Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

131–140 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#131

Earlier quoted context omitted.

Why are power stations on the same network with some guy with a USB key?

Because people still use USB drives to copy information to airgapped computers. It is easier than the alternatives.

Yes, they do. Yes, it easier. Yet, it completely undoes the "airgap" thing.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#132

Earlier quoted context omitted.

I understand that people love open source, but how is that relevant here? For example OpenSSL is open source, yet it didn't prevent Heartbleed and other exploits from happening?

OpenSSL was an example of open source done badly; neither of our communities can claim to be universally perfect. The solution, was to fork and replace OpenSSL with a superior project: LibreSSL. That part of the story, is a success for open source. It shows us recovering quickly and permanently from the worst catastrophe imaginable.

How widely is LibreSSL used, compared to OpenSSL?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#133
post #46

Can't law enforcement follow the transactions of the public address of the ransom bitcoin wallet until the bitcoin is sold?

There are services that will mix your coins making it impossible to track because he will receive other people coins from the pool.

Do you think it would be possible for those services to block or 'embargo' transactions from 'tainted' addresses, such as the ones used for the cyberattacks' ransom?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#134
post #25

From the Guardian: "He adds that the fear is that the ransonware cannot be broken and thus data and files infected are either lost or that the only way to get them back would be to pay the ransom, which would involve giving money to criminals." The new terrorism. https://www.theguardian.com/society/live/2017/may/12/england...

How is it terrorism if the purpose is to get money?

I meant it in a more general way: a group of horrible people taking over a core function of society and saying "If you don't do x we will do y." And they will actually do y.

As you may have gathered, my original statement is more eloquent.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#135
Isn't it peculiar that Russia remains the least hit or not even hit at all? It seems like the West was a clear target. Connecting the dots here, it's suffice to say Shadow Brokers serves Russian interests.

We are seeing bullet holes from what seem to have been cyber warfare between the former cold war foes.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#136
post #78
post #34

Earlier quoted context omitted.

In defense of these medical devices, that is actually a FDA requirement. The entire combination of the system is certified to work, and even one patch for a security vulnerability leaves open the possibility that the patch breaks something and people die! Of course it goes without saying that you need to ensure that a virus cannot run on this machine by some other means. If these machines can get infected they automa…

This 100x. I know it's extremely easy to Monday morning quarterback hospital IT but it's not as simple as people think. There's legal and, far more importantly, medical implications to updating software at a hospital. Oh you think it's ridiculous we use i.e. 7 in compatibility mode? It's because our mission critical emr only works in that (well it really works in everything but it's certified in 7) and if we use anyt…

Which is why bog standard COTS OS shouldn't be used for these types of devices. They should use a proper hardened embedded OS that has some form of mandatory access control / capability isolation system.

The long and short don't use standard desktop Windows (or even standard embedded Windows), Linux or MacOS to run these devices.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#137

I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.

To be completely fair, it's not the NSA's fault that software has faults. Its the software manufacturers'. The ethical concern here is whether the NSA should have reported the holes to the manufacturers and the failure to handle its privileged knowledge in a safe manner.

Is it not likely that the secret police of the world's most powerful empire in history is leveraging companies into creating these vulnerabilities?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#139

Earlier quoted context omitted.

OpenSSL was an example of open source done badly; neither of our communities can claim to be universally perfect. The solution, was to fork and replace OpenSSL with a superior project: LibreSSL. That part of the story, is a success for open source. It shows us recovering quickly and permanently from the worst catastrophe imaginable.

How widely is LibreSSL used, compared to OpenSSL?

[deleted]

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#140
post #34

Earlier quoted context omitted.

In defense of these medical devices, that is actually a FDA requirement. The entire combination of the system is certified to work, and even one patch for a security vulnerability leaves open the possibility that the patch breaks something and people die! Of course it goes without saying that you need to ensure that a virus cannot run on this machine by some other means. If these machines can get infected they automa…

Seems like the FDA should certify on software tests and not software versions.

Including virus like attacks and fuzzing.
Post reply on HN