Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

291–300 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#291
post #185

Earlier quoted context omitted.

> This shows that no agency is immune from leaks That's well known for a long time. During cold war a lot of Russian weapons were based on the US designs. There is a TV series, Americans, which shows how to manipulate people and steal secrets. Even atomic bomb secrets were stolen (by Klaus Fuchs and others). So I guess a lot of people in military complex make a lot of money on these exploits, PRISM and other projects…

If you explicitly ask someone with the form "are there are organizations that are infalliable to leaks?" they're likely to say "no of course not. Humans make errors" But if you phrase it to something like "Can the government be trusted with backdoors to protect us from terrorists and Chinese hackers", then suddenly public sentiment will change dramatically.

To quote Göring,

> Göring: Oh, that is all well and good, but, voice or no voice, the people can always be brought to the bidding of the leaders. That is easy. All you have to do is tell them they are being attacked and denounce the pacifists for lack of patriotism and exposing the country to danger. It works the same way in any country.

Patriotism is both a wonderful and terrible thing, and it is made worse by fearing the "other". Any time people create a boogeyman (China, Mexico, Muslims, what have you), be on the lookout for what the true motivations are.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#292
post #170

Earlier quoted context omitted.

I'm sure this sort of stuff doesn't help with speedy updates. https://arstechnica.com/tech-policy/2017/03/public-universit...

I saw this at work from the inside of a big telco that did this. They replaced one guy who needed only vague instructions to configure complex software replaced by a team of five who needed detailed step-by-step manuals written out by the vendor and still took twice as long and couldn't cope with any hiccups along the way. I do not believe outsourcing saves money. It only does so either by cutting quality of service,…

I've never seen a case where outsourcing of general-purpose IT things saves money over the long-term. It might make the budget look better for a year or two. Which, I think, is the motivation for a lot of the people making decisions to outsource. It is cheaper right now, so who cares about later?

Special-purpose stuff can still be cheaper to outsource, though. If I need something to work next week and it would take my staff a month to get up to speed, I'd spend the money on outsourcing it.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#293

Earlier quoted context omitted.

How could you ever possibly verify that?

By simplifying the design, until your team can verify its security without throwing up their arms in frustration at the mere prospect. When people's lives are on the line, security is more important than features or convenience.

What you're describing is formal verification. While I agree with what you're saying, I'm not sure if you're just understating the the complexity of formally verifying systems or if you're implying that "being really careful and doing your due diligence" is practically invulnerable.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#295

I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.

And it follows that anything that can create such harm CAN and eventually will "leak" or fall into the wrong hands.

Maybe one day, as a species, we'll learn not to create this kind of devices.

(sorry if the message seems too exaggerated)

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#296

Earlier quoted context omitted.

Humor me... if encryption had a backdoor, then ransomware could be effectively mitigated.... Though I'm not a proponent of backdoors by any means, I don't see the logical flaw here.

How would you practically do that? Send all those encrypted hard drives to NSA to be decrypted? Publish the backdoor, effectively rendering that encryption scheme broken?

Just ask the NSA to send you the un-encrypted files - they probably have them in their database anyway.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#298
post #10

One of the side effect if states participate in the proliferation of offensive tools. Won't be the last time state-sponsored tools, exploits or backdoors fall into the hands of interested third parties. I think collateral damage like that is way underrated by politicians all around the globe that call for their respective intelligence agencies to build up offensive capabilities to be able to conduct cyber warfare and…

The vulnerability is already patched, it is not a 0-day. Regardless of the leak, anyone could have reverse engineered the security patch to see how it worked.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#299
post #280

Earlier quoted context omitted.

Good time to remind folks that gmail, facebook, whatsapp, amazon etc aren't going to be able to protect their data forever at the levels they currently are capable off. A couple of bad business decisions and they are where yahoo is today. So be smart about how you use these services and educate the non-technical folks around you.

What would 'being smart' about using these services mean? It is pretty difficult to get through life in the modern age without using email for sensitive documents (or at least without using ACCESS to your email as a way to gain access to sensitive services, eg password reset emails, proof of ownership, etc) Since email in the modern world has this type of importance, what should I do? If you say gmail can't protect t…

I would say that it's probably smart to occasionally purge all your content from online services and keep your data in cold storage you physically control.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#300
post #185

I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.

> This shows that no agency is immune from leaks That's well known for a long time. During cold war a lot of Russian weapons were based on the US designs. There is a TV series, Americans, which shows how to manipulate people and steal secrets. Even atomic bomb secrets were stolen (by Klaus Fuchs and others). So I guess a lot of people in military complex make a lot of money on these exploits, PRISM and other projects…

[deleted]
Post reply on HN