Live data from Hacker News

How the NSA Plans to Infect “Millions” of Computers with Malware

firstlook.org

21–30 of 182 posts

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#23
> GCHQ cooperated with the hacking attacks despite having reservations about their legality. One of the Snowden files, previously disclosed by Swedish broadcaster SVT, revealed that as recently as April 2013, GCHQ was apparently reluctant to get involved in deploying the QUANTUM malware due to “legal/policy restrictions.” A representative from a unit of the British surveillance agency, meeting with an obscure telecommunications standards committee in 2010, separately voiced concerns that performing “active” hacking attacks for surveillance “may be illegal” under British law.

Wow, finally a limit on what GCHQ thinks that they are allowed to do! Now can the NSA be prosecuted for these actions when done in the UK? #notgonnahappen

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#24
post #20

Earlier quoted context omitted.

Revolution is a tool of limited usefulness, and violent ones very often put something back in that is just as bad as what they ejected (see also: the KGB).

It's more complicated than that. ----->[ good times ]---->[ hard times ] ---> [fascism] --\ ^ | \-------------------[revolution] Revolution merely starts the cycle again. We'll always end up with the KGB, Stasi, NSA, GCHQ, CIA etc so you have to deconstruct society regularly to flush it out. We're stuck in a pretty long loop at the moment just verging on hard times. Edit: the "good times" above is optional.

Luckily, our founding fathers built in a way to achieve the same effects as a revolution without any violence.

If you were to start an armed insurrection, the government would be totally justified in ending you. Not a smart decision given today's level of technology. It was through sheer luck that the American revolution worked at all: the British commanders were so incredibly incompetent that they checkmated themselves.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#25
post #20

Earlier quoted context omitted.

Revolution is a tool of limited usefulness, and violent ones very often put something back in that is just as bad as what they ejected (see also: the KGB).

It's more complicated than that. ----->[ good times ]---->[ hard times ] ---> [fascism] --\ ^ | \-------------------[revolution] Revolution merely starts the cycle again. We'll always end up with the KGB, Stasi, NSA, GCHQ, CIA etc so you have to deconstruct society regularly to flush it out. We're stuck in a pretty long loop at the moment just verging on hard times. Edit: the "good times" above is optional.

It should also be noted that revolution sucks majorly.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#26
post #20

Earlier quoted context omitted.

It's more complicated than that. ----->[ good times ]---->[ hard times ] ---> [fascism] --\ ^ | \-------------------[revolution] Revolution merely starts the cycle again. We'll always end up with the KGB, Stasi, NSA, GCHQ, CIA etc so you have to deconstruct society regularly to flush it out. We're stuck in a pretty long loop at the moment just verging on hard times. Edit: the "good times" above is optional.

Luckily, our founding fathers built in a way to achieve the same effects as a revolution without any violence. If you were to start an armed insurrection, the government would be totally justified in ending you. Not a smart decision given today's level of technology. It was through sheer luck that the American revolution worked at all: the British commanders were so incredibly incompetent that they checkmated themsel…

Actually its been remarkably effective in other countries, have you been reading the news? Our own soldiers have not been terribly effective at pacifying unrest, and the locals have nothing but rifles etc.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#27
post #20

Earlier quoted context omitted.

It's more complicated than that. ----->[ good times ]---->[ hard times ] ---> [fascism] --\ ^ | \-------------------[revolution] Revolution merely starts the cycle again. We'll always end up with the KGB, Stasi, NSA, GCHQ, CIA etc so you have to deconstruct society regularly to flush it out. We're stuck in a pretty long loop at the moment just verging on hard times. Edit: the "good times" above is optional.

Luckily, our founding fathers built in a way to achieve the same effects as a revolution without any violence. If you were to start an armed insurrection, the government would be totally justified in ending you. Not a smart decision given today's level of technology. It was through sheer luck that the American revolution worked at all: the British commanders were so incredibly incompetent that they checkmated themsel…

Firstly, your "founding fathers" - ha now there's a joke. Do you think anyone respects those amendments? Nope. If they thought that, you wouldn't be stocked up with weapons.

And we all know how effective that technology is at ending all those pesky terrorists with their zip guns and IEDs...

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#28

Remember, Microsoft is part of this plot, even if they have "plausible deniability". Microsoft is giving NSA access to lists of vulnerabilities Windows has many months before Microsoft even begins to work on a fix. They are in effect helping NSA break into many computers, even if they are up to date. http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t... Every single one of these vulnerabilities could be see…

No. None of this is accurate.

Microsoft gets information about vulnerabilities from the same sources as everyone else. They outspend every other software vendor by something like 4:1 on outside software security consultants. If they are in a privileged position regarding WinAPI software vulnerabilities at all, it is a marginally privileged position. No security person working at Microsoft would tell you they were confident that outsiders weren't holding severe, exploitable vulnerabilities back.

NSA, meanwhile, is as competent at sourcing vulnerabilities as any organization on the planet. They have internal research teams that generate them that are presumably competitive with any private research team, and they apparently purchase vulnerabilities like everyone else --- not from Microsoft, but from research teams that sell vulnerabilities.

Microsoft gives pre-release information about vulnerabilities to lots of different organizations; for instance, the IDS and network security vendors get pre-release info to create signatures. This program is, IIRC, over a decade old.

NSA is a dual-role organization; it also houses the USG's center for defensive technology expertise. It is the opposite of surprising that NSA would have the same relationship with Microsoft as, say, Symantec would.

Finally, CISPA does nothing resembling what you claimed it does. CISPA is opt-in; it cannot be used to force a company to disclose anything. CISPA is about incident data, not vulnerabilities. It is already lawful to share vulnerability information with the government. The gray area in data sharing is non- anonymized incident data, which can be covered by any of 10+ different regulations that make even IP-level metadata risky to share for collaborative defense.

CISPA is an extraordinarily short bill; you can simply read it instead of taking my word for it.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#29
post #7

Remember, Microsoft is part of this plot, even if they have "plausible deniability". Microsoft is giving NSA access to lists of vulnerabilities Windows has many months before Microsoft even begins to work on a fix. They are in effect helping NSA break into many computers, even if they are up to date. http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t... Every single one of these vulnerabilities could be see…

This. Very frustrating as I work with a Microsoft-oriented company at the moment. Any mention of this to their architectural team results in nothing short of "mwuhahaha you're talking shit". There is some weird universal trust there that really makes no sense at all. To add insult to injury they don't log, don't have an IDS and don't have a clue stick to hit themselves with. Their funeral!

As if having an IDS would make a difference.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#30

Earlier quoted context omitted.

Luckily, our founding fathers built in a way to achieve the same effects as a revolution without any violence. If you were to start an armed insurrection, the government would be totally justified in ending you. Not a smart decision given today's level of technology. It was through sheer luck that the American revolution worked at all: the British commanders were so incredibly incompetent that they checkmated themsel…

Actually its been remarkably effective in other countries, have you been reading the news? Our own soldiers have not been terribly effective at pacifying unrest, and the locals have nothing but rifles etc.

It's kind of interesting to think about. Remember the hullabaloo just after the Boston bomber lit off the bomb but wasn't caught yet? Imagine all of that societal rage focused on a small group of people who have started an armed conflict and killed a few policemen, and you can imagine how quickly that group will be annihilated.
Post reply on HN