After Further investigation, it appears this attack could be in relation to this http://www.cvedetails.com/cve/CVE-2015-1875/
Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
241–250 of 505 posts
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#242I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#243Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#244Earlier quoted context omitted.
If I understand correctly, there were no backdoors used here. Only zero-days. If the NSA is guilty of anything, they're guilty of not informing system designers of exploitable vulnerabilities. But then the argument becomes entirely ideological and naive since we all know the NSA's mission is almost entirely counter to that outcome. Edit : Apparently, not zero days. Vulnerabilities were patched months ago. I think the…
> Only zero-days. The exploits released by Wikileaks' Vault 7 dump went public months ago. They're as much a 0-day as JFK's assassination was just a few days ago.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#245Earlier quoted context omitted.
>It is possible to build and deploy secure software. By secure, you don't mean 100% secure, do you?
I mean secure as in, when the last of that product line's devices have retired or died of old age, there have been no successful exploits against that product.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#246Earlier quoted context omitted.
They'll probably be tumbled (i.e Bitcoin laundering), meaning that we'll get no info from the transactions at all.
I haven't looked into tumbling recently, whats the volume look like these days? So far the attack has yielded less than 5 btc, I'd guess that amount can be laundered safely. Whats the current limit?
This is assuming the attackers know what they are doing. I would be against that.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#247I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.
I agree with this but there is a good argument to be made that well engineered backdoors are better than intelligence agencies hoarding undisclosed exploits.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#248Earlier quoted context omitted.
They'll probably be tumbled (i.e Bitcoin laundering), meaning that we'll get no info from the transactions at all.
I haven't looked into tumbling recently, whats the volume look like these days? So far the attack has yielded less than 5 btc, I'd guess that amount can be laundered safely. Whats the current limit?
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#249Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#250Earlier quoted context omitted.
That's wrong. If you run a large installation of computers, and you do not have a plan and a process for quickly deploying security patches, you should be fired with cause. In this specific case, there are mitigations available that do not require installation of software, but merely a configuration change. Also in this specific case, the people who run IT at NHS are completely incompetent, and this has been well-doc…
> Also in this specific case, the people who run IT at NHS are completely incompetent That's what you get when you defund critical services.