10 ms·
Leaked NSA Malware Threatens Windows Users Around the World
- cm2187 9y agoWhat I find sort of (a little) comforting is that the NSA seems to be relying on zero days. All these leaks have not really revealed any structural backdoor in any of the major operating systems.
- dorianm 9y agoFor instance, the LastPass vulnerability was an architectural mistake.
- ajross 9y agoThat's my feeling too. Likewise for hardware backdoors. Yes: it's certainly possible that these things exist. But if they do they're exotic and closely held. They aren't part of the routine hacking toolkits in use in the intelligence community. Routine surveillance happens via routine means that we've already baked into threat models. In this case, it seems (though I can't find confirmation) like standard firewalling of SMB (what you get if you click the "untrusted network" category on connecting to the cafe wifi or whatever) would be enough to protect a user.
- deleted 9y ago[deleted]
- draugadrotten 9y agoIt could be necessary for NSA to rely on zero days or implanted bugs. Any entry point must be possible to close quickly, as soon as the enemy discovers it. Creating what you call structural back doors would make it possible for the enemy to use the same structural back door. Along these lines, I would expect the NSA to encourage the use of cryptography and encrypted software/Secure Boot/secure communications while they ensure the NSA have a set of extra keys and can sign software at will.
- cm2187 9y agoYou can use public-private key cryptography that the enemy cannot compromise unless they compromise the NSA (the private keys).
- draugadrotten 9y agoWell, there are known stories of "accidental" key leaks: https://www.schneier.com/blog/archives/2016/08/microsoft_accid.html https://www.schneier.com/blog/archives/2016/08/microsoft_acc...
- deno 9y agoThat would still stand out as a sore thumb. Deliberate introduction of hard to exploit 0days would be precisely how they would do it. All you need is one plant with commit access.
- Cyph0n 9y agoPublic key crypto can be broken if the certificate isn't securely pinned on the client. In other words, the adversary could insert their own cert and replicate the exploit.
- aub3bhat 9y agoWait what? Cert pinning is not required for RSA pkcs.
- nnfy 9y agoPerhaps this "leak" was intentional and designed to obscure darker dealings by our friendly NSA.
- CamperBob2 9y agoEspecially if it has the effect of driving more Windows 10 uptake.
- lawnchair_larry 9y agoHere's a twist: they're the same thing. Most seasoned security folks know that the way to backdoor something is to leave an innocent bug in it. Plausible deniability, impossible to prove it was a backdoor because it looks just like any other exploitable bug. Not that I'm suggesting that the NSA did leave these as backdoors. I don't believe that to be the case. But if you want one, that is how you do it. If you ever find a blatant backdoor in some software, you're either dealing with an amateur, or someone who wanted to be found in order to send a message/misdirect you.
- inetknght 9y agoI was going to say basically the same thing. :+1:
- handedness 9y agoIf only there was a means by which you could vote his comment up so as to indicate your agreement.
- inetknght 9y agoYeah man, if only upvoting something could be measured against something other than raw count.
- cm2187 9y agoThe problems with bugs is that they can be exploited by the bad guys. A door with a public private key can only be exploited by you.
- kichik 9y agoThey did have a backdoor in the Dual_EC_DRBG PRNG algorithm that was widely used. It's not a major operating system, but it was used in a lot of products. https://en.wikipedia.org/wiki/Dual_EC_DRBG https://en.wikipedia.org/wiki/Dual_EC_DRBG
- trendia 9y agoThere are diffeeent levels of ethics in hacking: 1) finding a bug and notifying the company 2) finding a bug and releasing/selling 3) finding a bug and using it 4) intentionally adding bugs to software without notifying anyone 5) intentionally adding bugs to software and claiming it's secure This was level 5
- kichik 9y agoYou could potentially argue it's even worse. They paid RSA to intentionally add a bug so they can't be directly blamed for it.
- throwaway2048 9y agofinding a bug and releasing it, and finding a bug and selling it are hardly equivilent.
- rdtsc 9y ago> NSA had worked during the standardization process to eventually become the sole editor of the Dual_EC_DRBG standard, Yes that was a devilishly well executed backdoor, on so many levels.
- beagle3 9y agoMostly on the political level; it was considered suspect by serious cryptographers essentially as soon as it was introduced.
- pdkl95 9y ago> backdoor A backdoor is far too obvious for widespread use, which is the needed anyway. The NSA (and FVEY in general) instead spends a lot of money on programs like BULLRUN (Edgehill at GCHQ) that try to bypass the need for backdoors and weaken encryption. PSYOPS for nerds[1] is much cheaper and easier than direct backdoors or other technical methods. Instead of a backdoor we have IPSEC standards that is overly complicated, had to implement, and mandated "null" encryption support[2]. Most communication channels remain in plaintext or encrypted with keys that are recoverable, too short, or easily MitMed. [1] https://archive.fosdem.org/2014/schedule/event/nsa_operation_orchestra/ https://archive.fosdem.org/2014/schedule/event/nsa_operation... [2] http://www.mail-archive.com/cryptography@metzdowd.com/msg12325.html http://www.mail-archive.com/cryptography@metzdowd.com/msg123...
- stordoff 9y ago1. I imagine they'd be more or less the same thing. Any mandated/deliberate backdoor is probably going to look very similar to an accidental bug - it lets you deny it exists, gives a valid explanation for if/when it is found, and potentially lets an NSA/software company "double-employee" add it without the company knowing. 2. It'd probably be a method of last resort, so the NSA et al. would gather and use zero days anyway. Any use of the backdoor risks it being noticed, so using other entry points make sense if possible. A less comforting interpretation would be that relying on zero days suggests they are confident in their ongoing ability to find them and/or have a sizeable cache of unknown exploits already, so adding a deliberate backdoor wouldn't provide any additional access.
- rdtsc 9y ago> lets an NSA/software company "double-employee" add it without the company knowing. I always wondered how that works. I am a full time employee at software company. Cannot imagine having extra time to report to another employer (NSA) and deal with their red tape and crap as well. Or does NSA show up at their doorstep with a bag full of cash - "Here you go, have this, and install a backdoor in your company's software. And we never met <wink>, <wink>" That sounds good on paper so to speak, I just have a hard time imagining a realistic scenario. Now finding 0-days and hoarding them, I can see that.
- toyg 9y agoYou assume the mole is an MS employee first and an NSA op second. Traditionally, the opposite is true: if you want to infiltrate a somewhat friendly entity, you do it by engineering the hire of trusted individuals. This is more secure, since there is no risk that one of the guys will get cold feet and blow the whistle. So you monitor universities and you make contact with some of the brightest sparks. You promise them a good job in exchange for the possibility that, one day, they might have to act For The Good of The Country; and in the meantime they'll even be In The Know, which will place them above their peers - excitement! Ambition! Then you lobby a few higher-ups you're friend with, to hire these guys in this or that group. They are top-notch talent, immaculate credentials, so the hire is a slam dunk. They go about their business, being good kernel devs or whatnot, and every few months you give them a quick call to catch up - there is no need for extensive briefing, nobody really cares about the going-ons of Team Kernel A356. When "the favour" is required, the guy is comfortable in his position and doesn't want to leave it, so there is no chance he'll say no.
- eps 9y agoIs there a list of exact attack vectors for the lazy? Both tools in the demo video are SMB-based. I wonder how exploitable is a machine if it has SMB properly disabled and blocked.
- jlgaddis 9y agoThere's an incomplete "summary of leaked data" at https://www.bleepingcomputer.com/news/security/shadow-brokers-release-new-files-revealing-windows-exploits-swift-attacks/ https://www.bleepingcomputer.com/news/security/shadow-broker...
- cm2187 9y agoLooking at this list it seems to affect mostly older versions of windows servers and servers with SMB running. I'd say it would mostly be a problem on intranets than windows based web servers.
- noinsight 9y ago> and servers with SMB running. Which is going to be Domain Controllers, the most highly privileged servers on most corporate networks. And accessible to the "entire" network too. Group Policy is distributed through SMB shares.
- deleted 9y ago[deleted]
- gerdesj 9y agoDisabling SMB is possible but it means you will not be accessing a Windows file share or providing one. Fine if you don't need it. https://support.microsoft.com/en-gb/help/2696547/how-to-enable-and-disable-smbv1,-smbv2,-and-smbv3-in-windows-vista,-windows-server-2008,-windows-7,-windows-server-2008-r2,-windows-8,-and-windows-server-2012 https://support.microsoft.com/en-gb/help/2696547/how-to-enab... For my money, disable SMBv1 anyway and use a firewall and (V)LANs. Samba, pop this under [global] to disable SMBv1 min protocol = SMB2 To disable it try "systemctl stop smbd" or "/etc/init.d/smbd stop" or ... 8)
- symlinkk 9y agoDirect link to the leak: https://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-translation https://steemit.com/shadowbrokers/@theshadowbrokers/lost-in-... RIP Windows users.
- alpb 9y agoRelevant tweets from/retweeted_by @snowden - https://twitter.com/Snowden/status/852950725881712640 https://twitter.com/Snowden/status/852950725881712640 - https://twitter.com/campuscodi/status/852885596221689856 https://twitter.com/campuscodi/status/852885596221689856 - https://twitter.com/Snowden/status/852989758364147712 https://twitter.com/Snowden/status/852989758364147712 - https://twitter.com/josephfcox/status/852983848862461953 https://twitter.com/josephfcox/status/852983848862461953 - https://twitter.com/Snowden/status/852987207170371587 https://twitter.com/Snowden/status/852987207170371587 - https://twitter.com/alexstamos/status/852984589463175169 https://twitter.com/alexstamos/status/852984589463175169 - https://twitter.com/Snowden/status/852974864461963265 https://twitter.com/Snowden/status/852974864461963265 - https://twitter.com/TalBeerySec/status/852869388067844096 https://twitter.com/TalBeerySec/status/852869388067844096 - https://twitter.com/Snowden/status/852967606088806401 https://twitter.com/Snowden/status/852967606088806401 - https://twitter.com/Snowden/status/852966739084275712 https://twitter.com/Snowden/status/852966739084275712 - https://twitter.com/josephfcox/status/852908421703753728 https://twitter.com/josephfcox/status/852908421703753728
- spangry 9y agoI really regret reading some of the replies to those tweets. There's something I need to know: the people going on about Snowden being a traitor, helping 'the Russians' etc... On the 'average American' to 'village idiot' scale, which end are these people closer to? This is not a rhetorical question btw. I just want to get some insight into what the 'average American' thinks about Snowden.
- deanclatworthy 9y agoI've been following this closely over the last couple of hours on Twitter as the news broke. What does it mean in practice? From what I have read one of the vulnerabilities seems to be a 0day targeting SMB on Windows. One commentator suggested it's enabled by default on the majority of Windows machines (of that I am sceptical). Presumably most people are behind a router which would stop this in its tracks? A lot of people (who I would probably take seriously) suggest disconnecting Windows machines from the internet for the time-being. Is it really this bad? Are there millions of Windows (home-)users who are vulnerable (by default) today?
- BinaryIdiot 9y ago> Presumably most people are behind a router which would stop this in its tracks? Trouble is there are millions of IoT devices with terrible security some of which are alway owned and inside the network. They could be used as a delivery tool to attack multiple machines inside of a network. I'm not sure how many folks connect directly to the internet anymore. Hopefully not many.
- Teichopsia 9y ago"Connect directly". Could you please elaborate on that?
- BinaryIdiot 9y agoConnecting a computer directly to a modem, not a router.
- Teichopsia 9y agoThanks.
- jacquesm 9y ago> One commentator suggested it's enabled by default on the majority of Windows machines (of that I am sceptical). It's been a while since I used windows but there used to be such a thing as the administrative share. https://en.wikipedia.org/wiki/Administrative_share https://en.wikipedia.org/wiki/Administrative_share So I don't find that hard to believe at all.
- UnoriginalGuy 9y agoThis entire article is a gross mischaracterisation of the facts and risks. The only major zero days released for Windows in this bundle targeted SMB (SMBv1, SMBv2, & SMBv3). By default Windows firewalls SMB and has since Windows XP SP2. Many home and business users then typically have a NAT between the Windows Firewall and the internet, offering a second layer of protection. Few companies intentionally expose SMB to the internet. Generally users are required to VPN in before then being able to contact an SMB endpoint. The type of language in this article is designed to mislead non-technical readers into believing they're at risk e.g.: > The software could give nearly anyone with sufficient technical knowledge the ability to wreak havoc on millions of Microsoft users. So either the article author lacks the technical literacy to understand why this is untrue, or they know it to be untrue and are trying to implant fear into their readership. In either case, not a good look for The Intercept.
- 086421357909764 9y agoIsn't that the Intercepts whole M.O. though?
- jacquesm 9y ago> Few companies intentionally expose SMB to the internet. True, but in your average coffee shop setup if a user has SMB running you could reach them via a local IP if it isn't firewalled off on the machine itself.
- vmarsy 9y agoI think jlgaddis' link[1] is more informative than the theintercept.com article : https://www.bleepingcomputer.com/news/security/shadow-brokers-release-new-files-revealing-windows-exploits-swift-attacks/ https://www.bleepingcomputer.com/news/security/shadow-broker... I feel the HN submission should point to that instead. The Outlook Exchange, RDP, Kerberos, ... exploits are scary, even though some only seem to affect older Windows versions. [1] https://news.ycombinator.com/item?id=14117336 https://news.ycombinator.com/item?id=14117336
- nthcolumn 9y agoSo MSFT to take a pasting when the exchange reopens?
- ChuckMcM 9y agoWouldn't it be nice if the NSA turned over all of its now compromised zero days to Microsoft so that Microsoft could patch them all?
- israrkhan 9y agoI find it very irresponsible that NSA did not report these vulnerabilities to Microsoft after they had fallen into hands of shadow broker (no longer zeroday). Shadowbroker announced possession of these zerodays around 3 months ago. NSA had good 3 months to work with Microsoft to patch these. They chose not to.
- SomeStupidPoint 9y agoIt's possible the NSA isn't sure what the Shadow Brokers have.
- emn13 9y ago...which doesn't make it any less irresponsible. However, judging by https://technet.microsoft.com/en-us/library/security/ms17-010.aspx https://technet.microsoft.com/en-us/library/security/ms17-01... it's likely somebody had some advance knowledge, somehow. Oh, and hey: https://blogs.technet.microsoft.com/msrc/2017/04/14/protecting-customers-and-evaluating-risk/ https://blogs.technet.microsoft.com/msrc/2017/04/14/protecti...
- israrkhan 9y agoIn their original leak, Shadowbroker released a list of all file names in the encrypted part of the archive. They just did not release the password at that time. See following tweet by shadowbrokers from Jan 7. https://twitter.com/shadowbrokerss/status/817960380815306752 https://twitter.com/shadowbrokerss/status/817960380815306752
- bigbugbag 9y agoWhy would they ? Have they ever done something similar ?
- sigmar 9y agoAll of the vulnerabilities were patched by March. https://blogs.technet.microsoft.com/msrc/2017/04/14/protecting-customers-and-evaluating-risk/ https://blogs.technet.microsoft.com/msrc/2017/04/14/protecti...
- andrewvijay 9y agoOh yes! I have my brothers windows7 laptop in my home now. Im on a mac. Can I remotely hack that windows machine from my mac using any of these exploits? Can someone help? What are the things that I should know ?
- fixxer 9y agoUsing Windows threatens Windows Users Around the World.
- fixxer 9y agoUsing Windows threatens Windows Users Around the World.