Live data from Hacker News

NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows

nsa.gov

11–20 of 40 posts

Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows

#11
post #10

You can totally trust our advice for all your digital security needs. - your friendly neighborhood intelligence agency.

You don't trust NSA, so you're going to not patch your systems? Are you worried that the patch is a delivery vehicle for their APT implants?

I'm not worried about anything. Just that an organization whose prime objective it is to hack, exploit, cheat, deceive, and exfiltrate has no place giving advice to the general public.

Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows

#12

Who has the fear of visiting a URL owned by a three letter agency known for nefarious spying activities? I do! So here is a third party report for anyone else that views three letter agency URLs as having all the appeal of a trip to a virtual leper colony: https://www.zdnet.com/article/even-the-nsa-is-urging-windows...

I can almost picture the NSA staff meeting: "Let's bait Hacker News randos by issuing an advisory about a nearly internet-wide vulnerability that gives unrestricted access to Windows computers. Then, when they visit our website to learn more, we'll nab them!"

Thanks for taking a bullet for the team on this one, Internet stranger.

Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows

#13

Who has the fear of visiting a URL owned by a three letter agency known for nefarious spying activities? I do! So here is a third party report for anyone else that views three letter agency URLs as having all the appeal of a trip to a virtual leper colony: https://www.zdnet.com/article/even-the-nsa-is-urging-windows...

I can almost picture the NSA staff meeting: "Let's bait Hacker News randos by issuing an advisory about a nearly internet-wide vulnerability that gives unrestricted access to Windows computers. Then, when they visit our website to learn more, we'll nab them!" Thanks for taking a bullet for the team on this one, Internet stranger.

Reminds me of the UK UFO trap story. In the UK it's illegal to listen to police on scanners so detectives transmitted a hoax radio message about a UFO landing near Doncaster, South Yorkshire, then arrested several people who turned up at the spot, charging them with illegally using scanners to monitor police radio transmissions.

Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows

#14

Who has the fear of visiting a URL owned by a three letter agency known for nefarious spying activities? I do! So here is a third party report for anyone else that views three letter agency URLs as having all the appeal of a trip to a virtual leper colony: https://www.zdnet.com/article/even-the-nsa-is-urging-windows...

You're not important enough to waste a 0day on.

Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows

#15

Who has the fear of visiting a URL owned by a three letter agency known for nefarious spying activities? I do! So here is a third party report for anyone else that views three letter agency URLs as having all the appeal of a trip to a virtual leper colony: https://www.zdnet.com/article/even-the-nsa-is-urging-windows...

I can almost picture the NSA staff meeting: "Let's bait Hacker News randos by issuing an advisory about a nearly internet-wide vulnerability that gives unrestricted access to Windows computers. Then, when they visit our website to learn more, we'll nab them!" Thanks for taking a bullet for the team on this one, Internet stranger.

If this was a story on a paywalled site and I had a non paywall link then I would share it for the benefit of others.

Similarly, if a story is on a website owned by paranoid people with a track record of harm I would prefer to read a third party report. I don't believe I am alone in that.

Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows

#17

Who has the fear of visiting a URL owned by a three letter agency known for nefarious spying activities? I do! So here is a third party report for anyone else that views three letter agency URLs as having all the appeal of a trip to a virtual leper colony: https://www.zdnet.com/article/even-the-nsa-is-urging-windows...

I can almost picture the NSA staff meeting: "Let's bait Hacker News randos by issuing an advisory about a nearly internet-wide vulnerability that gives unrestricted access to Windows computers. Then, when they visit our website to learn more, we'll nab them!" Thanks for taking a bullet for the team on this one, Internet stranger.

Can't trick me into installing your backdoor patch!

Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows

#19
The advisory links to https://www.nsa.gov/Portals/70/documents/what-we-do/cybersec... (PDF)

I really wonder what the utility for that distribution form is, are there people printing these out? Or is there some requirement for them to generate a document ID that they could not get for plain web/HTML documents?

Re: NSA Cybersecurity Advisory: Patch Remote Desktop Services on Legacy Windows

#20

The advisory links to https://www.nsa.gov/Portals/70/documents/what-we-do/cybersec... (PDF) I really wonder what the utility for that distribution form is, are there people printing these out? Or is there some requirement for them to generate a document ID that they could not get for plain web/HTML documents?

Do you mean to ask why is the same content published in PDF format? I quite like PDFs these days. Self-contained, archiveable, readable, sane layout, JavaScript-free, (usually) ad/cookie/tracking-free, no social media sharing buttons... the only drawback is no/poor reflow of text to fit device screen size. But I’ll live with that.
Post reply on HN