Live data from Hacker News

Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

nytimes.com

111–116 of 116 posts

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#111
post #4

This is merely a taste of what is to come. When President Obama stated in December[0] that we will deliver a "proportional response" to Russian hacking at the "time and place of our own choosing", it seemed that most of the country was proud, almost gleeful at the thought that we would be striking back. I for one was mortified. We should not be escalating cyberwar, even if we do have proof of who attacked us. People…

Man's way to peace is by having a bigger gun than his neighbor.

That's obscenely naive.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#112

Earlier quoted context omitted.

The primary way for the NSA to be a defensive organization would be for it to very publicly take a lead in closing up the holes they find on a structural level. Whether the NSA hoards zero-day exploits or not isn't the big issue since someone will be doing that. The issue is they should be sounding the alarm on whatever broad class of system vulnerabilities they find. They should be evangelizing against remotely upda…

> The issue is they should be sounding the alarm on whatever broad class of system vulnerabilities they find. Sounds like the IAD mission. Examples: - https://github.com/iadgov/Pass-the-Hash-Guidance/blob/master... - https://www.iad.gov/iad/library/reports/nsa-methodology-for-... I mention that first one especially because Pas-The-Hash was a major reason the most recent ransomware outbreak was able to get onto alread…

My gawd, Firefox is telling the iad's security certificate is broken. Now if there was ever a sign the world is going to heck, that would be it.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#113

Earlier quoted context omitted.

> The issue is they should be sounding the alarm on whatever broad class of system vulnerabilities they find. Sounds like the IAD mission. Examples: - https://github.com/iadgov/Pass-the-Hash-Guidance/blob/master... - https://www.iad.gov/iad/library/reports/nsa-methodology-for-... I mention that first one especially because Pas-The-Hash was a major reason the most recent ransomware outbreak was able to get onto alread…

My gawd, Firefox is telling the iad's security certificate is broken. Now if there was ever a sign the world is going to heck, that would be it.

on this page they try to explain:

https://www.nsa.gov/what-we-do/information-assurance/

> Note: The IAD.Gov website uses TLS 1.2, supported by a Department of Defense (DoD) PKI certificate, to ensure confidentiality and integrity for all users. IAD.Gov website users will need to have the current DoD Root and Intermediate Certificate Authorities (CA) loaded into their browsers to avoid receiving untrusted website notifications.

I mean it still doesn't make sense ... Where it says "for all users" it should say "for those who have this certificate installed" because that's what the warning is about. And "to avoid receiving untrusted website notifications" should read "for a more secure connection" because, you know, what's the goal here, really? :)

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#114

Earlier quoted context omitted.

Oh what a world we live in where cyberwarfare could result in death. I would have never thought, as a kid, that life (and death) would end up this "real".

The hacker Karl Koch [1] thought being responsible for the disaster at Chernobyl [2] back in 1986 causing 2M deaths in the last 30 years. I think we will never know whether he was right or not. [1] https://en.wikipedia.org/wiki/Karl_Koch_(hacker) [2] (German) https://de.wikipedia.org/wiki/KGB-Hack

> The hacker Karl Koch [1] thought being responsible for the disaster at Chernobyl [2] back in 1986 causing 2M deaths in the last 30 years.

I don't think that's right, the German wikipedia article says:

> Im April 1986 kam es zur Katastrophe von Tschernobyl. Karl Koch, zu diesem Zeitpunkt schon lange schwer drogenabhängig und in einem oft zweifelhaften geistigen Zustand, sah dies als unmittelbare Folge eines seiner Hacks an, da er kurz vorher in den Rechner eines Atomkraftwerks eingedrungen war.

Unless my understanding of German is flawed, what I'm reading is that it was Koch's drug-fueled paranoia that made him believe he was responsible for the Chernobyl disaster because he had recently hacked into a computer in a nuclear power station. It doesn't say whether this computer even was in Chernobyl, maybe he didn't know exactly where the computer on the other end was, or maybe it was more paranoia. He was, after all, in a pretty bad state near the end of his "career".

It's such a fascinating and sad story, this guy. I've watched the film "23 nichts ist wie es scheint" (initially because of the RAW/Discordia/Illuminatus Trilogy references) a long time ago, but I don't remember anything about Chernobyl in that film (but it was a long time ago).

There was another film, a US movie IIRC, that tells his story from the side of an FBI or CIA (or some agency) agent chasing him. I forget the title, anyone know?

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#115

Earlier quoted context omitted.

I can name at least one netsec guy who attributes his entire team's existence to the NSA calling his employer and doing exactly that.

Sounds like that netsec guy's team serves military customers then?

No, they do design work for consumer products.

But good job reading my prior comments :)

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#116

Earlier quoted context omitted.

Sounds like that netsec guy's team serves military customers then?

No, they do design work for consumer products. But good job reading my prior comments :)

What type of consumer products? And I'm not sure what comments you're referring to.
Post reply on HN