Live data from Hacker News

Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475

cisa.gov

21–24 of 24 posts

Re: Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475

#21
post #18
post #3

It'd be useful if someone at State could inform CISA of the meaning of the term "nation-state", unless CISA is very subtly trying to signal which particular countries these attacks are coming from, since nation-states are a small subset of all countries.

Nation-state actors are just illegal criminal organizations, authorities, backed by governments. Above the law, with large budgets.

Uhh, I think you mean legal criminal organizations. Which, you believe should be illegal.

I mean, maybe you meant illegal, in the sense that they are not always in clear legal status (e.g, NSA doing illegal things), but I think for the reader "legal criminal organizations" makes more sense to the point.

Another way to write it maybe would be "sanctioned criminal organizations" but that would be confusing with the secondary meaning of sanctioned. Oh language :(

Re: Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475

#22

Can someone enlighten me why they write the IP adresses with brackets surrounding the last dot? 0.0.0[.]0 instead of 0.0.0.0

It's common in security to 'defang' strings that may be interpreted as URLs to prevent accidental visits.

Re: Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475

#23
post #22

Can someone enlighten me why they write the IP adresses with brackets surrounding the last dot? 0.0.0[.]0 instead of 0.0.0.0

It's common in security to 'defang' strings that may be interpreted as URLs to prevent accidental visits.

Thanks!

Re: Multiple Nation-State Threat Actors Exploit CVE-2022-47966 and CVE-2022-42475

#24
post #11

Earlier quoted context omitted.

Whatever else is going on with terms like "nation-state", there's some creepy politics behind the notion that countries are generally nations. I'm fine with the idea that "nation-states" don't generally exist. The word "state" in "state-level actor" is unambiguous.

Honestly, with or without “nation-”, “state-level actor” is a useless phrase, because (other than juridically ), “state” isn't a level of an actor (particularly, it isn’t a capability level.) If you mean a “major regional power”-level actor, or a “global superpower”-level actor, then say that, but a category that includes both the United States of America and Tuvalu isn't communicating a coherent capability level in…

>“state-level actor” is a useless phrase

I disagree.

Google can probably outspend the Israeli government, but the Israeli government has capabilities Google will never acquire because Google's control over its employees is limited (mainly to contract law). Google cannot sentence an employee to decades in prison for betraying Google's secrets.

So for example, it turns out that 1 or 2 of the employees of the Manhattan Project betrayed the project by giving nuclear secrets to the Soviet Union, but at least the US government had a realistic chance of keeping secrets there whereas a private corporation embarking on a project of similar scale (i.e., a similar number of employees with similar levels of knowledge and skill) has no realistic hope of doing so.

I think this argument is relevant to computer security because having an exploit is almost completely useless if the entity you hope to use the exploit against knows you have the exploit.

Post reply on HN