Live data from Hacker News

NSA infected 50,000 computer networks with malicious software

nrc.nl

61–70 of 96 posts

Re: NSA infected 50,000 computer networks with malicious software

#62

It's stories like this that make me wish we had the term "national security" as narrowly defined as the term "treason". I wouldn't be surprised if many of America's largest corporations most often present their corporate interests as national security interests when they are lobbying our politicians. Looking at that map, we need to be asking questions about where so many of those "implants" are located. I'm not surpr…

Not to excuse the actions, which I find deplorable. Isn't Brazil one of our major agricultural trading partners? Making the internal security interests of Brazil our security interests? If our food supply was cut by 1/3 during half the year, that could be a big issue.

Re: NSA infected 50,000 computer networks with malicious software

#63
post #33
post #28

Earlier quoted context omitted.

> The news is the scope of the intrusions (installing malware on 50k computers), and of the motivations for the behavior. GCHQ have said for at least 15 years that their mission is to monitor all communications, world wide, at frequencies from DC to light. They've said that they provide intelligence for their customers, who are the Ministry of Defence and other parts of government. (MI5, MI6, etc). > It's about globa…

I don't know anything about GCHQ, but I don't want British intelligence to have intimate details about my life stored in some nosql database, and I see it as an offensive maneuver by a foreign government from which my government fails to protect me. See my reply to tptacek's post sibling to yours for a general response to your inquiry.

I see it as an offensive maneuver by a foreign government from which my government fails to protect me.

Which is why you should be angry at your government for failing to protect you.

Re: NSA infected 50,000 computer networks with malicious software

#64
post #18

Earlier quoted context omitted.

>But it is intellectually dishonest to pretend that people are just now discovering that NSA was breaking into computers around the world. That is literally the charter of the NSA. It's why they exist at all. You're presenting a red herring here, tptacek. Any third grader who played played Splinter Cell would say, "No duh!" But the news isn't that the NSA is breaking into computers. The news is the scope of the intru…

Yup. TBH I simply don't understand the logic that makes an offensive act against a non-combatants by an individual illegal, but somehow permits that same act against non-combatants by a nation state. It it is illegal for an individual to murder someone, then it should be illegal for the government to do so. If it is illegal for a programmer to infect thousands of computers of innocent people with malware, then it sho…

What does illegal mean in the context of government? The government decides what's illegal. If you want to declare some government's action illegal, you need to find a bigger government to impose their laws on the little government.

Re: NSA infected 50,000 computer networks with malicious software

#65
post #47
post #31

Earlier quoted context omitted.

The only thing I find even more fascinating than his unwavering attempt to defend the despicable actions of the NSA is how these posts end up every time as the top comments.

I don't think it's defending. It's one part nerd-based "I've known about this forever. It's obvious!" and one part "this is their purpose — yes, it's abhorrent, but that's the entire mission, so don't be surprised when they do what they are chartered to do."

I'd take a bet that it's mostly the former (and the latter is rather similar to it). It's not just that some people get off on pointing out that something is 'obvious', it's that lots of other people feel the same way. So they upvote.

A somewhat similar example that always comes to mind in these cases (and for some reason happens relatively often among my 'geekier' friends) is when someone says 'I don't dream'. There's always a smart-ass around to point out that everybody dreams, but they just don't always remember it. I don't know if that's true, but that's irrelevant..

It might be technically true, but it's pedantic and misses the point of the statement. And it cuts off a potentially interesting conversation for the sole purpose of making this person sound smart.

I've noticed myself doing this too (I privately call it 'snoping' someone), and have been trying to avoid it as much as possible since I became aware of it.

Re: NSA infected 50,000 computer networks with malicious software

#66
post #23
post #6

Earlier quoted context omitted.

Sovereign countries interact in the state of nature. Your country has a problem with the NSA? Pick up a SAT solver and build yourself some ROP shellcode and hit us back. Oh wait: your country's already doing that . Do I like it? No. We don't work with the USG, and that's one of many reasons why.

My country? Are you kidding, they couldn't hack their way out of a paper bag. Any expertise and equipment they have is provided by the NSA, and they're a bunch of B-players with no budget. The whole situation is uncomfortably asymmetric. Economies of scale I guess. Winner takes it all.

Yup. Winner takes all. Everybody else gets their noses rubbed in the dirt.

Re: NSA infected 50,000 computer networks with malicious software

#67

what pisses me off most about this is that if you, Joe Public does it, it's illegal and if you get caught, you're arrested and charged for computer fraud, espionage or whatever else they can pin on you. But it's fine for them to do the same thing. The hypocrisy is disgraceful.

Steal a little and they throw you in jail, steal a lot and they make you King.

Ain't that the truth

Re: NSA infected 50,000 computer networks with malicious software

#68

So, the 250 lb gorilla in the room: Linux, or Windows or ...? Seriously, I'd like to know. I mean it's probably Windows for all the usual reasons (incomparable installed base, lots of attack surface, active exploit community, MSFT gives exploits to NSA before publishing), but what if it isn't? What if all this is done by Cisco IOS?

Given the amount of closed source routing hardware built by U.S. companies, it would surprise me more if they weren't complicit in similar activities to Microsoft on this topic. I've never been big on conspiracy theories, but this isn't really so much a conspiracy as what would be an obvious point of being able to distribute information from global sources.

When Iran buys computer hardware via third parties, odds are the software may well be a generation or two older... Having knowledge of internal exploit vectors would be invaluable to a state actor (like the NSA).

In my career I've been contacted (usually by recruiter) to consider projects by the RIAA, MPAA and the NSA... None of these were cracking projects or otherwise covert that I am aware of. Just the same, I don't think I could work for an organization that works directly against ideologies that I believe in.. those being liberty, privacy and the greater public good. On the last point some may well believe that these organizations work towards that, I disagree.

Re: NSA infected 50,000 computer networks with malicious software

#69
post #3

We don't need the Snowden disclosures to know this; it has for 15 years been the worst kept secret in computer security. People from the various groups in NSA that do this work talk about having done it on Twitter. Some of the smartest people in vulnerability research came from stints in NSA. Be outraged that we're spying on your country if that makes you feel better, I guess. I'd rather nobody spied on each other ei…

Be outraged that we're spying on your country if that makes you feel better, I guess. I'd rather nobody spied on each other either.

Opposition to the tactics of the NSA/GCHQ does not require you to be opposed to the existence of spies. That's an old, tired argument, which we didn't need to go into the first time. Of course spies spy, but should they do so without boundaries, without proper supervision, and above the law? Should they do so outside wartime and on allies? Should they be given the very real capacity to subvert our democracies and networks worldwide? Who then will keep them in check if the head of the NSA decides he wants regime change at home? How will we know if this has happened?

Personally I don't think this world-weary acceptance of lawbreaking is an appropriate response, and I'm outraged that spies in my country (GCHQ) have been collaborating with collection of data worldwide and handing it over to the NSA, without any respect for international law or the interests of their own country.

The important discussion to be had is on where the boundaries to NSA surveillance lie, and how to perform adequate supervision of them, and just what laws they are not allowed to break. At the very least I think we need a proper inquiry into those topics, which we have not been offered thus far. Spies could (and have) assassinate, kidnap, subvert the political process, and break into networks worldwide but should they do those things to allies and domestically? Should we fund them to keep doing it? Should we accept the perpetual state of war which has been engendered by wars on terrorism and drugs, and the use of that to justify tyranny, assassination and subversion of the democratic process? If we say they can and will do all these things, because it's just what they do, we might as well given up on the pretence of a democracy we currently enjoy.

There are very good reasons the NSA is not supposed to be used domestically, and I'd argue those reasons should also extend to allies, if only because not doing so means your country will no longer have any real allies at all. Why should anyone trust the US or UK in trade negotiations when they've been shown to cheat and steal at every opportunity? Why should Sri Lanka say not just laugh in the face of the UK when Cameron talks of human rights, and China laugh in the face of the US when it complains about intrusive industrial espionage? The blowback on this topic is very real and deep and is only going to be reinforced by reactions like yours above which come down to 'spies will be spies'. The defensive capabilities of the NSA should be far more important than the offensive ones in my opinion, particularly in times of peace. Acting as if you are in a perpetual state of war with other nations, including your closest allies and even domestic population, will lead them to treat you the same way.

The spies have become a supranational organisation which apparently doesn't feel it is answerable to anyone; even the politicians who are ostensibly in charge of them. I think that's dangerous and worthy of note.

Re: NSA infected 50,000 computer networks with malicious software

#70

Earlier quoted context omitted.

Yup. TBH I simply don't understand the logic that makes an offensive act against a non-combatants by an individual illegal, but somehow permits that same act against non-combatants by a nation state. It it is illegal for an individual to murder someone, then it should be illegal for the government to do so. If it is illegal for a programmer to infect thousands of computers of innocent people with malware, then it sho…

What does illegal mean in the context of government? The government decides what's illegal. If you want to declare some government's action illegal, you need to find a bigger government to impose their laws on the little government.

If you live in a nation of laws, i.e. some form of functioning democracy, the people decide what is legal through their representatives, and this can change gradually as attitudes shift. The government is supposed to be an instrument of the people, not the other way around.
Post reply on HN