Live data from Hacker News

How the U.S. Hacked ISIS

npr.org

11–20 of 56 posts

Re: How the U.S. Hacked ISIS

#12
post #6

Earlier quoted context omitted.

> I wish articles like this would divulge some details of the technical side of hacking, rather than keep it a mystical field of study. Why would you publicly inform your enemy of a vulnerability?

I listened to the report on this article on my way to work. I had the exact same thought as you. I was annoyed that they kept it so general, but it makes sense from the perspective of keeping the target in the dark on the methods used.

I will add, I've undergone various security-focused corporate trainings over the years, once our trainer was a retired Airman, formerly attached to the NSA.

Had had one and exactly one story he was allowed to share with us, and that was incredibly vague like the article. "We infected the target's mother's PC, when the target was fixing the machine we had an asset fake a crisis prompting the target to (stupidly) access a target machine from the mother's infected PC." As he explained, this was all he was authorized to share. The reality is there is very little they can share without prior clearance from the agency, and this is a non-trivial process.

Re: How the U.S. Hacked ISIS

#13

Like others, I'm also left wondering what methods the US is really using. Obviously, it's too soon to disclose all the details. But compare this (where the few strategies disclosed involve methods like "guess the answer to a security question") to something where we do know the details. For example, the Stuxnet worm used multiple OS zero days and involved hacking or otherwise exfiltrating signing keys from multiple o…

I'm pretty sure that's a given and I think its pretty expected their not going to put details on some news article

Re: How the U.S. Hacked ISIS

#14

I wish articles like this would divulge some details of the technical side of hacking, rather than keep it a mystical field of study. What did they hack and how did they “get in”? Contrary to the title, there is little “how” and mostly “what”.

Funny, I had the exact opposite reaction. Part of me wishes we divulged less about our tactics.

Our? Were you involved in the operation?

Re: How the U.S. Hacked ISIS

#16

I would hope that a country with the largest military industrial complex in the world can hack a group of camel herders in a desert. Doesn't seem particularly impressive

Also since they supplied equipment to them it would not have been as difficult to trojan it.

Re: How the U.S. Hacked ISIS

#18

I wish articles like this would divulge some details of the technical side of hacking, rather than keep it a mystical field of study. What did they hack and how did they “get in”? Contrary to the title, there is little “how” and mostly “what”.

Funny, I had the exact opposite reaction. Part of me wishes we divulged less about our tactics.

Assuming you're an American, you eventually have a civic duty to find out what they did so you can evaluate them. You can't wait forever, because once everyone involved has moved on far enough with their careers (or retired) it won't be possible for your evaluation to have any impact. Declassification has to happen at a reasonable speed in order for our system to work.

Although I don't know, I think this story was released for exactly that purpose, to improve public support for the NSA and Cyber Command. With Snowden being in the news lately I'm sure they're looking for opportunities to run cool war stories to balance out their image.

Post reply on HN