Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

241–250 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#241
I was debugging a private web app today when I noticed a python script agent suddenly performing a port scan on me. it was querying for something called "a2billing/common/javascript/misc.js". After googling that phrase it seems im not the only person who has seen this today. The country of origin of the IP was Britain.

After Further investigation, it appears this attack could be in relation to this http://www.cvedetails.com/cve/CVE-2015-1875/

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#242

I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.

I agree with this but there is a good argument to be made that well engineered backdoors are better than intelligence agencies hoarding undisclosed exploits.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#244
post #237

Earlier quoted context omitted.

If I understand correctly, there were no backdoors used here. Only zero-days. If the NSA is guilty of anything, they're guilty of not informing system designers of exploitable vulnerabilities. But then the argument becomes entirely ideological and naive since we all know the NSA's mission is almost entirely counter to that outcome. Edit : Apparently, not zero days. Vulnerabilities were patched months ago. I think the…

> Only zero-days. The exploits released by Wikileaks' Vault 7 dump went public months ago. They're as much a 0-day as JFK's assassination was just a few days ago.

[deleted]

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#245

Earlier quoted context omitted.

>It is possible to build and deploy secure software. By secure, you don't mean 100% secure, do you?

I mean secure as in, when the last of that product line's devices have retired or died of old age, there have been no successful exploits against that product.

How could you ever possibly verify that?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#246

Earlier quoted context omitted.

They'll probably be tumbled (i.e Bitcoin laundering), meaning that we'll get no info from the transactions at all.

I haven't looked into tumbling recently, whats the volume look like these days? So far the attack has yielded less than 5 btc, I'd guess that amount can be laundered safely. Whats the current limit?

I can't speak for a current safe limit, but it isn't very hard to transfer funds between various cryptocurrencies. Tumbling is not secure with a large amount of coins. All you have to do is monitor all transactions and figure out what went in and what came back out. If you start splitting things off in small amounts on various blockchains things become much harder to track.

This is assuming the attackers know what they are doing. I would be against that.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#247
post #242

I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.

I agree with this but there is a good argument to be made that well engineered backdoors are better than intelligence agencies hoarding undisclosed exploits.

Is there? I can't think of one.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#248

Earlier quoted context omitted.

They'll probably be tumbled (i.e Bitcoin laundering), meaning that we'll get no info from the transactions at all.

I haven't looked into tumbling recently, whats the volume look like these days? So far the attack has yielded less than 5 btc, I'd guess that amount can be laundered safely. Whats the current limit?

A cursory check doesn't bring up any Helix (the largest tumbler out there) stats. I'm not certain they even make that info public. Also I wouldn't know how to measure the level of privacy in this context.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#250
post #166
post #22

Earlier quoted context omitted.

That's wrong. If you run a large installation of computers, and you do not have a plan and a process for quickly deploying security patches, you should be fired with cause. In this specific case, there are mitigations available that do not require installation of software, but merely a configuration change. Also in this specific case, the people who run IT at NHS are completely incompetent, and this has been well-doc…

> Also in this specific case, the people who run IT at NHS are completely incompetent That's what you get when you defund critical services.

funding is necessary but not the determining factor. There are just as many incompetent IT admins in well funded private companies earning top pay, Sensible and aware top management is far more critical,
Post reply on HN