Live data from Hacker News

Source Code Similarities Between NSA Malware and 'Regin' Trojan

spiegel.de

191–200 of 200 posts

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#191
post #169
post #55

down voting on HN has become absurd. Also noticing this on other comments in this thread.

The comment you're complaining about downvotes looks to be at +33 right now. The downvote situation is always in flux, which is one reason why the HN guidelines ask you not to post comments complaining about being downvoted. I'm going to detach this subthread and mark it off topic now.

your guidance always welcome. i think posting about the community despite requests not to happens because there isn't a thread or forum to discuss administrivia. when people feel something strange or new is happening on the administrative side they are more likely to ask peers what is up rather than email site administrators.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#192
post #151

Earlier quoted context omitted.

I've experienced a couple of really bad downvotes as well lately, and they had definitely no intention of editorial feedback, but it was quite obviously mindless prejudice, almost on the level of /r/politics or /r/worldnews. I wished HN would replace downvotes with a system for short and private annotations, so that people could receive concrete feedback, not something that is vaguely implied by a number. That would…

Even better would be to turn on an option for a user to show/hide political posts from the site all together

That would be nice, but in practice, there's no commonly accepted clear criteria for what is "political" and what is not, and any attempts to enforce some such criteria would likely bring arbitrary and unfair results.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#193

Earlier quoted context omitted.

Also "source code"... This is clearly not source code.

"This is clearly not source code." that's assembler

By saying they've released "source code" they're claiming to have somehow got hold of extra information (i.e. done some old-fashioned journalism and got hold of C code or whatever, containing comments and symbols and human information about intent). In fact they've just downloaded a publicly available binary and disassembled it.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#194
post #171

Earlier quoted context omitted.

Attacking someone who is attacking you is also a form of defense. Please let Sun Tzu know if you have questions. This is very important and not intuitive at all, though I don't particularly care about helping you to understand it better since it's considered common knowledge in the modern era.

I can do this all day: In order to be able to attack somebody who's attacking you, you need exploits available to you. If you have exploits available to you, you're making yourself attackable. Do you really not see the problem here?

I see the problem is in your statement

>If you have exploits available to you, you're making yourself attackable.

Do you?

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#195
post #101

Earlier quoted context omitted.

For some malwares that may be true, but I doubt Regin was that sloppy.

Why not? Stuxnet got into the wild and I wouldn't consider it sloppy at all.

There's a big difference between "got into the wild" and "caused harm to innocent users".

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#196
post #169

Earlier quoted context omitted.

The comment you're complaining about downvotes looks to be at +33 right now. The downvote situation is always in flux, which is one reason why the HN guidelines ask you not to post comments complaining about being downvoted. I'm going to detach this subthread and mark it off topic now.

your guidance always welcome. i think posting about the community despite requests not to happens because there isn't a thread or forum to discuss administrivia. when people feel something strange or new is happening on the administrative side they are more likely to ask peers what is up rather than email site administrators.

I think that's spot on, but also that having a thread or forum to "discuss administrivia" would be worse than the status quo.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#197
post #38

Earlier quoted context omitted.

that link is mostly paywalled. do you have another source?

Search the title. But from old memory: Hilux trucks are built amazingly and have awesome reliability. Real, authentic, Hilux trucks are thus valued by freedom fighters/terrorists in Afghanistan. Canada donated a bunch if real Hilux trucks to Afghanistan, and these vehicles had a Maple Leaf logo. People associated the Maple Leaf with the quality of Hilux, to the point of at least one person getting a Maple Leaf tattoo…

Would be great if HN auto-swapped links to paywalled sites with a link to query on search site instead.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#198
post #196

Earlier quoted context omitted.

your guidance always welcome. i think posting about the community despite requests not to happens because there isn't a thread or forum to discuss administrivia. when people feel something strange or new is happening on the administrative side they are more likely to ask peers what is up rather than email site administrators.

I think that's spot on, but also that having a thread or forum to "discuss administrivia" would be worse than the status quo.

Spoken like a true Stalinist, and so true. It would be complete debauchery. Unless the comments auto-delete after N minutes. This would create a very interesting metric giving insights into psychology at the same time. That is, it would be interesting to explore the relationship between N minutes on downvote thread and number of down vote comments in other threads. With conclusions like "1.2 minutes is just enough downvote-thread time for the individual to feel they released their angst enough while also having a R powered reduction on complaints overall in other threads"

I don't know why HN doesn't do these types of crazy experiments in social/political science. I'd have a heigh day.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#199

Earlier quoted context omitted.

Not disclosing vulnerabilities is not a question of attacking or defending, it's just stupid to keep vulnerabilities open. I also didn't propose to uncompromisingly favor attack capabilities. I still don't think effective cyber defense is possible on a national level without leading the edge on offensive abilities as well.

I really don't want to explain it a third time, so let me just ask you a question instead: How do you lead the edge on offensive abilities without keeping vulnerabilities/bugs secret? Let me rephrase that: How do you lead the edge on offensive abilities without weakening the security of the people who are paying your salary; the very same people you swore an oath to protect? Please explain to me how that is possible…

Remote exploits work surprisingly well on unpatched systems, stupid users, malconfigured hardware/software and if that doesn't work, maybe it's time for a bit of oldfashioned humint.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#200
Right on the GCHQ website it states: "In addition, we are also pleased to announce that GCHQ and MI5 are working with their US partners to further strengthen UK-US collaboration on cyber security ..."

I think it is fair to say they all use the same tools!

Post reply on HN