Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

311–320 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#311

Earlier quoted context omitted.

What would 'being smart' about using these services mean? It is pretty difficult to get through life in the modern age without using email for sensitive documents (or at least without using ACCESS to your email as a way to gain access to sensitive services, eg password reset emails, proof of ownership, etc) Since email in the modern world has this type of importance, what should I do? If you say gmail can't protect t…

I would say that it's probably smart to occasionally purge all your content from online services and keep your data in cold storage you physically control.

There is quite a large cost to that, though. Being able to search through old emails is a lifesaver. I can't count how many times I have searched through email to find some account info I set up years ago, or to get date information about when something happened. Just today, I searched my email for my old FastTrak account info, and found it on an email from 5 years ago.

Deleting all my email would be a big cost to pay for a gain that I can't exactly quantify; I would have to figure out the likelihood of my data being leaked over time and the cost to me if the data was leaked. That isn't readily obvious what the risk factor is for me, but I KNOW the cost factor.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#312
post #280

Earlier quoted context omitted.

Good time to remind folks that gmail, facebook, whatsapp, amazon etc aren't going to be able to protect their data forever at the levels they currently are capable off. A couple of bad business decisions and they are where yahoo is today. So be smart about how you use these services and educate the non-technical folks around you.

What would 'being smart' about using these services mean? It is pretty difficult to get through life in the modern age without using email for sensitive documents (or at least without using ACCESS to your email as a way to gain access to sensitive services, eg password reset emails, proof of ownership, etc) Since email in the modern world has this type of importance, what should I do? If you say gmail can't protect t…

Did I say stop using them?

Distribute risk. Use multiple accounts. Don't handle all work/financial stuff on a single account. Keep work and personal accounts separate. Reduce the number of hours you spend online being a data milch cow for these corps. This automatically reduces dependence. Don't allow messenger chat transcript backups to happen by just uninstalling the app every other night. Don't restore any saved transcripts on disk on reinstall.

I could go on and on but basic rule is use your imagination. Don't use these tools the way they want you to use them. Use them as you would use a tool in a workshed as an aid, not as a drug you are dependent on.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#313

Edit: Botnet stats and spread (switch to 24H to see full picture): https://intel.malwaretech.com/botnet/wcrypt Live map: https://intel.malwaretech.com/WannaCrypt.html Relevant MS security bulletin: https://technet.microsoft.com/en-us/library/security/ms17-01... Edit: Analysis from Kaspersky Lab: https://securelist.com/blog/incidents/78351/wannacry-ransomw...

Great info. So, for the layman. How vulnerable are users behind a firewall or broadband router?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#314
post #194
post #162

Earlier quoted context omitted.

also that it is very unethical for the US government to find some vulnerability in android/windows/whatever and not report it

Is it particularly unethical? Many governments around the world are discovering 0-days in commonly deployed products and not revealing that to the vendor, but instead using it as a weapon for navigating computer networks. Revealing the vulnerability would place the US Govt at a distinct disadvantage.

the entirety of your argument seems to be "it's not unethical because other countries do it", which is not compelling when you consider other forms of unethical behavior using this defense.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#315
> The attacks were reminiscent of the hack that took down dozens of websites last October, including Twitter, Spotify and PayPal, via devices connected to the internet, including printers and baby monitors.

Lazy writing at NYTimes; what on earth does this attack have to do with the one at hand? It's not broadly the same type of attack, nor the same scale, nor the same outcome.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#316
post #78
post #34

Earlier quoted context omitted.

In defense of these medical devices, that is actually a FDA requirement. The entire combination of the system is certified to work, and even one patch for a security vulnerability leaves open the possibility that the patch breaks something and people die! Of course it goes without saying that you need to ensure that a virus cannot run on this machine by some other means. If these machines can get infected they automa…

This 100x. I know it's extremely easy to Monday morning quarterback hospital IT but it's not as simple as people think. There's legal and, far more importantly, medical implications to updating software at a hospital. Oh you think it's ridiculous we use i.e. 7 in compatibility mode? It's because our mission critical emr only works in that (well it really works in everything but it's certified in 7) and if we use anyt…

I'm curious, not trying to be smart: 1. Would running Windows 7 in a VM violate the certified software load? 2. Is new device software being written to run in containers/hypervisor level?

I could understand if 1 would be a violation, but perhaps, after today, the FDA could fast track manufacturer patches to run software loads on VMs?

I don't imagine 2 would solve current infrastructure issues any time soon given the size of investments in current equipment, but could it be a best practice going forward?

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#317

Earlier quoted context omitted.

They'll probably be tumbled (i.e Bitcoin laundering), meaning that we'll get no info from the transactions at all.

I haven't looked into tumbling recently, whats the volume look like these days? So far the attack has yielded less than 5 btc, I'd guess that amount can be laundered safely. Whats the current limit?

You don't have to worry about tumbling anymore.

You can use XMR.to, Shapeshift.io, or Changelly.com over TOR to move funds directly into another another blockchain currency. So have fun following things around Bitcoin blockchain like some high tech sleuth, but thats a wild goose chase.

I buy all my cryptocurrencies through those kind of services nowadays, because there's no risk or temptation to keep coins on custodial exchanges, instead of in a private wallet. As well as no worries about withdrawal limits (although shapeshift has fairly low per transaction limits, just make an additional transaction)

For unlinking the transaction, the only currency you want to cross-chain into is Monero. With its Ring Signatures and Stealth Addresses it is a private blockchain by default (in comparison with some other cryptocurrencies that have a secondary optional privacy feature like Zcash/Shadowcash/Dash).

I'm actually surprised that the ransomware isn't taking Monero directly yet as some exchanges have direct Monero/USD markets already.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#318

Earlier quoted context omitted.

If you explicitly ask someone with the form "are there are organizations that are infalliable to leaks?" they're likely to say "no of course not. Humans make errors" But if you phrase it to something like "Can the government be trusted with backdoors to protect us from terrorists and Chinese hackers", then suddenly public sentiment will change dramatically.

To quote Göring, > Göring: Oh, that is all well and good, but, voice or no voice, the people can always be brought to the bidding of the leaders. That is easy. All you have to do is tell them they are being attacked and denounce the pacifists for lack of patriotism and exposing the country to danger. It works the same way in any country. Patriotism is both a wonderful and terrible thing, and it is made worse by feari…

I'm yet to see anything positive from patriotism. It's a form of outdated tribalism. Even the idea of a nation-state isn't that old - this all started with the Napoleonic Wars.

Patriotism always leads to "us" vs "them", it seems.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#319
post #185

I think this is an excellent example that we can all reference the next time someone says that governments should be allowed to have backdoors to encryption etc. This shows that no agency is immune from leaks and when these tools fall into the wrong hands the results are truly catastrophic.

> This shows that no agency is immune from leaks That's well known for a long time. During cold war a lot of Russian weapons were based on the US designs. There is a TV series, Americans, which shows how to manipulate people and steal secrets. Even atomic bomb secrets were stolen (by Klaus Fuchs and others). So I guess a lot of people in military complex make a lot of money on these exploits, PRISM and other projects…

> There is a TV series, Americans, which shows how to manipulate people and steal secrets.

Extremely high production values, but 99% historically inaccurate. I see it as the fantasy of a CIA officer who invented super-spies (that were at the same time sleepers and incredibly active) just to justify the US failures during the Cold War.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#320
post #65

So... I'm running Linux on all my systems, how bad will it be for me?

My university sent around an email with a photo of GRUB displaying some ransomware message with a demand 222 bitcoins. Sure freaked me out, as a linux user who usually gets to ignore emails like this, but upon investigation it was unrelated [1] to today's events. The screenshot was of ransomware that while still terrifying, existed before today.

[1] https://www.welivesecurity.com/2017/01/05/killdisk-now-targe...

Post reply on HN