Live data from Hacker News

Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

nytimes.com

91–100 of 116 posts

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#91

Earlier quoted context omitted.

I don't want the NSA to become a defensive organization. I like that Iran's nuclear program is being delayed. That's not a defensive action. You don't seem to be proposing that the NSA become defensive, either. If Russia attacks us and we don't respond, that's not even defensive. That's dismantling.

so you want to live in a world where both countries don't have any power? Sounds Utopian. Defence is only card in this game worth playing especially when it comes to infrastructure attacks.

> so you want to live in a world where both countries don't have any power? Sounds Utopian.

Or post-apocalyptic.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#92
post #4

This is merely a taste of what is to come. When President Obama stated in December[0] that we will deliver a "proportional response" to Russian hacking at the "time and place of our own choosing", it seemed that most of the country was proud, almost gleeful at the thought that we would be striking back. I for one was mortified. We should not be escalating cyberwar, even if we do have proof of who attacked us. People…

The primary way for the NSA to be a defensive organization would be for it to very publicly take a lead in closing up the holes they find on a structural level. Whether the NSA hoards zero-day exploits or not isn't the big issue since someone will be doing that. The issue is they should be sounding the alarm on whatever broad class of system vulnerabilities they find. They should be evangelizing against remotely upda…

This is so obvious and true that everyone cannot help but overlook it.

What happened to the days when the NSA helped make world class crypto like AES256 in a public forum?

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#93
post #92

Earlier quoted context omitted.

The primary way for the NSA to be a defensive organization would be for it to very publicly take a lead in closing up the holes they find on a structural level. Whether the NSA hoards zero-day exploits or not isn't the big issue since someone will be doing that. The issue is they should be sounding the alarm on whatever broad class of system vulnerabilities they find. They should be evangelizing against remotely upda…

This is so obvious and true that everyone cannot help but overlook it. What happened to the days when the NSA helped make world class crypto like AES256 in a public forum?

I think the world-class individuals who made the NSA into a competent organization left after the end of the Cold War. It looks to have been run by wingnuts ever since; Keith Alexander's "Star Trek" room ( https://www.theguardian.com/commentisfree/2013/sep/15/nsa-mi... ) comes to mind.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#94

Earlier quoted context omitted.

I don't want the NSA to become a defensive organization. I like that Iran's nuclear program is being delayed. That's not a defensive action. You don't seem to be proposing that the NSA become defensive, either. If Russia attacks us and we don't respond, that's not even defensive. That's dismantling.

Cyberweapons created by the USA were used to shut down the entire national hospital system of the UK, one of their biggest allies. Good job USA! Iran is educated enough to make nuclear weapons, but you want their program shut down because you think they're not responsible enough to be trusted with nuclear weapons. The US is educated enough to make cyber-weapons, but I want their program shut down because I think they…

You are applying logic to politics, if that worked we wouldn't have problems.

We demand Iran disarm to shame them on the world stage as violators of non-proliferation treaties, and we only do this because they are our "enemy" if they weren't we would care. It cronyism and nepotism just on the scales of nations, and I don't think that can change for a while.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#95
post #34

Earlier quoted context omitted.

so you want to live in a world where both countries don't have any power? Sounds Utopian. Defence is only card in this game worth playing especially when it comes to infrastructure attacks.

Defense may be the only game worth playing, but how will that work? Unlike the real military where civilians simply don't own the hardware, in computer security they do. NSA isn't a hardware or software vendor, and the corporations that are don't have much of a profit motive to heavily invest in security. They aren't actually liable for problems unlike say a car manufacturer that releases a faulty product, which leav…

Change the law and make them liable. This would let the market solve the problem, but there is no way microsoft, cisco and the like would go for it.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#97
Closed source vs open source. Why are such exploits not so evident on mac, linux, bsd etc? Is it only because microsoft dominates the desktop market? Edward snowden clearly showed MS relation to the NSA. I do not believe at all such exploits are ${Discovered} by the NSA. But the exploits are backdoors that MS provides. That is why they are now blaming the NSA and putting on a marketing campain to show how much they care about everyone ${Security}. So what if this is the case? To me its pretty obvious who created this mess.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#98
post #87
post #83

Earlier quoted context omitted.

> SWAT-ing of a country Iraq comes to mind, although the forged information came from the invading country's own services.

I think Ahmed Chalabi played a key role there as well, and there are suggestions that he was an Iranian agent.

There's no denying that Ahmed Chalabi was an Iranian agent of influence, but whether he was working for the Iranian clandestine services is unknown.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#99
post #41

I’ve never liked the term ‘cyberweapon’. It is subtly misleading and gives the non-technical masses misconceptions about how exploits actually work. Cyberweapon implies that exploits are created by governments and let loose on the world, when in reality exploits are existing flaws that were simply discovered by governments or individuals. Exploits are like a serious manufacturing defect in a lock that was only discov…

While I understand where you're coming from, and I agree with you to some extent, it's not really that simple. While the majority of exploits we currently see in the wild are things I think the "defective lock" analogy works well for, there's a subset of attacks that would be equivalent to cutting the lock with bolt cutters. In those cases, there are specially crafted tools that aren't exploiting a defective lock, th…

In this case we're talking about the recent NSA exploits leaked by Shadow Brokers and then utilized by WannaCry and the Petya attack. Both of those had a "weapon" (the ransomware itself) that spread by way of an exploit found by NSA (a defect in Windows that people failed to patch).

In this case, I feel that blaming NSA for the exploit and calling those "cyberweapons" is wrong. The entity who put the ransomware on top of them and deployed them built a weapon.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#100

Closed source vs open source. Why are such exploits not so evident on mac, linux, bsd etc? Is it only because microsoft dominates the desktop market? Edward snowden clearly showed MS relation to the NSA. I do not believe at all such exploits are ${Discovered} by the NSA. But the exploits are backdoors that MS provides. That is why they are now blaming the NSA and putting on a marketing campain to show how much they c…

For all his quirks, RMS has made points in the past that I'm kicking myself for not taking seriously. I just wish that the FSF wasn't so tied up in minutiae -- it turns people off.

It's a sad fact that the face of proprietary tech is that of a handsome young generic "disruptor", while Open Source / Free Software / Libre / GNU//blah is less-cheerful Steve Wozniak.

Post reply on HN