TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Halluxwater: NSA Exploit of the Day

84 点作者 zmh超过 11 年前

9 条评论

timsally超过 11 年前
This article states the NSA developed an exploit for a product made by a Chinese networking and telecommunications firm. Honest question for HN readers inside the US: does anyone seriously have a problem with this? In my mind it falls squarely within the NSA&#x27;s mission, i.e. this is we pay them to do! Question for HN readers outside the US: can you credibly claim your intelligence agencies aren&#x27;t trying to do the same thing?<p>For those thinking about whether such things could be used inside the United States. Of course they can. So can all the equipment and weapons the military buys. And it&#x27;s happened before! The gun in the Fort Hood shootings was bought and paid for by US tax dollars and it was used to kill a civilian. So this raises the question, is the military to be trusted with weaponry it needs for its defense mission even though they could be used in the US? Similarly, is the NSA to be trusted with exploits it needs for its SIGINT mission? Interesting question. An infantryman could go rogue at any time and use his service weapon against US citizens and someone at the NSA could use an exploit for personal gain, but on the whole I believe the system accounts for these possibilities in a reasonable and controlled way.<p>If this information is true, it seems a little crazy to me to be propagating it since there isn&#x27;t really a domestic&#x2F;whistleblower angle. At least, no more of a domestic angle than the military developing a new missile. Some of Snowden&#x27;s disclosures are responsible for starting a productive civil liberties debate in the United States, there&#x27;s no denying that. But these disclosures are ones of a different color in my opinion.
评论 #7135112 未加载
评论 #7135494 未加载
评论 #7135023 未加载
评论 #7135106 未加载
评论 #7135669 未加载
评论 #7136466 未加载
评论 #7135201 未加载
评论 #7136344 未加载
评论 #7135194 未加载
评论 #7134970 未加载
评论 #7136794 未加载
评论 #7135717 未加载
评论 #7134938 未加载
评论 #7135216 未加载
rurounijones超过 11 年前
Well the US govt has been saying that Huawei kit could not be trusted... I guess they were right...
jevinskie超过 11 年前
Does anyone know the process that took this leak from the Snowden dumps to Schneier&#x27;s site? Did Schneier seek consensus from the the other recipients that he should release this particular information? Did Schneier unilaterally decide to release this?<p>Regarding the article, I think it is fascinating proof of the lengths that state-level actors will go through to backdoor their targets.
评论 #7135049 未加载
Zarathust超过 11 年前
So you need access to the router first with enough power to force a firmware update. What would surprise me is if there are vendors immune from this kind of APT. Given the money and talent invested in those hacks, bricking a whole cargo container of router doesn&#x27;t seem out of reach, dissolving it in acid or other potentially destructive reverse engineering.<p>If they own the vendor source code then it is even easier, but the mere fact that it is a router&#x2F;firewall and not an off the shelf Dell pc is of little importance.
higherpurpose超过 11 年前
Sounds like typical NSA&#x2F;US gov modus operandi: accuse others of stuff they&#x27;re already doing.
评论 #7136177 未加载
zmh超过 11 年前
The picture:<p><a href="http://leaksource.files.wordpress.com/2013/12/nsa-ant-halluxwater.jpg" rel="nofollow">http:&#x2F;&#x2F;leaksource.files.wordpress.com&#x2F;2013&#x2F;12&#x2F;nsa-ant-hallux...</a>
评论 #7134978 未加载
joshwa超过 11 年前
Worth browsing the whole &quot;catalog&quot;:<p><a href="http://leaksource.wordpress.com/2013/12/30/nsas-ant-division-catalog-of-exploits-for-nearly-every-major-software-hardware-firmware/" rel="nofollow">http:&#x2F;&#x2F;leaksource.wordpress.com&#x2F;2013&#x2F;12&#x2F;30&#x2F;nsas-ant-division...</a>
atmosx超过 11 年前
So if you are a company in need of some security, you&#x27;d better of with some open source alternative (i.e. Linux&#x2F;*BSD?
pistle超过 11 年前
NSA logos are horrible.