Live data from Hacker News

U.S. firm helped the spyware industry build a digital weapon for sale overseas

washingtonpost.com

11–19 of 19 posts

Re: U.S. firm helped the spyware industry build a digital weapon for sale overseas

#12
post #7

76 points and no comments? What I came here to ask is, what is the Youtube vulnerability?

What I came here to ask is, what is the Youtube vulnerability? "The user sees the “cute animal videos” he expects, according to Citizen Lab, but the malicious code exploits a flaw in Adobe’s Flash video player to take control of the computer."

Man, I skimmed that way too fast. Basically just MITM for non-SSL connections.

Re: U.S. firm helped the spyware industry build a digital weapon for sale overseas

#14
Well this certainly sheds some light on Google's decision to try to force SSL encryption by factoring that into their page ranking algorithm(s). Among the speculation was the idea that it was a way of flipping off the NSA, and like-agencies, by making their job harder by encouraging others to encrypt their traffic. In my opinion, this speculation now has more sturdy ground to stand on.

It's a shame that we're reduced to posting our outrage on the internet and left with no real actionable moves on the issue. We can fight it by working towards encrypting our data/traffic, but we can't force a public conversation on the issue that would result in stopping the all-out effort to collect an analyze the actual data. We'll forever be in a cat-and-mouse game over the issue. With the people involved in this having a significant leg up over the global community and always being one step ahead.

I get that this sort of thing can, and likely is, used to protect the general public from nefarious actors. What's a shame is that at this point we assume it's also used against the general public, an assumption that comes with good reason.

Re: U.S. firm helped the spyware industry build a digital weapon for sale overseas

#16
post #10

So, does anyone have any inside knowledge (or good references) to what Google ended up doing when they recently started switching their networks to use encrypted transports? Do they run over ip4 or ip6, and are they using traditional vpn or ipsec? I've previously been rather sceptical to the "new improved support for encryption and authentication" ipv6 brings -- I mean we're already late rolling out ipv6 -- is compli…

I think advocating ipv6 is a good idea in general. IPSec was originally developed as part of the ipv6 stack. It's theoretically built in, and should be used whenever possible.

http://en.wikipedia.org/wiki/IPv6#Network-layer_security

Re: U.S. firm helped the spyware industry build a digital weapon for sale overseas

#17
post #3

Earlier quoted context omitted.

> 76 points and no comments? This could very well be the effect of the recent proof that everybody is effectively under surveillance now (it's called "the Chilling Effect").

I dunno, there's been much more controversial and 'risky' subjects with plenty of comments. At least to my mind. I mean, people haven't been exactly signing the praises of the NSA, have they?

It's probably because they've been signing NDAs

Re: U.S. firm helped the spyware industry build a digital weapon for sale overseas

#18

Earlier quoted context omitted.

> 76 points and no comments? Water is wet. There's just not much to comment on.

Yes. Don't use Flash or Java in your browser.

I'd expand that to include any third party plugin that executes live code. Flash and Java are just the two with the greatest penetration and the worst security records.
Post reply on HN