This is merely a taste of what is to come. When President Obama stated in December[0] that we will deliver a "proportional response" to Russian hacking at the "time and place of our own choosing", it seemed that most of the country was proud, almost gleeful at the thought that we would be striking back. I for one was mortified. We should not be escalating cyberwar, even if we do have proof of who attacked us. People…
Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons
81–90 of 116 posts
Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons
#82This is merely a taste of what is to come. When President Obama stated in December[0] that we will deliver a "proportional response" to Russian hacking at the "time and place of our own choosing", it seemed that most of the country was proud, almost gleeful at the thought that we would be striking back. I for one was mortified. We should not be escalating cyberwar, even if we do have proof of who attacked us. People…
Whether the NSA hoards zero-day exploits or not isn't the big issue since someone will be doing that. The issue is they should be sounding the alarm on whatever broad class of system vulnerabilities they find.
They should be evangelizing against remotely updateable hard drive firmware, against insecure IoT devices and similar things.
Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons
#83Earlier quoted context omitted.
> When we strike back, does Russia then strike back again? What does it look like after four or five volleys? Will entire power grids be down for days or weeks? Will the stock market crash? And at what point, after "cyber-damaging" some piece of critical infrastructure (and/or harming/killing people), does the the other side run out of exploits and just launch actual missiles instead?
This is an under-appreciated point. We've forgotten all the old hard Cold War lessons about escalation. What we are seeing now is a huge expansion of deniable and proxy warfare. Everyone is still (I hope) clear that sending an actual tank division across the Polish/Ukraine border would be met with nukes. So the question is, what is the largest most damaging attack that can be carried out without reprisal, and how do…
Iraq comes to mind, although the forged information came from the invading country's own services.
Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons
#84I’ve never liked the term ‘cyberweapon’. It is subtly misleading and gives the non-technical masses misconceptions about how exploits actually work. Cyberweapon implies that exploits are created by governments and let loose on the world, when in reality exploits are existing flaws that were simply discovered by governments or individuals. Exploits are like a serious manufacturing defect in a lock that was only discov…
While the majority of exploits we currently see in the wild are things I think the "defective lock" analogy works well for, there's a subset of attacks that would be equivalent to cutting the lock with bolt cutters.
In those cases, there are specially crafted tools that aren't exploiting a defective lock, they're destroying the basic premise that let the lock work.
I'd say that RowHammer fits that description pretty aptly. It's a cyberweapon. It's not an exploit.
It's so much of a weapon that (as far as I know, someone please correct me if I'm out of date!) there's still no known mitigation strategy that completely solves the problem. We have lots of partial mitigations, but nothing surefire yet.
So... it's both. We certainly have lots of defective locks, but we also have some very nasty tools that exploit some fundamental premises of our tech in clearly malicious ways, and were absolutely designed and implemented to do exactly that.
Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons
#85Earlier quoted context omitted.
> When we strike back, does Russia then strike back again? What does it look like after four or five volleys? Will entire power grids be down for days or weeks? Will the stock market crash? And at what point, after "cyber-damaging" some piece of critical infrastructure (and/or harming/killing people), does the the other side run out of exploits and just launch actual missiles instead?
This is an under-appreciated point. We've forgotten all the old hard Cold War lessons about escalation. What we are seeing now is a huge expansion of deniable and proxy warfare. Everyone is still (I hope) clear that sending an actual tank division across the Polish/Ukraine border would be met with nukes. So the question is, what is the largest most damaging attack that can be carried out without reprisal, and how do…
Only if those tanks are under foreign flags. If they're under "rebel" flags, then nobody cares.
Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons
#86I’ve never liked the term ‘cyberweapon’. It is subtly misleading and gives the non-technical masses misconceptions about how exploits actually work. Cyberweapon implies that exploits are created by governments and let loose on the world, when in reality exploits are existing flaws that were simply discovered by governments or individuals. Exploits are like a serious manufacturing defect in a lock that was only discov…
However, a government deliberately hiding results from their medical research, or misleading/exploiting their pharmacy industry would be in a dark ethical corner.
Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons
#87Earlier quoted context omitted.
This is an under-appreciated point. We've forgotten all the old hard Cold War lessons about escalation. What we are seeing now is a huge expansion of deniable and proxy warfare. Everyone is still (I hope) clear that sending an actual tank division across the Polish/Ukraine border would be met with nukes. So the question is, what is the largest most damaging attack that can be carried out without reprisal, and how do…
> SWAT-ing of a country Iraq comes to mind, although the forged information came from the invading country's own services.
Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons
#88Earlier quoted context omitted.
This is an under-appreciated point. We've forgotten all the old hard Cold War lessons about escalation. What we are seeing now is a huge expansion of deniable and proxy warfare. Everyone is still (I hope) clear that sending an actual tank division across the Polish/Ukraine border would be met with nukes. So the question is, what is the largest most damaging attack that can be carried out without reprisal, and how do…
> SWAT-ing of a country Iraq comes to mind, although the forged information came from the invading country's own services.
Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons
#89Earlier quoted context omitted.
A defensive response would be to inform major vendors of our own infrastructure (i.e. Microsoft, Cisco) of the gaping holes in their systems, instead of leaving them open for the world to attack.
I can name at least one netsec guy who attributes his entire team's existence to the NSA calling his employer and doing exactly that.
Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons
#90Earlier quoted context omitted.
> Most of these common ransom-ware and viruses are easily avoided, and only succeed because of naive users. The problem is that the large majority of the users is naive.
So you think this stockpile is mostly viruses/trojans that would target random users and hope it spreads to important systems, or hope there's important systems manned by naive people? These kind of exploits are everywhere, and I'd say the NSA is hardly the biggest threat in that arena.
It's more likely a list of exploits across different devices that give you various levels of access to do as you wish with. Some are probably nothing to worry about, some might be something that gives you the ability to get into the machine and encrypt whole sections.