Live data from Hacker News

NSA infected 50,000 computer networks with malicious software

nrc.nl

41–50 of 96 posts

Re: NSA infected 50,000 computer networks with malicious software

#41
post #30
post #3

We don't need the Snowden disclosures to know this; it has for 15 years been the worst kept secret in computer security. People from the various groups in NSA that do this work talk about having done it on Twitter. Some of the smartest people in vulnerability research came from stints in NSA. Be outraged that we're spying on your country if that makes you feel better, I guess. I'd rather nobody spied on each other ei…

Well, I am in the software industry, but not the security industry. And I don't recall anyone mentioning to this to me. Or on HN. Can you point to some HN threads that discussed this in detail before Snowden? For example, when China was hacking Google, some people may off-handedly said, "well we do it too", but nobody gave specifics as Snowden did. His revelations were extremely useful.

Ditto. During all the "China is hacking us" stories, I never once recall any piece of news that talked about what we were doing to the rest of the World. As someone who is also in software, if such a story had been published, I would have been among those in the United States most likely to have read such a story.

If you have articles with publish dates pre-Snowden with lots of examples like the revelations in the posted story, please share. I want to figure out how I missed this.

Re: NSA infected 50,000 computer networks with malicious software

#42
post #39
post #17

Earlier quoted context omitted.

As much as I really don't like what the NSA is doing, this argument isn't valid. Law enforcement privileges cannot be directly compared to those of regular citizens. If you want to argue they've abused their privileges... then I'm with you 1,337%

Is NSA "law enforcement" though? They are spies. It is (or should be) also quite illegal for them to be doing that to its own citizens, so if they do that, they should be in prison. Too bad we live in a time where the president of US and Congress, prefer to protect these guys no matter what (whether it's spying or torture), instead of punishing them according to the law.

I really don't consider the NSA to be law enforcement. What, if any, US laws are they responsible for enforcing?

The FBI, Secret Service, Highway Patrol, city, state and country police departments, sheriffs, etc. are all in charge of enforcing laws. The NSA and the CIA as far as I can tell are not. Additionally neither are really tasked with domestic operations of any kind. National domestic law enforcement issues fall under the jurisdiction of the FBI.

Re: NSA infected 50,000 computer networks with malicious software

#43
post #17

Don't people usually get to spend decades in prison for that? Shouldn't justice be the same for the NSA as it was for Kevin Mitnick?

As much as I really don't like what the NSA is doing, this argument isn't valid. Law enforcement privileges cannot be directly compared to those of regular citizens. If you want to argue they've abused their privileges... then I'm with you 1,337%

I don't think the NSA is a law enforcer. They are an intelligence collector which may utilized by either the military, law enforcement, or executive branch.

Law enforcement still has to behave within the confines of the law. Unfortunately what we've had in the US is a revolving door of individuals who neither respect nor enforce the law. The Obama administration's attacks on whistle blowers is the equivalent to an organized criminal syndicate attempted to intimidate and snuff out informants.

Law enforcement has been turned upon itself, rather than going after the individuals breaking the law, they are going after those who are providing evidence of the crime.

For the record, and I've stated this before, there are two very separate issues here -- what the NSA does to the US & what the NSA does to everyone else. I am only referring to what is occurring in the US against US citizens (and US corporations.) There is very little disagreement that what has been done in the past and what likely is continuing does not fall within the confines of US law. The complicit and conspiratorial behavior among the highest levels of law enforcement & military mean there is no investigation, no prosecution, no tribunal for what is undoubtedly illegal behavior.

What the US's allies think about blanket surveillance and espionage is another matter, which should be debated between citizens of those democracies.

Re: NSA infected 50,000 computer networks with malicious software

#44
post #32
post #31

Earlier quoted context omitted.

The only thing I find even more fascinating than his unwavering attempt to defend the despicable actions of the NSA is how these posts end up every time as the top comments.

I don't think I've seen him defend their actions, just explain them. I, for one, appreciate it. He is in a sphere that I am not in, and were I to guess whether or not this was well-known behavior, I would have guessed not. And, apparently, I would have been wrong. So I thank tptacek for sharing what he knows that I don't know. That is, after all, why I come here.

But this is exactly the point!

We could close down all news sites and stop reporting on all crimes - because, hey, the cop, the robber and the victim knew already hours ago that somebody had been robbed.

The argument that something should be a no-story, just because I personally suspected/knew about it already for some time screams of delusional self-importance worldview to me.

Re: NSA infected 50,000 computer networks with malicious software

#45
post #24
post #23

Earlier quoted context omitted.

My country? Are you kidding, they couldn't hack their way out of a paper bag. Any expertise and equipment they have is provided by the NSA, and they're a bunch of B-players with no budget. The whole situation is uncomfortably asymmetric. Economies of scale I guess. Winner takes it all.

Cheer up. We're also protecting the world's shipping lanes.

The US Navy capture smaller vessels quite regularly. The larger pirate boats may have non-combatants and/or hostages aboard so the rules-of-engagement limit the Navy actions.

Re: NSA infected 50,000 computer networks with malicious software

#46
It's stories like this that make me wish we had the term "national security" as narrowly defined as the term "treason".

I wouldn't be surprised if many of America's largest corporations most often present their corporate interests as national security interests when they are lobbying our politicians.

Looking at that map, we need to be asking questions about where so many of those "implants" are located. I'm not surprised by all the little yellow dots covering China and Russia, But what are they doing littered all over Latin America (except Venezuela and Cuba). I would like to here the justification for considering Brazil a national security threat. Same for the red dots in places like Spain, Portugal and France.

The only national security threat in Brazil AFAIK is the Comando Vermelho[0], which operates out of Rio de Janeiro. And even then, only a few of the criminal organization leaders in Brazil tenuously relevant to US national security interests, such as Fernandinho Beira Mar[1].

The only way to justify the extent of such offensive implants is if we are using a definition of "national security" that is overly broad.

The only conclusion I can come to is that we've effectively waging a war against the rest of the World without an act of Congress declaring such a war.

[0] http://en.wikipedia.org/wiki/Comando_Vermelho

[1] IIRC, FBM is responsible for supplying a lot of the advanced Russian-made arms to the FARC. Even then the FARC is only a national security interest of the US because of our completely failed war on drugs.

Re: NSA infected 50,000 computer networks with malicious software

#47
post #31

Earlier quoted context omitted.

Has there ever been an NSA thread where you didn't take the opportunity to tell us why whatever the NSA has been doing is completely normal and expected?

The only thing I find even more fascinating than his unwavering attempt to defend the despicable actions of the NSA is how these posts end up every time as the top comments.

I don't think it's defending. It's one part nerd-based "I've known about this forever. It's obvious!" and one part "this is their purpose — yes, it's abhorrent, but that's the entire mission, so don't be surprised when they do what they are chartered to do."

Re: NSA infected 50,000 computer networks with malicious software

#48
So, the 250 lb gorilla in the room: Linux, or Windows or ...?

Seriously, I'd like to know. I mean it's probably Windows for all the usual reasons (incomparable installed base, lots of attack surface, active exploit community, MSFT gives exploits to NSA before publishing), but what if it isn't? What if all this is done by Cisco IOS?

Re: NSA infected 50,000 computer networks with malicious software

#49
post #4

What would happen if NSA mistakenly targets a nuclear reactor, and a bug in the malicious software caused a meltdown. Is that a declaration of war, similar to a US launching a nuke? Would US be liable, and under what jurisdiction? Could the US President be put under Interpool arrest warrant, charged as an terrorist? Sabotage, especially when the target can not be fully verified, is a dangerous game. IP addresses are…

>What would happen if NSA mistakenly targets a nuclear reactor, and a bug in the malicious software caused a meltdown.

First order of business is covering your tracks. An accident happened, period.

>Is that a declaration of war, similar to a US launching a nuke? Would US be liable, and under what jurisdiction?

No. At worst you get to use your diplomatic channels to sort things out. Rembember, the target also needs to save face. Having allowed NSA to cause a reactor meltdown is not something anybody would want in their CV.

>Could the US President be put under Interpool arrest warrant, charged as an terrorist?

I do not know enough about Interpol to offer an answer on this one. But I would say that it is as likely as having USA kicked out of Nato or UN. One would have to start a parallel institution without US for that to be even remotely possible.

Re: NSA infected 50,000 computer networks with malicious software

#50
post #32
post #31

Earlier quoted context omitted.

The only thing I find even more fascinating than his unwavering attempt to defend the despicable actions of the NSA is how these posts end up every time as the top comments.

I don't think I've seen him defend their actions, just explain them. I, for one, appreciate it. He is in a sphere that I am not in, and were I to guess whether or not this was well-known behavior, I would have guessed not. And, apparently, I would have been wrong. So I thank tptacek for sharing what he knows that I don't know. That is, after all, why I come here.

Don't you think that he's being a little inflammatory with statements this?

  But it is intellectually dishonest to pretend that
  people are just now discovering that NSA was breaking 
  into computers around the world.
By your own admission, you are just now discovering that the NSA was breaking into computers around the world.
Post reply on HN