Live data from Hacker News

Thousands of computers now compromised with leaked NSA tools, researchers say

cyberscoop.com

141–150 of 173 posts

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#141

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…

I find it strange that you seem to be ignorant of the basic concepts of obsfucation and plausible deniability, yet act as though you are knowledgeable of IT security.

Do you also believe spies in the physical world use secret entrances with brass placards placed above them?

People like you are the reason why organizations fail at security.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#142

Earlier quoted context omitted.

> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…

I think a more reasonable approach would be to have a hard time limit on each discovered exploit. Something like 180 days to use it for any missions, after which they must report the exploit and get it patched. This shortens the window for any leaks or independent discovery while still allowing it to be used for important intelligence gathering activities. In turn this will create a pressure to keep finding more expl…

I love comments like this, because they acknowledge that there are two valuable things here: (a) collecting sigint via available means & (b) keeping infrastructure secure.

The best solution enables both of these to the maximal extent possible (and has honest discussions about their relative values).

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#143

I like the idea of the agencies being allowed to use a zero-day with some asterisks. * The zero-day has to be powerful enough to allow the agency to gain full access & remotely patch the zero day -- i.e. if the zero-day gets out, and the agency didn't warn the manufacturer ahead of time and instead used it for its own purposes, it must have the capability to "immediately" scan the internet for the vulnerability and p…

At some point, they'd make the patch, and discover they need access again for some reason. We'd be right back where we started.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#144

Earlier quoted context omitted.

> literally why they were created to do The NSA is supposed to do both defense and offense. The defense came up, for example, when they improved DES to resist differential cryptanalysis (which the public crypto world hadn't discovered yet) before DES was standardized. But that was a long time ago; at least since 9/11 the offense side seems to have pretty much eaten the defense, as far as we can tell. (See: https://en…

If the IA department in the NSA were smart enough to figure out every vulnerability that the SIGINT department discovered and got everything fixed, SIGINT would be impotent. Clearly, things like SELinux make SIGINT's job harder, but your suggestion that SIGINT should handicap itself is ludicrous on its face.

Clearly you don't realize the origin of SELinux and why it's such a limp dick.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#145
I have heard the NSA mission in this regard characterized as both defensive, and offensive. Defensive in that they protect our infrastructure (a counter-intel role), and offensive in that they attempt to exploit the infrastructure of our adversaries (and others) for sigint. They trick is finding the right balance, and I don't think there's much hope for agreement on that at the moment. I also find the debate a difficult one to engage in because there are large information asymmetries and much of what we're trying to discuss is obscured by secret courts, classified documents, etc. My impression is that even the people who are tasked with oversight don't get the full picture, so what do we hope to know about it. I've had experiences in industry that I can't talk about that maybe you (in the general sense) haven't had that also inform my views.

Personally, my view is that we should be putting the focus on the defensive side. Protect infrastructure, IP, etc. I believe the reputation of technology in general is harmed by the offensive mission, and US companies disproportionately so. There is now even greater incentives for our adversaries (and friends) to foster development of technologies that compete directly with US products in their own jurisdictions (where they can get a look under the hood).

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#146
I am worried about the firmware of Intel processors which I believe have had firmware since the mid-1990s or a bit later. Is this possible and are there tools "in the wild" that are capable of doing this? Does Intel do some sort of checksum to ensure that this cannot happen?

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#147
post #96

Earlier quoted context omitted.

> If you put backdoors in, or exploit 0days for your own This seems like a disingenuous statement. I believe many reasonable folks would agree that inserting backdoors is an awful idea. However, there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors. Mentioning backdoors dilutes the discussion as it makes it seem like there is any sort of relationship with 0-day ex…

> there is no evidence at all which indicates the exploits leaked by Shadow Brokers are intentional backdoors And this seems a little disingenuous. Perhaps there is no evidence so far regarding these particular leaks from Shadow Brokers, but in general the NSA has a history of creating backdoors. You and I discussed some of this a bit already in one of the older NSA threads: https://en.wikipedia.org/wiki/Bullrun_(dec…

Perhaps there is no evidence so far regarding these particular leaks from Shadow Brokers

And right there, GP is correct. Either there is evidence to suggest that these were planted backdoors (difficulty: patched out long before the leaks), or there is not.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#148

Earlier quoted context omitted.

Poetic, but you shot yourself in the foot in the first paragraph. "That we have centralized global social networks carries risks that the majority of people are not able to experience" If the majority of people do not experience the consequences of the risks of whatever-it-is-your-railing-against, if those risks are never realised by the majority, your argument evaporates.

Perhaps the reason most of us don't experience the risks is because the nature of cyber warfare is more subtle than any other form of warfare in history. Social engineers prefer to be undetectable, that means they're doing it right.

Then it's hard to tell where the line between (cyber) warfare and social engineering can be drawn.

Is what Facebook did[1] (does?) warfare? I sometimes like to dabble in hyperbolic alarmism, so I'm inclined to want to say yes.

Maybe it's a sign of progress that we now consider emotional manipulation "war". It's probably less harmful, by all accounts, than slaughtering each other.

1. https://www.theguardian.com/technology/2014/jun/29/facebook-...

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#149

Earlier quoted context omitted.

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it. That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary. That doesn't solve the fact that NSA's competitors could find a…

> If it ever leaks We have evidence that the NSA has no idea from where or through whom it's leaking. My impulse is to say "you get so many years to use an exploit, maybe more with higher-up approval, and then you must disclose it." Unfortunately, with virtually zero independent oversight of these agencies, I have no faith such rules would be followed.

We aren't at war with a country, we don't need spy agencies.

Disband the CIA, NSA and their 3 letter brothers. Fold personal and funding into the FBI. This doesn't make me a fan of the FBI, but at least there is some transparency. IMO

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#150

Earlier quoted context omitted.

Perhaps the reason most of us don't experience the risks is because the nature of cyber warfare is more subtle than any other form of warfare in history. Social engineers prefer to be undetectable, that means they're doing it right.

Then it's hard to tell where the line between (cyber) warfare and social engineering can be drawn. Is what Facebook did[1] (does?) warfare? I sometimes like to dabble in hyperbolic alarmism, so I'm inclined to want to say yes. Maybe it's a sign of progress that we now consider emotional manipulation "war". It's probably less harmful, by all accounts, than slaughtering each other. 1. https://www.theguardian.com/techno…

I agree on all accounts. Facebook testing emotional manipulation is corporate psyops weapons development.

Marshall McLuhan postulated back in the 1970 about the future of warfare:

>World War I a railway war of centralization and encirclement. World War II a radio war of decentralization concluded by the Bomb...

>World War III is a guerilla information war with no division between military and civilian participation

Post reply on HN