Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…
> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…
Thousands of computers now compromised with leaked NSA tools, researchers say
101–110 of 173 posts
Re: Thousands of computers now compromised with leaked NSA tools, researchers say
#102Earlier quoted context omitted.
> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…
> there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors And this seems a little disingenuous. Perhaps there is no evidence so far regarding these particular leaks from Shadow Brokers, but in general the NSA has a history of creating backdoors. You and I discussed some of this a bit already in one of the older NSA threads: https://en.wikipedia.org/wiki/Bullrun_(dec…
Re: Thousands of computers now compromised with leaked NSA tools, researchers say
#103Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…
> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…
EDIT: I would agree that without intent to gain access, it's not inserting a backdoor.
Re: Thousands of computers now compromised with leaked NSA tools, researchers say
#104Earlier quoted context omitted.
Consider a few salient states: the U.S., Iran, Russia, ... If computers worldwide are mostly secure, which see the greatest benefit? If they're a festering pile of vulnerabilities, which see the greatest cost? That's the choice, as U.S. policy, of where you can focus your efforts. It's not a choice of secure U.S. computers and insecure Russian ones. The way you're framing it presumes SIGINT is in charge and positivel…
> The way you're framing it presumes SIGINT is in charge. You fundamentally misunderstood my post, whiis causing you to reach strange conclusions. Neither is "in charge." They are two separate entities with separate missions. Some of the systems developed and documented by IA make the job of SIGINT difficult if our adversaries implement them as well. How would spying from the air have prevented Iran from developing i…
Iran with nukes seems to me a lesser threat to us than an uncontrolled U.S. government.
Re: Thousands of computers now compromised with leaked NSA tools, researchers say
#105Earlier quoted context omitted.
> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…
Would it be crazy to say sitting on exploits is effectively "inserting a backdoor"? Maybe it doesn't have a doormat but it certainly still grants you access. To me this would seem against the mission statement of protecting national security when a whole list of them are published, like now... EDIT: I would agree that without intent to gain access, it's not inserting a backdoor.
That seems intentionally dishonest, no? If I disagree with a position I'm not justified in intentionally misrepresenting it because I feel morally correct. Unless you're alleging that these vulnerabilities were intentionally placed there, I don't understand why you'd feel the need to say that. Worrying about the effects of stockpiling vulnerabilities seems like a defensible position in and of itself.
Re: Thousands of computers now compromised with leaked NSA tools, researchers say
#106Earlier quoted context omitted.
> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…
Would it be crazy to say sitting on exploits is effectively "inserting a backdoor"? Maybe it doesn't have a doormat but it certainly still grants you access. To me this would seem against the mission statement of protecting national security when a whole list of them are published, like now... EDIT: I would agree that without intent to gain access, it's not inserting a backdoor.
Re: Thousands of computers now compromised with leaked NSA tools, researchers say
#107Earlier quoted context omitted.
> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…
Would it be crazy to say sitting on exploits is effectively "inserting a backdoor"? Maybe it doesn't have a doormat but it certainly still grants you access. To me this would seem against the mission statement of protecting national security when a whole list of them are published, like now... EDIT: I would agree that without intent to gain access, it's not inserting a backdoor.
Part of the NSA's job is signals intelligence, so they specifically find the vulnerabilities as a means of access. And if that were not the case, they would not have spent the time finding the vulnerabilities, so those 0-days would still exist and be potential attack vectors regardless.
Re: Thousands of computers now compromised with leaked NSA tools, researchers say
#108Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…
> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…
Many 0-days are built of of multiple bugs. A triple letter may use bug #1 and bug #2 to get a result, but another party will use bug #1 and bug #3 to get a similar result. Back to square one with corporate/government/personal equipment getting hacked reducing overall security.
Re: Thousands of computers now compromised with leaked NSA tools, researchers say
#109* The zero-day has to be powerful enough to allow the agency to gain full access & remotely patch the zero day -- i.e. if the zero-day gets out, and the agency didn't warn the manufacturer ahead of time and instead used it for its own purposes, it must have the capability to "immediately" scan the internet for the vulnerability and patch it where accessible.
* If the above condition is not satisfied, or if the agency can't/won't dedicate the resources to develop a backup patch, it should be required to alert the manufacturer immediately.
Does this cost more? Yes. Does it limit some of the monitoring capabilities they will have? Yes. The second seems like a pro. The first one seems like a worthy compromise for questionable activity with high potential for collateral damage.
Re: Thousands of computers now compromised with leaked NSA tools, researchers say
#110It would be interesting (although I expect impossible) to figure out how many of those thousands were compromised by the NSA vs those compromised by people who got the tools through the leak. It was nice that Microsoft had already fixed a bunch of them (almost like they were told ahead of time they were coming). It is also interesting to read the outrage about the tools and the presentations on how to use them. If yo…
Because we aren't talking about bombs. We are talking about security.
We are concerned about "nuclear proliferation". Why aren't we concerned about the proliferation of these tools? It takes material to make nuclear weapons (obviously nuclear weapons are much more concerning, that isn't my point), but it only takes instructions to create and use security exploits. In this scenario, threats only have power for everyone who knows about them, and that is inherently dangerous. We should put all of our focus into getting rid of security exploits, not creating them.