Live data from Hacker News

Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

mobile.nytimes.com

461–470 of 505 posts

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#461

Earlier quoted context omitted.

Yes, 70+ countries.

Botnets don't care about countries. It's not an attack against 70+ countries, it's an attack against everyone on the internet.

The point was that it is worldwide.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#462

Earlier quoted context omitted.

Botnets don't care about countries. It's not an attack against 70+ countries, it's an attack against everyone on the internet.

The point was that it is worldwide.

When a nuclear bomb is dropped on Hiroshima, is that an attack against hundreds of buildings, or is it an attack against Hiroshima? :)

Thinking of it as "an attack against 70+ countries" is an anachronism. The attack doesn't care about countries. It doesn't even need to acknowledge their existence.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#463

Earlier quoted context omitted.

What would 'being smart' about using these services mean? It is pretty difficult to get through life in the modern age without using email for sensitive documents (or at least without using ACCESS to your email as a way to gain access to sensitive services, eg password reset emails, proof of ownership, etc) Since email in the modern world has this type of importance, what should I do? If you say gmail can't protect t…

Just make sure whatever email provider you use offers IMAP and use a client like Thunderbird to keep a local copy in sync. Back that up somewhere safe and you're fine. If you need good, fast search, use something like X1.

This was something I thought POP did better since it requires maintaining one's own copies after downloading. But it was much less convenient as people used more devices.

Sad that managing our own multi device services is so time consuming.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#464
post #409

Earlier quoted context omitted.

The scary thing is that it's about the group as opposed to people not in the group. This tribalism is nothing but scary.

It can be, yes. But it's often patriotism that is seen as what enabled things like the congressional Republicans in the Nixon era to authorize the special investigations which brought him down. That's only one example - there are plenty of others where an individual puts the interest of the group ahead of themselves. That isn't always a bad thing: the alternative is the tyranny of the strong, where the strongest indi…

Snowden comes to mind.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#466
post #409

Earlier quoted context omitted.

The scary thing is that it's about the group as opposed to people not in the group. This tribalism is nothing but scary.

It can be, yes. But it's often patriotism that is seen as what enabled things like the congressional Republicans in the Nixon era to authorize the special investigations which brought him down. That's only one example - there are plenty of others where an individual puts the interest of the group ahead of themselves. That isn't always a bad thing: the alternative is the tyranny of the strong, where the strongest indi…

I could also care about justice and people in general regardless of race or nationality or where they live.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#467
post #413

What gets me is why we don't see more viruses that _deliver_ the patch to fix the vulnerability. It's perhaps a little more difficult as you'd need a vulnerability to keep spreading the innoculation. Arguably, though you release the virus, let it spread and then trigger the innoculation using a mechanism like calling out to a webserver, just as the kill switch worked here.

You run the risk of jail time without the upside of ransom payments.

True, plus, I forget the legislation but you are effectively breaking into the computer first which is a crime. Committing a crime for a noble outcome is still a crime.

Incentives is a real issue here and those that provide the patch would, reasonably, expect a reward i.e. MS for updates, AV provider for testing, finding and securing the vulnerability and a whitehat for disclosure. However, there is no reason why a "charitable" hacking group wouldn't do this as part of some sort of digital vigilantism. Sometimes people do things without extrinsic reward and the thrill here is that it is as hard as cracking, but you get to know that your efforts could be immediately applied.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#468
post #413

What gets me is why we don't see more viruses that _deliver_ the patch to fix the vulnerability. It's perhaps a little more difficult as you'd need a vulnerability to keep spreading the innoculation. Arguably, though you release the virus, let it spread and then trigger the innoculation using a mechanism like calling out to a webserver, just as the kill switch worked here.

That's an interesting idea: release a virus to cite a virus. Reminds me of the game Uplink, where [spoiler alert] you choose to either help spread a virus to destroy the Internet, or help spread a "counter-virus", hacking large servers to cure them before they're overrun. Digital vigilantism, that's what that is.

"Digital vigilantism" that's exactly it.

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#469
post #443

I see the Rust Evangelism Strike Force are out in action again. Guys, it may surprise you, but some of this kit predates Rust :)

Er, aside from yours, there are literally two comments in this 444-comment thread that have mentioned Rust, both of them written by a single person. Given that both those comments also mention sel4, perhaps we ought to invoke the sel4 Evangelism Strike Force? :P

Re: Cyberattacks in 12 Nations Said to Use Leaked N.S.A. Hacking Tool

#470

The real world doesn't update in 2 months. (I wish it did.) The NSA should have responsibly disclosed the vulnerabilities they had been sitting on as soon as they were discovered. That protects national security - not this.

Wikileaks should have disclosed before dumping publicly. Burning down the house to prove that there are fire safety issues is the wrong approach.

Likewise not calling the fire department when you know all of our houses are likely to be burnt down in the hopes that some "bad guys" might get burnt is also the wrong approach.
Post reply on HN