could just go ahead and let the government write ring-0 antivirus for us.

I think you understand that my comment was phrased generically so that the logic applies to multiple scenarios (not just this one).

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#77

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it. That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary. That doesn't solve the fact that NSA's competitors could find a…

> If it ever leaks

You mean, if they become aware of it leaking. Exploits can leak and be utilized without anyone being aware of it, for years. It's not like you see a mushroom cloud on the horizon and your earthquake detectors wobble.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#78

Earlier quoted context omitted.

> 3. Create detection signatures for the exploit to run against Upstream collected internet communications. Yes, it's a good thing that very illegal cyberattacks are never done over encrypted channels. To catch the once-in-a-blue-moon hacker who has their bots log in to the mothership with ssh or something, we could just go ahead and let the government write ring-0 antivirus for us.

I think you understand that my comment was phrased generically so that the logic applies to multiple scenarios (not just this one).

The only signatures that could ever appear in the open would be from, very specifically, attacks on encryption implementations during startup (heartbleed attacked keepalive for example, so no help there). The attack surface of the application itself will always lie entirely behind the no-visiblity line.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#79

Earlier quoted context omitted.

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it. That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary. That doesn't solve the fact that NSA's competitors could find a…

> it's hard to seriously argue that the NSA should stop exploiting computers. It's their role. We need them, just like we need a military. Would you say the same of Chinese government hackers and Syran military? If yes, OK. I understand you accept the need for competition in arms. If not, can you explain why?

> Would you say the same of Chinese government hackers and Syran military?

No, for the same reason why I'm okay with the US military having nukes but wouldn't be okay with Syria having them.

Obviously it'd be great if we could get by with no military powers having to possess zero-day exploits (or nukes), but so long as we can't be sure no other nations are benefiting from such exploits, it makes no sense strategically to forbid our own governments from doing the same.

Post reply on HN