Threat actors using hoarded NSA exploits: Did the USA axe its own leg?

Anorion

Sith Lord
Staff member
Admin
Ok, this is month old news, but no thread on it, and the issue is still relevant considering that this is a story that is well over a five years in the making, posting a thread now.

In 2013, leaked documents by Edward Snowden showed that NSA had tools that allowed it unprecedented power of invasive surveillance across the world. The US government agreed to reveal the most damaging vulnerabilities to the technology companies. (Sidenote: CIA did not do so, and the tools it developed are catalogued in the Vault 7 leaks.)

A group calling themselves the ShadowBrokers stole some of these tools in 2016, and put them on auction. While security researchers believed the tools to be legit, there was not much interest in the auction. An anonymous troll executed a series of bitcoin transactions that rickrolled the shadowbrokers. The shadowbrokers then tried to sell the tools directly. When that failed, they just dumped the tools.

The mess was flagged as a major problem towards the end of 2016 itself, and tech news sites pointed out the serious repercussions what happens when zerodays hoarded by government agencies, and tools based on them, get into criminal hands.

One of the dumped exploits by the ShadowBrokers, was EternalBlue. Although Microsoft had already issued a patch, so it was not technically a zeroday, to major malware attacks in 2017 used this EternaBlue vulnerability. Petya, and WannaCry.

Last month, the US publicly blamed North Korea for the WannaCry ransomware attacks. Soon after, UK followed suit.

So, who should be blamed more here?
 

whitestar_999

Super Moderator
Staff member
To be frank,the one who deserves most blame is public & its apathy towards cyber security.I still see people running XP systems & doing valuable financial transactions on them or never updating their windows/AV software.People here are ready to kill & burn public property over film releases but nobody asked how Indian govt/Indian IT companies are responding to Meltdown & Spectre threat.
 
OP
Anorion

Anorion

Sith Lord
Staff member
Admin
Yeah, pretty sure that many systems are vulnerable despite so many attacks. A firefighting approach to cybersecurity is totally the reason why two major attacks could exploit the same, already patched vulnerability.

Still, somewhere I think that it is strange for US officials to point fingers at threat actors allegedly related to North Korea, who at most used unsophisticated Frankenstein malware to execute the attacks, using tools created by the US in the first place.
 

Nerevarine

Incarnate
To be frank,the one who deserves most blame is public & its apathy towards cyber security.I still see people running XP systems & doing valuable financial transactions on them or never updating their windows/AV software.People here are ready to kill & burn public property over film releases but nobody asked how Indian govt/Indian IT companies are responding to Meltdown & Spectre threat.
Cybersecurity should be a thing in college. I mean the actual thing, not theory, wat is a virus saar.
 

whitestar_999

Super Moderator
Staff member
College?I say a 10th class student should know the difference between normal DV certificate(white bar HTTPS) & EV certificate(aka green bar HTTPS). Virus & malware should be included in 7th class syllabus.
 

Desmond

Destroy Erase Improve
Staff member
Admin
College?I say a 10th class student should know the difference between normal DV certificate(white bar HTTPS) & EV certificate(aka green bar HTTPS). Virus & malware should be included in 7th class syllabus.
Agreed. Almost all kids these days operate cellphones and have a blatant disregard for privacy. No point training old dogs with new tricks, we must train the kids.
 

topgear

Super Moderator
Staff member
Agreed. Almost all kids these days operate cellphones and have a blatant disregard for privacy. No point training old dogs with new tricks, we must train the kids.

Don't keep your hopes up : ( Do read these articles )

Many can't place their state on map, don't know how to subtract: Survey on Indian teens

37% of teens don’t know name of state they live in: ASER - Times of India

First we need birth control acts in place, next control population and next not quantity but quality of education. Overpopulation lead to many bad things which might not happen if and only people, sigh ..... anyway this can take a new thread I guess so stopping as this may go offtopic but I think you got the idea.
 

Desmond

Destroy Erase Improve
Staff member
Admin
Don't keep your hopes up : ( Do read these articles )

Many can't place their state on map, don't know how to subtract: Survey on Indian teens

37% of teens don’t know name of state they live in: ASER - Times of India

First we need birth control acts in place, next control population and next not quantity but quality of education. Overpopulation lead to many bad things which might not happen if and only people, sigh ..... anyway this can take a new thread I guess so stopping as this may go offtopic but I think you got the idea.
Man, this is just sad.

Makes you wonder what are they learning in schools.
 
Top Bottom