Live data from Hacker News

Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

nytimes.com

81–90 of 116 posts

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#81
post #4

This is merely a taste of what is to come. When President Obama stated in December[0] that we will deliver a "proportional response" to Russian hacking at the "time and place of our own choosing", it seemed that most of the country was proud, almost gleeful at the thought that we would be striking back. I for one was mortified. We should not be escalating cyberwar, even if we do have proof of who attacked us. People…

Maybe the hacks were a side show, maybe the hacks were designed to raise awareness of Bitcoins in the collective consciousness?

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#82
post #4

This is merely a taste of what is to come. When President Obama stated in December[0] that we will deliver a "proportional response" to Russian hacking at the "time and place of our own choosing", it seemed that most of the country was proud, almost gleeful at the thought that we would be striking back. I for one was mortified. We should not be escalating cyberwar, even if we do have proof of who attacked us. People…

The primary way for the NSA to be a defensive organization would be for it to very publicly take a lead in closing up the holes they find on a structural level.

Whether the NSA hoards zero-day exploits or not isn't the big issue since someone will be doing that. The issue is they should be sounding the alarm on whatever broad class of system vulnerabilities they find.

They should be evangelizing against remotely updateable hard drive firmware, against insecure IoT devices and similar things.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#83
post #69
post #22

Earlier quoted context omitted.

> When we strike back, does Russia then strike back again? What does it look like after four or five volleys? Will entire power grids be down for days or weeks? Will the stock market crash? And at what point, after "cyber-damaging" some piece of critical infrastructure (and/or harming/killing people), does the the other side run out of exploits and just launch actual missiles instead?

This is an under-appreciated point. We've forgotten all the old hard Cold War lessons about escalation. What we are seeing now is a huge expansion of deniable and proxy warfare. Everyone is still (I hope) clear that sending an actual tank division across the Polish/Ukraine border would be met with nukes. So the question is, what is the largest most damaging attack that can be carried out without reprisal, and how do…

> SWAT-ing of a country

Iraq comes to mind, although the forged information came from the invading country's own services.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#84
post #41

I’ve never liked the term ‘cyberweapon’. It is subtly misleading and gives the non-technical masses misconceptions about how exploits actually work. Cyberweapon implies that exploits are created by governments and let loose on the world, when in reality exploits are existing flaws that were simply discovered by governments or individuals. Exploits are like a serious manufacturing defect in a lock that was only discov…

While I understand where you're coming from, and I agree with you to some extent, it's not really that simple.

While the majority of exploits we currently see in the wild are things I think the "defective lock" analogy works well for, there's a subset of attacks that would be equivalent to cutting the lock with bolt cutters.

In those cases, there are specially crafted tools that aren't exploiting a defective lock, they're destroying the basic premise that let the lock work.

I'd say that RowHammer fits that description pretty aptly. It's a cyberweapon. It's not an exploit.

It's so much of a weapon that (as far as I know, someone please correct me if I'm out of date!) there's still no known mitigation strategy that completely solves the problem. We have lots of partial mitigations, but nothing surefire yet.

So... it's both. We certainly have lots of defective locks, but we also have some very nasty tools that exploit some fundamental premises of our tech in clearly malicious ways, and were absolutely designed and implemented to do exactly that.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#85
post #69
post #22

Earlier quoted context omitted.

> When we strike back, does Russia then strike back again? What does it look like after four or five volleys? Will entire power grids be down for days or weeks? Will the stock market crash? And at what point, after "cyber-damaging" some piece of critical infrastructure (and/or harming/killing people), does the the other side run out of exploits and just launch actual missiles instead?

This is an under-appreciated point. We've forgotten all the old hard Cold War lessons about escalation. What we are seeing now is a huge expansion of deniable and proxy warfare. Everyone is still (I hope) clear that sending an actual tank division across the Polish/Ukraine border would be met with nukes. So the question is, what is the largest most damaging attack that can be carried out without reprisal, and how do…

> Everyone is still (I hope) clear that sending an actual tank division across the Polish/Ukraine border would be met with nukes.

Only if those tanks are under foreign flags. If they're under "rebel" flags, then nobody cares.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#86
post #41

I’ve never liked the term ‘cyberweapon’. It is subtly misleading and gives the non-technical masses misconceptions about how exploits actually work. Cyberweapon implies that exploits are created by governments and let loose on the world, when in reality exploits are existing flaws that were simply discovered by governments or individuals. Exploits are like a serious manufacturing defect in a lock that was only discov…

Chemical and biologic weapons also fit your bill: we didn't create or invent anthrax or smallpox.

However, a government deliberately hiding results from their medical research, or misleading/exploiting their pharmacy industry would be in a dark ethical corner.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#87
post #83
post #69

Earlier quoted context omitted.

This is an under-appreciated point. We've forgotten all the old hard Cold War lessons about escalation. What we are seeing now is a huge expansion of deniable and proxy warfare. Everyone is still (I hope) clear that sending an actual tank division across the Polish/Ukraine border would be met with nukes. So the question is, what is the largest most damaging attack that can be carried out without reprisal, and how do…

> SWAT-ing of a country Iraq comes to mind, although the forged information came from the invading country's own services.

I think Ahmed Chalabi played a key role there as well, and there are suggestions that he was an Iranian agent.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#88
post #83
post #69

Earlier quoted context omitted.

This is an under-appreciated point. We've forgotten all the old hard Cold War lessons about escalation. What we are seeing now is a huge expansion of deniable and proxy warfare. Everyone is still (I hope) clear that sending an actual tank division across the Polish/Ukraine border would be met with nukes. So the question is, what is the largest most damaging attack that can be carried out without reprisal, and how do…

> SWAT-ing of a country Iraq comes to mind, although the forged information came from the invading country's own services.

That should come as a hint that state actors are not the only ones capable of deploying informational weapons.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#89

Earlier quoted context omitted.

A defensive response would be to inform major vendors of our own infrastructure (i.e. Microsoft, Cisco) of the gaping holes in their systems, instead of leaving them open for the world to attack.

I can name at least one netsec guy who attributes his entire team's existence to the NSA calling his employer and doing exactly that.

Sounds like that netsec guy's team serves military customers then?

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#90
post #23
post #12

Earlier quoted context omitted.

> Most of these common ransom-ware and viruses are easily avoided, and only succeed because of naive users. The problem is that the large majority of the users is naive.

So you think this stockpile is mostly viruses/trojans that would target random users and hope it spreads to important systems, or hope there's important systems manned by naive people? These kind of exploits are everywhere, and I'd say the NSA is hardly the biggest threat in that arena.

It's probably not a stockpile of viruses/trojans.

It's more likely a list of exploits across different devices that give you various levels of access to do as you wish with. Some are probably nothing to worry about, some might be something that gives you the ability to get into the machine and encrypt whole sections.

Post reply on HN