Live data from Hacker News

Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

nytimes.com

21–30 of 116 posts

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#21

Not trying to claim whataboutism, but I think there's an elephant in the room. The end result of the NSA saying "ok, as of today we've completely disarmed our cyberweapon stockpile and released patches for all vulnerabilities to the appropriate software companies" wouldn't be the end of cyberattacks. It would just be someone else doing them. I don't know what the real solution is. Maybe there is none.

work towards no zero days.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#22
post #4

This is merely a taste of what is to come. When President Obama stated in December[0] that we will deliver a "proportional response" to Russian hacking at the "time and place of our own choosing", it seemed that most of the country was proud, almost gleeful at the thought that we would be striking back. I for one was mortified. We should not be escalating cyberwar, even if we do have proof of who attacked us. People…

> When we strike back, does Russia then strike back again? What does it look like after four or five volleys? Will entire power grids be down for days or weeks? Will the stock market crash?

And at what point, after "cyber-damaging" some piece of critical infrastructure (and/or harming/killing people), does the the other side run out of exploits and just launch actual missiles instead?

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#23
post #12
post #9

Two questions 1. Why do they not simply take the weapons of a network? Maybe store it on some physical media, or a computer not networked unless it's time to take a Kim down a notch? 2. Are these "weapons" really that dastardly? Most of these common ransom-ware and viruses are easily avoided, and only succeed because of naive users. Backdoors aren't a weapon, they're there on purpose. Sniffing, spying, and logging ca…

> Most of these common ransom-ware and viruses are easily avoided, and only succeed because of naive users. The problem is that the large majority of the users is naive.

So you think this stockpile is mostly viruses/trojans that would target random users and hope it spreads to important systems, or hope there's important systems manned by naive people? These kind of exploits are everywhere, and I'd say the NSA is hardly the biggest threat in that arena.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#25
post #4

This is merely a taste of what is to come. When President Obama stated in December[0] that we will deliver a "proportional response" to Russian hacking at the "time and place of our own choosing", it seemed that most of the country was proud, almost gleeful at the thought that we would be striking back. I for one was mortified. We should not be escalating cyberwar, even if we do have proof of who attacked us. People…

Oh what a world we live in where cyberwarfare could result in death. I would have never thought, as a kid, that life (and death) would end up this "real".

The hacker Karl Koch [1] thought being responsible for the disaster at Chernobyl [2] back in 1986 causing 2M deaths in the last 30 years. I think we will never know whether he was right or not.

[1] https://en.wikipedia.org/wiki/Karl_Koch_(hacker)

[2] (German) https://de.wikipedia.org/wiki/KGB-Hack

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#26

Cyberwar hasn't necessarily led to the massive loss of life associated with nuclear or chemical weapons. Until that happens (or like with nuclear weapons, we can culturally show how much of a zero-sum game it is), ordinary people won't have an incentive to take action. Technically minded people may carry capital, but we're vastly outnumbered by the dwindling working class politically.

The only way a nuclear system could be compromised is if there was some idiot surfing the internet on it, or if someone intricately familiar with the systems and network tailored an exploit to target it. If we have teams of people targeting specific systems like this, and just hovering over the execution button, then I'd say this is a huge problem. Nothing in this article really described the nature of the threat these weapons pose.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#27
This does NOT bode well for the future of humanity. It seems that war is only war when people on your side are dying. Once everything is sufficiently automated it will be possible to wage war without risking any of your humans. I don't want to know where that leads

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#28

Hopefully these issues will also put a stop to government's requesting software backdoor access.

Five Eyes are meeting this week to develop a backdoor plan...There should definitely be a big backlash against it, especially in light of recent events.

Backdoors in US infrastructure = invitation to Russia and China to go right through it.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#29

Not trying to claim whataboutism, but I think there's an elephant in the room. The end result of the NSA saying "ok, as of today we've completely disarmed our cyberweapon stockpile and released patches for all vulnerabilities to the appropriate software companies" wouldn't be the end of cyberattacks. It would just be someone else doing them. I don't know what the real solution is. Maybe there is none.

The point is that there would be fewer cyber attacks, both because the NSA itself would no longer be adding to the number of hacks and because the NSA would use their sizeable budget to discover and disclose vulnerabilities, presumably making all of us safer.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#30
post #19

Not trying to claim whataboutism, but I think there's an elephant in the room. The end result of the NSA saying "ok, as of today we've completely disarmed our cyberweapon stockpile and released patches for all vulnerabilities to the appropriate software companies" wouldn't be the end of cyberattacks. It would just be someone else doing them. I don't know what the real solution is. Maybe there is none.

Somebody could have done that right now as well, but nobody did make them so far (or used them in any significant way that people know of). Instead of (ab)using somebody else's mistakes to your own advantage (and possibly have it backfire) you could also tell that person about their mistakes so the whole world could benefit and there would be 1 issue less in the world to worry about.

People have, in the past. The problem is that we will never remove all 0days until we stop releasing software. That's not to say we shouldn't try (to Quarrelsome's point), but eventually the stockpile today will be obsoleted by the stockpile of tomorrow. And if nation states didn't have a pile, the seedy side of the internet would, alongside trading botnets, credit card lists, etc. My point being that while noble efforts, it won't go away and we need to figure out how to deal with it.

Here's one reason such a stockpile could be used for good: say a previously unknown vuln is attacking "our" (whomever that is for you) infrastructure. The command and control has been traced back to a cluster that's vulnerable to one of the weapons in your stockpile. Now you can potentially disable it, stop it spreading, tell all of them to run an updated version of the code that essentially does nothing, etc. For all I know, this could have happened already.

Post reply on HN