Live data from Hacker News

FBI Accesses Computers Around Country to Delete Microsoft Exchange Hacks

vice.com

11–20 of 54 posts

Re: FBI Accesses Computers Around Country to Delete Microsoft Exchange Hacks

#11
post #2

> By deleting the web shells, FBI personnel will prevent malicious cyber actors from using the web shells to access the servers and install additional malware on them If the FBi is in your computer you have already lost. Your box is as good as dead and you might aswell do a full factory reset or it that's too bothersome, buy a new box. Sometimes buying a whole new box is cheaper than cleaning up malware using special…

This is very poor advice. “If the FBI is in your box you’re already dead.” No, in this case, they are fixing a hack. I don’t want them touching my stuff, but that’s hardly “dead”. “Cheaper to buy a new box” Reinstalling and reconfiguring is always cheaper than buying new and reconfiguring. This reasoning is very poor, why did you feel the need to make this comment?

lol "rm shell.js or if that's too bothersome buy a new machine"

Re: FBI Accesses Computers Around Country to Delete Microsoft Exchange Hacks

#12
post #5

Sweet, since we now have the precedence that the FBI can invade your machine without permission whenever they want for national security reasons I can't wait the glorious future we have before us. Now the FBI can access your machine and start modifying things because you are expressing displeasure at your public officials which is a sign of "terrorist behavior", oops you're using your blog to say things the governmen…

do you have an alternative? would you feel better if it wasn't FBI? or if these remained unfixed?

It is a Microsoft product, it would have been better if Microsoft was forced to push a patch for the vulnerability and code to remove the exploit in their AV definitions or their malicious software removal tool through Windows update.

Re: FBI Accesses Computers Around Country to Delete Microsoft Exchange Hacks

#13
post #5

Sweet, since we now have the precedence that the FBI can invade your machine without permission whenever they want for national security reasons I can't wait the glorious future we have before us. Now the FBI can access your machine and start modifying things because you are expressing displeasure at your public officials which is a sign of "terrorist behavior", oops you're using your blog to say things the governmen…

Is it really that bad and different than what they do in the physical world? If someone breaks into your home and they are still inside when the police show up, they won't just give you a call and tell you someone is inside your home. They will go in there and get the criminal out of your home. The threat actors are actively stealing information and are inside the networks of many companies, some with the expertise to get rid of the bad guys but some without that expertise. Yes, invading networks without warrants to investigate and prosecute people would be extremely bad. But this seems like it falls on the exigent circumstances side of the law and doesn't sound so bad.

Re: FBI Accesses Computers Around Country to Delete Microsoft Exchange Hacks

#14

Hah, so they're using the remote backdoor to delete the remote backdoor?

It's sort of the same logic given why we shouldn't require backdoors in general in devices: if the good guy can use it, so can the bad guy. Just, in this case it's being done in reverse.

Re: FBI Accesses Computers Around Country to Delete Microsoft Exchange Hacks

#16
post #12

Earlier quoted context omitted.

do you have an alternative? would you feel better if it wasn't FBI? or if these remained unfixed?

It is a Microsoft product, it would have been better if Microsoft was forced to push a patch for the vulnerability and code to remove the exploit in their AV definitions or their malicious software removal tool through Windows update.

But then we wouldn’t have this opportunity to set this far reaching legal precedent.

Re: FBI Accesses Computers Around Country to Delete Microsoft Exchange Hacks

#17
post #2

> By deleting the web shells, FBI personnel will prevent malicious cyber actors from using the web shells to access the servers and install additional malware on them If the FBi is in your computer you have already lost. Your box is as good as dead and you might aswell do a full factory reset or it that's too bothersome, buy a new box. Sometimes buying a whole new box is cheaper than cleaning up malware using special…

This is very poor advice. “If the FBI is in your box you’re already dead.” No, in this case, they are fixing a hack. I don’t want them touching my stuff, but that’s hardly “dead”. “Cheaper to buy a new box” Reinstalling and reconfiguring is always cheaper than buying new and reconfiguring. This reasoning is very poor, why did you feel the need to make this comment?

I don't think he means that because it's the FBI. I think he means that since the FBI is using the vulnerability itself to patch affected systems that you've already been compromised if the FBI is able to do this to your system.

Re: FBI Accesses Computers Around Country to Delete Microsoft Exchange Hacks

#18
The Justice Department had to get court approval to access private servers and remove malicious software.

But, why does the FBI have to do this?

Why does a federal agency have to remove a software virus from private servers? There are private companies that can do this.

Re: FBI Accesses Computers Around Country to Delete Microsoft Exchange Hacks

#20
post #5

Sweet, since we now have the precedence that the FBI can invade your machine without permission whenever they want for national security reasons I can't wait the glorious future we have before us. Now the FBI can access your machine and start modifying things because you are expressing displeasure at your public officials which is a sign of "terrorist behavior", oops you're using your blog to say things the governmen…

Is it really that bad and different than what they do in the physical world? If someone breaks into your home and they are still inside when the police show up, they won't just give you a call and tell you someone is inside your home. They will go in there and get the criminal out of your home. The threat actors are actively stealing information and are inside the networks of many companies, some with the expertise t…

It's a tragic precedent that is the result of decades of technical debt. Of course I'm not at all surprised to learn that the feds would rather take more unchecked power for themselves than use their mouthpieces to pressure Congress into forcing an industry wide focus on security that has teeth. From top to bottom the internet of things needs to be redesigned to treat every port and every communicated bit as potentially hostile. In the current state of affairs it is not outside the realm of possibilities for a lone actor to use a few RCEs in Windows, *nix, android and iPhones to brick billions of devices overnight. We should be glad that terrorists and nation states are using 0 days with relative discretion for profit and reputation protection instead of destroying critical infrastructure that would take in the range of years to decades to rebuild. I fear that our generation is going to have to learn this lesson the same way the Japanese learned about the horrors of nuclear bombs. Shit. Imagine if stuxnet had been given the capabilities to smoke CPUs, RAM, HDDs or anything else it could get write access to, like water pumps, or pressure regulators.
Post reply on HN