How the NSA Plans to Infect “Millions” of Computers with Malware
1–10 of 182 posts
Re: How the NSA Plans to Infect “Millions” of Computers with Malware
#2Re: How the NSA Plans to Infect “Millions” of Computers with Malware
#3Really, how does that work Mikko? You don't even have a copy of any malware to make that statement.
All the hyperbole about how this is somehow unique is really getting old. Exploit kit authors have had shitty PHP web applications that accomplish the same task for ages: manage thousands of bots by grouping them together with a point and click management interface. It sounds like, prior to TURBINE, NSA had a single person tasked to oversee every action taken by hand, which is kind of inefficient if you ask me, so it stands to reason they would try to manage that process with technology.
How do you cool yourself First Look when you're reporting on this in 2014? Jeez.
Re: How the NSA Plans to Infect “Millions” of Computers with Malware
#4http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t...
Every single one of these vulnerabilities could be seen as a backdoor, except Microsoft can have plausible deniability, since they are not actually putting a backdoor in the OS themselves - they're "just telling NSA about the vulnerabilities that exist".
If something like CISPA passes, which NSA keeps pushing for, this capability will expand dramatically, as all companies will be forced to give these vulnerabilities to NSA, but not to "protect us" and for cyber "security", as they keep claiming when they try to promote laws like these, but for offense. They will hoard every single one of them, and then use them in such automated systems to infect millions of computers.
Re: How the NSA Plans to Infect “Millions” of Computers with Malware
#5The NSA and its cohorts set up fake Facebook websites, spoof security certificates, secretly record webcam streams, vacuum up everything they can lay their hands on etc.
Meanwhile the CIA coolly wipes hundreds of documents from the machines of those who are investigating it, and when caught, threaten their overseers with criminal charges.
Given the scale of their operations, tens of billions of dollars in budgets and how many years they've been at it (this article essentially talks about what the NSA was doing in 2009), is it now futile to think that govt. agencies around the world can ever be expected to turn the clock back?
I mean, really, is there any possible reality that involves the NSA/GCHQ deleting the mountains of data they have surreptitiously recorded? And unplugging or reversing the hundreds of traps, backdoors, viruses, intercepts, decoys that are aimed at common citizens?
Re: How the NSA Plans to Infect “Millions” of Computers with Malware
#6Remember, Microsoft is part of this plot, even if they have "plausible deniability". Microsoft is giving NSA access to lists of vulnerabilities Windows has many months before Microsoft even begins to work on a fix. They are in effect helping NSA break into many computers, even if they are up to date. http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t... Every single one of these vulnerabilities could be see…
Not impossible for NSA to get in but a lot more difficult.
Re: How the NSA Plans to Infect “Millions” of Computers with Malware
#7Remember, Microsoft is part of this plot, even if they have "plausible deniability". Microsoft is giving NSA access to lists of vulnerabilities Windows has many months before Microsoft even begins to work on a fix. They are in effect helping NSA break into many computers, even if they are up to date. http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t... Every single one of these vulnerabilities could be see…
Very frustrating as I work with a Microsoft-oriented company at the moment. Any mention of this to their architectural team results in nothing short of "mwuhahaha you're talking shit". There is some weird universal trust there that really makes no sense at all.
To add insult to injury they don't log, don't have an IDS and don't have a clue stick to hit themselves with.
Their funeral!
Re: How the NSA Plans to Infect “Millions” of Computers with Malware
#8Remember, Microsoft is part of this plot, even if they have "plausible deniability". Microsoft is giving NSA access to lists of vulnerabilities Windows has many months before Microsoft even begins to work on a fix. They are in effect helping NSA break into many computers, even if they are up to date. http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t... Every single one of these vulnerabilities could be see…
And this is why I'm glad my main OS is linux. Not impossible for NSA to get in but a lot more difficult.
You're cute.
Re: How the NSA Plans to Infect “Millions” of Computers with Malware
#9“When they deploy malware on systems,” Hypponen says, “they potentially create new vulnerabilities in these systems, making them more vulnerable for attacks by third parties.” Really, how does that work Mikko? You don't even have a copy of any malware to make that statement. All the hyperbole about how this is somehow unique is really getting old. Exploit kit authors have had shitty PHP web applications that accompli…
Unless you're asserting that adding back doors makes a system more secure.
Re: How the NSA Plans to Infect “Millions” of Computers with Malware
#10“When they deploy malware on systems,” Hypponen says, “they potentially create new vulnerabilities in these systems, making them more vulnerable for attacks by third parties.” Really, how does that work Mikko? You don't even have a copy of any malware to make that statement. All the hyperbole about how this is somehow unique is really getting old. Exploit kit authors have had shitty PHP web applications that accompli…
Simple: every process running on a system is a process that can be exploited, especially those processes that involve network communication. The NSA's exploits are processes running on the system they are attacking. They utilize network communications. These processes are open to exploitation by third parties, just like all the other legitimate processes.