Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> In addition, if Russia had stolen the hacking tools, it would be senseless to publicize the theft, let alone put them up for sale. It would be like a safecracker stealing the combination to a bank vault and putting it on Facebook. Once revealed, companies and governments would patch their firewalls, just as the bank would change its combination.

Why would this be bad for Russians (if this was indeed the Russians)? We can/should assume that Russia has it's own methods of infiltrating systems. The value of this data to them would be knowledge of how it's done, not necessarily hoarding and replicating how the NSA does it. If anything, having vendor's patch exploits that they're not using, but their enemy is, would be a great chess move.



The longer the russian's know or have the exploits without the NSA knowing they've been compromised, the longer they can hold it against them. -- Imagine you've hacked a bank network vs robbing a single bank, and every week you take 1 penny from all users without anyone knowing, and do this for 3+ years... you'd get a lot more than a one-off bank robbery... That's the long game that Russia would play - milk it for every ounce of use, and keep it totally secret.

They get nothing from exposing it, hacktivists on the other hand get a lot more, and are more boastful about their exploits.


Hold what against them? The exploit? That makes no sense.

The Russians do not use the exact same set of tools that the NSA does. Sure, they may have discovered some of the same exploits, but the two do not have the same "toolbox" strictly speaking. Releasing a set of tools used by the NSA doesn't mean that Russia loses access to the systems that they have compromised...

Your bank heist analogy doesn't apply here.


"Oh okay. So you're gonna be making a lot of money, right?"

"Yeah."

"Right. It's not yours?"

"Well it becomes ours."

"How is that not stealing?"


I imagine if the NSA knows of a zero day that its systems are patched against it or at least their IPS blocks that attack.


To be honest, it's very difficult to have a clear view on whether is makes sense to call the Russians on this or not. We know too little and we speculate to much :-)

Plus, for a USA agency, it goes without saying that when shit hits the fan it's either Russians, Chinese or Aliens not necessarily in that order.


Yes, this Bamford argument doesn't make much sense either. It seems to imply that the Russians and Americans are working from the same set of vulnerabilities. I don't know anyone who does this work professionally who thinks that's likely to be true.


The analogy is faulty. It's not only about breaking into systems but also about knowledge of other countries hacking operations.

If the Russians knows NSAs tools they know what to look for when trying to figure out what NSA is up to. That's hugely valuable information.


I think you agreed with me.


Also is the narrative that its a state sponsored hacker vs a russia-based hacktivist?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: