Live data from Hacker News

Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

nytimes.com

101–110 of 116 posts

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#101
post #34

Earlier quoted context omitted.

Defense may be the only game worth playing, but how will that work? Unlike the real military where civilians simply don't own the hardware, in computer security they do. NSA isn't a hardware or software vendor, and the corporations that are don't have much of a profit motive to heavily invest in security. They aren't actually liable for problems unlike say a car manufacturer that releases a faulty product, which leav…

Regulate operating systems. Fund programs and research to work out how to create operating systems for our infrastructure that contain less zero days. Ensure we're the ones that find the zero days first. The reason we're vulnerable is because we're unwilling to pay the cost of finding the exploits but people in developing nations ARE because they work for "less". Right now our economies and systems reward those that…

Regulate operating systems.

When we're trying to protect ourselves from the vulnerabilities hoarded by our government, I think that asking them to regulate the OS might just be a step backward.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#102
post #4

This is merely a taste of what is to come. When President Obama stated in December[0] that we will deliver a "proportional response" to Russian hacking at the "time and place of our own choosing", it seemed that most of the country was proud, almost gleeful at the thought that we would be striking back. I for one was mortified. We should not be escalating cyberwar, even if we do have proof of who attacked us. People…

How big is the space of potential exploits?

If organization A searches for exploits for five years in a given piece of software, and organization B does the same, what percentage of the exploits they find will be found by both rather than just one?

If hackers/governments tend to find the same exploits as each other then it makes more sense to take a defensive strategy since you can protect against a large portion of the weapons your enemies develop. But if there's not much overlap in which exploits are found then an offensive strategy may make more sense.

In the nuclear arms race there was basically one type of attack and one set of mitigations. In cyberwarfare there are potentially endless types of attacks, each with its own set of mitigations. This changes the calculus.

The likelihood of one's weapons being stolen and used against you, your allies, or humanity in general is also a huge consideration.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#103
post #4

This is merely a taste of what is to come. When President Obama stated in December[0] that we will deliver a "proportional response" to Russian hacking at the "time and place of our own choosing", it seemed that most of the country was proud, almost gleeful at the thought that we would be striking back. I for one was mortified. We should not be escalating cyberwar, even if we do have proof of who attacked us. People…

The primary way for the NSA to be a defensive organization would be for it to very publicly take a lead in closing up the holes they find on a structural level. Whether the NSA hoards zero-day exploits or not isn't the big issue since someone will be doing that. The issue is they should be sounding the alarm on whatever broad class of system vulnerabilities they find. They should be evangelizing against remotely upda…

> The issue is they should be sounding the alarm on whatever broad class of system vulnerabilities they find.

Sounds like the IAD mission. Examples:

- https://github.com/iadgov/Pass-the-Hash-Guidance/blob/master...

- https://www.iad.gov/iad/library/reports/nsa-methodology-for-...

I mention that first one especially because Pas-The-Hash was a major reason the most recent ransomware outbreak was able to get onto already-patched machines.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#104
post #4

This is merely a taste of what is to come. When President Obama stated in December[0] that we will deliver a "proportional response" to Russian hacking at the "time and place of our own choosing", it seemed that most of the country was proud, almost gleeful at the thought that we would be striking back. I for one was mortified. We should not be escalating cyberwar, even if we do have proof of who attacked us. People…

> When we strike back, does Russia then strike back again?

It seems that Russia is happy to continually strike regardless of retaliation.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#105
post #29

Not trying to claim whataboutism, but I think there's an elephant in the room. The end result of the NSA saying "ok, as of today we've completely disarmed our cyberweapon stockpile and released patches for all vulnerabilities to the appropriate software companies" wouldn't be the end of cyberattacks. It would just be someone else doing them. I don't know what the real solution is. Maybe there is none.

The point is that there would be fewer cyber attacks, both because the NSA itself would no longer be adding to the number of hacks and because the NSA would use their sizeable budget to discover and disclose vulnerabilities, presumably making all of us safer.

> because the NSA would use their sizeable budget to discover and disclose vulnerabilities

Right now, the process is:

1. Find a way to survey the target environment, learn what software and hardware they are running

2. Acquire vulnerabilities to exploit the known target software/hardware, either from a third-party, a contractor, or manual reverse engineering of those specific components.

3. Adapt mission specific payloads to use on the target.

4. Use for as long as needed.

5. Disclose to vendor after the purpose is served.

If the agency mission changed to be purely about discovery and reporting, that might not help the general public. If this were to happen, it seems like the focus would likely be on protection of only software/hardware in classified systems, as that is already their defensive mission. Instead of having things like EternalBlue patched we would have them open and available for a different party to discover. That seems worrisome to me, but I am really curious to know if you might have a different take on how this would work.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#106

With the initial vector being some widely used Ukranian tax software, and the network vector as psexec/wmic mimikatz harvested credentials, the actual usage of 'NSA cyberweapons' was just a backup. I suspect this attack would have had a similar number of victims without EtBl/DoPu and EtRo. The existence of 'nation state' offensive tools has little baring on exploitability for poorly configured enterprise network, whe…

You are correct regarding the most recent ransomware not actually needing EternalBlue and just adding it if needed (As proof of concept code is widely available for it).

I think concerns include things like WannaCry too though, which did indeed rely primarily on use of EternalBlue.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#107
post #16

> White House officials have deflected many questions, and responded to others by arguing that the focus should be on the attackers themselves, not the manufacturer of their weapons. Am i to understand that if somebody would manage to steal nuclear warheads and launch them we don't hold the people who failed to protect them responsible?

A nuclear weapon is a little different than a patched SMB exploit.

I agree that's a bit of a stretch for a comparison. I think it would be closer to saying that the NSA found a key to a company's system, didn't inform the company, and then got the key stolen from them by criminals which then brought down the system.

Obviously that's extremely simplified, but all parties here are at fault. And all we're seeing is a bunch of finger pointing, with not enough defensive and preventative action being taken.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#108
post #16

> White House officials have deflected many questions, and responded to others by arguing that the focus should be on the attackers themselves, not the manufacturer of their weapons. Am i to understand that if somebody would manage to steal nuclear warheads and launch them we don't hold the people who failed to protect them responsible?

A nuclear weapon is a little different than a patched SMB exploit.

The principle should be the same.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#109
post #4

This is merely a taste of what is to come. When President Obama stated in December[0] that we will deliver a "proportional response" to Russian hacking at the "time and place of our own choosing", it seemed that most of the country was proud, almost gleeful at the thought that we would be striking back. I for one was mortified. We should not be escalating cyberwar, even if we do have proof of who attacked us. People…

The primary way for the NSA to be a defensive organization would be for it to very publicly take a lead in closing up the holes they find on a structural level. Whether the NSA hoards zero-day exploits or not isn't the big issue since someone will be doing that. The issue is they should be sounding the alarm on whatever broad class of system vulnerabilities they find. They should be evangelizing against remotely upda…

I'm not a coder but from listening around here. What if a government agency took the lead to develop a safer open source operating system. With the knowledge they have regarding attack vectors. they would seem to have elevated insight n what to avoid.
Post reply on HN