Slashdot Mirror


Hacks Raise Fear Over NSA's Hold on Cyberweapons (nytimes.com)

Nicole Perlroth, and David Sanger, writing for The New York Times: Twice in the past month, National Security Agency cyberweapons stolen from its arsenal have been turned against two very different partners of the United States -- Britain and Ukraine. The N.S.A. has kept quiet, not acknowledging its role in developing the weapons (alternative source). White House officials have deflected many questions, and responded to others by arguing that the focus should be on the attackers themselves, not the manufacturer of their weapons. But the silence is wearing thin for victims of the assaults, as a series of escalating attacks using N.S.A. cyberweapons have hit hospitals, a nuclear site and American businesses. Now there is growing concern that United States intelligence agencies have rushed to create digital weapons that they cannot keep safe from adversaries or disable once they fall into the wrong hands. On Wednesday, the calls for the agency to address its role in the latest attacks grew louder, as victims and technology companies cried foul. Representative Ted Lieu, a California Democrat and a former Air Force officer who serves on the House Judiciary and Foreign Affairs Committees, urged the N.S.A. to help stop the attacks and to stop hoarding knowledge of the computer vulnerabilities upon which these weapons rely.

103 comments

  1. just like gun control by Anonymous Coward · · Score: 0

    the focus should be on the attackers themselves, not the manufacturer of their weapons... or the weapons themselves.

    1. Re:just like gun control by Opportunist · · Score: 4, Insightful

      Unlike real weapons, these weapons can be multiplied easily. Try that with a tank.

      That alone should mean that these "virtual guns" are under a tighter control. Even a nuke can only detonate once, but one such "weapon" can be used all over the globe billions of times.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    2. Re:just like gun control by Anonymous Coward · · Score: 0

      They do try to focus on the attackers. That's the whole point behind background check requirements.

    3. Re:just like gun control by Anonymous Coward · · Score: 0

      (Different AC)

      Exactly. The problem here is that people are trying to apply pre- information age thinking to post- information age constructs. This idea that you can build a cyber "weapon" that can only attack "bad" people and cannot be trivially altered to ignore whatever protections you put into place to keep it from being used against "good" people, is ludicrous.

      Just look at WannaCry. How long after the kill-switch url was discovered did a version come to light that ignored that url?

    4. Re:just like gun control by Shotgun · · Score: 4, Insightful

      The analogy is that these are very much like biological weapons. If you're going to use those, you have to be damn sure that the "good guys" all have vaccines, and that the weapon can't mutate.

      There is a very good reason that biological weapons are NOT used.

      --
      Aah, change is good. -- Rafiki
      Yeah, but it ain't easy. -- Simba
    5. Re:just like gun control by XXongo · · Score: 2, Insightful

      Exactly. The problem here is that people are trying to apply pre- information age thinking to post- information age constructs. This idea that you can build a cyber "weapon" that can only attack "bad" people and cannot be trivially altered to ignore whatever protections you put into place to keep it from being used against "good" people, is ludicrous.

      Yes, exactly like guns. It's ludicrous to think you can proliferate millions of guns to "good" people, and they won't be also used by "bad" people.

    6. Re:just like gun control by BlueStrat · · Score: 1

      Yes, exactly like guns. It's ludicrous to think you can proliferate millions of guns to "good" people, and they won't be also used by "bad" people.

      Well, the horses have already left the barn on criminals having/using guns. They aren't going to turn them in if they were banned.

      The question remaining is, do you allow people the ability to defend themselves, seeing as police rarely ever arrive in time to do anything other than write reports and gather evidence, or do you leave them defenseless?

      Note that there are far more good people than bad people. That means that by allowing people to arm themselves there will be far more good people with guns vs bad people with guns, and the only thing that stops a bad guy with a gun is a good guy with a gun.

      The option to disarm everyone is impossible in the US, too many guns already out there and far too easy to smuggle in across the land borders. Any serious attempt would only trigger a civil war.

      Strat

      --
      Progressivism (aka US 'Liberalism'): Ideas so good they need a police/surveillance-state to enforce.
    7. Re:just like gun control by executioner · · Score: 1
      much like anything else you will always have a small portion of the population that can't handle using some "item" appropriately, or safely.

      or should we just ban anything that can be used by "bad" people to commit crimes? or should we focus on the individual that commits the crimes instead of their chosen tools?

      --
      "They who can give up essential liberty to obtain a little temporary safety, deserve neither liberty nor safety."
    8. Re: just like gun control by Anonymous Coward · · Score: 0

      Imagine a nuke getting lost to terrorists. Wouldn't you blame it's legitimate owner for not securing it appropriately?

    9. Re:just like gun control by Anonymous Coward · · Score: 0

      The analogy is that these are very much like biological weapons. If you're going to use those, you have to be damn sure that the "good guys" all have vaccines, and that the weapon can't mutate.

      There is a very good reason that biological weapons are NOT used.

      This is the right answer.

    10. Re: just like gun control by Anonymous Coward · · Score: 0

      Both actually. I am pretty sure that you would be the first to blame Russia, if somehow a terrorist manages to acquire a Russian nuke on the black market, then blows it in the middle of US mainland.

    11. Re:just like gun control by Anonymous Coward · · Score: 2, Interesting

      do you allow people the ability to defend themselves, seeing as police rarely ever arrive in time to do anything other than write reports and gather evidence, or do you leave them defenseless?

      Note that there are far more good people than bad people. That means that by allowing people to arm themselves there will be far more good people with guns vs bad people with guns, and the only thing that stops a bad guy with a gun is a good guy with a gun

      And this is why, every day, so many shootings are interrupted or prevented by good guys with guns. Obviously the media don't report these incidents. If we could only further increase gun ownership we might be able to stop mass-shootings entirely.

    12. Re:just like gun control by phayes · · Score: 1

      The NSA _DID_ tell Microsoft and the other targeted software firms which vulnerabilities they were using months before the russians began releasing them (and pointing their finger at the NSA). It's the reason that patches were available on Win10 before the russian release and that Microsoft released patches for their unsupported OS's _the_day_ the russians leaked them.

      Now there are better questions that need to be answered: Why are people blaming the NSA, and _ONLY_ the NSA? We know that the exploits were not a major problem until the russians released them because the NSA used the exploits for years and the public impact was nonexistent -- because the NSA was using them in targeted exploits and not as a tool of widespread untargeted economic destruction the way the russians have. We also know that the Russians have used other 0Days in the past and will certainly use different 0Days in the future that they didn't steal from the NSA. At what point will you recognise that the NSA _isn't_ the major problem here and that the big problem is with Putin's "patriotic" hackers spreading malware without _any_ thought to the consequences? Why does Putin get a free pass?

      --
      Democracy is a sheep and two wolves deciding what to have for lunch. Freedom is a well armed sheep contesting the issue
    13. Re:just like gun control by Anonymous Coward · · Score: 0

      do you allow people the ability to defend themselves, seeing as police rarely ever arrive in time to do anything other than write reports and gather evidence, or do you leave them defenseless?

      Note that there are far more good people than bad people. That means that by allowing people to arm themselves there will be far more good people with guns vs bad people with guns, and the only thing that stops a bad guy with a gun is a good guy with a gun

      And this is why, every day, so many shootings are interrupted or prevented by good guys with guns. Obviously the media don't report these incidents. If we could only further increase gun ownership we might be able to stop mass-shootings entirely.

      I bet it happens maybe 5 times a day. But yet police kill 136 Americans every single day during routine traffic stops.

    14. Re:just like gun control by Anonymous Coward · · Score: 0

      Yes, exactly like guns. It's ludicrous to think you can proliferate millions of guns to "good" people, and they won't be also used by "bad" people.

      Uh, except, no one ever said bad people wouldn't obtain or use guns (nice straw-man). That's exactly the reason guns are legal for law abiding citizens -- to protect the good from the bad.

      Unfortunately, some lack the intelligence to see the solution, even when it's right in front of them. Others are smart enough, but refuse to acknowledge the truth. I wonder which category you fall under.

    15. Re:just like gun control by AutodidactLabrat · · Score: 0

      Well and good
      Except for that nasty FBI demonstrating that those "Good Guy" claims are overinflated and often nonsensical
      And many armed people can ADD to the death toll
      And this is why no one rushes to repeat these oft-exaggerated claims!

    16. Re:just like gun control by AutodidactLabrat · · Score: 1

      Except the "Good" seem to fail MOST of the time
      Or even Add to the carnage!

    17. Re:just like gun control by AutodidactLabrat · · Score: 0
    18. Re:just like gun control by Anonymous Coward · · Score: 0

      Note that there are far more good people than bad people. That means that by allowing people to arm themselves there will be far more good people with guns vs bad people with guns, and the only thing that stops a bad guy with a gun is a good guy with a gun

      And this is why, every day, so many shootings are interrupted or prevented by good guys with guns. Obviously the media don't report these incidents. If we could only further increase gun ownership we might be able to stop mass-shootings entirely.

      I bet it happens maybe 5 times a day. But yet police kill 136 Americans every single day during routine traffic stops.

      5 times a day isn't even close considering the inner city gang violence. Not to mention, you fail to consider the amount of crime prevented by having armed police on the streets and at the ready. You need only look south of the border to see how things go when the criminals run things. Your thinking is beyond naive.

      Also, police don't kill 136 Americans every day. That stat was about how many unarmed blacks were supposedly killed by police in the first 6 months of 2016. I know the news media has abused their position and has overblown the issue by many magnitudes, especially leading up to the election, but we would all know it if 136 people were killed by police "every single day". That's almost 50,000 people a year. Fake news anyone?

      The real stat, by best estimates, is about 1000 people per year are killed by police. Most are criminals who were a danger to the community, which is why they got shot. Who would have thought? The facts make much more sense than falsehoods and lies.

    19. Re:just like gun control by Anonymous Coward · · Score: 0

      Except the "Good" seem to fail MOST of the time
      Or even Add to the carnage! [harvardpolitics.com]

      That's not what the article said. Not to mention, you ignore the largest and most significant group of "good" guys out there, our police and military. If it weren't for them, you might not even be alive to peddle such intellectually bankrupt ideas.

      Regardless, in a free society, we should all have the choice to protect ourselves however we see fit. This is especially the case for women and others who can be easily overpowered by someone who would rob, rape, and kill for their next crack rock or even just for the hell of it. In a world like that, I'll take my chances with protecting myself and allowing my fellow man and woman to do the same.

    20. Re:just like gun control by Anonymous Coward · · Score: 0

      Not that grandparent wasn't blowing smoke, but note that a comment from an AC on slashdot doesn't qualify as news of any kind, fake or otherwise.

    21. Re: just like gun control by Anonymous Coward · · Score: 0

      ...but what if they're using "assault hacks" that look scared???

    22. Re:just like gun control by Opportunist · · Score: 1

      Because we don't expect the Russians to be the good guys. We do kinda expect that from an organization that is allegedly protecting us.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    23. Re:just like gun control by phayes · · Score: 1

      Were that true there would have to be _some_ condemnation of Russian hackers amongst the incessant blaming of the NSA. As that's not the case and people like shotgun keep repeating the same falsehoods, something else is happening & it's not innocent.

      --
      Democracy is a sheep and two wolves deciding what to have for lunch. Freedom is a well armed sheep contesting the issue
  2. Cyber... by Frosty+Piss · · Score: 3, Funny

    Only my opinion, but I really dislike this ter, "cyberweapon". Actually, anything with "cyber" other than "cybersex" sets me off a bit...

    --
    If you want news from today, you have to come back tomorrow.
    1. Re:Cyber... by Anonymous Coward · · Score: 1

      You should really try regular sex. Once you do, cybersex will seem just as distasteful and cyberweapons, cyberbullying, and cyberspace.

    2. Re:Cyber... by Anonymous Coward · · Score: 0

      Only my opinion, but I really dislike this ter, "cyberweapon". Actually, anything with "cyber" other than "cybersex" sets me off a bit...

      "Cyber" shows that completely incompetent military and law enforcement people were able to swamp the real infosec community by posing as pros and nobody stopped them.
      For awhile there were tons of infosec "management" that couldn't do shit but draw squares and triangles and diagrams in visio describing vague security philosophies.. they made way more than actual technical security types too.

      Fucking pisses me off.

    3. Re:Cyber... by Anonymous Coward · · Score: 0

      What, swamping the real pros? The ones that bicker and argue about who is "ethical" and who isn't, who play bad cowboy vs good cowboy with coloured hats? Those pros?

      I have actually less trouble with terms like "cyberspace", which tries to describe the landscape, however ineptly, than the much more common "hacks", "hacking", and "hackers". Those terms mean diddly squat any longer, and their theft has left us bereft of previously useful words. To the point I don't need to read any news item or press release containing such terms, because the last 9000 times I tried, the information I need was not to be found.

      Also, the military and law enforcement types typically did ask the "pros", and then went with the advice they got. So the "infosec" crowd, those purveyors of fine imperial textiles, are who we really have to thank for this and the other shit.

      Face it. The "infosec community" are a bunch of s'kiddies that failed to grow up and they don't produce anything that's even half as useful as it needs to be. No blaming the military for that.

      Oh, and "awhile" means "for a while".

    4. Re:Cyber... by Anonymous Coward · · Score: 0

      Nah. Regular sex takes too much work. The seeking, wooing, spending money and time one way or the other, doing stuff you don't want to do. Even when you get there, the variety suffers massively and scheduling is such a pain. Then there's the risks of STD's, unwanted pregnancy, wives and girlfriends meeting at brunch.

      Get the real thing when you can, enjoy romance insomuch as your preference. But even when you do, when you are honest with yourself and directly compare the two options with all the good and bad, isolating for all variables, cybersex and the like is clearly better in the long run.

    5. Re:Cyber... by Anonymous Coward · · Score: 0

      Which is why Trump talking about "the Cyber, we have to get better at the Cyber", had me laughing so hard I scared my dogs.

      Then I had to explain to my wife what Cyber was. Then I had to explain how I knew what cyber was.

      Thanks Trump.

  3. And they want masterdecryption keys, too. by Desler · · Score: 5, Insightful

    Even worse than that is they expect us to believe that they can securely escrow master keys to break all encryption. What a bunch of jokers.

    1. Re:And they want masterdecryption keys, too. by Anonymous Coward · · Score: 0

      "Let me get this straight. You can't even keep things secured under current encryption standards. And you want to weaken encryption?" -Skeptical Black Kid Meme

  4. Ukraine is a partner of the US? by Anonymous Coward · · Score: 0

    That's news to me.

    1. Re:Ukraine is a partner of the US? by xxxJonBoyxxx · · Score: 1

      I found this for you:
      https://en.wikipedia.org/wiki/Ukraine%E2%80%93United_States_relations

    2. Re:Ukraine is a partner of the US? by Anonymous Coward · · Score: 0

      I refer you to the overthrow of the Ukranian government and the ongoing civil war.

    3. Re:Ukraine is a partner of the US? by WillAffleckUW · · Score: 1

      Yes, that's why NATO troops are there, and why Russia attacked them with cyberweapons which then spread to India, Pakistan, and other countries.

      Russia is not our friend.

      And the easiest way to defeat them is to triple or quadruple Renewable Energy usage, cutting off their supply lines at the knees.

      --
      -- Tigger warning: This post may contain tiggers! --
  5. A weapon? by Anonymous Coward · · Score: 0

    It's not really a weapon if it only works on a vulnerability.

    1. Re: A weapon? by Anonymous Coward · · Score: 1

      Eg, skin is vulnerable to penetration by small bits of high velocity metal, so guns aren't weapons?

    2. Re:A weapon? by Desler · · Score: 3, Insightful

      Your statement doesn't even make sense. So if I shoot a rocket at the cracked part of a wall the rocket ceases to be a weapon?

    3. Re: A weapon? by Anonymous Coward · · Score: 0

      Lots of things are vulnerable to penetration by small bits of high velocity metal, not just skin, so guns are weapons, Dumas.

    4. Re:A weapon? by Anonymous Coward · · Score: 0

      Your example doesn't make sense either. Like, what the fuck?

    5. Re:A weapon? by Desler · · Score: 1

      A crack in a wall would be the "vulnerability" so supposedly using something against it would mean it is not a weapon.

  6. A word to the wise: by Gravis+Zero · · Score: 4, Insightful

    Never create a weapon that you wouldn't want to fall into the hands of your worst enemy.

    --
    Anons need not reply. Questions end with a question mark.
    1. Re:A word to the wise: by GameboyRMH · · Score: 1

      And these are weapons that the enemy can just stumble upon anywhere out in the world. A cyberweapon is really just a secret, but it's a decent (if tortured) analogy to think of them as camouflaged, remote-detonatable explosives that are hiding all over the place. The world is almost made of these bombs just waiting for someone to figure out how to set them off, and if we identify them we can neutralize them all without much trouble. But if we keep secret the fact that a certain kind of tree will go off like a nuclear bomb if you shine a green laser at it so that the NSA can blow up terrorists' bases via the shrubberies, then we're also making it possible for ISIS to stumble upon the alternative use of that tree and set off nukes on everyone's front lawn.

      --
      "When information is power, privacy is freedom" - Jah-Wren Ryel
    2. Re:A word to the wise: by Anonymous Coward · · Score: 0

      Wow! You weren't joking about the tortured!

    3. Re:A word to the wise: by chispito · · Score: 1

      Never create a weapon that you wouldn't want to fall into the hands of your worst enemy.

      That's nonsensical. What advantage or tool would you want your worst enemy to have?

      --
      The Daddy casts sleep on the Baby. The Baby resists!
    4. Re:A word to the wise: by Anonymous Coward · · Score: 0

      Wow! You weren't kidding about the tortured!

    5. Re:A word to the wise: by houghi · · Score: 1

      To me it feels more like two brothers and one keeps yelling, while holding his hand and shouting "Stop hitting yourself. Stop hitting yourself."

      --
      Don't fight for your country, if your country does not fight for you.
    6. Re: A word to the wise: by Anonymous Coward · · Score: 0

      Yep, love the tortured analogy :) Also, the USA has a hell of a lot more nuclear bomb trees than its enemies. Doesn't make sense to spread around weapons that are most effective against yourselves, does it? Someone at the NSA isn't paying attention.

    7. Re: A word to the wise: by Anonymous Coward · · Score: 0

      lol you ascribe a level of wisdom heretofore unseen in human history, to wit; war.

    8. Re:A word to the wise: by Anonymous Coward · · Score: 0

      That's nonsensical. What advantage or tool would you want your worst enemy to have?

      What you WANT is irrelevant, what CAN HAPPEN is the point

    9. Re:A word to the wise: by Gravis+Zero · · Score: 3, Insightful

      Things that can only be used to defend and help their common man.

      --
      Anons need not reply. Questions end with a question mark.
    10. Re: A word to the wise: by Anonymous Coward · · Score: 0

      Because clearly, nobody else could ever do the same engineering work. You're fucking stupid.

    11. Re:A word to the wise: by chispito · · Score: 1

      My enemy has a knife. I should not have a knife because if I drop it he might have two knives.

      --
      The Daddy casts sleep on the Baby. The Baby resists!
    12. Re:A word to the wise: by Gravis+Zero · · Score: 1

      Perhaps you should make shields instead of knives.

      --
      Anons need not reply. Questions end with a question mark.
    13. Re: A word to the wise: by qbast · · Score: 1

      And if I drop it, he will have two knives and a shield. Not helping.

    14. Re: A word to the wise: by Anonymous Coward · · Score: 0

      You didnt read about the leaks.l much did you... these are tools that utilize vulnerabilities to INFECT machines with PAYLOADS.

    15. Re:A word to the wise: by mi · · Score: 1

      Never create a weapon that you wouldn't want to fall into the hands of your worst enemy.

      So, like, no swords and no clubs either, huh?

      --
      In Soviet Washington the swamp drains you.
    16. Re:A word to the wise: by Anonymous Coward · · Score: 0

      wise people already know this.

      a word to the average-man would be more beneficial.

    17. Re: A word to the wise: by GameboyRMH · · Score: 1

      Yes, tools that use secret vulnerabilities. If there were no vulnerabilities, or if they were not kept secret and subsequently patched, the tools would be useless and the payloads would never be put in place.

      --
      "When information is power, privacy is freedom" - Jah-Wren Ryel
    18. Re: A word to the wise: by chispito · · Score: 1

      Thanks for this. Suddenly I'm imagining a comedy bit about the pitfalls of pacifism.

      --
      The Daddy casts sleep on the Baby. The Baby resists!
  7. The "what could go wrong?" agency... by Anonymous Coward · · Score: 0

    I mean, seriously. That's the motto for pretty much all their operation and its role in securing a democracy.

  8. Shut up stupid! by Anonymous Coward · · Score: 0

    There is no NSA
    No cyber weapons
    No hacks
    No internet
    No technology
    No fear
    none of that. It's all fake news. It's all good, dude.

  9. Re:Vmod do3n by Anonymous Coward · · Score: 1

    Truer words have never been spoken

  10. Reminds me of how when there is a mass shooting by Anonymous Coward · · Score: 0

    the NRA apologists are always out in force telling us that in light of the tragedy it's really not the time to talk about gun control.

    1. Re:Reminds me of how when there is a mass shooting by Anonymous Coward · · Score: 0

      the NRA apologists are always out in force telling us that in light of the tragedy it's really not the time to talk about gun control.

      Just like the NSA apologists always out in force telling us that in light of the malware it's really not time to talk about their role.

  11. So here it is by sjames · · Score: 4, Funny

    The NSA. It pooped it's pants right there in the public square. And rather than trying to clean up, it just stands there yelling "MY SHIT DON'T STINK!" while continuing to make squeaky farts..

    This is probably go to a new school next year level public humiliation, but they apparently have no shame.

    If you should see someone who works for the NSA, hand them a roll of toilet paper.

    1. Re:So here it is by XXongo · · Score: 1, Insightful

      The NRA. It pooped its pants right there in the public square. And rather than trying to clean up, it just stands there yelling "MY SHIT DON'T STINK!" while continuing to make squeaky farts..

      This is probably go to a new school next year level public humiliation, but they apparently have no shame.

      If you should see someone who works for the NRA, hand them a roll of toilet paper.

    2. Re:So here it is by Anonymous Coward · · Score: 1

      The NRA. It pooped its pants right there in the public square. And rather than trying to clean up, it just stands there yelling "MY SHIT DON'T STINK!" while continuing to make squeaky farts..

      This is probably go to a new school next year level public humiliation, but they apparently have no shame.

      If you should see someone who works for the NRA, hand them a roll of toilet paper.

      The NRA protects your right to use weapons for legitimate and legal purpose.

      The NSA creates weapons to be used any way they please, legal or otherwise.

      Kindly fuck off with your senseless analogies.

    3. Re:So here it is by BlueStrat · · Score: 2

      The NSA. It pooped it's pants right there in the public square. And rather than trying to clean up, it just stands there yelling "MY SHIT DON'T STINK!" while continuing to make squeaky farts..

      This is probably go to a new school next year level public humiliation, but they apparently have no shame.

      If you should see someone who works for the NSA, hand them a roll of toilet paper.

      OMG I wish this would become a thing!

      Order toilet paper sent to NSA HQ! Bury them in literally tons and tons of shit-paper every single day! Photos of piles of rolls at their doors and trucks lined up to unload more making the rounds on social media, the news cycle, etc!

      Let's make it possible for drivers to see a new sign along the highways in Virginia; "See The World's Largest Mountain Of Toilet Paper! Visit NSA HQ Alexandria Next Exit!"

      Destroy them with laughter! Make them such a worldwide joke (I know, they already do such a good job) that nobody takes them seriously and nobody wants to work for nor be associated with them.

      Strat

      --
      Progressivism (aka US 'Liberalism'): Ideas so good they need a police/surveillance-state to enforce.
    4. Re:So here it is by Anonymous Coward · · Score: 0

      The NSA lobbies for the rights of arms manufacturers to remain massively profitable.

    5. Re:So here it is by OutOnARock · · Score: 1

      you are one stupid douchebag

  12. Encrypted message for the Saved: by Anonymous Coward · · Score: 0

    NOTICE: IF YOU ARE NOT A MUSLIM, YOU ARE NOT AUTHORIZED TO READ THIS POST. PLEASE COMMIT SUICIDE IMMEDIATELY, YOU FUCKING INFIDEL. (IF YOU ARE GAY, ALSO PLEASE COMMIT SUICIDE)

    74. 29. 49. 32434. 320. 20. 10. 30293. 405. 2-1. 384. 54345612 23454954. 933. 92224. 94950393 82930493.

    The butter covered boy must be kidnapped, and made to be a sex slave. For men.

    95933. 3495. 91002993. 493023. 4994. 2043994905049. 9320 939 495002.

    As the cloud spreads and drops the rain, the moon smiles. In pain.

    39. 455. 102332. 59030 390200039549. 49200 382. 38483. 930020934.

    Jump inside the puddle. Remain inside the mandelbrot set.

    1. Re:Encrypted message for the Saved: by Anonymous Coward · · Score: 0

      We are one. Our blood we shed for The Prophet. Our souls, we give to The Prophet. Only when we have given our All to The Prophet can we save Humanity. We Must Kill Ourselves, and in so doing, Save Ourselves, and Save Humanity.

      Allahu Ackbar.

  13. If the corporations weren't identical to the gov. by kelanos · · Score: 1

    The market would be tanking.

    How can anyone innovate, compete, and do business when everything they make can be destroyed 'with a click of a button'?

    This situation is enforcing the status quo to a hideous degree. The time is long past for violent revolt.

  14. This rollercoaster ride is just getting started. by Ungrounded+Lightning · · Score: 2

    But the silence is wearing thin for victims of the assaults, as a series of escalating attacks using N.S.A. cyberweapons have hit hospitals, a nuclear site and American businesses.

    IMHO it's just getting started. The source code to a whole BUNCH of their tools has gotten out - a treasure trove for the bad guys. Now they don't have to design this stuff themselves - it's all there, ready to be customized. We're just seeing the leading edge from the early adopters.

    Now there is growing concern that United States intelligence agencies have rushed to create digital weapons that they cannot keep safe from adversaries or disable once they fall into the wrong hands.

    Well, DUH! If you've got the source it's anywhere from reasonably easy to trivial to disable or change any kill switch. Changing vulnerable mechanisms key to the operation are more difficult, but still doable. So even if they did spend extra engineer time to build in the equivalent of "gun smart chips" - and they worked - it would, at best, be initially mitigating but ultimately futile.

    --
    Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
  15. ....or introduce security flaws by HalAtWork · · Score: 1

    ....or introduce security flaws that let the enemy use your own stock against you

  16. They can be undone by Anonymous Coward · · Score: 0

    "create digital weapons that they cannot keep safe from adversaries or disable..."

    We can't un-invent nuclear, chemical or bacterial weapons, But we can fix the vulnerabilities exploited by cyber weapons. The NSA **chose** not to tell the vendors about the vulnerabilities they found.

  17. Re: This rollercoaster ride is just getting starte by Anonymous Coward · · Score: 0

    The thing is, the vulnerabilities are the valuable code anyways. The rest of the stuff, the command and control, etc are shit that can be cobbled together by a random kid out of MIT in a weekend.
    So once those are leaked the vendors are able to patch pretty quickly. Then it's a matter of patch deployment which is unfortunately a hot mess.

  18. Weak Encryption by Anonymous Coward · · Score: 0

    We could have very strong encryption, hardware, and software as well as very secure infrastructure. But noooo. The NSA and other 3 letter organizations got industry to put out weak versions of all of this just so they could easily hack into anything. And now it is coming full circle. What private industry needs to do is blow the whistle on all the crap the NSA, CIA, FBI, etc. have forced them to do in regards to weakening their products. And then go about strengthening everything.

  19. not IDENTIFIABLY used... FTFY by Anonymous Coward · · Score: 1

    There is plenty of speculation to be made over have many of the current 'epidemics' we've had in the recent world are simply mutations, versus being field testing of refined biological agents against captive populations.

    Dump a slightly modified flu virus in your own, or a foreign nation's livestock, one intended to hop into humans, then wait and watch and document its effectiveness, issues, etc. Make individual changes across dozens of mild contagions, then use the resulting field data to help refine the 'master agent' combining each technique you utilized on individual samples to create something far more effective.

    It is about as farfetched as a US Space Corps...

  20. Re: This rollercoaster ride is just getting start by Anonymous Coward · · Score: 0

    I find it odd that a kid has to be from MIT to do this, you place the bar pretty high. Actually, anyone with basic coding skills can do this stuff, especially the latest ransomware. These are criminal gangs, I doubt they recruit MIT students.

  21. The other thing to remember by PraiseBob · · Score: 3, Informative

    One other aspect to keep in mind- For YEARS now, the intelligence services of the USA have been pouring millions of dollars a year into the Black Hat Black Markets, where these vulnerabilities are traded and sold. They aren't some bit player, occasionally picking up a new trick, they are the primary source of funding to many of these marketplaces.

    The bugs would still exist either way, but the government has been intentionally funding organized crime into developing these vulnerabilities, and making the situation much worse. Since they are the primary entity putting money into this marketplace, they are playing the key role to allow black hats to quit their day job and focus on writing exploits.

    1. Re:The other thing to remember by Anonymous Coward · · Score: 3, Insightful

      [citation needed]

  22. It's a game theory problem by modzer0 · · Score: 2

    The thing about vulnerabilities is one single entity can't find everything. If you're then disclosing those to get everything patched you are harming your offensive capabilities. It may impact another party's offensive capabilities as well, but it's very likely they have vulnerabilities that you don't know about. So then you have a double edged sword. Do you keep the exploit to use offensively and risk the undisclosed exploit being used against you, or disclose it and still risk another undisclosed exploit you don't know about still being used against you? Exploits are a limited resource and they expire. Once used they have an even shorter shelf life before discovery. You don't know when things will get discovered by another party as well. They need a constant influx of new vulnerabilities because the ones they have may not be useful against an assigned target tomorrow. Your warhead, information collection, and mission ability is all determined by the offensive software you have at your disposal. Everyone else will call it malware. A reachable known target can be implanted with a non-replicating tool. These are the most covert, but also the most difficult as you may not have a direct path to the target machine. That goes into getting access to a well defended network. That requires something that spreads on it's own so it can possibly reach the machines you need coverage on. This is also a double edged sword as putting in limitations to spreading also gives away the fact it's not a random infection. Those type of tools always end up spreading to unintended places and getting examined by security researchers. If a worm component is added then you cross into the realms of epidemiology and outbreaks though without geographic isolation as a barrier. It only takes one user in a network to get infected and then it'll spread until AV and OS patches catch up. So disclosing vulnerabilities isn't always an option if you want to remain effective offensively. It becomes a lot like a classic game theory problem The strategic choice would be to hang onto as many vulnerabilities as long as they can, and that's what everyone does.

    1. Re:It's a game theory problem by Anonymous Coward · · Score: 0

      The NSA knew these vulnerabilities were close to being discovered or were already discovered by foreign state actors. Instead of risking the repercussions of independent tool development the NSA allowed these to escape. This will effectively stop independent development since they are easier to use than starting from scratch. Unbeknownst to the hackers who will subsequently deploy the tools, the code released by the NSA will be used to trace the development history of each tool. In doing so the NSA will be able to compile a detailed map of the hacking networks that used the tool. These headline news stories are being used to sell the tools to any hacker group naive enough to use them.

    2. Re:It's a game theory problem by AHuxley · · Score: 1

      The problem is the automated side of a lot of the gov backed malware.
      Visit a site get gov malware. Have wifi on at a location, get gov malware.
      "A reachable known target can be implanted with a non-replicating tool."
      That was seen with "The Inside Story of How British Spies Hacked Belgium’s Largest Telco"
      https://theintercept.com/2014/...
      "The hack would remain undetected for two years, until the spring of 2013."
      Re "This is also a double edged sword as putting in limitations to spreading also gives away the fact it's not a random infection."
      The US is back to the sword and shield problem. Contractors want to sell the gov products and earn over time. The gov needs to go on missions, have good news to tell and request more budget growth. The US also has to be protected from all such efforts in the wild. AV brands must also not discover any tools in the wild.
      AV brands must blame other nations thanks to code litter, lungs, servers, ip found, private sector experts talking to the media.
      It all works if its just the mil, gov and special forces doing the work around the world. The UK showed what could be done in the 1950-90's with much less funding and less staff.
      Too many contractors, too many new staff having to get results to keep funding. The politics, faith, interests, contacts of so many new staff.
      Vetting slows or is just transferred from some past employment and interesting people get very interesting jobs.
      Tools walk, are sold, get lost, given to other nations due to their need or to charm other govs and make friends, get found in use in the wild, kept for later and sold, tested from home.
      So many well understood issues due to so many missions and rapid expansion. Security should have kept up.

      --
      Domestic spying is now "Benign Information Gathering"
    3. Re:It's a game theory problem by AHuxley · · Score: 1

      A limited hang out to see who finds what, comments on what, who has skills?
      Most other security services learned from that in the 1920-60's and now know to question why interesting things that just appear.

      --
      Domestic spying is now "Benign Information Gathering"
  23. good for you by Anonymous Coward · · Score: 0

    it's about doing a NON-SERICE.

    logically thought through, hording code bugs is to keep systems buggy overall.
    they don't believe in improving the computing environment but instead believe
    in creating a global environment of buggy software(*) for their benefit.

    if the 3 l3tt3rs were guys with moral they would subscribe to the tough but worthy
    cause of improving the global computing environment.
    some might argue, that it is not possible to make computing 100% secure but just throwing out the baby with the bath water is not the impression that the American founding fathers had in mind when creating the nation?

    in other words, they are saboteurs not builders and creators!

    (*)considering that this is a american governmental branch and that a lot of computer tech,
    like cpus and software is created in the same country (and pays some taxes) this is extremely astonishing: the state doing you a DISSERVICE!

  24. So how many? by CODiNE · · Score: 1

    If a couple 0dayz (+ a month or two) can cause this kind of a mess. Then how many guys worldwide are actively writing exploits? I think the skill should have at least a few thousand practitioners, so where is the daily chaos?

    I do see to some extent the frustration the NSA must have over this. If the abusers weren't dropping ransom ware everywhere this wouldn't have had such a huge impact.

    Nasty 0days come out every week.

    --
    Cwm, fjord-bank glyphs vext quiz
  25. Butterfingers by Anonymous Coward · · Score: 0

    Maybe work on something that improves your grip?

  26. Remember Coventry by dynamator · · Score: 1

    It was alleged (and since debunked) that during WW II Churchill sacrificed Coventry to mask the fact that the British had compromised German military ciphers. Does the sequestering of these exploits really serve the greater good? By its actions, the NSA has failed in what SHOULD be it's primary goal to preserve the life, liberty, and property of the citizens of our nation and our allies.

  27. Traitor worship by mi · · Score: 0

    Sure, leaks are illegal. But, unless they are also considered wrong, people will keep doing them — for publicity or other aggrandizement, etc.

    The constant harping on the US in general and the NSA in particular creates the perception, that hurting and embarrassing both somehow improves the world — a demonstrable falsehood.

    Similarly, the worshiping of Snowden, who fully bought into the above-mentioned falsehood, and of Manning, who leaked the classified data not even to make the world a better place, but simply to impress acquaintances — make leaking glamorous even if still dangerous. And copy-cats follow.

    This traitor-worship ought to stop. Even if you do (foolishly) believe, NSA is evil, you still can not betray the secrets entrusted to you — just as you would not murder, for example, to "raise awareness". Not only because it is illegal, but also because it is wrong.

    --
    In Soviet Washington the swamp drains you.
  28. Wait it out by gatkinso · · Score: 1

    Soon enough these exploits will be patched.

    The NSA would be insane to get involved.

    --
    I am very small, utmostly microscopic.
    1. Re:Wait it out by Anonymous Coward · · Score: 0

      Soon enough these exploits will be patched.

      because you know FOR SURE that all of the NSA's exploits have been made public

      sucker

  29. Wrong hands by Anonymous Coward · · Score: 0

    The phrase "fall into the wrong hands" is often used in articles like these. I would say that with the U.S. past 70 years of history, these weapons were in the wrong hands the moment they were created.

  30. Check it out! by Anonymous Coward · · Score: 0

    Another Slashdot article that will draw so many foreign opinions (er, scripted talking points) about American intelligence apparatus!

  31. Hacks Raise Fear Over NSA's Hold on Cyberweapons # by najajomo · · Score: 1

    Seriously as long as you don't use Microsoft Windows on the Intel chip set you should be safe. And who exactly had their fear raised over this. What I would like to know is what retard made the decision to store all his hacking tools on the Internet.

  32. And even deeper is the great irony... by Paul+Fernhout · · Score: 1

    From my essay: http://www.pdfernhout.net/reco...
    "Likewise, even United States three-letter agencies like the NSA and the CIA, as well as their foreign counterparts, are becoming ironic institutions in many ways. Despite probably having more computing power per square foot than any other place in the world, they seem not to have thought much about the implications of all that computer power and organized information to transform the world into a place of abundance for all. Cheap computing makes possible just about cheap everything else, as does the ability to make better designs through shared computing. ...
        There is a fundamental mismatch between 21st century reality and 20th century security thinking. Those "security" agencies are using those tools of abundance, cooperation, and sharing mainly from a mindset of scarcity, competition, and secrecy. Given the power of 21st century technology as an amplifier (including as weapons of mass destruction), a scarcity-based approach to using such technology ultimately is just making us all insecure. Such powerful technologies of abundance, designed, organized, and used from a mindset of scarcity could well ironically doom us all whether through military robots, nukes, plagues, propaganda, or whatever else... Or alternatively, as Bucky Fuller and others have suggested, we could use such technologies to build a world that is abundant and secure for all.
        So, while in the past, we had "nothing to fear but fear itself", the thing to fear these days is ironcially ... irony. :-)"

    Thanks for the interesting link to the harvardpolitics site.

    --
    A 21st century issue: the irony of technologies of abundance in the hands of those still thinking in terms of scarcity.
    1. Re:And even deeper is the great irony... by AutodidactLabrat · · Score: 0

      Glad to be a voice in the wilderness of Slashdot Libertarian alt-right nonsense

  33. Lets not forget the propigators by Anonymous Coward · · Score: 0

    Isn't Wikileaks somewhat responsible here, after all one can't just drop loaded guns on a playground and then disavow all responsibility for the mayhem that would follow.

  34. Re: Reminds me of how when there is a mass shootin by Anonymous Coward · · Score: 0

    And they're both wrong.