Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

151–160 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#151

Earlier quoted context omitted.

I worry that they might sell it as a reason backdoors are necessary: if only we had backdoors, we could've saved those patients! The flaw of this logic would be lost on most lawmakers.

Humor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.

The logic is sound in theory. But in practice if the government can't protect its exploits, they mot likely can't protect their keys to the backdoor.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#152

Earlier quoted context omitted.

OpenSSL was an example of open source done badly; neither of our communities can claim to be universally perfect. The solution, was to fork and replace OpenSSL with a superior project: LibreSSL. That part of the story, is a success for open source. It shows us recovering quickly and permanently from the worst catastrophe imaginable.

How widely is LibreSSL used, compared to OpenSSL?

There is no way to know for sure, because we have not embedded telemetry / spyware in open source operating systems.

One of the problems here, is that large organizations are reluctant to update software across a large population of computers. If those updates were smaller, more transparent, and could be separated based on whether they are a security fix, a new feature, or a new tool that allows a 3rd party to monitor user activity, then the sysadmins would be empowered to close security issues quickly, while introducing minimal risk.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#153
post #144

Just use Linux and 90% of your problems with malware is history.Your own customization of kernel will make your even more secure.

Let's not pretend that Linux is invulnerable to the class of exploits that make this kind of malware possible [1]. Windows isn't a target because it's vulnerable (all software is vulnerable). Windows is targeted because it's widely used. If the majority of systems were using Linux, malware authors would simply adapt to write malware targeting Linux instead.

[1] https://nvd.nist.gov/vuln/detail/CVE-2016-7117

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#154

I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.

To be completely fair, it's not the NSA's fault that software has faults. Its the software manufacturers'. The ethical concern here is whether the NSA should have reported the holes to the manufacturers and the failure to handle its privileged knowledge in a safe manner.

I agree about this ethical concern, but this attack also shows that reporting the holes to manufacturers is of limited use -- these exploits have been known to manufacturers since at least March, and while patches have shipped, the computers remain vulnerable. Clearly, automatic security updates are still not aggressive enough to prevent these kinds of problems. Though it isn't clear from the article how out-of-date the vulnerable systems are, which would help in planning for the future. For example, Windows 10 pushes security updates very aggressively, and I wonder how many of the infected computers were running Windows 10 -- health care providers' computer systems are often notoriously out-of-date.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#155

Edit: Botnet stats and spread (switch to 24H to see full picture): https://intel.malwaretech.com/botnet/wcrypt Live map: https://intel.malwaretech.com/WannaCrypt.html Relevant MS security bulletin: https://technet.microsoft.com/en-us/library/security/ms17-01... Edit: Analysis from Kaspersky Lab: https://securelist.com/blog/incidents/78351/wannacry-ransomw...

> from Kaspersky Lab ... the lab with ties to Russian intelligence, who are suspected of leaking the NSA tools.

Your point?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#156

Earlier quoted context omitted.

Humor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.

Well, the bigger problem would be ensuring that the criminals used known broken encryption. The only advantage is that many of these attacks are copy-cat, so if you released the source code for a broken ransomware implementation, it will probably get used more or less verbatim… as has been shown in the past. ( https://threatpost.com/bitcrypt-ransomware-deploying-weak-cr... , https://www.utkusen.com/blog/destroying-th…

If they don't just replace your data outright with noise.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#157

Earlier quoted context omitted.

I worry that they might sell it as a reason backdoors are necessary: if only we had backdoors, we could've saved those patients! The flaw of this logic would be lost on most lawmakers.

Humor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.

Why would ransomers use encryption with a back door? It's not like you can force them to only use the crackable math.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#158
post #134

Earlier quoted context omitted.

How is it terrorism if the purpose is to get money?

I meant it in a more general way: a group of horrible people taking over a core function of society and saying "If you don't do x we will do y." And they will actually do y. As you may have gathered, my original statement is more eloquent.

It isn't more eloquent, because it's wrong. Wouldn't saying: "The new mafia." or "The new shake-down" be more accurate?

Terrorism is done for political reasons and often involves things that involve putting fear into the populace. Your general "If you don't do x we will do y." statement does cover terrorism, but it covers terrorism because it covers _all kinds of threats_. So I suppose what you really meant was: "The new threat."

Words are important :]

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#159
Q: does anyone know how to disable regular internet access in Windows except through a virtual machine (VMware or Virtualbox)?

I have set up my mom to use a live debian cd through VMware, but I would also like to disable networking through Windows Edge and Explorer. I don't know how to do this however.

Myself, I follow a similar scheme but using a linux virtual guest and host. Is it easy to disable networking for all networking except for apt/yum and vmware/kvm?

Lastly, does anyone know what it costs for a personal subscription to grsecurity?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#160

Edit: Botnet stats and spread (switch to 24H to see full picture): https://intel.malwaretech.com/botnet/wcrypt Live map: https://intel.malwaretech.com/WannaCrypt.html Relevant MS security bulletin: https://technet.microsoft.com/en-us/library/security/ms17-01... Edit: Analysis from Kaspersky Lab: https://securelist.com/blog/incidents/78351/wannacry-ransomw...

I don't understand. What exactly do the live map points represents and where does the data come from?

https://www.malwaretech.com/2016/01/exploring-peer-to-peer-b...
Post reply on HN