Live data from Hacker News

Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

nytimes.com

51–60 of 116 posts

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#51
post #34

Earlier quoted context omitted.

Defense may be the only game worth playing, but how will that work? Unlike the real military where civilians simply don't own the hardware, in computer security they do. NSA isn't a hardware or software vendor, and the corporations that are don't have much of a profit motive to heavily invest in security. They aren't actually liable for problems unlike say a car manufacturer that releases a faulty product, which leav…

Regulate operating systems. Fund programs and research to work out how to create operating systems for our infrastructure that contain less zero days. Ensure we're the ones that find the zero days first. The reason we're vulnerable is because we're unwilling to pay the cost of finding the exploits but people in developing nations ARE because they work for "less". Right now our economies and systems reward those that…

I see that going wrong too. If operating systems need to be certified, where does that leave free open source projects?

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#52

How does one protect themselves, or loved ones? I feel this may come across as a silly question, but if escalation continues, I believe I won't be the only one asking this question.

Frequent offline backups, software updates, disabling software features you don't need.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#53

This does NOT bode well for the future of humanity. It seems that war is only war when people on your side are dying. Once everything is sufficiently automated it will be possible to wage war without risking any of your humans. I don't want to know where that leads

> Once everything is sufficiently automated it will be possible to wage war without risking any of your humans.

i don't see how that could possibly work. just because people won't die directly from a weapon anymore doesn't mean they aren't negatively impacted in this hypothetical scenario. i'm thinking of attacks crippling key infrastructure which could lead to large scale supply shortages

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#54

Earlier quoted context omitted.

> I'm not sure why we collectively decided to lack courage In this case courage is stupidity. Why waste time knocking out their power when we can spend that time making our power more secure. You're like a web master with a downed site due to a DDOS going: > Well I've DDOSed the attacker's site so its okay no its not, you've achieved nothing. Get with the program; this is a defence world not an offence one.

In situations where Person A is attacking Person B and making it sound like Person A's solution is the only one, Person A is usually mistaken. My mind is open. Convince me. Why is it a good idea to remove the threat of retaliation from our toolkit? It seems like one of the most persuasive reasons not to attack us.

I will attack you yet convince you that someone else attacked you. Now you're off attacking the wrong person and your power grid IS STILL OFFLINE.

Just put all the effort into keeping the grid up. Absorb all attacks and then export that IP and tech for healthy profit. Its the only winning move.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#55
post #16

> White House officials have deflected many questions, and responded to others by arguing that the focus should be on the attackers themselves, not the manufacturer of their weapons. Am i to understand that if somebody would manage to steal nuclear warheads and launch them we don't hold the people who failed to protect them responsible?

A nuclear weapon is a little different than a patched SMB exploit.

How's that different in terms of responsibility?

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#56

Earlier quoted context omitted.

Oh what a world we live in where cyberwarfare could result in death. I would have never thought, as a kid, that life (and death) would end up this "real".

The hacker Karl Koch [1] thought being responsible for the disaster at Chernobyl [2] back in 1986 causing 2M deaths in the last 30 years. I think we will never know whether he was right or not. [1] https://en.wikipedia.org/wiki/Karl_Koch_(hacker) [2] (German) https://de.wikipedia.org/wiki/KGB-Hack

It's such an extraordinary claim that, without evidence, it's reasonable enough to dismiss. The causes of Chernobyl have been pretty exhaustively thrashed out, and it all seems pretty well explained without any hacking intrusion.

If every claim like this has to be met with a shrug and "I guess we'll never know the truth" then it becomes very hard to ever know anything, because there's always some nutter willing to claim something that's totally at odds with all the available evidence.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#57

Earlier quoted context omitted.

In situations where Person A is attacking Person B and making it sound like Person A's solution is the only one, Person A is usually mistaken. My mind is open. Convince me. Why is it a good idea to remove the threat of retaliation from our toolkit? It seems like one of the most persuasive reasons not to attack us.

I will attack you yet convince you that someone else attacked you. Now you're off attacking the wrong person and your power grid IS STILL OFFLINE. Just put all the effort into keeping the grid up. Absorb all attacks and then export that IP and tech for healthy profit. Its the only winning move.

Obviously attribution becomes far more important with cyberattacks, but that's a tangential point.

You're acting like the power grid going offline is equivalent to a thermonuclear explosion. Yes, it will suck, but it's temporary. And afterwards, those exploit vectors will be patched.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#59
post #34

Earlier quoted context omitted.

Defense may be the only game worth playing, but how will that work? Unlike the real military where civilians simply don't own the hardware, in computer security they do. NSA isn't a hardware or software vendor, and the corporations that are don't have much of a profit motive to heavily invest in security. They aren't actually liable for problems unlike say a car manufacturer that releases a faulty product, which leav…

Regulate operating systems. Fund programs and research to work out how to create operating systems for our infrastructure that contain less zero days. Ensure we're the ones that find the zero days first. The reason we're vulnerable is because we're unwilling to pay the cost of finding the exploits but people in developing nations ARE because they work for "less". Right now our economies and systems reward those that…

This would take an extraordinary departure from our current politics. Government intruding on software would (rightly) cause cries from the most stalwart Free Software advocates and from proprietary software companies.

Can you imagine the outcry if a new Linux fork had to seek government approval in order to post their distribution?

Can you expect Google or Oracle to fail to lobby the government to make sure they don't have to get each major revision certified?

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#60

Earlier quoted context omitted.

I will attack you yet convince you that someone else attacked you. Now you're off attacking the wrong person and your power grid IS STILL OFFLINE. Just put all the effort into keeping the grid up. Absorb all attacks and then export that IP and tech for healthy profit. Its the only winning move.

Obviously attribution becomes far more important with cyberattacks, but that's a tangential point. You're acting like the power grid going offline is equivalent to a thermonuclear explosion. Yes, it will suck, but it's temporary. And afterwards, those exploit vectors will be patched.

> Obviously attribution becomes far more important with cyberattacks, but that's a tangential point.

No its not, its the whole point. The point of the age of information is that it is a departure from the age of blood and steel. The tactics of blood and steel that you are supporting have no place in this future and are counter-productive. The point of the age of information is that power is no longer solely in the hands of nations. Therefore treating it as a case of "stomping on the bad people" means your attack spread increases from all the nations in the world to all the people in the world. Added to that the evidence of those attacks can and will be forged. You're chasing shadows and its not worth it. Just build a better shield, that's all that matters.

Post reply on HN