Live data from Hacker News

South Korea military cyber command was hacked

english.yonhapnews.co.kr

41–50 of 64 posts

Re: South Korea military cyber command was hacked

#42
post #35

Earlier quoted context omitted.

It will take a while to google-walk through all that, but thank you. Do you feel this is a comprehensive recipie to move to a (enterprise wide) computing platform where the attacker has the paying field tipped against them (it seems the other way round today)

It doesn't sound comprehensive enough to me, though better than what's around. My own comprehensive recipe is simply "put nickpsecurity in charge". :)

I was thinking the same thing. What I was describing is about using the disadvantages of a platform like RiscV yo our advantage. Rather than running network stacks, compositing and other things on the main processor which will likely trail intel processors in performance for a time, we design the hardware to do what hardware does best.

Re: South Korea military cyber command was hacked

#43
post #20

No one will be safe until governments stop hoarding 0-days. Until we all realize we live in a glass house, the hacks will continue. The best solution is to split the NSA and similar agencies into two. One for developing new tools that produces safer code and finding flaws and reporting them to companies so they get patched. The second for offense.

The NSA is already partly split like this. There are parts that work to improve security.

Re: South Korea military cyber command was hacked

#44
post #26
post #21

Earlier quoted context omitted.

I'm not sure how splitting up the NSA fixes anything. Wouldn't the new offensive organization still be compelled to seek out zero-day exploits as well for their mission? What happens when they find one that the defensive organization hasn't found yet?

Better than the current setup. The defensive side sole responsibility is to find critical flaws and report them. This would also include investigating breaches in US infra and making sure things get patched. Right now, you don't even have the defensive side.

[deleted]

Re: South Korea military cyber command was hacked

#45
post #20

No one will be safe until governments stop hoarding 0-days. Until we all realize we live in a glass house, the hacks will continue. The best solution is to split the NSA and similar agencies into two. One for developing new tools that produces safer code and finding flaws and reporting them to companies so they get patched. The second for offense.

Why do you think it matters if NSA stops hoarding 0-days? Let's put that into perspective - iPhone jailbreaking community hacks every new release in days/weeks. And that's just a few people doing it for fun and not getting paid. Companies like Cellebrite have more people paid good money to do the same thing, so they're likely to have an even bigger stash of working exploits. And that's for a locked down device which…

It is special because it is government. We have tax payer money going to support thousands of people finding 0-days. What I am proposing is to move some of those funds to be defensive and since it is government, the intention and motivation is to make more secure software. It also forces companies and the industry in general to pay more attention to this stuff.

Right now, government doesn't care. Right now, it is cheaper to get hacked, spew all your information, and then say, "sorry". Not right.

Re: South Korea military cyber command was hacked

#46
post #21
post #20

No one will be safe until governments stop hoarding 0-days. Until we all realize we live in a glass house, the hacks will continue. The best solution is to split the NSA and similar agencies into two. One for developing new tools that produces safer code and finding flaws and reporting them to companies so they get patched. The second for offense.

I'm not sure how splitting up the NSA fixes anything. Wouldn't the new offensive organization still be compelled to seek out zero-day exploits as well for their mission? What happens when they find one that the defensive organization hasn't found yet?

Splitting IAD off from SIGINT wouldn't reduce the number of zero-days the government collected, but it would:

* Ensure that the advice IAD was generating was untainted by SIGINT influence

* Enable IAD to independently collect vulnerability intelligence and disseminate it (most importantly, to vendors) without having to endure a bogus equities process to ensure they weren't blowing a SIGINT operation.

Of course, this only works if IAD is stripped completely out of the NSA, and perhaps out of the DoD entirely. IAD probably belongs under DHS.

Re: South Korea military cyber command was hacked

#47
post #20

No one will be safe until governments stop hoarding 0-days. Until we all realize we live in a glass house, the hacks will continue. The best solution is to split the NSA and similar agencies into two. One for developing new tools that produces safer code and finding flaws and reporting them to companies so they get patched. The second for offense.

When a government researcher (or government-funded researcher) discovers a new Flash vulnerability, the government hasn't created the vulnerability, nor have they prevented anyone else from discovering that same vulnerability.

Lobbying against SIGINT vulnerability collection doesn't actually make us materially safer --- even if things like the "Shadow Brokers" became routine (rather than the unprecedented shitstorm it actually was), the number and caliber of the vulnerabilities we're talking about are a tiny fraction of the threat we face.

Re: South Korea military cyber command was hacked

#48
post #45

Earlier quoted context omitted.

Why do you think it matters if NSA stops hoarding 0-days? Let's put that into perspective - iPhone jailbreaking community hacks every new release in days/weeks. And that's just a few people doing it for fun and not getting paid. Companies like Cellebrite have more people paid good money to do the same thing, so they're likely to have an even bigger stash of working exploits. And that's for a locked down device which…

It is special because it is government. We have tax payer money going to support thousands of people finding 0-days. What I am proposing is to move some of those funds to be defensive and since it is government, the intention and motivation is to make more secure software. It also forces companies and the industry in general to pay more attention to this stuff. Right now, government doesn't care. Right now, it is che…

We probably do not support "thousands of people" finding zero-days. We might not even support 100 effective researchers.

Re: South Korea military cyber command was hacked

#49

>speculation that North Korea might be behind the latest cyber attack Does North have hackers skilled enough to perform such (or any) attacks? How did they acquire their skills given the internet is forbidden there?

If they don't, there are skilled hackers elsewhere who would sell their services.

Re: South Korea military cyber command was hacked

#50
post #27

"vaccine routing server" = next-gen firewall running UTM?

From the context, my first thought was something like a centralized server providing anti-virus software and/or updates hosts on the internal portion of the network.

Considering the timeline (within the last month or two) and the recently discovered issues in antivirus products from multiple vendors, I think that this scenario (or something similar) is, at the least, plausible.

A compromised UTM firewall would not be unheard of either.

Post reply on HN