3 ms·
Seems safe to assume that everybody's been infected by this point, eh?
by LoveLeadAcid 5y ago
Seems safe to assume that everybody's been infected by this point, eh?
- viraptor 5y agoNo. More infections = more noise. If you want to target specific people for a long time, you want to make as little noise as possible. This includes unexpected traffic, file artefacts, background energy use, etc. Although now that the cat is out of the bag, I'm sure some groups are working to reproduce it for mass-infection. Especially since this looks wormable.
- LoveLeadAcid 5y agoI disagree, the NSA has shown us all that sucking in all data and worrying about sorting it later is the way to go. EDIT: yikes, I’ve upset the Unit 8200 agents.
- viraptor 5y agoThis is a different context, different targeted group, different use case, than what we've seen with global NSA monitoring. You're comparing apples to oranges.
- meowface 5y agoPassively collecting data on the wire is different from actively exploiting a device to execute malware. Any entity trying to work with intelligence agencies is definitely going to be careful and somewhat sparing with their use of an "S-tier" zero-day like this. (Unless they have reason to believe it's already likely been burned, in which case they might decide to hastily machine gun it while it's still viable.)
- alfalfasprout 5y agoWith extremely valuable zero-days like this targeting is the way to go b/c you don't want the zero-day discovered by putting it out extensively in the wild. Obviously it's always a question of time anyways.
- mhh__ 5y agoThey are able to drink from the firehose, though. This is an exploit on a device rather than a nations infrastructure. That being said Stuxnet had done its business before it went public.
- fmajid 5y agoThe NSA was unable to protect its offensive crown jewels from the Shadow Brokers, and when they could not auction them off and decided to just release them in the public domain, that led to things like Wannacry or Petya that almost sank (pun intended) the world's No.1 shipping line, Maersk. And yet those buffoons want us to trust them with master decryption keys for all encryption protocols.