Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

231–240 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#231

Earlier quoted context omitted.

I agree about this ethical concern, but this attack also shows that reporting the holes to manufacturers is of limited use -- these exploits have been known to manufacturers since at least March, and while patches have shipped, the computers remain vulnerable. Clearly, automatic security updates are still not aggressive enough to prevent these kinds of problems. Though it isn't clear from the article how out-of-date…

I would be curious about this too. I'd assume many of them would be running Windows 7, maybe? (Let's hope it's not XP). Also, does Windows 10 Pro attached to a domain controller still have the same aggressive updates? Or do domain admins dictate that policy? At one company I worked at, everyone in IT could volunteer for the patch group to get security patches a few days before the rest of the machines. That seems to…

> Let's hope it's not XP

BMJ released a report[0] just two days ago alleging that up to 90% of the NHS's computers are still running XP.

> Many hospitals use proprietary software that runs on ancient operating systems. Barts Health NHS Trust’s computers attacked by ransomware in January ran Windows XP. Released in 2001, it is now obsolete, yet 90% of NHS trusts run this version of Windows.

[0] http://www.bmj.com/content/357/bmj.j2214

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#232

Earlier quoted context omitted.

>It is possible to build and deploy secure software. By secure, you don't mean 100% secure, do you?

I mean secure as in, when the last of that product line's devices have retired or died of old age, there have been no successful exploits against that product.

Has there ever been such a product? What about exploits on the software/hardware underlying the supposedly secure software?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#233

I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.

If I understand correctly, there were no backdoors used here. Only zero-days. If the NSA is guilty of anything, they're guilty of not informing system designers of exploitable vulnerabilities. But then the argument becomes entirely ideological and naive since we all know the NSA's mission is almost entirely counter to that outcome. Edit : Apparently, not zero days. Vulnerabilities were patched months ago. I think the…

No zero days were used. This was patched in March.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#234
post #226

Earlier quoted context omitted.

https://www.malwaretech.com/2016/01/exploring-peer-to-peer-b...

>To ensure the entire network is discovered, we should start the crawler off with multiple supernode IPs and store all IPs found into a database, then each time we restart the crawler we seed it with the list of IPs found during the previous crawler; repeating this process for a couple of hours ensure all online nodes are found. This would just discover supernodes though right? Or any node at some point broadcasts as…

Yes to your first question, no to your second. He goes on to explain that, "In order to map all workers, we’d need to set up multiple supernodes across the botnet which log incoming connections (obviously every worker doesn’t connect to every supernode at the same time, so it’s important that our supernodes have a stronger presence in the botnet)."

From what I understand the process is:

1. Write a program to pretend to be a compromised peer requesting a connection to a Supernode in order to obtain a peer list of other Supernodes.

2. Recursively crawl for existing Supernodes + the list of Supernode IPs. Store all addresses found.

3. Set up one or more Supernodes and 'infiltrate' the peer list of already established Supernodes. Log incoming connections from Workers.

http://whatis.techtarget.com/definition/botnet-sinkhole

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#235

Earlier quoted context omitted.

Humor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.

> if encryption had a backdoor This is the flaw in the logic. "Encryption" can't have a backdoor any more than math can have a back door. Specific types of encryption can. But there's nothing to stop a malicious user from using a non-backdoored encryption algorithm or inventing their own.

Yeah, I don't think ransomware is going to use the US approved algorithm. What they are doing is already illegal.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#236
It looks to me like common stupidity...people opening attachments that they should not be opening. No need to involve CIA NSA or other tree letters agency hacking tool...just old school phishing. I see this happening much to often....people opening *.pdf.js attachment. No need for another conspiracy theory...stupidity explains it all. Just my 50¢.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#237

I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.

If I understand correctly, there were no backdoors used here. Only zero-days. If the NSA is guilty of anything, they're guilty of not informing system designers of exploitable vulnerabilities. But then the argument becomes entirely ideological and naive since we all know the NSA's mission is almost entirely counter to that outcome. Edit : Apparently, not zero days. Vulnerabilities were patched months ago. I think the…

> Only zero-days.

The exploits released by Wikileaks' Vault 7 dump went public months ago. They're as much a 0-day as JFK's assassination was just a few days ago.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#238

I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.

To be completely fair, it's not the NSA's fault that software has faults. Its the software manufacturers'. The ethical concern here is whether the NSA should have reported the holes to the manufacturers and the failure to handle its privileged knowledge in a safe manner.

Ok, so show us how you write perfectly secure code. It's sure as hell is the NSA's fault here for mishandling all their hacks into commercial sw.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#239

Earlier quoted context omitted.

I mean secure as in, when the last of that product line's devices have retired or died of old age, there have been no successful exploits against that product.

Has there ever been such a product? What about exploits on the software/hardware underlying the supposedly secure software?

Critical devices should either be simple, or they should run open source firmware. If governments had required the ability to audit the IC designs that go into medical, military and national infrastructure equipment, then we would now have open source ICs.

I am seeing an incredible resistance to this idea of increasing the situational awareness and capabilities of the people who provision and maintain large deployments. Perhaps it is too soon to propose solutions. Perhaps, today, we should just express solidarity with the victims, and try to warn operators of unaffected, but vulnerable systems to temporarily take them offline.

My apologies to those that I have offended. As a software developer who has struggled for years to articulate the need for transparency and simplicity in our systems, I feel very frustrated right now.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#240

Earlier quoted context omitted.

Let's not pretend that Linux is invulnerable to the class of exploits that make this kind of malware possible [1]. Windows isn't a target because it's vulnerable (all software is vulnerable). Windows is targeted because it's widely used. If the majority of systems were using Linux, malware authors would simply adapt to write malware targeting Linux instead. [1] https://nvd.nist.gov/vuln/detail/CVE-2016-7117

all software is vulnerable This is false, and spreads FUD. It does a great disservice to those who do meticulously maintain their systems, to those who sacrifice convenience and beauty for stability and security, to those who take the time to scrutinize other people's work. It is possible to build and deploy secure software. Linux dominates the datacenter; we are a high value target, and have been for quite some time…

I had a feeling I might get called out on that... I meant that for all practical purposes, all software is theoretically vulnerable. Of course verifiable computing is a thing, but wildly impractical for most applications.

Meticulously maintained is not even close to being invulnerable. Everyone would like to say they meticulously maintain the projects they work on, but it would be incredibly arrogant to say that you couldn't conceive of ever unintentionally introducing a vulnerability.

Post reply on HN