Live data from Hacker News

Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

nytimes.com

1–10 of 116 posts

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#2
With the initial vector being some widely used Ukranian tax software, and the network vector as psexec/wmic mimikatz harvested credentials, the actual usage of 'NSA cyberweapons' was just a backup.

I suspect this attack would have had a similar number of victims without EtBl/DoPu and EtRo.

The existence of 'nation state' offensive tools has little baring on exploitability for poorly configured enterprise network, when most victims were exploited by open source offensive tools, even when patched.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#4
This is merely a taste of what is to come.

When President Obama stated in December[0] that we will deliver a "proportional response" to Russian hacking at the "time and place of our own choosing", it seemed that most of the country was proud, almost gleeful at the thought that we would be striking back. I for one was mortified.

We should not be escalating cyberwar, even if we do have proof of who attacked us. People are going to die. We can see from this article that hacking can cause serious real-world problems.

When we strike back, does Russia then strike back again? What does it look like after four or five volleys? Will entire power grids be down for days or weeks? Will the stock market crash?

It's time for the American people to demand that the N.S.A. become a defensive organization, not an offensive one. And it's time for us to demand peace in general. Cyberwar is war.

[0] http://www.cnn.com/2016/12/15/politics/obama-russia-hacking-...

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#5
post #4

This is merely a taste of what is to come. When President Obama stated in December[0] that we will deliver a "proportional response" to Russian hacking at the "time and place of our own choosing", it seemed that most of the country was proud, almost gleeful at the thought that we would be striking back. I for one was mortified. We should not be escalating cyberwar, even if we do have proof of who attacked us. People…

Oh what a world we live in where cyberwarfare could result in death. I would have never thought, as a kid, that life (and death) would end up this "real".

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#8
post #4

This is merely a taste of what is to come. When President Obama stated in December[0] that we will deliver a "proportional response" to Russian hacking at the "time and place of our own choosing", it seemed that most of the country was proud, almost gleeful at the thought that we would be striking back. I for one was mortified. We should not be escalating cyberwar, even if we do have proof of who attacked us. People…

I don't want the NSA to become a defensive organization. I like that Iran's nuclear program is being delayed. That's not a defensive action.

You don't seem to be proposing that the NSA become defensive, either. If Russia attacks us and we don't respond, that's not even defensive. That's dismantling.

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#9
Two questions

1. Why do they not simply take the weapons of a network? Maybe store it on some physical media, or a computer not networked unless it's time to take a Kim down a notch?

2. Are these "weapons" really that dastardly? Most of these common ransom-ware and viruses are easily avoided, and only succeed because of naive users. Backdoors aren't a weapon, they're there on purpose. Sniffing, spying, and logging can potentially cause some chaos. But are these really some kind of Zero-cool level hyrda's that they can sink oil-tankers with?

Re: Hacks Raise Fear Over N.S.A.’s Hold on Cyberweapons

#10
Not trying to claim whataboutism, but I think there's an elephant in the room. The end result of the NSA saying "ok, as of today we've completely disarmed our cyberweapon stockpile and released patches for all vulnerabilities to the appropriate software companies" wouldn't be the end of cyberattacks. It would just be someone else doing them. I don't know what the real solution is. Maybe there is none.
Post reply on HN