Live data from Hacker News

Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

nytimes.com

31–40 of 116 posts

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#31

Earlier quoted context omitted.

I don't want the NSA to become a defensive organization. I like that Iran's nuclear program is being delayed. That's not a defensive action. You don't seem to be proposing that the NSA become defensive, either. If Russia attacks us and we don't respond, that's not even defensive. That's dismantling.

so you want to live in a world where both countries don't have any power? Sounds Utopian. Defence is only card in this game worth playing especially when it comes to infrastructure attacks.

Yes, that would suck. But that's the aggresor's decision, not ours.

I'm not sure why we collectively decided to lack courage, but it's unsettling.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#32

Not trying to claim whataboutism, but I think there's an elephant in the room. The end result of the NSA saying "ok, as of today we've completely disarmed our cyberweapon stockpile and released patches for all vulnerabilities to the appropriate software companies" wouldn't be the end of cyberattacks. It would just be someone else doing them. I don't know what the real solution is. Maybe there is none.

>wouldn't be the end of cyberattacks. This is a strawman. No one knowledgeable is saying it would create 100% security, just that it would be a net increase in the security of our infrastructure.

The sentiment I've seen from people is "if we can just stop the NSA from doing these, our problems will go away".

What I'm saying is not to do nothing, but rather we need to have a plan for continued attacks (like how spam filters came into being) in addition to trying to get any and all vulns fixed.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#33
post #22
post #4

This is merely a taste of what is to come. When President Obama stated in December[0] that we will deliver a "proportional response" to Russian hacking at the "time and place of our own choosing", it seemed that most of the country was proud, almost gleeful at the thought that we would be striking back. I for one was mortified. We should not be escalating cyberwar, even if we do have proof of who attacked us. People…

> When we strike back, does Russia then strike back again? What does it look like after four or five volleys? Will entire power grids be down for days or weeks? Will the stock market crash? And at what point, after "cyber-damaging" some piece of critical infrastructure (and/or harming/killing people), does the the other side run out of exploits and just launch actual missiles instead?

Do these missiles require a working communications network? If this goes on long enough, there might not be any way to launch them.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#34

Earlier quoted context omitted.

I don't want the NSA to become a defensive organization. I like that Iran's nuclear program is being delayed. That's not a defensive action. You don't seem to be proposing that the NSA become defensive, either. If Russia attacks us and we don't respond, that's not even defensive. That's dismantling.

so you want to live in a world where both countries don't have any power? Sounds Utopian. Defence is only card in this game worth playing especially when it comes to infrastructure attacks.

Defense may be the only game worth playing, but how will that work? Unlike the real military where civilians simply don't own the hardware, in computer security they do.

NSA isn't a hardware or software vendor, and the corporations that are don't have much of a profit motive to heavily invest in security. They aren't actually liable for problems unlike say a car manufacturer that releases a faulty product, which leaves what exactly... reputation that takes a hit? But every vendor has bugs and security issues and the market isn't really punishing anyone.

Is the future effectively an enormous government subsidy to profitable corporations (i.e. NSA and other US government agencies basically become extensions of corporate America's QA department)? Is the future heavy regulations to create the proper financial incentives and/or penalties so corporations start seriously spending on security?

It's easy to say "the government should do something!!" but what exactly will that look like?

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#35

Earlier quoted context omitted.

so you want to live in a world where both countries don't have any power? Sounds Utopian. Defence is only card in this game worth playing especially when it comes to infrastructure attacks.

Yes, that would suck. But that's the aggresor's decision, not ours. I'm not sure why we collectively decided to lack courage, but it's unsettling.

> I'm not sure why we collectively decided to lack courage

In this case courage is stupidity. Why waste time knocking out their power when we can spend that time making our power more secure. You're like a web master with a downed site due to a DDOS going:

> Well I've DDOSed the attacker's site so its okay

no its not, you've achieved nothing. Get with the program; this is a defence world not an offence one.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#36
post #34

Earlier quoted context omitted.

so you want to live in a world where both countries don't have any power? Sounds Utopian. Defence is only card in this game worth playing especially when it comes to infrastructure attacks.

Defense may be the only game worth playing, but how will that work? Unlike the real military where civilians simply don't own the hardware, in computer security they do. NSA isn't a hardware or software vendor, and the corporations that are don't have much of a profit motive to heavily invest in security. They aren't actually liable for problems unlike say a car manufacturer that releases a faulty product, which leav…

Regulate operating systems. Fund programs and research to work out how to create operating systems for our infrastructure that contain less zero days. Ensure we're the ones that find the zero days first.

The reason we're vulnerable is because we're unwilling to pay the cost of finding the exploits but people in developing nations ARE because they work for "less".

Right now our economies and systems reward those that fly by their pants and don't care for security. That is the problem. The free buffet of infinite growth from technology startups is the very thing that also gives us this pain and we need to learn to eat less.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#37

Earlier quoted context omitted.

I don't want the NSA to become a defensive organization. I like that Iran's nuclear program is being delayed. That's not a defensive action. You don't seem to be proposing that the NSA become defensive, either. If Russia attacks us and we don't respond, that's not even defensive. That's dismantling.

A defensive response would be to inform major vendors of our own infrastructure (i.e. Microsoft, Cisco) of the gaping holes in their systems, instead of leaving them open for the world to attack.

I can name at least one netsec guy who attributes his entire team's existence to the NSA calling his employer and doing exactly that.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#39

Earlier quoted context omitted.

Man's way to peace is by having a bigger gun than his neighbor.

At some point, someone will use their Bitsy Big-Boy Boomeroo, and that'll be the end of that.

Thus ushering in a new era of peace and prosperity for the termites scuttling through the ruins of human civilization. Sounds like a plan.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#40
post #22

Earlier quoted context omitted.

> When we strike back, does Russia then strike back again? What does it look like after four or five volleys? Will entire power grids be down for days or weeks? Will the stock market crash? And at what point, after "cyber-damaging" some piece of critical infrastructure (and/or harming/killing people), does the the other side run out of exploits and just launch actual missiles instead?

Do these missiles require a working communications network? If this goes on long enough, there might not be any way to launch them.

Why do you think that different countries have put missiles in submarines ?
Post reply on HN