Live data from Hacker News

Thousands of computers now compromised with leaked NSA tools, researchers say

cyberscoop.com

41–50 of 173 posts

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#41

Which is exactly what we crazy cookoo conspiracy theorists have been warning about. It's the same slipperly slope we already went through in the 90's crypto wars, but SV gets amnesia when it gets lots of stupid company valuations and forgets all those lessons apparently. Bottom line is this. If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massive…

>Which is exactly what we crazy cookoo conspiracy theorists have been warning about. Which is what exactly? That a spy agency is spying? >If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massively weakened infrastructure, corporate, and government security I don't agree with putting in backdoors, but I don't see how exploiting backdoors by your se…

> Which is what exactly? That a spy agency is spying?

To spell it out: backdoors are of course a helpful tool for a security agency, but once the key for the backdoors falls into the wrong hands the potential for misuse is monstrous because, well, the backdoors are in all kinds of potentially critical systems systems, e.g. even in the cellphones of high ranking officials (or in cellphones of their families) etc.

To get the same intel by different means than a backdoor is of course much more expensive. So one needs to find the sweet spot, where the utility as a function of cost and security is maximized. That sweet spot likely does not involve backdoors.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#43
post #37

Earlier quoted context omitted.

The antidote seems to be for the NSA to maintain a security report for each discovered zero day. If it ever leaks, they can send the target company the report, which explains both what the exploit is and how to fix it. That seems fair enough. The NSA needs to exploit flaws, but they can be a bit less evil about it by being ready to fix them if necessary. That doesn't solve the fact that NSA's competitors could find a…

> If it ever leaks, they can send the target > company the report. Any usage of the exploit by the NSA constitutes leaking it. You can't treat cyberweapons like normal weapons. The analogy is not that you come up with a secret bomb design and drop it on the target, but that to use your bomb you must send the full Top Secret designs for the bomb to every target, hoping that they voluntarily use it to blow themselves u…

Sort of. For example, the NSA developed a way to hotpatch an ethernet adapter's firmware to respond to incoming packets that operate out of band with normal IP packets. Meaning it's a way to communicate with a target computer that's completely undetectable by standard tools. Using such an exploit against a computer isn't typically a risk, because the target you're exploiting isn't sophisticated enough to catch the exploit. And even if they were, and they send their computer to a foreign intelligence agency for extensive analysis, that typically wouldn't confer an advantage to that agency. They were already developing their own exploits to use against us, and there are only so many unique techniques.

The way to protect against this is probably to have constant security audits. But these are expensive, so the situation is that there will always be exploitable computers and software, especially when a nation-state adversary is doing the exploitation.

The solution is what it's always been: Political control. We have terrifying weapons, and what keeps them at bay is aligning the incentives of our politicians so that the calculus of employing them is more costly than keeping them unused. (Unfortunately this may not be possible with cyberweapons, because unlike real weapons, there is no death and destruction as a side effect.)

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#44

Earlier quoted context omitted.

We have evidence that the NSA has no idea from where or through whom it's leaking. The general consensus seems to be that Russia was the source of the leaks. The US government knows this, and everyone involved knows who is leaking what, and why. If so, then this is a political move. Is there evidence to contradict this? https://www.nytimes.com/2016/08/17/us/shadow-brokers-leak-ra...

Its impossible now. Wikileaks showed the the cia goes into incredible detail to frame other countries. https://www.wired.com/2017/03/wikileaks-cia-dump-gives-russi... http://thehackernews.com/2017/03/cia-marble-framework.html I also bet that other countries do the exact same thing, probably even more likely considering the "marble project" source code is leaked. http://www.dailymail.co.uk/news/article-4427452/CIA-lau…

>Wikileaks showed the the cia goes into incredible detail to frame other countries.

No.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#45

Earlier quoted context omitted.

>Which is exactly what we crazy cookoo conspiracy theorists have been warning about. Which is what exactly? That a spy agency is spying? >If you put backdoors in, or exploit 0days for your own, they will get out in the wild eventually, and suddenly you have massively weakened infrastructure, corporate, and government security I don't agree with putting in backdoors, but I don't see how exploiting backdoors by your se…

The NSA leverages these exploits to spy on foreign nations. That's fine, spies should spy... But it does beg the question: who's protecting our information from foreign intrusions?

Isn't that partly the mission statement of the NSA and CIA and FBI?

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#46

Earlier quoted context omitted.

We probably need the NSA. It's their job to exploit computers the same way it's the job of the military to apply force. It's difficult to say that we can do without the NSA any more than we can do without a military. In that light, the context is to reduce the impact of the NSA's necessary goals. Higher up in the thread, it was claimed that one of the most feared branches of the intelligence arm of the most powerful…

> It's their job to exploit computers the same way it's the job of the military to apply force. That's one half of their job, the other half is to secure government infrastructure from exactly the type of attacks they use on other countries. The problem there is that it sets up an incredible tension since how do you get the message out about a 0-day in windows to protect your 'own' side without your opponents getting…

> how do you get the message out about a 0-day in windows

American companies get disclosures, foreign companies do not.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#48
post #18

Side topic: How can the free market/enterprise work properly if there are backdoors and zero days all over the place?

If your threat model includes 3 letter agencies, the short answer is that you cannot.

Problem is that the 3-letter agencies tools get leaked and then are open for script Kidd to use. So you're threat model has a dristributive connection to the 3-letters no matter what.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#49
It would be interesting (although I expect impossible) to figure out how many of those thousands were compromised by the NSA vs those compromised by people who got the tools through the leak. It was nice that Microsoft had already fixed a bunch of them (almost like they were told ahead of time they were coming).

It is also interesting to read the outrage about the tools and the presentations on how to use them. If you have ever read the user's manual for a cluster bomb which no doubt tells you in detail how to maximize the number of people it will kill, you get a sense of how destructive and outrageous war can be. Why should cyber war be any different? And how is it any different to use a zero day to compromise a system than it is to use an architectural feature of a building to bring it down on top of its occupants (other than the obvious loss of life). Exploiting defects in the deployed system to maximize the effectiveness of a munition, not a new thing at all. Just the reality of warfare.

We're pretty clearly already in a form of warfare and it is having visible effects on things like infrastructure and elections. So how do we make the battles visible to the common folks? How do convince Mom & Dad to patch their router so that they don't inadvertently aid the 'badguys' in their quest for dominance on the digital battlefield?

Definitely feels like Phase III of the Internet has begun to me.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#50

It would be interesting (although I expect impossible) to figure out how many of those thousands were compromised by the NSA vs those compromised by people who got the tools through the leak. It was nice that Microsoft had already fixed a bunch of them (almost like they were told ahead of time they were coming). It is also interesting to read the outrage about the tools and the presentations on how to use them. If yo…

[deleted]
Post reply on HN