[Cryptography] Shadow Brokers :: powerful NSA hacking tools leaked

John Denker jsd at av8n.com
Wed Aug 17 00:17:56 EDT 2016


Reference:
  Ellen Nakashima
  Gomorrah Post, August 16, 2016
    https://www.washingtonpost.com/world/national-security/powerful-nsa-hacking-tools-have-been-revealed-online/2016/08/16/bce4f974-63c7-11e6-96c0-37533479f3f5_story.html

> “Without a doubt, they’re the keys to the kingdom,” said one former 
> TAO employee,

> Said a second former TAO hacker who saw the file: “From what I saw, 
> there was no doubt in my mind that it was legitimate.”

> The file contained 300 megabytes of information, including several
> “exploits,” or tools for taking control of firewalls in order to
> control a network, and a number of implants that might, for instance,
> exfiltrate or modify information.


The original instructions for obtaining the files are at
  https://archive.is/rdYpc#selection-724.0-724.1

but dereferencing the pointers leads to a lot of disabled pages.

That is IMHO unfortunate.  Surely quite a few bad guys have already
grabbed copies of the tools.  The next step is for the good guys to
figure out how to defend against the attacks.

-------------

IANAL, and the NSA folks consider themselves above the law anyway,
but I am reminded of the doctrine of /strict liability/.
  https://the-barristers-toolbox.com/2013/10/03/closing-arguments-strict-liability-dangerous-instrumentalities-vicarious-liability-and-use-of-the-lion-analogy/

It looks to me like the NSA's pet lion got away.

Maybe they will exhibit some sense of responsibility and common
decency, and immediately release patches so everybody can defend
against the depredations of their escaped lion.


More information about the cryptography mailing list