6 ms·
Distrusting Windows was the wisest thing you did since you climbed off your horse. [1] No, seriously. How is it paranoia to think the NSA was/is surveilling yo
by zippoxer 9y ago
Distrusting Windows was the wisest thing you did since you climbed off your horse. [1]
No, seriously. How is it paranoia to think the NSA was/is surveilling your Windows installation if we already have proof that they have the means [2] and motivation [3] to do it at scale?
[1] http://www.quotes.net/show-quote/34121 http://www.quotes.net/show-quote/34121
[2] https://en.wikipedia.org/wiki/EternalBlue https://en.wikipedia.org/wiki/EternalBlue
[3] https://en.wikipedia.org/wiki/PRISM_(surveillance_program) https://en.wikipedia.org/wiki/PRISM_(surveillance_program)
- willstrafach 9y agoThere is no proof of means or motivation to use 0-days at scale. In fact, using EternalBlue "at-scale" would have caused it to not stay a 0-day for very long.
- sillysaurus3 9y agoThat's not true. When an exploit shows up on a computer, "How did it get there?" is often the hardest question. There's no way to know short of capturing it in a lab environment. If you're talking about "at scale" being "the entire world," then yes. But usually the NSA tends to target their operations regionally, e.g. Iran.
- shallot_router 9y agoAny use of a zero-day risks burning it, and this was one of NSA's most potent zero-days. I imagine they used it rarely and wisely; probably trying other exploits first.
- rdiddly 9y agoAnd so now it's in the hands of people who have no such foresight. Which means soon it will be mitigated. Which means that despite all the pain right now, in the long run Wikileaks actually may end up having kind of helped humanity.
- willstrafach 9y ago> Which means soon it will be mitigated. It was fixed in a security patch one month before the Shadow Brokers leak. All computers affected by this ransomware outbreak (and WannaCry) were those who decided not to patch.
- rdiddly 9y agoI suppose with the word "mitigation" kind of already having a connotation in the security community, I probably shouldn't have used it without making clear that I wanted the term to include its more banal implications such as "install the patch" and/or "get your systems off that old-ass OS!"
- boomboomsubban 9y agoWikileaks was not involved, they're securely posting CIA documents.
- deleted 9y ago[deleted]
- boomboomsubban 9y ago>and this was one of NSA's most potent zero-days. Says who? We have no idea what they're sitting on, even our guesses come from terrible data.
- willstrafach 9y agoTo clarify, I am not talking about attribution. When I say "not stay a 0-day for very long" I am referring to the fact that 0-day use by any threat actor is generally going to be very targeted, because the chance of a PSP and/or network tap logging artifacts or alerting the user is extremely risky in regards to potential exposure of the intrusion, causing the 0-day to likely get burned (Since discovery allows for detection signatures and patches to be quickly created, as well as remediations applied to affected systems).
- catdog 9y agoThey don't need to deploy 0days if the vendor (willingly or unwillingly) cooperates. Also Microsoft began to heavily spy onto Windows users as part of normal operation making it difficult to impossible to fully opt out.
- willstrafach 9y agoI don't understand how that would be possible. Such a change would be detected and very loudly discussed, making it pretty useless. There would be very little positive gain yet a whole lot of negative blowback from doing such a thing.
- maxander 9y agoI honestly cannot tell if this is brilliant sarcasm or if you'be somehow missed all the "very loud discussion" about Windows 10 on HN. :)
- willstrafach 9y agoIf you are referring to the level of analytics gathered, I fully agree! My point is, there would be a similarly loud reaction (at a wider scale) if a backdoor were introduced.
- cantchooseone 9y agoHow could you tell a backdoor from a regular bug? From a code perspective, of course.
- kahnpro 9y agoHave you installed Windows 10 lately? It's all there in plain English.
- willstrafach 9y agoI am definitely not a fan of all the default analytics gathered, not cool, but I took "cooperates" to be referencing legitimately malicious software.
- deleted 9y ago[deleted]