TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Hacking Team, Computer Vulnerabilities, and the NSA

73 pointsby nerdyover 9 years ago

6 comments

PhantomGremlinover 9 years ago
Schneier didn&#x27;t discuss what is IMO the biggest reason for NSA not to report vulnerabilities: it&#x27;s &quot;pissing into the wind&quot;, it&#x27;s futile. When 10 vulnerabilities are reported and fixed, 11 new ones are quickly found. The vulnerabilities are overwhelming us.<p>Back around the year 2000 Microsoft was being beaten up for all the vulnerabilities in their software. So in 2002 Bill Gates announced &quot;Trustworthy Computing&quot;.[1][2]<p><pre><code> Microsoft Chairman Bill Gates announced a major strategy shift across all its products, including its flagship Windows software, to emphasize security and privacy over new capabilities. </code></pre> In 2014 Microsoft finally threw in the last towel, folding the group they formed into other units. They gave up. Microsoft lost not because they were incompetent, but because the problem is too big to attack in a conventional manner.<p>I don&#x27;t know what the answer is, but we need to approach things very differently. To quote Dr. Peter Venkman: &quot;the usual stuff isn&#x27;t working&quot;.<p>[1] <a href="http:&#x2F;&#x2F;www.foxnews.com&#x2F;story&#x2F;2002&#x2F;01&#x2F;16&#x2F;bill-gates-announces-microsoft-strategy-shift-toward-security-privacy.html" rel="nofollow">http:&#x2F;&#x2F;www.foxnews.com&#x2F;story&#x2F;2002&#x2F;01&#x2F;16&#x2F;bill-gates-announces...</a> [2] <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Trustworthy_computing" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Trustworthy_computing</a>
评论 #10228077 未加载
评论 #10223726 未加载
tptacekover 9 years ago
There&#x27;s a fourth reason NSA wouldn&#x27;t have tipped off every vendor impacted by HT exploits: because they have no business breaking into commercial vulnerability research teams networks, grabbing their exploits, and burning them. It is in fact probably unlawful for them to do so (those actions having as they do an impact on US F-500 companies that use --- for better or worse --- tools from companies like HT to evaluate their own security).<p>This is a positive comment, not a normative one. I don&#x27;t know how I feel about entities busting up companies like HT, but I do think I know that the world would be better off without companies like HT.
评论 #10223620 未加载
评论 #10224176 未加载
评论 #10223770 未加载
codezeroover 9 years ago
While I wouldn&#x27;t put it past the NSA – why would we assume the NSA had infiltrated Hacking Team?
评论 #10223085 未加载
评论 #10222979 未加载
评论 #10224670 未加载
ewass9000over 9 years ago
If you do not realize that we have always been monitored, usually without a legal vehicle, by government agancies, you are just too young. If you believe for one second that the NSA is more of a threat than the ultimate climate created by the aggregation of every set of data collected by ISPs, Cloud service providers, app makers, and social media, please start thinking and researching just a few more steps ahead. Attacks will be patched, the NSA will decrypt in real time until someone finds a way to embarras them. The natural growth of company driven data theft and distribution can only result in an environment with revoloutionary sceintific achievement and statistical analysis that poses unpresidented virtual and physical threats to individuals and groups. The simple fact is our users have been slowly trained to implement and act upon concepts and technology they do no understand. When a person that can hardly type can watch a video online with explicit instructions on how to hijack a cell phone, but easily use too much power and suspend service in an area, what do we really change when housese burn and heart attack victims die because they have no 911 service?
NullCharacterover 9 years ago
Schneier apparently doesn&#x27;t even know what the NSA stands for (National Security <i>Administration</i>?) and yet seems it&#x27;s safe to assume that they had infiltrated Hacking Team, and then proceeds to make a whole bunch of judgements and follow-on assumptions based off that first baseless assumption all while pandering to his userbase.<p>Well done, Bruce.
评论 #10223696 未加载
评论 #10224037 未加载
benmmurphyover 9 years ago
It would be interesting to know if the NSA has explicit special access or has infiltrated the bug reporting programs for important vendors. Are browser bugs or iphone bugs important enough that the NSA has some guy in Apple or Firefox feeding them bug reports on the side?
评论 #10224081 未加载
评论 #10223137 未加载