Live data from Hacker News

South Korea military cyber command was hacked

english.yonhapnews.co.kr

31–40 of 64 posts

Re: South Korea military cyber command was hacked

#31

I wonder if it is time for a reboot. If the castles we have built so far turn out to be made of gauze instead of stone, maybe we need to rethink it all, in the same way we need to rethink energy policy Every Intel motherboard since 2008 has had a "spy" on board, almost every home router is working for someone's botnet and will never be patched, medical devices and factory automation systems ship with default password…

RiscV, TCP+crypto offload, hardware switchports with luajit or nf rules. Reactive UI with hardware rendering and compositing.

Hardware keystore with physical switch to generate and enroll keys, user/owner controlled secrets, one-time programmable as an option, hardwired SAK and OS personality switching key.

Real-time security isolation kernel, hardware-enforced containerization with MMU-protected GPU passthrough.

Re: South Korea military cyber command was hacked

#32
post #31

I wonder if it is time for a reboot. If the castles we have built so far turn out to be made of gauze instead of stone, maybe we need to rethink it all, in the same way we need to rethink energy policy Every Intel motherboard since 2008 has had a "spy" on board, almost every home router is working for someone's botnet and will never be patched, medical devices and factory automation systems ship with default password…

RiscV, TCP+crypto offload, hardware switchports with luajit or nf rules. Reactive UI with hardware rendering and compositing. Hardware keystore with physical switch to generate and enroll keys, user/owner controlled secrets, one-time programmable as an option, hardwired SAK and OS personality switching key. Real-time security isolation kernel, hardware-enforced containerization with MMU-protected GPU passthrough.

It will take a while to google-walk through all that, but thank you. Do you feel this is a comprehensive recipie to move to a (enterprise wide) computing platform where the attacker has the paying field tipped against them (it seems the other way round today)

Re: South Korea military cyber command was hacked

#33
post #20

No one will be safe until governments stop hoarding 0-days. Until we all realize we live in a glass house, the hacks will continue. The best solution is to split the NSA and similar agencies into two. One for developing new tools that produces safer code and finding flaws and reporting them to companies so they get patched. The second for offense.

[deleted]

Re: South Korea military cyber command was hacked

#34
post #20

No one will be safe until governments stop hoarding 0-days. Until we all realize we live in a glass house, the hacks will continue. The best solution is to split the NSA and similar agencies into two. One for developing new tools that produces safer code and finding flaws and reporting them to companies so they get patched. The second for offense.

We don't make every building a blast shelter and everyone wear body armor. People who walk through the steps of attacking the US physically are going to succeed.

Our security strategy is to:

A) surveil, infiltrate, and block conspiracies to do so before they happen, and

B) identify, track, and punish our attackers after the fact.

I don't think (and "cyber" policy makers don't seem to think) that making every piece of software free of vulnerabilities is realistic. Sabotaging hacking groups, and building sufficiently scary capabilities for retaliation against nation-states that might attack us, seems much more attainable.

Re: South Korea military cyber command was hacked

#35
post #31

Earlier quoted context omitted.

RiscV, TCP+crypto offload, hardware switchports with luajit or nf rules. Reactive UI with hardware rendering and compositing. Hardware keystore with physical switch to generate and enroll keys, user/owner controlled secrets, one-time programmable as an option, hardwired SAK and OS personality switching key. Real-time security isolation kernel, hardware-enforced containerization with MMU-protected GPU passthrough.

It will take a while to google-walk through all that, but thank you. Do you feel this is a comprehensive recipie to move to a (enterprise wide) computing platform where the attacker has the paying field tipped against them (it seems the other way round today)

It doesn't sound comprehensive enough to me, though better than what's around. My own comprehensive recipe is simply "put nickpsecurity in charge". :)

Re: South Korea military cyber command was hacked

#36
post #20

No one will be safe until governments stop hoarding 0-days. Until we all realize we live in a glass house, the hacks will continue. The best solution is to split the NSA and similar agencies into two. One for developing new tools that produces safer code and finding flaws and reporting them to companies so they get patched. The second for offense.

We don't make every building a blast shelter and everyone wear body armor. People who walk through the steps of attacking the US physically are going to succeed. Our security strategy is to: A) surveil, infiltrate, and block conspiracies to do so before they happen, and B) identify, track, and punish our attackers after the fact. I don't think (and "cyber" policy makers don't seem to think) that making every piece of…

[deleted]

Re: South Korea military cyber command was hacked

#37
post #22

Earlier quoted context omitted.

As much as the US Media wants to you think North Korea is cut off from the rest of the world, it's not. They have a space program and nuclear program, which is more than what a lot of other countries can say. It's not a bunch of people living under thatch houses. If the government wants to make strides in something, they will. They can send their students overseas and get their education there. They can collaborate w…

As much as the US Media wants to you think North Korea is cut off from the rest of the world, it's not. The US media doesn't say that. The average N. Korean is very much cut off from the rest of the world....somewhat changing with smuggled in phone and DVDs, but still.

> The average N. Korean is very much cut off from the rest of the world.

We aren't talking about the average N. Korean. Their best and brightest are sent offshore to study in STEM fields (with their family held hostage against their eventual return of course).

Re: South Korea military cyber command was hacked

#38
post #20

No one will be safe until governments stop hoarding 0-days. Until we all realize we live in a glass house, the hacks will continue. The best solution is to split the NSA and similar agencies into two. One for developing new tools that produces safer code and finding flaws and reporting them to companies so they get patched. The second for offense.

Why do you think it matters if NSA stops hoarding 0-days? Let's put that into perspective - iPhone jailbreaking community hacks every new release in days/weeks. And that's just a few people doing it for fun and not getting paid. Companies like Cellebrite have more people paid good money to do the same thing, so they're likely to have an even bigger stash of working exploits. And that's for a locked down device which has all the incentives of being a closed platform.

There's nothing special about NSA or 0-days here. We're using very generic platforms. Lots of organisations have exploits. We're still in a situation where you can point a fuzzer for a few hours at any popular app and get yourself a new 0-day. The only thing that will help you is getting rid of the possibility of exploitation, and limiting the scope when it happens.

Re: South Korea military cyber command was hacked

#39
post #20

No one will be safe until governments stop hoarding 0-days. Until we all realize we live in a glass house, the hacks will continue. The best solution is to split the NSA and similar agencies into two. One for developing new tools that produces safer code and finding flaws and reporting them to companies so they get patched. The second for offense.

So you would like the federal government to effectively subsidize large technology companies by providing free QA for commercial products?

Re: South Korea military cyber command was hacked

#40
post #11

>speculation that North Korea might be behind the latest cyber attack Does North have hackers skilled enough to perform such (or any) attacks? How did they acquire their skills given the internet is forbidden there?

I seem to recall that the Sony hack was attributed to North Korean hackers and while many people laughed it off, serious investigations pointed that it was really the case. (Just on top of my head, I'll let you dig for sources.)

serious analysis pointed to iran (malware shared traits with that used in saudi aramco hack a year or two prior), probably because nk and iran have some kind of offensive sharing arrangement on cyber, but the nuclear deal was in the works and the last thing the obama admin wanted to deal with was a perceived provocation.
Post reply on HN