TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Snowden: NSA just lost control of its Top Secret arsenal of digital weapons

657 点作者 Yrlec大约 8 年前

32 条评论

cyphunk大约 8 年前
A good time to remember the official US Intelligence Community statement and policy&#x2F;lie on 0days, as given post-heartbleed:<p><pre><code> When Federal agencies discover a new vulnerability in commercial and open source software – a so-called “Zero day” vulnerability because the developers of the vulnerable software have had zero days to fix it – it is in the national interest to responsibly disclose the vulnerability rather than to hold it for an investigative or intelligence purpose. </code></pre> <a href="https:&#x2F;&#x2F;icontherecord.tumblr.com&#x2F;post&#x2F;82416436703&#x2F;statement-on-bloomberg-news-story-that-nsa-knew" rel="nofollow">https:&#x2F;&#x2F;icontherecord.tumblr.com&#x2F;post&#x2F;82416436703&#x2F;statement-...</a><p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=7575802" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=7575802</a>
评论 #14069358 未加载
评论 #14069334 未加载
评论 #14069351 未加载
评论 #14069614 未加载
spydum大约 8 年前
Why is everybody posting&#x2F;curious about the language of the blog post and not the contents of the file?<p>I&#x27;ve looked through some of the contents.. Some look incredibly old, but others target odd things.. lots of cPanel. My only guess is take the low hanging fruit to build &quot;jump box&quot; type systems?<p>Some odd examples: ElegantEagle&#x2F;toffeehammer.. focuses on cgiecho for RCE. The thing is, a CVE was just released for this case maybe a month ago?: <a href="http:&#x2F;&#x2F;www.cvedetails.com&#x2F;cve&#x2F;CVE-2017-5613&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.cvedetails.com&#x2F;cve&#x2F;CVE-2017-5613&#x2F;</a><p>So if this dump was from 2013, why did the CVE recently pop up? Or is that coincidence?
评论 #14070136 未加载
sillysaurus3大约 8 年前
It&#x27;s pretty fascinating to read the Shadow Broker&#x27;s posts. They have to write something, since they can&#x27;t just say &quot;I work for Russia and we&#x27;re reminding America that they&#x27;re not invulnerable.&quot; So they have to come up with all sorts of contrived reasons about why they&#x27;re doing this, complete with broken english to fool stylometry detection that walks the fine line between being believable and preposterous. Someone spent a lot of work getting it to look so terrible.
评论 #14068785 未加载
评论 #14069340 未加载
评论 #14068755 未加载
评论 #14069713 未加载
评论 #14069027 未加载
评论 #14068692 未加载
评论 #14069938 未加载
评论 #14070122 未加载
评论 #14068702 未加载
tenaciousJk大约 8 年前
He goes on to further state:<p>&quot;Quick review of the #ShadowBrokers leak of Top Secret NSA tools reveals it&#x27;s nowhere near the full library, but there&#x27;s still so much here that NSA should be able to instantly identify where this set came from and how they lost it. If they can&#x27;t, it&#x27;s a scandal.&quot;
itchyjunk大约 8 年前
Asking a president to do x,y or z by making this type of public statement probably implies it&#x27;s geared towards the immediate readers and not some leader that might read it.<p>The security agencies might have made a lot of enemy over the years so it&#x27;s not clear who benefits from this. Either financially or as ego boost.<p>The internet is definitely bigger that what most people might have predicted 20 years ago. So its not really a big surprising to see as much or even more power struggle than in real world battle fields.<p>Since every side has a propaganda to peddle, I, personally can draw no reasonable or coherent conclusions on what type of decisions are shaping the world I live in. But I am nonetheless curious to see how this all plays out in the coming years.<p>There is a related post on HN about this. [0]<p>---------------------------------<p>[0] <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=14066596" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=14066596</a>
评论 #14068736 未加载
iandanforth大约 8 年前
Can someone remind me why Snowden would be in a position to comment on if this release comprises a full or partial set of hacking tools? Specifically, does this imply that his cache of data included a list of these tools, or was his day to day job one such that he would have been normally in contact with this toolset?
评论 #14068455 未加载
评论 #14068883 未加载
hl5大约 8 年前
Obviously, Perl is the NSA top language choice due to it&#x27;s built in support for obfuscation and job security.
评论 #14068836 未加载
评论 #14069320 未加载
akud大约 8 年前
The content reads pretty clearly like a native English speaker imitating immature hacker-speak. It comes across as if it were written by a script-kiddy; that may be intentional.
评论 #14069479 未加载
评论 #14069109 未加载
评论 #14069421 未加载
theocean154大约 8 年前
Looking through some of the code and some of the docs, these look old. In absence of a lot of time or some missing docs, not sure how usable these things are.
评论 #14068615 未加载
评论 #14068746 未加载
评论 #14068603 未加载
评论 #14068580 未加载
评论 #14068599 未加载
r721大约 8 年前
Nicholas Weaver‏: &quot;Overall, though, it looks like the auction file from Shadow Brokers is mostly a bust, better stuff in the free file.&quot;<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;ncweaver&#x2F;status&#x2F;850797548717481984" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;ncweaver&#x2F;status&#x2F;850797548717481984</a><p>the grugq: &quot;Calling it now: the first ShadowBrokers dump was an expensive signal. This latest one was not (expensive, that is.)&quot;<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;thegrugq&#x2F;status&#x2F;850825305845399552" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;thegrugq&#x2F;status&#x2F;850825305845399552</a>
评论 #14069933 未加载
mcintyre1994大约 8 年前
From the Medium post linked (<a href="https:&#x2F;&#x2F;medium.com&#x2F;@shadowbrokerss&#x2F;dont-forget-your-base-867d304a94b1" rel="nofollow">https:&#x2F;&#x2F;medium.com&#x2F;@shadowbrokerss&#x2F;dont-forget-your-base-867...</a>)<p>- Don’t care if you swapped wives with Mr Putin, double down on it, “Putin is not just my firend he is my BFF”.<p>- Don’t care if the election was hacked or rigged, celebrate it “so what if I did, what are you going to do about it”.<p>This has got to be a fake group trying to discredit Trump right? I don&#x27;t like him or what he&#x27;s doing, but surely surely his supporters don&#x27;t subscribe to at least the latter view there?
评论 #14068865 未加载
tyingq大约 8 年前
More context: <a href="https:&#x2F;&#x2F;en.m.wikipedia.org&#x2F;wiki&#x2F;The_Shadow_Brokers" rel="nofollow">https:&#x2F;&#x2F;en.m.wikipedia.org&#x2F;wiki&#x2F;The_Shadow_Brokers</a>
评论 #14068441 未加载
codezero大约 8 年前
A lot of the scripts appear to have been written by the same person, or is that just me reading into it? They have a distinct comment style in both Python and Perl.<p>Also, a lot of the tools appear to instruct people to paste various things in to them. I find it unlikely that a single person wrote all the tooling for the NSA, but, who knows.
评论 #14069525 未加载
strictnein大约 8 年前
&gt; &quot;NSA just lost control of its Top Secret arsenal of digital weapons&quot;<p>This is just inaccurate, or at least purposefully misleading. The NSA did not just lose control of its &quot;Top Secret arsenal of digital weapons&quot;.<p>They &quot;lost control&quot; of mainly a bunch of old exploits whose release will not matter because anyone who is running this old junk won&#x27;t be updating their servers because of this news.
fixxer大约 8 年前
I don&#x27;t know anything about the value of this crap, but I do find it interesting to grep through looking at the IPs (which I presume are compromised machines from which they are initiating attacks). See `.&#x2F;bin&#x2F;pyside&#x2F;targets.py`
评论 #14068703 未加载
remarkEon大约 8 年前
I haven&#x27;t read enough broken English to take a gander at what the native language is for the authors of that...manifesto. Anyone have a good guess? There&#x27;s some pretty common mistakes throughout (&quot;peoples&quot; for people, &quot;Americans&#x27; having&quot; for &quot;Americans have&quot;).
评论 #14068480 未加载
评论 #14068795 未加载
评论 #14068486 未加载
Animats大约 8 年前
This stuff looks old. There are versions for Solaris and SCO Unix.
评论 #14068942 未加载
评论 #14069102 未加载
jasonhansel大约 8 年前
I wonder what this is for: <a href="https:&#x2F;&#x2F;github.com&#x2F;x0rz&#x2F;EQGRP&#x2F;blob&#x2F;master&#x2F;Linux&#x2F;bin&#x2F;strangeFiles.py" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;x0rz&#x2F;EQGRP&#x2F;blob&#x2F;master&#x2F;Linux&#x2F;bin&#x2F;strangeF...</a><p>It looks like it&#x27;s searching for files&#x2F;directories with unusual names (like &quot;. &quot;) that system administrators wouldn&#x27;t normally notice.
评论 #14070597 未加载
znfi大约 8 年前
I have a bit of a hard time understanding why so many people think this is written by Russians. Obviously the grammar is not correct, but it would seem very strange to think this has any significance, and it seems more plausible that it was done in an attempt to hide the authors identity. (My spontaneous feeling was that it was written by Jar Jar Binks, and not Russians, for whatever that&#x27;s worth.)<p>I&#x27;m not from the US and have not followed the news from there recently, but from what little I have seen much of the actual contents of the message does seem to reflect the feelings of Trumps &quot;base&quot;? Or would people more familiar with US politics say this is incorrect?
jorblumesea大约 8 年前
Is there any doubt the Shadow Brokers are Russian and working for Russian interests? The timing of releases, international events concerning both countries and pointed measures are far too suspicious to be considered circumstantial.
评论 #14069515 未加载
评论 #14071066 未加载
eps大约 8 年前
Likely a response to the Syrian airbase tomahawking from a couple of days ago?<p>Russians are known for what they themselves call &quot;asymetrical answers&quot;, so this seems to fit the pattern.
评论 #14069720 未加载
0x38B大约 8 年前
Like others are saying, there&#x27;s a mismatch between the overall sentence structure and progression - which strikes me as more native - and the mistakes. I don&#x27;t buy the verb misconjugation especially, a Russian ESL learner at that level would get that right more often than not.<p>Source: many conversations with Russians learning English (also near-native Russian)
i336_大约 8 年前
Excuse me while I just...<p>ALLL RIIIIGHT!!<p>Not because I&#x27;m especially interested in the tools (although, granted, I have not had a look at any of them yet), but because I always wished this could be given to everyone.<p>Also, for a moment there, I was concerned 7z was insecure and that the passphrase had been bruteforced. Apparently not! Very nice.
hl5大约 8 年前
Regardless of the source, full disclosure works. Whomever is responsible for releasing this material is also improving computer security for <i>everyone</i>. Thank you.
zengid大约 8 年前
All of this spy vs spy intrigue makes my head hurt
mavdi大约 8 年前
Given the latest world events, I&#x27;ve personally come to realise that security agencies play an important role in keeping us safe, from external entities or from ourselves.<p>This is disaster in my (current) opinion. We tend to dismiss the work the likes of NSA do, not thinking much about what would happen if they didn&#x27;t do it. Snowden categorically dismissing anything that NSA does, just means he&#x27;s a deluded idealist, much like I used to be.
评论 #14069199 未加载
评论 #14069175 未加载
评论 #14069222 未加载
评论 #14069241 未加载
评论 #14069931 未加载
评论 #14069188 未加载
shitgoose大约 8 年前
shadowbrokerss remind me of this guy:<p><a href="https:&#x2F;&#x2F;www.youtube.com&#x2F;user&#x2F;FPSRussia" rel="nofollow">https:&#x2F;&#x2F;www.youtube.com&#x2F;user&#x2F;FPSRussia</a><p>100% American from Georgia, sometimes loses Russian accent and slips into perfect English:)
Harken大约 8 年前
&quot;We voted for you, comrade. Here is old malware from deepnet kiddy porn site post for to confuse.&quot;<p>Could be Russia pissed about puppet twitching without permission, or could be Bannon (via Cambridge Analytics?) pissed about puppet twitching without permission.<p>Twitch, puppet, twitch!
评论 #14069714 未加载
评论 #14069715 未加载
theocean154大约 8 年前
ElegantEagle. nice
评论 #14068946 未加载
elastic_church大约 8 年前
ShadowBroker&#x27;s blog posts always crack me up
评论 #14068544 未加载
oculusthrift大约 8 年前
remember that 1000s of paid russians were used to interrupt our election on sites like reddit. wouldn&#x27;t be surprised if a few leaked to this site. especially with green accounts.
评论 #14082125 未加载
评论 #14069465 未加载
评论 #14069888 未加载
评论 #14069777 未加载
评论 #14069753 未加载
lngnmn大约 8 年前
Looks like bullshit. It does not match the vault7 leak, which is supposed to be from the very same NSA.<p>It is Russians. The classic example of Dunning Kruger effect. In a generally low IQ environment and primitive criminalized cultural environment they truly believe that what is enough to fool everyone around them, including the bosses (who are supposed to be really smart), will surely fool everyone else.<p>This is the phenomenon of negative selection of a cancer-like corrupted society (which ran for a three decades already) at work. They are literally decades behind of the technological progress and culture of the modern civilization.<p>They simply have no idea of what possible level of intelligence and sophistication could be found in places with decades of consistent high-IQ-based selection, like companies staffed with top 5% of MIT&#x2F;Standford&#x2F;Caltech&#x2F;Berkeley graduates and what this kind of organization could do (think of Apple, Google, etc).<p>A high-tech US govt agency would never had such a crap in their folders. They are not a bunch of disconnected from reality, overconfident, self-deluded with their own primitive propaganda Russian punks.