Live data from Hacker News

Thousands of computers now compromised with leaked NSA tools, researchers say

cyberscoop.com

91–100 of 173 posts

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#91

Earlier quoted context omitted.

> literally why they were created to do The NSA is supposed to do both defense and offense. The defense came up, for example, when they improved DES to resist differential cryptanalysis (which the public crypto world hadn't discovered yet) before DES was standardized. But that was a long time ago; at least since 9/11 the offense side seems to have pretty much eaten the defense, as far as we can tell. (See: https://en…

If the IA department in the NSA were smart enough to figure out every vulnerability that the SIGINT department discovered and got everything fixed, SIGINT would be impotent. Clearly, things like SELinux make SIGINT's job harder, but your suggestion that SIGINT should handicap itself is ludicrous on its face.

Consider a few salient states: the U.S., Iran, Russia, ... If computers worldwide are mostly secure, which see the greatest benefit? If they're a festering pile of vulnerabilities, which see the greatest cost? That's the choice, as U.S. policy, of where you can focus your efforts. It's not a choice of secure U.S. computers and insecure Russian ones.

The way you're framing it presumes SIGINT is in charge and positively welcomes insecure U.S. computers. I'm saying that's bad for us. I've seen others saying the same.

Also, secure computers would not make spying go away, and SIGINT would not be impotent. Its powers are still increasing with, e.g., surveillance of whole populations from the air with high-res video cameras. Comms spying would go back to retail instead of wholesale data collection.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#92

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

What does this have to do with SV company valuations?

Seems like you're pigeonholing a pet issue into something totally unrelated.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#93

It would be interesting (although I expect impossible) to figure out how many of those thousands were compromised by the NSA vs those compromised by people who got the tools through the leak. It was nice that Microsoft had already fixed a bunch of them (almost like they were told ahead of time they were coming). It is also interesting to read the outrage about the tools and the presentations on how to use them. If yo…

> Definitely feels like Phase III of the Internet has begun to me.

I knew it wouldn't be that semantic web babble nonsense. I really hope it is the realization that infosec is important and we become closer to real engineers that factor in risk. My only fear is that it results in more useless regulatory oversight with marginal ROI.

The recent controls put on zero day sales are a good example. They will do nothing to prevent the proliferation of malware and only punish honest companies helping to secure systems with practical attacks.

It's like how the city I live in (Toronto) just enacted another round of rent control to deal with a lack of affordable housing. Rent control makes people happy by seeming to address the problem but ultimately historically has always resulted in less development of affordable housing by disincentivizing investment rather than helping developers build more buildings cheaper, by reducing red tape.

This is what we need to do with security research. Stop villianizing researching exploits and sending innocent kids to jail and start paying them good money for their (often profitless) energy expenditure.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#94
post #89

Earlier quoted context omitted.

There is no evidence of mass wiretapping from AT&T or Verizon even after Snowden. The rest of your post shows you still don't have any idea what PRISM is even after Snowden and the government disclosed it.

I'm well aware of PRISM :-) You misunderstand me. PRISM is the program, but it needed an HQ! Here is that HQ: https://en.wikipedia.org/wiki/Utah_Data_Center Here is one such example of such a wiretapping program under AT&T: https://en.wikipedia.org/wiki/Room_641A And there are many more. It just depends on what you call "evidence". Is it your own definition, or are you relying on others to tell you what is and isn't…

You very clearly don't know what PRISM is. According to Snowden's documents, PRISM is the program that brings the FBI's FISA electronic communication wiretaps into the NSA's databases. It has absolutely nothing to do with Room 641A, which also doesn't do what you think it does.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#95
post #89

Earlier quoted context omitted.

I'm well aware of PRISM :-) You misunderstand me. PRISM is the program, but it needed an HQ! Here is that HQ: https://en.wikipedia.org/wiki/Utah_Data_Center Here is one such example of such a wiretapping program under AT&T: https://en.wikipedia.org/wiki/Room_641A And there are many more. It just depends on what you call "evidence". Is it your own definition, or are you relying on others to tell you what is and isn't…

You very clearly don't know what PRISM is. According to Snowden's documents, PRISM is the program that brings the FBI's FISA electronic communication wiretaps into the NSA's databases. It has absolutely nothing to do with Room 641A, which also doesn't do what you think it does.

I didn't say it had to do with Room 641A. That was a separate and distinct reply to your allegations over no proof of wiretapping.

Look at the very first sentence:

https://en.wikipedia.org/wiki/PRISM_(surveillance_program)

> PRISM is a secret code name for a program under which the United States National Security Agency (NSA) collects internet communications from at least nine major US internet companies

And here:

> Documents indicate that PRISM is "the number one source of raw intelligence used for NSA analytic reports", and it accounts for 91% of the NSA's internet traffic acquired under FISA section 702 authority." The leaked information came to light one day after the revelation that the FISA Court had been ordering a subsidiary of telecommunications company Verizon Communications to turn over to the NSA logs tracking all of its customers' telephone calls

You're talking out of your ass. Clearly. You can't even do basic research on the most public open knowledge base on the internet.

Just saying there is no evidence of mass wiretapping of AT&T's infra makes you look ignorant as hell.

Next you're going to tell me this is just a fraternity club:

https://vimeo.com/193562415

https://theintercept.com/2016/11/16/the-nsas-spy-hub-in-new-...

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#96

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…

> there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors

And this seems a little disingenuous. Perhaps there is no evidence so far regarding these particular leaks from Shadow Brokers, but in general the NSA has a history of creating backdoors.

You and I discussed some of this a bit already in one of the older NSA threads:

https://en.wikipedia.org/wiki/Bullrun_(decryption_program)

https://en.wikipedia.org/wiki/Dual_EC_DRBG

The idea of "key escrow", used by the NSA in the Clipper Chip's Skipjack algorithm, is really a euphemism for a built-in cryptographic backdoor.

https://en.wikipedia.org/wiki/Clipper_chip

https://en.wikipedia.org/wiki/Key_escrow

https://en.wikipedia.org/wiki/Skipjack_(cipher)

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#97

Earlier quoted context omitted.

If the IA department in the NSA were smart enough to figure out every vulnerability that the SIGINT department discovered and got everything fixed, SIGINT would be impotent. Clearly, things like SELinux make SIGINT's job harder, but your suggestion that SIGINT should handicap itself is ludicrous on its face.

Consider a few salient states: the U.S., Iran, Russia, ... If computers worldwide are mostly secure, which see the greatest benefit? If they're a festering pile of vulnerabilities, which see the greatest cost? That's the choice, as U.S. policy, of where you can focus your efforts. It's not a choice of secure U.S. computers and insecure Russian ones. The way you're framing it presumes SIGINT is in charge and positivel…

> The way you're framing it presumes SIGINT is in charge.

You fundamentally misunderstood my post, whiis causing you to reach strange conclusions. Neither is "in charge." They are two separate entities with separate missions. Some of the systems developed and documented by IA make the job of SIGINT difficult if our adversaries implement them as well.

How would spying from the air have prevented Iran from developing it's nuclear program?

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#98

Earlier quoted context omitted.

>Which is exactly what we crazy cookoo conspiracy theorists have been warning about. Which is what exactly? That a spy agency is spying? >If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massively weakened infrastructure, corporate, and government security I don't agree with putting in backdoors, but I don't see how exploiting backdoors by your se…

>Which is what exactly? The fact that the three letters are continuously failing to understand the long term blowback potential of the programs they start, regardless of initial merit. In this case, instead of spending nearly as much time doing hardening documents, they were busy comprimising everything . The name of almost all of our fuckups in this arena is blowback . >I don't see how exploiting backdoors by your s…

>For example, the chairman on the senate intel committee is about to vote for more oversight of $secretprogram.

People's memories are way too short with this kind of stuff because something like this already happened: The CIA hacked the computers of the senate oversight committee responsible for investigating the CIAs record of torture.

https://www.theguardian.com/world/2014/jul/31/cia-admits-spy...

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#99
post #95

Earlier quoted context omitted.

You very clearly don't know what PRISM is. According to Snowden's documents, PRISM is the program that brings the FBI's FISA electronic communication wiretaps into the NSA's databases. It has absolutely nothing to do with Room 641A, which also doesn't do what you think it does.

I didn't say it had to do with Room 641A. That was a separate and distinct reply to your allegations over no proof of wiretapping. Look at the very first sentence: https://en.wikipedia.org/wiki/PRISM_(surveillance_program) > PRISM is a secret code name for a program under which the United States National Security Agency (NSA) collects internet communications from at least nine major US internet companies And here: >…

Look at Snowden's actual documents. It shows the data is actually collected by the FBI's Data Intercept Technology Unit (https://i.imgur.com/setOJIm.jpg), which is the organization within the FBI that handles electronic wiretaps . The FBI requests data for specific accounts from these companies using FISA warrants and NSLs, but only the data requested via FISA (i.e., for foreigners) are allowed into the NSA's systems.

Room 641A isn't a mass wiretapping system. Once again, see the documents from Snowden. It looks for communications from specific Internet endpoints that are being wiretapped under court order.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#100
post #95

Earlier quoted context omitted.

I didn't say it had to do with Room 641A. That was a separate and distinct reply to your allegations over no proof of wiretapping. Look at the very first sentence: https://en.wikipedia.org/wiki/PRISM_(surveillance_program) > PRISM is a secret code name for a program under which the United States National Security Agency (NSA) collects internet communications from at least nine major US internet companies And here: >…

Look at Snowden's actual documents. It shows the data is actually collected by the FBI's Data Intercept Technology Unit ( https://i.imgur.com/setOJIm.jpg ), which is the organization within the FBI that handles electronic wiretaps . The FBI requests data for specific accounts from these companies using FISA warrants and NSLs, but only the data requested via FISA (i.e., for foreigners) are allowed into the NSA's syste…

I never denied the FBI's role in this?

I never said Room 641A was a mass wiretapping system? Just that it was one example of many such wiretapping initiatives?

I also provided citations showing that this is more than just targeting specific accounts?

You're starting to sound like a shill, that won't do any good if you're trying to convince people of your narrative.

Post reply on HN