Live data from Hacker News

New Snowden Docs Indicate Scope of NSA Preparations for Cyber Battle

spiegel.de

1–10 of 295 posts

Re: New Snowden Docs Indicate Scope of NSA Preparations for Cyber Battle

#2
Judging by the scope of the attack on Belgacom in 2011 that battle is already underway, the surprise I guess should be that it is the allies attacking each other. If China or North Korea would have made an attack like this it would be trumpeted as an act of war, but because it is the UK with NSA assistance it's downplayed as much as possible.

Re: New Snowden Docs Indicate Scope of NSA Preparations for Cyber Battle

#3
At best this seems like an arms race but at worst, there are actually battles being fought (of a kind). I wonder what the digital equivalent of a nuke would be such that govts decide that diplomacy is better. Some kind of Digitally Affected Mutual Destruction (DAMD).

Re: New Snowden Docs Indicate Scope of NSA Preparations for Cyber Battle

#4
> the only law that applies is the survival of the fittest.

Is this such a problem? In a world where exploits are used to break infrastructure, isn't the best solution simply to build increasingly more secure code? If that won't solve the problem I don't know if legislation will. Right now a determined hacker can harm a company via the internet (e.g. Sony). Are laws really going to stop that from happening?

If not, please correct me. I know little about cyber warfare and would love to know more.

Re: New Snowden Docs Indicate Scope of NSA Preparations for Cyber Battle

#5
The last 2 articles I read were this one and the earlier piece on Google and neural nets [1]. It's easy to connect the two, add the pervasive integration of technology in our lives, mix in a healthy dose of paranoia --> see a SkyNet future.

[1]https://medium.com/backchannel/google-search-will-be-your-ne...

Re: New Snowden Docs Indicate Scope of NSA Preparations for Cyber Battle

#7
post #4

> the only law that applies is the survival of the fittest. Is this such a problem? In a world where exploits are used to break infrastructure, isn't the best solution simply to build increasingly more secure code? If that won't solve the problem I don't know if legislation will. Right now a determined hacker can harm a company via the internet (e.g. Sony). Are laws really going to stop that from happening? If not, p…

I think you are exactly right. Any solutions to this have to be technical and largely defensive. Legal or diplomatic solutions will only bind parties that intend to follow the law. Counter-attacking and deterrence will fail if the attacker is not defending much of anything, so that approach might work against states and state-backed actors, but not against non-state actors.

Re: New Snowden Docs Indicate Scope of NSA Preparations for Cyber Battle

#8
There was a long interview with Snowden posted recently, which didn't make it to the frontpage. I guess because of Snowden penalty on HN and Snowden fatigue. Anyway, he kept repeating a point which is quite easy to understand for the public I think.

https://news.ycombinator.com/item?id=8859606

And the reality is when it comes to cyber conflicts [...], we have more to lose.

We spend more on research and development than these other countries, so we shouldn’t be making the internet a more hostile, a more aggressive territory. We should be cooling down the tensions, making it a more trusted environment, making it a more secure environment, making it a more reliable environment, because that’s the foundation of our economy and our future.

[...]

The concept there is that there’s not much value to us attacking Chinese systems. We might take a few computers offline. We might take a factory offline. We might steal secrets from a university research programs, and even something high-tech. But how much more does the United States spend on research and development than China does? Defending ourselves from internet-based attacks, internet-originated attacks, is much, much more important than our ability to launch attacks against similar targets in foreign countries [...].

[...]

When you look at the problem of the U.S. prioritizing offense over defense, imagine you have two bank vaults, the United States bank vault and the Bank of China. But the U.S. bank vault is completely full. It goes all the way up to the sky. And the Chinese bank vault or the Russian bank vault of the African bank vault or whoever the adversary of the day is, theirs is only half full or a quarter full or a tenth full.

But the U.S. wants to get into their bank vault. So what they do is they build backdoors into every bank vault in the world. But the problem is their vault, the U.S. bank vault, has the same backdoor. So while we’re sneaking over to China and taking things out of their vault, they’re also sneaking over to the United States and taking things out of our vault. And the problem is, because our vault is full, we have so much more to lose. So in relative terms, we gain much less from breaking into the vaults of others than we do from having others break into our vaults.

Re: New Snowden Docs Indicate Scope of NSA Preparations for Cyber Battle

#9
post #4

> the only law that applies is the survival of the fittest. Is this such a problem? In a world where exploits are used to break infrastructure, isn't the best solution simply to build increasingly more secure code? If that won't solve the problem I don't know if legislation will. Right now a determined hacker can harm a company via the internet (e.g. Sony). Are laws really going to stop that from happening? If not, p…

Legislature can't prevent bad people from doing bad things. But it can prevent good people from doing bad or ignorant things, and it provides a framework to punish those who cause harm.

Every law can and does get broken, but that doesn't mean laws are useless.

Post reply on HN