4 ms·
I don't know how you can cite an example of Eternalblue and in the same sentence dismiss the risk. https://en.wikipedia.org/wiki/EternalBlue https://en.wikiped
by stainforth 6y ago
I don't know how you can cite an example of Eternalblue and in the same sentence dismiss the risk.
https://en.wikipedia.org/wiki/EternalBlue https://en.wikipedia.org/wiki/EternalBlue "On May 12, 2017, the worldwide WannaCry ransomware used this exploit to attack unpatched computers.[6][8][9][10][11][12]:1 On June 27, 2017, the exploit was again used to help carry out the 2017 NotPetya cyberattack on more unpatched computers."
- meowface 6y agoIn all of my posts I made it very clear that ETERNALBLUE and other leaked zero-days are an extremely serious risk. In each post, I variously described them as "turn-key WMDs", "magic powers bestowed onto ordinary people", and "huge risks", and included zero-days as an important caveat for everything I was trying to say. I don't at all mean to downplay the severity of the risk of leaked zero-days in the slightest. It's massive. ETERNALBLUE leaking was an unprecedented fuckup, not unlike a government bioweapons facility accidentally leaking a supervirus that causes a pandemic. (Not trying to say anything about COVID, here; just an apt analogy, I think.) However, I'd also say that zero-days aren't tools or part of tooling. They're discovered vulnerabilities - privileged knowledge, basically. Intelligence agencies possess a lot of privileged information which could be very damaging if leaked. If a software tool contains an exploit for a zero-day, thus leaking the zero-day, then, yes, the tools themselves are a huge threat. But I'm thinking more about the typical hacking and engineering tools you'd see, which generally aren't very weaponizable by the general public and not that interesting besides the purpose of potentially detecting their past usage and discovering things an intelligence agency might have done. That's why I said "as long as the zero-days and backdoors stay private, I think there isn't that much concern". I interpreted the poster as being concerned about the more ordinary things (they mentioned password cracking and botnets, for example), though I think I misunderstood them.