TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Russian Hackers Stole NSA Data on U.S. Cyber Defense

191 点作者 NwmG超过 7 年前

22 条评论

indubitable超过 7 年前
I find these allegations are deserving of some scrutiny. The entire story is quite bizarre when you begin to consider it. The NSA is apparently leaking like a broken pipe with this information. And it&#x27;s peculiar because this is information that makes our intelligence agencies look completely inept. That is a very good thing if this story is fake, but a very bad thing if its true.<p>It is stupefying that NSA contractors&#x2F;employees would be genuinely copying classified information that is heavily related to national security, and then just loading it up on their personal Windows PC with no apparent encryption or access controls. For instance why in the world wouldn&#x27;t they have OS level software restricting read access of a certain secure partition (or removable media) to a specific whitelist of processes? Or why wouldn&#x27;t they use an airgapped machine? Then there are issues like the NSA being so anxious and happy to leak this information, and then them indirectly &#x27;wink wink&#x27; confirming it publicly completely destroying the purpose of we don&#x27;t comment on speculation --- when you start commenting on certain speculation, it indirectly says something about other speculation that you actually choose not to comment on. They&#x27;re also seemingly unconcerned that somebody is leaking information that, if true, shows the NSA to be incompetent and also exposes attack vectors for enemy actors. There are also things like Kaspersky previously volunteering to provide complete source access to the government. Our government declined the offer. How does this make sense?<p>Since Iraq I have become much more critical of pretty much everything. Our media and our government lied to generate a case for war. And I feel lately that they are now trying to build a case for some sort of conflict, presumably cold, against Russia. Or at the minimum start Red Scare 3.0. I have no idea why they would want to do this, but I tend to abide Occam&#x27;s razor, and this all being true requires a lot more effort than this just being &quot;Yellowcake 2.0.&quot;
评论 #15411695 未加载
评论 #15411669 未加载
评论 #15411574 未加载
评论 #15411736 未加载
评论 #15411602 未加载
评论 #15412716 未加载
评论 #15412148 未加载
评论 #15412998 未加载
评论 #15413176 未加载
评论 #15412736 未加载
评论 #15411682 未加载
评论 #15412103 未加载
评论 #15412714 未加载
runesoerensen超过 7 年前
Kaspersky preempting (presumably) this story:<p><i>&quot;New conspiracy theory, anon sources media story coming. Note we make no apologies for being aggressive in the battle against cyberthreats&quot;</i><p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;e_kaspersky&#x2F;status&#x2F;915946040561487875" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;e_kaspersky&#x2F;status&#x2F;915946040561487875</a><p>Edit: Kaspersky press release <a href="https:&#x2F;&#x2F;usa.kaspersky.com&#x2F;about&#x2F;press-releases&#x2F;2017_kaspersky-lab-response-to-the-alleged-incident-reported-by-the-wall-street-journal-in-an-article-published-on-october-5-2017" rel="nofollow">https:&#x2F;&#x2F;usa.kaspersky.com&#x2F;about&#x2F;press-releases&#x2F;2017_kaspersk...</a>
评论 #15411192 未加载
评论 #15411118 未加载
killjoywashere超过 7 年前
I&#x27;m going to go out on a limb and propose a hypothesis:<p>The DoD&#x27;s hyper-innefficient contracting system rewards DC insiders and effectively limits the department&#x27;s ability to invest where investment is needed while draining the public coffers of unfathomable amounts of money.<p>The DoD&#x27;s hyper-ineffective personnel system inhibits personal development while at the same time making it nearly impossible to move laterally within the organzation, thus preventing thousands of experts in many fields (that is, many thousands of experts) from self-organizing into effective functional units.<p>These two issues have made the DoD ripe for attack in the digital domain, an area that has nothing to do with their other core missions areas which are all organized around delivering kinetic energy to adversaries.
评论 #15412079 未加载
评论 #15412729 未加载
uptown超过 7 年前
Access via Facebook: <a href="https:&#x2F;&#x2F;www.facebook.com&#x2F;flx&#x2F;warn&#x2F;?u=https%3A%2F%2Fwww.wsj.com%2Farticles%2Frussian-hackers-stole-nsa-data-on-u-s-cyber-defense-1507222108&amp;h=ATOgadigjpkHQL03AMcyhCHrXLBfAd6WUqXLQPOYEGXvFHFBlJiM_ba_YOKYSbu9_fwXtiH4rp6UMVDCmBhGYYmznJjDRmdxS8a7eCA&amp;_rdr" rel="nofollow">https:&#x2F;&#x2F;www.facebook.com&#x2F;flx&#x2F;warn&#x2F;?u=https%3A%2F%2Fwww.wsj.c...</a><p>Access via Archive: <a href="https:&#x2F;&#x2F;archive.fo&#x2F;szjBQ" rel="nofollow">https:&#x2F;&#x2F;archive.fo&#x2F;szjBQ</a>
评论 #15411075 未加载
评论 #15410806 未加载
iloveluce超过 7 年前
I hope NSA is doing the same with Russian Cyber Defense systems. This is what NSA should be focused on and not on turning its eavesdropping capabilities towards the homeland.<p>What if an adversary where to hack the NSA warehouses were all communications swept up by their eavesdropping efforts are stored?
评论 #15410920 未加载
评论 #15411205 未加载
评论 #15412054 未加载
评论 #15410935 未加载
评论 #15412751 未加载
deeth_starr_v超过 7 年前
Count me as a skeptic on this one. NSA employee&#x2F;contractor takes home classified docs and I am assuming hacking tools, Kaspersky detects the hacking tools and uploads them to Kaspersky, Kaspersky determines it&#x27;s NSA tools, notifies the Russian government, Russian government hacks the computer and gets all files. Then somehow NSA is able to deduce all this information. I&#x27;m not saying this is not possible, but I think their level of conviction on this is too high. A home computer is not going to have access logs. So let&#x27;s say they see NSA malware in the Kaspersky quarantine folder, and there is also other malware on the computer. They of course have to assume the worst, that Russia got all the files. But they are making a couple big logical jumps without proof. This article is just to sketchy on details for me to take it credibly.<p>Makes me think of the claim Cuba is using some kind of new radio brain weapon on US consulate workers in Cuba.
mhkool超过 7 年前
Remember the Chinese network equipment allegations? The agencies said hey had backdoors. That was never proven but what we know is that the agencies had access over nearly all Cisco equipment.<p>Now Kaspersky is the next &#x27;unsafe&#x27; non-American company... There are only allegations from an unreliable source: the agencies have lied regularly.<p>I am convinced that there is an anti-Kaspersky campaign since the agencies &#x27;like&#x27; the American antivirus vendors a lot more. I bet the agencies have ways to spy on users of American antivirus vendors.
评论 #15412872 未加载
austincheney超过 7 年前
Another damn NSA contractor took confidential information home. Epic fail.
评论 #15410948 未加载
评论 #15411503 未加载
cl289超过 7 年前
WWCS (What would Clapper Say):<p>Nov 15, 2017, to Congress: &quot;I can categorically deny that there were any leaks of this nature during my tenure as Director of National Intelligence.&quot;<p>June 22, 2020: &quot;Well, yes, I did say at the time that I denied it. But I said &#x27;categorically denied&#x27;- that is to say, under certain conditions, or categories, this could be denied. That is what I meant and I stand by that. I also used the word &#x27;can,&#x27; which is a sort of conditional; look it up in your grammar books. I did not say &#x27;I do deny,&#x27; but &#x27;I can deny.&#x27; There are conditions that might allow one to deny this assertion: i.e. what exactly is a Russian, what does it mean to leak, or to have leaked, or to have an inadvertant leak. That is what I meant and I stand by that also.&quot;
ericfrederich超过 7 年前
This came up in congress a couple weeks ago didn&#x27;t it? I think Rubio had mentioned Kapersky it knowing that it was a public hearing... some speculated that this was perhaps because he was privy to some classified things he couldn&#x27;t say publicly but wanted to get the word out that they can&#x27;t be trusted.
评论 #15412900 未加载
random023987超过 7 年前
Government drone copies NSA malware onto a system with Kaspersky security software installed for the purpose of detecting malware.<p>Brilliant
jakelarkin超过 7 年前
how Kaspersky was ever thought to be &quot;okay&quot; in the US enterprise&#x2F;government market has always been perplexing to me. Antivirus, something which literally inspects all of your files and network activity, made in the country that&#x27;s a hotbed of blackhat activity and home one of the most aggressive cyber-espionage militaries outside the US. yea okay great, sign me up.
评论 #15411632 未加载
评论 #15411299 未加载
评论 #15411157 未加载
pasbesoin超过 7 年前
Sorry. I have a point -- towards the end. Even if it&#x27;s one that gets me downvoted:<p>In my personal life, I&#x27;ve been wrestling with the decision to &quot;do the right thing&quot; and, for example, pay for digital media I consume. Help a friend in need, who doesn&#x27;t really reciprocate (because, &quot;the children&quot;, among other things). Purchase the health care insurance that takes away money I could otherwise spend on immediate treatment.<p>In each area, I&#x27;ve felt increasingly screwed over.<p>Shrinking catalogs, and money I paid spent on lawyers ensuring ever-greater rent-seeking as opposed to actual access to content.<p>My friend&#x27;s health on the rebound, while mine has suffered, including from the depression induced by their abandonment of our friendship once I was, apparently, no longer necessary.<p>A health care system that keeps jacking prices and trying also by legislative manipulation to push me out the door of coverage, regardless of my best efforts to work with it.<p>In all these matters, I&#x27;m coming to think that part of my failed response comes down to a simple matter: Don&#x27;t pay. Stop paying the very systems and people that or who are screwing you over.<p>So, here we have the NSA, that is (who are) ever more showing themselves to be incompetent with regard to what we hope they would accomplish, and outright aggressive and abusive with regard to us and matters that we consider commercial contract law, not their business, distracting rather than helpful, etc.<p>Helping prop up private IP rights and rent-seeking. Domestic spying. Accumulating so much data on everything that they can&#x27;t see the needle for the haystack -- so, grow the haystack!<p>I&#x27;m hardly one of these bullsh-t &quot;Conservative&quot; (that&#x27;s with a big &quot;C&quot;, to differentiate from the actual noun&#x2F;adjective, &quot;conservative&quot;), &quot;shrink&#x2F;starve the government&quot; types. Government plays an essential role: It is the definition of our collective organization and governance.<p>But in some areas, I really want to say, let&#x27;s simply stop paying for this shit.<p>Because when we pay for it, we only make it stronger. Not the effective governance we aspire to. Instead, this incompetence that also threatens aggression against its own society.
campuscodi超过 7 年前
Has anyone else noticed the influx of anti-Russia articles on the WSJ lately?
评论 #15413097 未加载
评论 #15412695 未加载
52-6F-62超过 7 年前
Is it just me, or is this possibly related to the Vault 7 materials on Wikileaks, and thus the WannaCry attacks that brought the NHS to its knees this past year?
codedokode超过 7 年前
I remember that Kaspersky helped to investigate some of cyberattacks perfromed allegedly by western agencies. Could not these articles be a part of revenge campaign to punish them?<p>And another thought, if we cannot trust foreign AV software, does it mean that every country must have at list one national AV product? Or maybe it would make sence to make some special API for AV software so that it can check files and processes but cannot send data to the Internet?
评论 #15411914 未加载
评论 #15413500 未加载
jpelecanos超过 7 年前
For whom do those hackers specifically work for (SVR, GRU, or <i>Spetssvyaz</i>)?
评论 #15414253 未加载
blackflame7000超过 7 年前
Does anyone really think the NSA isn&#x27;t trying to hack the Kremlin as well?
NN88超过 7 年前
Putin is screwed the minute Trump leaves.
igivanov超过 7 年前
No confirmation from the NSA, only &quot;leaks&quot; from anonymous &quot;multiple people with knowledge of the matter.&quot;<p>How do we know it&#x27;s not another piece of fake news riding the wave of &quot;Russia did it&quot;?
评论 #15411541 未加载
评论 #15411271 未加载
评论 #15411032 未加载
评论 #15411042 未加载
tryingagainbro超过 7 年前
NSA &#x2F;CIA and our National Security is as secure as the weakest link. They need not be traitors, just people that got too complacent...while Russia never sleeps (Like NSA does when Russians and others screw up.)<p>It isn&#x27;t easy but if tens of thousands people have access to something, it&#x27;s just a matter of time. And they need access &quot;to connect the dots&quot; so it&#x27;s a losing game.
评论 #15410966 未加载
评论 #15410958 未加载
mozumder超过 7 年前
&quot;An NSA contractor brought home documents about U.S. offensive cyber capabilities.<p>He used Kaspersky on his home computer.<p>Russian government hackers stole the documents.&quot;<p><a href="https:&#x2F;&#x2F;twitter.com&#x2F;ericgeller&#x2F;status&#x2F;915983591737319427" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;ericgeller&#x2F;status&#x2F;915983591737319427</a><p>So, yah, avoid Kaspersky AV software.
评论 #15411455 未加载
评论 #15412237 未加载
评论 #15410902 未加载