Earlier quoted context omitted.
I worry that they might sell it as a reason backdoors are necessary: if only we had backdoors, we could've saved those patients! The flaw of this logic would be lost on most lawmakers.
Humor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.
Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
151–160 of 505 posts
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#152Earlier quoted context omitted.
OpenSSL was an example of open source done badly; neither of our communities can claim to be universally perfect. The solution, was to fork and replace OpenSSL with a superior project: LibreSSL. That part of the story, is a success for open source. It shows us recovering quickly and permanently from the worst catastrophe imaginable.
How widely is LibreSSL used, compared to OpenSSL?
One of the problems here, is that large organizations are reluctant to update software across a large population of computers. If those updates were smaller, more transparent, and could be separated based on whether they are a security fix, a new feature, or a new tool that allows a 3rd party to monitor user activity, then the sysadmins would be empowered to close security issues quickly, while introducing minimal risk.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#153Just use Linux and 90% of your problems with malware is history.Your own customization of kernel will make your even more secure.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#154I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.
To be completely fair, it's not the NSA's fault that software has faults. Its the software manufacturers'. The ethical concern here is whether the NSA should have reported the holes to the manufacturers and the failure to handle its privileged knowledge in a safe manner.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#155Edit: Botnet stats and spread (switch to 24H to see full picture): https://intel.malwaretech.com/botnet/wcrypt Live map: https://intel.malwaretech.com/WannaCrypt.html Relevant MS security bulletin: https://technet.microsoft.com/en-us/library/security/ms17-01... Edit: Analysis from Kaspersky Lab: https://securelist.com/blog/incidents/78351/wannacry-ransomw...
> from Kaspersky Lab ... the lab with ties to Russian intelligence, who are suspected of leaking the NSA tools.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#156Earlier quoted context omitted.
Humor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.
Well, the bigger problem would be ensuring that the criminals used known broken encryption. The only advantage is that many of these attacks are copy-cat, so if you released the source code for a broken ransomware implementation, it will probably get used more or less verbatim… as has been shown in the past. ( https://threatpost.com/bitcrypt-ransomware-deploying-weak-cr... , https://www.utkusen.com/blog/destroying-th…
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#157Earlier quoted context omitted.
I worry that they might sell it as a reason backdoors are necessary: if only we had backdoors, we could've saved those patients! The flaw of this logic would be lost on most lawmakers.
Humor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#158Earlier quoted context omitted.
How is it terrorism if the purpose is to get money?
I meant it in a more general way: a group of horrible people taking over a core function of society and saying "If you don't do x we will do y." And they will actually do y. As you may have gathered, my original statement is more eloquent.
Terrorism is done for political reasons and often involves things that involve putting fear into the populace. Your general "If you don't do x we will do y." statement does cover terrorism, but it covers terrorism because it covers _all kinds of threats_. So I suppose what you really meant was: "The new threat."
Words are important :]
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#159I have set up my mom to use a live debian cd through VMware, but I would also like to disable networking through Windows Edge and Explorer. I don't know how to do this however.
Myself, I follow a similar scheme but using a linux virtual guest and host. Is it easy to disable networking for all networking except for apt/yum and vmware/kvm?
Lastly, does anyone know what it costs for a personal subscription to grsecurity?
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#160Edit: Botnet stats and spread (switch to 24H to see full picture): https://intel.malwaretech.com/botnet/wcrypt Live map: https://intel.malwaretech.com/WannaCrypt.html Relevant MS security bulletin: https://technet.microsoft.com/en-us/library/security/ms17-01... Edit: Analysis from Kaspersky Lab: https://securelist.com/blog/incidents/78351/wannacry-ransomw...
I don't understand. What exactly do the live map points represents and where does the data come from?