Live data from Hacker News

NSA director: 'Mythos "broke into almost all of our classified systems in hours"

economist.com

91–100 of 131 posts

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#91

Have to give it to Cyber Command. This is cheap and effective propAIganda. Of course, America is now the only nation on the planet with advanced weaponised AI models that are so good they beat billions of dollars and decades of IT security experience with some of the brightest minds in their fields within hours. If this were true, you’d see the president yapping and bragging about it on Truth before the NSA director…

>brightest minds

more like dimmest tbh

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#95
post #48

This quote from TFA is highly likely to be a conflation, exaggeration or extrapolation of what actually happened: > "On June 11th Mark Warner, the vice-chair of the Senate Intelligence Committee, said that General Joshua Rudd, who leads the National Security Agency and the Pentagon’s Cyber Command, had told him that Mythos “broke into almost all of our classified systems, not in weeks, but in hours”" Why: 1. It's a p…

Why not use Mythos to hack them and see what the report was

When you get your hands on it, let me know.

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#96
post #67

Earlier quoted context omitted.

I’m not familiar with this, but what does “solved” mean in this case? Guaranteed inability to compromise systems?

Pretty much. If you've got a microkernel / capabilities based OS, the amount of mischief that someone can cause is severely reduced. It's my belief that we can have general purpose, easy to use, secure computing for everyone. No UAC crap, or horrible systems like AppArmor, no virus scanners, etc... just computers that do what you want, and only what you want. We could have had it decades ago, if things had happened i…

Capabilities-based OSes aren't magic. Their robustness still depends on underlying assumptions, which may or may not hold. See eg relevant disclaimers in seL4 whitepaper(s).

And hardware glitches are a thing (edit: and supply chain attacks).

But I do agree that verified correct software can offer very strong guarantees that go well beyond those of commonly deployed software. We could have been in a much better place today.

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#97

Earlier quoted context omitted.

Pretty much. If you've got a microkernel / capabilities based OS, the amount of mischief that someone can cause is severely reduced. It's my belief that we can have general purpose, easy to use, secure computing for everyone. No UAC crap, or horrible systems like AppArmor, no virus scanners, etc... just computers that do what you want, and only what you want. We could have had it decades ago, if things had happened i…

How much does this limit what a computer can do? E.g. if I converted an Ubuntu desktop into a "secure microkernel", what functionality would be lost?

Everything but the specific usage

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#98

Earlier quoted context omitted.

Pretty much. If you've got a microkernel / capabilities based OS, the amount of mischief that someone can cause is severely reduced. It's my belief that we can have general purpose, easy to use, secure computing for everyone. No UAC crap, or horrible systems like AppArmor, no virus scanners, etc... just computers that do what you want, and only what you want. We could have had it decades ago, if things had happened i…

Capabilities-based OSes aren't magic. Their robustness still depends on underlying assumptions, which may or may not hold. See eg relevant disclaimers in seL4 whitepaper(s). And hardware glitches are a thing (edit: and supply chain attacks). But I do agree that verified correct software can offer very strong guarantees that go well beyond those of commonly deployed software. We could have been in a much better place…

To clarify: capabilities-based OS != verified correct software.

But there's much synergy there. Each enhances the other.

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#99
post #83

Earlier quoted context omitted.

Pretty much. If you've got a microkernel / capabilities based OS, the amount of mischief that someone can cause is severely reduced. It's my belief that we can have general purpose, easy to use, secure computing for everyone. No UAC crap, or horrible systems like AppArmor, no virus scanners, etc... just computers that do what you want, and only what you want. We could have had it decades ago, if things had happened i…

Can you recommend any modern systems that behave like that?

https://genode.org

Re: NSA director: 'Mythos "broke into almost all of our classified systems in hours"

#100

Earlier quoted context omitted.

How much does this limit what a computer can do? E.g. if I converted an Ubuntu desktop into a "secure microkernel", what functionality would be lost?

Everything but the specific usage

But what does that mean? Can I browse a webpage, open a doc, if those are listed as specific usage? And if not, what's the purpose of this and why are people talking about it with such import?
Post reply on HN