Live data from Hacker News

Thousands of computers now compromised with leaked NSA tools, researchers say

cyberscoop.com

121–130 of 173 posts

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#121

Earlier quoted context omitted.

The NSA leverages these exploits to spy on foreign nations. That's fine, spies should spy... But it does beg the question: who's protecting our information from foreign intrusions?

Before this runs the risk of becoming a universally acknowledged truth, is it fine? Actually wasn't "Gentlemen don't open each other mail", also a perfectly reasonable position? In the cyberwar the US already seems to be fighting against its own weapons! Would it actually be much better for a nation like the US to use its knowledge defensively and keep their citizens safe from foreign interference?

I also strongly advocate for information disclosure and collaborating with vendors.

However, I'm not convinced the NSA is the entity for that role. Organizationally, the NSA makes more sense as an R&D entity that discloses to offensive intelligence agencies and defensive security forces.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#122

Earlier quoted context omitted.

The CIA and NSA are externally oriented. Defense is arguably part of the FBI mission, however they don't have the NSA's level of skill or resources. The FBI might be able to detect abuse when it gets rampant but I have zero confidence that they would discover any of these exploits themselves. The FBI is mostly cleanup and criminal prosecution. We need an organization focused on preemptively securing our infrastructur…

The NSA is actually tasked with that mission: > NSA is concurrently charged with protection of U.S. government communications and information systems against penetration and network warfare. https://en.wikipedia.org/wiki/National_Security_Agency

Yes, government defense. Who protects the rest?

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#123

Earlier quoted context omitted.

I never said PRISM was the same program that engaged in mass surveillance. I also never mentioned Google. Your arguments keep starting off by strawmanning my own. But sure let's talk about Google. You really think Schmidt and friends are clean on this? He is a globalist authoritarian lap dog. https://wikileaks.org/google-is-not-what-it-seems/ And you're also fundamentally confused about something. See, the NSA does n…

> I never said PRISM was the same program that engaged in mass surveillance. You started off by saying you knew about PRISM because the NSA is building a large datacenter in Utah just to hold PRISM's data. > I also never mentioned Google. I never claimed you did. You claimed that PRISM ingested mass wiretapping data. That data would come from Google and other Internet companies according to the documents. My point wa…

I'm going to ignore your warping of my words and focus on the interesting bit here: again, Google.

You don't remember when news broke in 2014 that the NSA was snooping on Google's Gmail traffic that was flying around unencrypted within their own network? Google, rightfully embarrassed, subsequently enabled internal end-to-end encryption after the news broke.

Here it is straight from the horse's mouth: https://gmail.googleblog.com/2014/03/staying-at-forefront-of...

So... yeah. Not baseless at all. Meanwhile you have yet to provide a single citation throughout all of this.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#124

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it. That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary. That doesn't solve the fact that NSA's competitors could find a…

> The NSA needs to exploit flaws

there are plenty legal wiretapping/surveillance alternatives that don't rely on not fixing a compromised worldwide infrastructure.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#125

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

>Which is exactly what we crazy cookoo conspiracy theorists have been warning about. Which is what exactly? That a spy agency is spying? >If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massively weakened infrastructure, corporate, and government security I don't agree with putting in backdoors, but I don't see how exploiting backdoors by your se…

> I don't see how exploiting backdoors by your security agency is so nefarious.

Did you ever hear the tragedy of Stuxnet the wise?

Stuxnet was a cyberweapon so powerful and so well hidden it could use computers to cause nuclear centrifuges to fail.

Unfortunately, others learned from code the worm left behind, then other actors used the same techniques to infiltrate computers everywhere for a year. Ironic. It could save the world from nuclear weapons, but not computers.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#126
post #11

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

You haven't been a crazy cookoo conspiracy theorists since the Snowden dropped his info. Unless you've got conspiracies on other topics, then maybe. I think it's fairly common for even someone with a cursory knowledge of security to know that backdoors are a bad idea. The triple letters don't get their power from poor products. Those are going to be around no matter what. I'd rather this just drive a push toward more…

> You haven't been a crazy cookoo conspiracy theorists since the Snowden dropped his info.

neh, the world was calling for them to stop trying putting backdoors in security software for a while. To my generation it was the 2007 ecc curve primes. https://www.schneier.com/blog/archives/2007/11/the_strange_s...

to the previous generation it was the clipper.

Snowden really raised awarenes outside the security circles, but this has been an issue long time prior

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#127
post #79

Earlier quoted context omitted.

> it's hard to seriously argue that the NSA should stop exploiting computers. It's their role. We need them, just like we need a military. Would you say the same of Chinese government hackers and Syran military? If yes, OK. I understand you accept the need for competition in arms. If not, can you explain why?

> Would you say the same of Chinese government hackers and Syran military? No, for the same reason why I'm okay with the US military having nukes but wouldn't be okay with Syria having them. Obviously it'd be great if we could get by with no military powers having to possess zero-day exploits (or nukes), but so long as we can't be sure no other nations are benefiting from such exploits, it makes no sense strategicall…

So it equally makes no sense for China to forbid itself from using their own exploits? As long as they can't be sure America isn't benefiting from them, they'd better keep up with the arms race.

Or do you consider America to be special and that it deserves these powers more than other countries? Personally I don't think it's competent to hold them because it has an ongoing history of using its weapons to destroy other countries, property and lives. If I had to choose who wins the arms race, I would prefer a less hostile country like China or Germany to have them instead of America. But really, why not nobody? Exploits are offensive weapons, not defensive ones.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#128

Earlier quoted context omitted.

>Which is what exactly? The fact that the three letters are continuously failing to understand the long term blowback potential of the programs they start, regardless of initial merit. In this case, instead of spending nearly as much time doing hardening documents, they were busy comprimising everything . The name of almost all of our fuckups in this arena is blowback . >I don't see how exploiting backdoors by your s…

>For example, the chairman on the senate intel committee is about to vote for more oversight of $secretprogram. People's memories are way too short with this kind of stuff because something like this already happened: The CIA hacked the computers of the senate oversight committee responsible for investigating the CIAs record of torture. https://www.theguardian.com/world/2014/jul/31/cia-admits-spy...

That's just the time they got caught. We can be sure they do this constantly.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#129

Earlier quoted context omitted.

The NSA is actually tasked with that mission: > NSA is concurrently charged with protection of U.S. government communications and information systems against penetration and network warfare. https://en.wikipedia.org/wiki/National_Security_Agency

Yes, government defense. Who protects the rest?

Private entities protect themselves and their customers, to varying degrees, which is how it has always been.
Post reply on HN