Live data from Hacker News

Thousands of computers now compromised with leaked NSA tools, researchers say

cyberscoop.com

131–140 of 173 posts

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#131
post #39

"Once installed, DOUBLEPULSAR is a stealthy backdoor that’s difficult to detect and continuously relays new information back to its controller." Seems to contradict itself? If it's continuously relaying information, wouldn't that make it easy to detect?

I think what that means is that it's difficult to detect on the infected host machine. It's easy to detect at the network level, however.

Depending on the implementation of "continuously", it might not be easy there either. Most hosts have some reason to be on the internet. Therefore, with some cleverness, attack traffic can be hidden within normal, expected traffic.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#132

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

They don't even need to go out into the wild.

https://en.wikipedia.org/wiki/Aldrich_Ames

https://en.wikipedia.org/wiki/Robert_Hanssen

The US intelligence agencies have a less than stellar history regarding moles.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#133

Earlier quoted context omitted.

> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…

A unreported zero day is a de facto backdoor. The chain you mentioned has similar flaws as the current strategy. Step 3 would be incredibly difficult. It would be similar to detecting a virus signature, which are easily circumvented. The second party can use trivial techniques to change the signature in a way that makes it incredibly difficult to detect. Many 0-days are built of of multiple bugs. A triple letter may…

> A unreported zero day is a de facto backdoor

Traditionally the meaning of “backdoor” has involved intent as well as access. Unlike a basic bug, the system is working as designed but the designer wasn't trustworthy.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#134

Earlier quoted context omitted.

> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…

A unreported zero day is a de facto backdoor. The chain you mentioned has similar flaws as the current strategy. Step 3 would be incredibly difficult. It would be similar to detecting a virus signature, which are easily circumvented. The second party can use trivial techniques to change the signature in a way that makes it incredibly difficult to detect. Many 0-days are built of of multiple bugs. A triple letter may…

> A unreported zero day is a de facto backdoor.

This is not true. A backdoor indicates that Microsoft is aware of it (and/or colluded to put it in), but there is no evidence of that. I respect your disagreement with my thoughts on how they should handle 0-days, but re-defining "backdoor" does not seem helpful.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#135
post #95

Earlier quoted context omitted.

I didn't say it had to do with Room 641A. That was a separate and distinct reply to your allegations over no proof of wiretapping. Look at the very first sentence: https://en.wikipedia.org/wiki/PRISM_(surveillance_program) > PRISM is a secret code name for a program under which the United States National Security Agency (NSA) collects internet communications from at least nine major US internet companies And here: >…

Look at Snowden's actual documents. It shows the data is actually collected by the FBI's Data Intercept Technology Unit ( https://i.imgur.com/setOJIm.jpg ), which is the organization within the FBI that handles electronic wiretaps . The FBI requests data for specific accounts from these companies using FISA warrants and NSLs, but only the data requested via FISA (i.e., for foreigners) are allowed into the NSA's syste…

People did not read the source material of the Snowden leaks, only the editorialized articles which made unsubstantiated interpretations of what the leaked slides mean. That is probably why you are being downvoted, regardless of the fact that you are entirely correct.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#136

Tech security has been an afterthought for too long. The core technologies we use are putting us at grave risk in ways we simply cannot imagine. As we now are starting to realize, that all of our digital lives are permanently centrally recorded carries currently unimaginable risks down the road. That we have centralized global social networks carries risks that the majority of people are not able to experience or und…

Poetic, but you shot yourself in the foot in the first paragraph. "That we have centralized global social networks carries risks that the majority of people are not able to experience" If the majority of people do not experience the consequences of the risks of whatever-it-is-your-railing-against, if those risks are never realised by the majority, your argument evaporates.

Perhaps the reason most of us don't experience the risks is because the nature of cyber warfare is more subtle than any other form of warfare in history. Social engineers prefer to be undetectable, that means they're doing it right.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#137
post #79

Earlier quoted context omitted.

> Would you say the same of Chinese government hackers and Syran military? No, for the same reason why I'm okay with the US military having nukes but wouldn't be okay with Syria having them. Obviously it'd be great if we could get by with no military powers having to possess zero-day exploits (or nukes), but so long as we can't be sure no other nations are benefiting from such exploits, it makes no sense strategicall…

So it equally makes no sense for China to forbid itself from using their own exploits? As long as they can't be sure America isn't benefiting from them, they'd better keep up with the arms race. Or do you consider America to be special and that it deserves these powers more than other countries? Personally I don't think it's competent to hold them because it has an ongoing history of using its weapons to destroy othe…

> So it equally makes no sense for China to forbid itself from using their own exploits? As long as they can't be sure America isn't benefiting from them, they'd better keep up with the arms race.

Correct. Same goes for any nation. Since there's no way to be sure that other nations aren't developing zero-day exploits, not developing exploits of your own does nothing more than put you at a disadvantage.

> Or do you consider America to be special and that it deserves these powers more than other countries?

Yes. I know this seems to be a rather unpopular opinion with the HN crowd these days, but the US absolutely deserves to have better military capabilities than nations like Syria or China. (As for Germany, I'd also be mostly okay with them possessing exploits; as they're a democratic nation who I generally trust to act in the best interests of their citizens. I cannot say the same for Syria or China.)

> But really, why not nobody? Exploits are offensive weapons, not defensive ones.

That'd be great, but unfortunately it's not a realistic option. So long as one nation possesses and benefits from zero-day exploits (even secretly) then it makes no strategic sense for any other nation to intentionally put themselves at a disadvantage by not developing exploits of their own.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#138

Earlier quoted context omitted.

> I never said PRISM was the same program that engaged in mass surveillance. You started off by saying you knew about PRISM because the NSA is building a large datacenter in Utah just to hold PRISM's data. > I also never mentioned Google. I never claimed you did. You claimed that PRISM ingested mass wiretapping data. That data would come from Google and other Internet companies according to the documents. My point wa…

I'm going to ignore your warping of my words and focus on the interesting bit here: again, Google. You don't remember when news broke in 2014 that the NSA was snooping on Google's Gmail traffic that was flying around unencrypted within their own network? Google, rightfully embarrassed, subsequently enabled internal end-to-end encryption after the news broke. Here it is straight from the horse's mouth: https://gmail.g…

I cited Snowden's own documents.

According to Snowden's documents, the NSA used email envelope metadata where at least one side was a foreigner to build a connection graph, similar to pen register metadata collection. It didn't look at the contents, which it would have to do in order to be wiretapping. That program (STELLARWIND, which operated behind the Internet companies' backs, not PRISM, which operated via court orders on specific accounts) ended before Snowden even leaked it. https://www.theguardian.com/world/interactive/2013/jun/27/ns...

Let's recap. You claimed that PRISM is mass wiretapping. It isn't. You claimed that the NSA is mass wiretapping Verizon and AT&T. It isn't. Let's stick to your original claims and see them through to completion. Do you admit you were wrong about PRISM and the telcos?

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#139

Earlier quoted context omitted.

I'm going to ignore your warping of my words and focus on the interesting bit here: again, Google. You don't remember when news broke in 2014 that the NSA was snooping on Google's Gmail traffic that was flying around unencrypted within their own network? Google, rightfully embarrassed, subsequently enabled internal end-to-end encryption after the news broke. Here it is straight from the horse's mouth: https://gmail.g…

I cited Snowden's own documents. According to Snowden's documents, the NSA used email envelope metadata where at least one side was a foreigner to build a connection graph, similar to pen register metadata collection. It didn't look at the contents, which it would have to do in order to be wiretapping. That program (STELLARWIND, which operated behind the Internet companies' backs, not PRISM , which operated via court…

Citing Snowden's documents would involve actually giving me a link.

I did not say PRISM was mass wiretapping but it is indeed part of the surveillance suite of NSA programs. I did not adequately explain myself in my original post, but I cleared things up afterwards and you are ignoring that completely. You have consistently been framing my arguments in a specific way so that you can attack them in a specific way.

I also don't understand why you think that the NSA was not mass wiretapping both of those telco's major junctions. It's a known thing. It's not some fringe conspiracy theory. The Fed has been tapping phone lines since the very beginning. Not all of them sure, but certainly in a dragnet fashion. This has continued with the explosive growth of information networks into the 21st century. I provided links. I do not need to provide any more on that topic.

I've honestly never encountered someone before who so earnestly believes as you do that these programs are not widespread or dangerous or grossly overstepping their bounds. It's like denying climate change or something.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#140
post #63
post #54

Earlier quoted context omitted.

It was before Snowden. We have had hard facts since the 90's that mass wiretapping and exploitation has been going on thru vehicles like AT&T and Verizon. And we knew about PRISM for a good two years before its public disclosure. Sudden black square over a remote area in Utah in satellite imagery. Pictures of a massive contruct. Coupled with the fact that we knew they needed a place to centralize all of this collecte…

> It was before Snowden. I wasn't saying that's when it started. I was saying that's when people stopped viewing "government is listening to everyone" as conspiracy. > No one just wanted to frigging listen until they had a celebrity icon like Snowden to interest them... It didn't have anything to do with Snowden's "celebrity". Do you think he was a celebrity before he produced physical evidence ? Turns out, no one wa…

You're missing the point.

Someone already had proof.

Snowden was the one who managed to bring it to a mass audience. And I love him and respect him immensely for that. But I'm sure he also feels the same disdain that it took him completely destroying his life to convince people that something nefarious has been going on when many clues were already public and just routinely dismissed by people like the other guy arguing with me right now.

Yeah, he gave lots of evidence on programs we didn't even know existed. Like, the full extent of this situation. But we already had enough information to know that we should demand legislation and oversight and that 1984 has all but come true.

Post reply on HN