Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

91–100 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#91

Earlier quoted context omitted.

He has backups of his data. I personally use linux and my github repo is here[1] where i have a bunch of encryption related projects(zuluCrypt,SiriKali and lxqt_wallet). The last windows computer i used was windows xp. I dont want to move him to linux because i am not always around and he can ask other people for help when he is on windows. [1] https://github.com/mhogomchungu

Thank God for backups! And thank you for making sure people make backups. My mother is in a similar situation. She is an elementary school teacher, and has little time for unrelated endeavors like this. What time she does have, is spent in the garden, as it should be. Nevertheless, we are now seeing that the time-cost of closed source software, is greater than that of open-source software. My solution has been to pre…

How quickly some forget heartbleed.

The solution to malware is obscurity. Have an OS that no one wants to break into, and you won't be broken into.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#92
post #25

From the Guardian: "He adds that the fear is that the ransonware cannot be broken and thus data and files infected are either lost or that the only way to get them back would be to pay the ransom, which would involve giving money to criminals." The new terrorism. https://www.theguardian.com/society/live/2017/may/12/england...

How is it terrorism if the purpose is to get money?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#93

Earlier quoted context omitted.

I worry that they might sell it as a reason backdoors are necessary: if only we had backdoors, we could've saved those patients! The flaw of this logic would be lost on most lawmakers.

Humor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.

Assuming that the criminal opts to use the encryption with an NSA backdoor and the victim is able to schedule time at their local NSA Genius Bar to recover their data.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#94
post #18

Earlier quoted context omitted.

Well this justifies MS's decision for forced updates in Win10. Not that I like it, just saying.

> Well this justifies MS's decision for forced updates in Win10. Not that I like it, just saying. Unfortunately, I think the active hours period cannot be set to more than twelve hours, which is less than the time required for some surgical interventions. I can almost imagine it: OK everyone, ten-minute break while Windows installs its updates, this guy who's been on life support for the last ten hours can wait a lit…

Win10 Pro is more flexible, although you might have to drop down to Group Policy to do it. http://pureinfotech.com/defer-windows-10-upgrades-updates/ At the very least, the workstations can be pointed to internal WSUS servers which control the rollouts. I'm guessing that's how most of the currently-vulnerable computers stayed vulnerable until now.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#95

> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professio…

Karen Sandler has an interesting story about medical devices and how they are, literally, putting her life on the line. She's both a lawyer and a hacker, and you should hear the stories she tells about how people distrust her for this and think she's trying to trick them when all she wants to do is learn about the software and hardware that is keeping her alive:

https://www.youtube.com/watch?v=iMKHqO28FcI

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#96

Earlier quoted context omitted.

I worry that they might sell it as a reason backdoors are necessary: if only we had backdoors, we could've saved those patients! The flaw of this logic would be lost on most lawmakers.

Humor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.

Wouldn't the attackers just use a crypto scheme that didn't have a backdoor?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#97
post #70

Edit: Botnet stats and spread (switch to 24H to see full picture): https://intel.malwaretech.com/botnet/wcrypt Live map: https://intel.malwaretech.com/WannaCrypt.html Relevant MS security bulletin: https://technet.microsoft.com/en-us/library/security/ms17-01... Edit: Analysis from Kaspersky Lab: https://securelist.com/blog/incidents/78351/wannacry-ransomw...

Are we watching this thing wake up right now?

We are seeing new requests from existing bots, the historical data is not shown on this map.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#98
post #21

Wow, this is so insane. I really don't think the NSA should be finding vulnerabilities and keeping them to themselves. I mean I get it is all to help stop the bad guys, but if you are keeping cyber weapons like this. You should be required to keep them as secure and locked as possible if you don't follow responsible disclosure. Just like how a cop would keep their weapon on them, instead of sitting it down on the tab…

Your last sentence seems to contradict your first, whereas what you would really prefer is to disarm the police. Sadly I don't think that's so practical, in the same way that it would be impractical for US police to go unarmed given the high incidence of gun ownership in the US. I grew up in a country where police are not normally armed (other than with a small baton or similar personal defense weapon) and much prefe…

The problem with the gun analogy in your particular argument is that a 'cyber weapon' or exploit is the flip side of a flaw in normal software.

The NSA is in a very weird position because they have a task to protect the systems of the US (Information Assurance) but also to attack those of adversaries.

In this case I think they are legitimately to blame for failing to discharge their assurance duties. They've failed to properly calculate the risk of leaking the exploit and now US interests are harmed because of that failure. This is a direct result of stockpiling exploits and not exposing them to the respective software vendors. In my opinion the security of your own systems is more important the insecurity of that of your adversaries, which is why I believe that the hoarding is bad.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#99

I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.

To be completely fair, it's not the NSA's fault that software has faults. Its the software manufacturers'.

The ethical concern here is whether the NSA should have reported the holes to the manufacturers and the failure to handle its privileged knowledge in a safe manner.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#100

Earlier quoted context omitted.

I worry that they might sell it as a reason backdoors are necessary: if only we had backdoors, we could've saved those patients! The flaw of this logic would be lost on most lawmakers.

Humor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.

The logic is that encryption without a backdoor already exists, and no law can stop a criminal writing a virus from using that.
Post reply on HN