Live data from Hacker News

Thousands of computers now compromised with leaked NSA tools, researchers say

cyberscoop.com

81–90 of 173 posts

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#81

Earlier quoted context omitted.

> If it ever leaks We have evidence that the NSA has no idea from where or through whom it's leaking. My impulse is to say "you get so many years to use an exploit, maybe more with higher-up approval, and then you must disclose it." Unfortunately, with virtually zero independent oversight of these agencies, I have no faith such rules would be followed.

We have evidence that the NSA has no idea from where or through whom it's leaking. The general consensus seems to be that Russia was the source of the leaks. The US government knows this, and everyone involved knows who is leaking what, and why. If so, then this is a political move. Is there evidence to contradict this? https://www.nytimes.com/2016/08/17/us/shadow-brokers-leak-ra...

Well, that means that if they decided not to leak them they would still be known to others. So that's an excellent argument for disclosing to vendors anything that you do find if you're serious about this whole national security thing.

What it shows instead is that the NSA and other agencies could not care less about national security as long as they get to hack interesting targets elsewhere.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#82

Earlier quoted context omitted.

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it. That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary. That doesn't solve the fact that NSA's competitors could find a…

> it's hard to seriously argue that the NSA should stop exploiting computers. It's their role. We need them, just like we need a military. Would you say the same of Chinese government hackers and Syran military? If yes, OK. I understand you accept the need for competition in arms. If not, can you explain why?

Yes and no.

I'm not OK with the Chinese having slingshots and spears, never mind ICBMs and nuclear warheads. That doesn't stop them, and I'm not offended or shocked that they would be armed.

Regarding cyberwar, I prefer that the Chinese not know how to program computers or even find the "on" switch. I'm not offended or shocked that they manage this and much more.

The same goes for Syria.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#84

Earlier quoted context omitted.

> If it ever leaks We have evidence that the NSA has no idea from where or through whom it's leaking. My impulse is to say "you get so many years to use an exploit, maybe more with higher-up approval, and then you must disclose it." Unfortunately, with virtually zero independent oversight of these agencies, I have no faith such rules would be followed.

We have evidence that the NSA has no idea from where or through whom it's leaking. The general consensus seems to be that Russia was the source of the leaks. The US government knows this, and everyone involved knows who is leaking what, and why. If so, then this is a political move. Is there evidence to contradict this? https://www.nytimes.com/2016/08/17/us/shadow-brokers-leak-ra...

The article you linked only has a single citation for the Russian attribution, which is a Snowden quote: “circumstantial evidence and conventional wisdom indicates Russian responsibility”

Is there any evidence other than Snowden's speculation?

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#85
post #63
post #54

Earlier quoted context omitted.

It was before Snowden. We have had hard facts since the 90's that mass wiretapping and exploitation has been going on thru vehicles like AT&T and Verizon. And we knew about PRISM for a good two years before its public disclosure. Sudden black square over a remote area in Utah in satellite imagery. Pictures of a massive contruct. Coupled with the fact that we knew they needed a place to centralize all of this collecte…

> It was before Snowden. I wasn't saying that's when it started. I was saying that's when people stopped viewing "government is listening to everyone" as conspiracy. > No one just wanted to frigging listen until they had a celebrity icon like Snowden to interest them... It didn't have anything to do with Snowden's "celebrity". Do you think he was a celebrity before he produced physical evidence ? Turns out, no one wa…

"when people stopped viewing "government is listening to everyone" as conspiracy."

The entire point is that the public isn't listening to the dangers presented beforehand. Yes, now people dont think you're crazy for thinking we are surveilled heavily, but now the equivalent is when I tell people why they put the surveillance in place at all. Typical responses include "but they're just doing it for national security".

If 1/3 of the public only knew half the shit the gov was up to there would be a revolt tomorrow morning. It's deeper and darker than just massive surveillance. My only question for years has been if the public will wake up enough to realize it. With the failing education and financial systems and the propaganda levels turned up to 11, I'm beginning to doubt it.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#86

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

>Which is exactly what we crazy cookoo conspiracy theorists have been warning about. Which is what exactly? That a spy agency is spying? >If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massively weakened infrastructure, corporate, and government security I don't agree with putting in backdoors, but I don't see how exploiting backdoors by your se…

>Which is what exactly?

The fact that the three letters are continuously failing to understand the long term blowback potential of the programs they start, regardless of initial merit. In this case, instead of spending nearly as much time doing hardening documents, they were busy comprimising everything. The name of almost all of our fuckups in this arena is blowback.

>I don't see how exploiting backdoors by your security agency is so nefarious

When they use them for lawful purposes, such of foreign sigint, ok. With that kind of power though, at a bare minimum I would be concerned about abuses of that power domestically. At a minimum. I could wax on about all the reasons it could be bad for a long time.

>How about congressional, judicial and executive oversight? Because that's what we have now.

That's exactly what I said was needed. A technocratic oversight committe could exist in all branches on this subject. Also, we really don't have good oversight in place. Think about the kind of effects this has on potential oversight bodies...

For example, the chairman on the senate intel committee is about to vote for more oversight of $secretprogram. It's imperative to national security that this program not receive scrutiny, so it's allowed to use these 0days against them, find or plant blackmail material, and exploit that to get the chairman of oversight to not do it.

This is the kind of shit I was talking about having been warning people about. It's not just about the surveillance. Surveillance is always about control, not security, security is just the bullshit they sell the public to not induce outcry.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#87

Earlier quoted context omitted.

>Which is exactly what we crazy cookoo conspiracy theorists have been warning about. Which is what exactly? That a spy agency is spying? >If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massively weakened infrastructure, corporate, and government security I don't agree with putting in backdoors, but I don't see how exploiting backdoors by your se…

> literally why they were created to do The NSA is supposed to do both defense and offense. The defense came up, for example, when they improved DES to resist differential cryptanalysis (which the public crypto world hadn't discovered yet) before DES was standardized. But that was a long time ago; at least since 9/11 the offense side seems to have pretty much eaten the defense, as far as we can tell. (See: https://en…

If the IA department in the NSA were smart enough to figure out every vulnerability that the SIGINT department discovered and got everything fixed, SIGINT would be impotent. Clearly, things like SELinux make SIGINT's job harder, but your suggestion that SIGINT should handicap itself is ludicrous on its face.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#88
post #54
post #11

Earlier quoted context omitted.

You haven't been a crazy cookoo conspiracy theorists since the Snowden dropped his info. Unless you've got conspiracies on other topics, then maybe. I think it's fairly common for even someone with a cursory knowledge of security to know that backdoors are a bad idea. The triple letters don't get their power from poor products. Those are going to be around no matter what. I'd rather this just drive a push toward more…

It was before Snowden. We have had hard facts since the 90's that mass wiretapping and exploitation has been going on thru vehicles like AT&T and Verizon. And we knew about PRISM for a good two years before its public disclosure. Sudden black square over a remote area in Utah in satellite imagery. Pictures of a massive contruct. Coupled with the fact that we knew they needed a place to centralize all of this collecte…

There is no evidence of mass wiretapping from AT&T or Verizon even after Snowden. The rest of your post shows you still don't have any idea what PRISM is even after Snowden and the government disclosed it.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#89
post #54

Earlier quoted context omitted.

It was before Snowden. We have had hard facts since the 90's that mass wiretapping and exploitation has been going on thru vehicles like AT&T and Verizon. And we knew about PRISM for a good two years before its public disclosure. Sudden black square over a remote area in Utah in satellite imagery. Pictures of a massive contruct. Coupled with the fact that we knew they needed a place to centralize all of this collecte…

There is no evidence of mass wiretapping from AT&T or Verizon even after Snowden. The rest of your post shows you still don't have any idea what PRISM is even after Snowden and the government disclosed it.

I'm well aware of PRISM :-)

You misunderstand me. PRISM is the program, but it needed an HQ! Here is that HQ:

https://en.wikipedia.org/wiki/Utah_Data_Center

Here is one such example of such a wiretapping program under AT&T:

https://en.wikipedia.org/wiki/Room_641A

And there are many more. It just depends on what you call "evidence". Is it your own definition, or are you relying on others to tell you what is and isn't legitimate?

It's quite ironic that you are telling me I don't know what PRISM is when I knew about it long before it reached public, and presumably your own, attention.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#90
post #54

Earlier quoted context omitted.

It was before Snowden. We have had hard facts since the 90's that mass wiretapping and exploitation has been going on thru vehicles like AT&T and Verizon. And we knew about PRISM for a good two years before its public disclosure. Sudden black square over a remote area in Utah in satellite imagery. Pictures of a massive contruct. Coupled with the fact that we knew they needed a place to centralize all of this collecte…

I don't think anyone worth a damn as far as this subject is concerned would have labeled you a conspiracy theorist. Anyone with an even passing knowledge of security assumed something of this nature was going on. It just logically follows, given the explosion of computers in every aspect of life, that the NSA would be doing this. Side note, what black image in a remote area of Utah? If you're talking about the Bluffd…

https://en.wikipedia.org/wiki/Utah_Data_Center

I distinctly remember a point when it was not visible. That is how I discovered the plans to build a complex there years ago. This was probably remedied not long after we started catching wind.

I'm sure it would not be difficult for Google, et al. to retroactively "fix" their public imagery data.

Post reply on HN