I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.
If I understand correctly, there were no backdoors used here. Only zero-days. If the NSA is guilty of anything, they're guilty of not informing system designers of exploitable vulnerabilities. But then the argument becomes entirely ideological and naive since we all know the NSA's mission is almost entirely counter to that outcome. Edit : Apparently, not zero days. Vulnerabilities were patched months ago. I think the…
Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
251–260 of 505 posts
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#252I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.
> This shows that no agency is immune from leaks That's well known for a long time. During cold war a lot of Russian weapons were based on the US designs. There is a TV series, Americans, which shows how to manipulate people and steal secrets. Even atomic bomb secrets were stolen (by Klaus Fuchs and others). So I guess a lot of people in military complex make a lot of money on these exploits, PRISM and other projects…
But if you phrase it to something like "Can the government be trusted with backdoors to protect us from terrorists and Chinese hackers", then suddenly public sentiment will change dramatically.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#253It looks to me like common stupidity...people opening attachments that they should not be opening. No need to involve CIA NSA or other tree letters agency hacking tool...just old school phishing. I see this happening much to often....people opening *.pdf.js attachment. No need for another conspiracy theory...stupidity explains it all. Just my 50¢.
plenty of stupidity for sure, but the stupidity is at the number of unpatched systems
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#254Earlier quoted context omitted.
I definitely agree wrt intentional exploits ("backdoors") to be added. To me this news highlights the need for fundamentally safe software. Just like we might have safety laws in the automotive or airline industry.
If the NHS has been significantly crippled by this, and the NSA is partly at fault, could the NHS successfully sue the NSA in the UK? (edit: my logic and phrasing was really bad)
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#255It looks to me like common stupidity...people opening attachments that they should not be opening. No need to involve CIA NSA or other tree letters agency hacking tool...just old school phishing. I see this happening much to often....people opening *.pdf.js attachment. No need for another conspiracy theory...stupidity explains it all. Just my 50¢.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#256Earlier quoted context omitted.
It isn't more eloquent, because it's wrong. Wouldn't saying: "The new mafia." or "The new shake-down" be more accurate? Terrorism is done for political reasons and often involves things that involve putting fear into the populace. Your general "If you don't do x we will do y." statement does cover terrorism, but it covers terrorism because it covers _all kinds of threats_. So I suppose what you really meant was: "The…
Ah sorry, I got it wrong twice. But you got me thinking again: because this ransomware is targeting the infrastructure itself (national healthcare service) isn't this playing with fear too? If I was in hospital, or my friends/family, I would be acutely paranoid that medical devices will go wrong, medicine administration will go wrong, the A&E will go bonkers et cetra. I've worked in healthcare before, and this kind o…
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#257> "Microsoft rolled out a patch for the vulnerability last March, but hackers took advantage of the fact that vulnerable targets — particularly hospitals — had yet to update their systems." > "The malware was circulated by email; targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets." It sounds like the basic (?) security practices recommended by professio…
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#258Earlier quoted context omitted.
I don't understand. What exactly do the live map points represents and where does the data come from?
https://www.malwaretech.com/2016/01/exploring-peer-to-peer-b...
How is he able to add new supernodes to the cluster? I would expect a supernode to have some sort of credentials that are used for authentication. If not, isn't it possible to neutralize the botnet by overloading it with supernodes that don't send malicious commands?
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#259I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.
To be completely fair, it's not the NSA's fault that software has faults. Its the software manufacturers'. The ethical concern here is whether the NSA should have reported the holes to the manufacturers and the failure to handle its privileged knowledge in a safe manner.
The NSA has a specific mission to secure the nation's infrastructure. In witholding key information from US companies, it's failing that mission.
Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool
#260Earlier quoted context omitted.
also that it is very unethical for the US government to find some vulnerability in android/windows/whatever and not report it
Is it particularly unethical? Many governments around the world are discovering 0-days in commonly deployed products and not revealing that to the vendor, but instead using it as a weapon for navigating computer networks. Revealing the vulnerability would place the US Govt at a distinct disadvantage.
Your point is actually valid, but that doesn't mean I have the intention to pardon the NSA for having compromised the network of my university, the same network I used each and every single day during my studies (and no, I am not a terrorist, nor I know anyone involved in terrorism, child pornography, or what-else they had in mind).
Sorry to say, but "anyone is doing it", is not an excuse or a reason for doing something.
If instead of exploiting half of the world, they had dedicated their experience in making their (and everyone else) infrastructure safer (by sharing security conscious design concepts, considerations with software developers and hardware manufacturers), now we probably would not have had massive botnets, exploitations and leaks (least but not least the political consequences of perpetrating and sustaining this kind of decisions).
Where is the point when maintaining the supremacy of one's country over the others through deceit, intrigue, and espionage costs too much in terms of negative outcomes?
For me that line, US and many others included, has been passed a long time ago. But that's just my humble opinion. Each one is free to draw conclusions through his own point of view.