Live data from Hacker News

Thousands of computers now compromised with leaked NSA tools, researchers say

cyberscoop.com

101–110 of 173 posts

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#101

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…

I think a more reasonable approach would be to have a hard time limit on each discovered exploit. Something like 180 days to use it for any missions, after which they must report the exploit and get it patched. This shortens the window for any leaks or independent discovery while still allowing it to be used for important intelligence gathering activities. In turn this will create a pressure to keep finding more exploits as old ones expire, and that in turn will mean more get fixed 180 days later, etc.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#102
post #96

Earlier quoted context omitted.

> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…

> there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors And this seems a little disingenuous. Perhaps there is no evidence so far regarding these particular leaks from Shadow Brokers, but in general the NSA has a history of creating backdoors. You and I discussed some of this a bit already in one of the older NSA threads: https://en.wikipedia.org/wiki/Bullrun_(dec…

I definitely do not deny any previous instances. I am very against backdoors and will never defend them. But it is an extreme accusation to make against Microsoft in this case without evidence, so the fact that there is no evidence should be stated clearly to ensure people do not get confused.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#103

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…

Would it be crazy to say sitting on exploits is effectively "inserting a backdoor"? Maybe it doesn't have a doormat but it certainly still grants you access. To me this would seem against the mission statement of protecting national security when a whole list of them are published, like now...

EDIT: I would agree that without intent to gain access, it's not inserting a backdoor.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#104

Earlier quoted context omitted.

Consider a few salient states: the U.S., Iran, Russia, ... If computers worldwide are mostly secure, which see the greatest benefit? If they're a festering pile of vulnerabilities, which see the greatest cost? That's the choice, as U.S. policy, of where you can focus your efforts. It's not a choice of secure U.S. computers and insecure Russian ones. The way you're framing it presumes SIGINT is in charge and positivel…

> The way you're framing it presumes SIGINT is in charge. You fundamentally misunderstood my post, whiis causing you to reach strange conclusions. Neither is "in charge." They are two separate entities with separate missions. Some of the systems developed and documented by IA make the job of SIGINT difficult if our adversaries implement them as well. How would spying from the air have prevented Iran from developing i…

Well, I said the spying mission of NSA should not override the security of the U.S., and pointed to the contrast between the old sometimes-improvement of crypto standards and the new backdooring of them. You answered that my "suggestion that SIGINT should handicap itself is ludicrous on its face." I don't care if the NSA's SIGINT department does not value our information security; we, the citizens, do. Their narrow departmental interest goes against our interest. The NSA as a whole used to better approximate that interest, back sometime in the 20th century, even if very imperfectly (see Bamford's history). This conversation was missing this point about the NSA's broader mission.

Iran with nukes seems to me a lesser threat to us than an uncontrolled U.S. government.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#105

Earlier quoted context omitted.

> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…

Would it be crazy to say sitting on exploits is effectively "inserting a backdoor"? Maybe it doesn't have a doormat but it certainly still grants you access. To me this would seem against the mission statement of protecting national security when a whole list of them are published, like now... EDIT: I would agree that without intent to gain access, it's not inserting a backdoor.

>Would it be crazy to say sitting on exploits is effectively "inserting a backdoor"

That seems intentionally dishonest, no? If I disagree with a position I'm not justified in intentionally misrepresenting it because I feel morally correct. Unless you're alleging that these vulnerabilities were intentionally placed there, I don't understand why you'd feel the need to say that. Worrying about the effects of stockpiling vulnerabilities seems like a defensible position in and of itself.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#106

Earlier quoted context omitted.

> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…

Would it be crazy to say sitting on exploits is effectively "inserting a backdoor"? Maybe it doesn't have a doormat but it certainly still grants you access. To me this would seem against the mission statement of protecting national security when a whole list of them are published, like now... EDIT: I would agree that without intent to gain access, it's not inserting a backdoor.

its a 0day. a bug not intentional. the effect is the same but can and ussually does get fixed(whether timely or not is another thing).

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#107

Earlier quoted context omitted.

> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…

Would it be crazy to say sitting on exploits is effectively "inserting a backdoor"? Maybe it doesn't have a doormat but it certainly still grants you access. To me this would seem against the mission statement of protecting national security when a whole list of them are published, like now... EDIT: I would agree that without intent to gain access, it's not inserting a backdoor.

Hard to say, that is much more of moral argument rather than one you could argue much based on fact.

Part of the NSA's job is signals intelligence, so they specifically find the vulnerabilities as a means of access. And if that were not the case, they would not have spent the time finding the vulnerabilities, so those 0-days would still exist and be potential attack vectors regardless.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#108

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…

A unreported zero day is a de facto backdoor. The chain you mentioned has similar flaws as the current strategy. Step 3 would be incredibly difficult. It would be similar to detecting a virus signature, which are easily circumvented. The second party can use trivial techniques to change the signature in a way that makes it incredibly difficult to detect.

Many 0-days are built of of multiple bugs. A triple letter may use bug #1 and bug #2 to get a result, but another party will use bug #1 and bug #3 to get a similar result. Back to square one with corporate/government/personal equipment getting hacked reducing overall security.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#109
I like the idea of the agencies being allowed to use a zero-day with some asterisks.

* The zero-day has to be powerful enough to allow the agency to gain full access & remotely patch the zero day -- i.e. if the zero-day gets out, and the agency didn't warn the manufacturer ahead of time and instead used it for its own purposes, it must have the capability to "immediately" scan the internet for the vulnerability and patch it where accessible.

* If the above condition is not satisfied, or if the agency can't/won't dedicate the resources to develop a backup patch, it should be required to alert the manufacturer immediately.

Does this cost more? Yes. Does it limit some of the monitoring capabilities they will have? Yes. The second seems like a pro. The first one seems like a worthy compromise for questionable activity with high potential for collateral damage.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#110

It would be interesting (although I expect impossible) to figure out how many of those thousands were compromised by the NSA vs those compromised by people who got the tools through the leak. It was nice that Microsoft had already fixed a bunch of them (almost like they were told ahead of time they were coming). It is also interesting to read the outrage about the tools and the presentations on how to use them. If yo…

> Why should cyber war be any different?

Because we aren't talking about bombs. We are talking about security.

We are concerned about "nuclear proliferation". Why aren't we concerned about the proliferation of these tools? It takes material to make nuclear weapons (obviously nuclear weapons are much more concerning, that isn't my point), but it only takes instructions to create and use security exploits. In this scenario, threats only have power for everyone who knows about them, and that is inherently dangerous. We should put all of our focus into getting rid of security exploits, not creating them.

Post reply on HN