3 ms·
“When they deploy malware on systems,” Hypponen says, “they potentially create new vulnerabilities in these systems, making them more vulnerable for attacks by
by bitsteak 13y ago
“When they deploy malware on systems,” Hypponen says, “they potentially create new vulnerabilities in these systems, making them more vulnerable for attacks by third parties.”
Really, how does that work Mikko? You don't even have a copy of any malware to make that statement.
All the hyperbole about how this is somehow unique is really getting old. Exploit kit authors have had shitty PHP web applications that accomplish the same task for ages: manage thousands of bots by grouping them together with a point and click management interface. It sounds like, prior to TURBINE, NSA had a single person tasked to oversee every action taken by hand, which is kind of inefficient if you ask me, so it stands to reason they would try to manage that process with technology.
How do you cool yourself First Look when you're reporting on this in 2014? Jeez.
- pkinsky 13y agoBotnets require remote management. This means adding hidden backdoors, with the assumption that they will remain hidden. If such a backdoor becomes known to bad actors, they will exploit it. Unless you're asserting that adding back doors makes a system more secure.
- jmcmichael 13y ago> Really, how does that work Mikko? You don't even have a copy of any malware to make that statement. Simple: every process running on a system is a process that can be exploited, especially those processes that involve network communication. The NSA's exploits are processes running on the system they are attacking. They utilize network communications. These processes are open to exploitation by third parties, just like all the other legitimate processes.
- jmcmichael 13y ago> All the hyperbole about how this is somehow unique is really getting old. The big news is that the most powerful people on the planet are now using the same script-kiddie techniques against the rest of the world, in secret, without oversight, on an industrial scale. EDIT: Judging from your github account, you appear to be a developer working on a open-source whistleblower platform. Given that the NSA's efforts would likely be focused on the users applications such as yours, do you not find these revelations to be directly relevant to your goals in developing this software?
- dTal 13y agoHypponen said "potentially" and it is an absolutely defensible statement. You go around poking holes in a system, don't be surprised if other people find the holes. You gonna trust the guy who hacked your machine to lock the door behind him on the way out? >All the hyperbole about how this is somehow unique is really getting old. The issue isn't that the spooks have developed some superweapon. The issue is that they've signaled intent and means to do mass espionage on citizens, not just at the network level, but at the machine level. This is as if your local law enforcement handed out burglars tools to all their officers so they could get into everyone's homes "to check for drugs". "Eh, burglars tools are nothing special" totally misses the point.
- gregsq 13y agoDefinition of the word 'potential' cited in the Oxford Dictionary. "Having or showing the capacity to develop into something in the future" Or alternatively "Having possibility, capability, or power." Or in Merrium-Webster: "expressing possibility ; specifically : of, relating to, or constituting a verb phrase expressing possibility, liberty, or power by the use of an auxiliary with the infinitive of the verb (as in “it may rain”)" I can see no difficulty in the authors expression of the idea of possibility.