7 ms·
The way I describe it to friends and family is that there are basically two levels of protection: - Protecting yourself from rub of the mill malware that is lo
by overkill28 5y ago
The way I describe it to friends and family is that there are basically two levels of protection:
- Protecting yourself from rub of the mill malware that is looking to make money off of you. You can do this pretty effectively by always updating your software as soon as you can and avoiding sketchy and unnecessary apps and websites
- Protecting yourself from an attack by a nation state level agency. I don't think there is any way to be safe from this, and people who are targeted like this need to use protection that go well beyond the choice of cell phone or chat app
- dylan604 5y agoUntil run of the mill malware learns of a vuln only thought to be known by nation states, and then all hell breaks loose.
- jonplackett 5y agoDon't know why you're getting down voted, that's literally what happened with WannaCry https://www.acronis.com/en-gb/articles/nhs-cyber-attack/ https://www.acronis.com/en-gb/articles/nhs-cyber-attack/
- jdavis703 5y ago> Protecting yourself from an attack by a nation state level agency. My personal data was hacked by a nation-state level agency. The only way I could’ve prevented that is by not working in a national security position for that country’s geopolitical rival. Now the only thing I can reasonably do is avoid ever stepping foot in that country lest they detain me for “extra questioning.”
- randall 5y agoSorry… sounds really rough.
- jdavis703 5y agoEh, thanks but don’t feel bad for me. There’s hundreds of other countries I can visit. I feel bad for the dissidents who are targeted within their own country and have no hope to leave.
- ipaddr 5y agoWhich country?
- basementcat 5y agoThe OPM breach was attributed to China. My personal data was also disclosed in the breach and I’ve since traveled to China multiple times. https://en.m.wikipedia.org/wiki/Office_of_Personnel_Management_data_breach https://en.m.wikipedia.org/wiki/Office_of_Personnel_Manageme...
- dillondoyle 5y agoAnd worse targeted abroad. Russia, China, Saudi. They all target, sometimes kill, sometimes abduct abroad. Even in the US... Scary.
- cto_of_antifa 5y agoI assume you knew the possible consequences when you made that decision, or you should have. Maybe you shouldnt have made the choice to work for a state level agency and actively reproduce the violence that that carries along with it.
- pcl 5y agoTime to be “that guy”… “Nation state” is a well-defined term in the political sciences, and we misuse it here on HN all the time. To quote Wikipedia: “A nation state is a political unit where the state and nation are congruent. It is a more precise concept than "country", since a country does not need to have a predominant ethnic group.” https://en.m.wikipedia.org/wiki/Nation_state https://en.m.wikipedia.org/wiki/Nation_state
- Angostura 5y agoThat wasn’t a misuse though - was it?
- pcl 5y agoWell, perhaps the original poster was using it accurately. In my experience, the common HN usage really translates to “country with a big military budget”, which is not at all what the term means. Neither the US nor Russia are nation states. China and San Marino are both nation states. I’m guessing the poster meant “countries like the US, Russia and China”, and not “countries like China and San Marino.”
- jrochkind1 5y agoHonestly I think they just mean "state". Yes, some states have more resources than others, but the ones without a lot of resources generally aren't engaging in cyber attacks, and "state" as a general category is good enough summary. I think people say "nation state" in part just because it flows better rhythmically, and in part because of that whole "westphalian" thing; and because the word "state" has other confusing meanings (including in CS, state as in 'state machine'; and the 50 USA states). But really on HN when talking about "threat actors", they mostly just mean "state-level". (See I had to add -level to make it rhythmically like 'nation state' again, the one syllable 'state' is just too short it just plops into your sentence ruining it) [Hey, why is it called the United Nations instead of the United States anyway? Oops, cause there already is a United States. But the UN is clearly an organization of States not Nations. But the things are conflated and confused generally in European nationalist ideologies of the 18th-20th centuries, that have affected our vocabulary and concepts for these things, it's not just HN. "Nation" is often used as a synonym for "State", so "nation state" ends up just kind of doubling down] I say "state-level actor". Almost any contemporary liberal democracy (and not only those) at least formally defines itself as a state of it's citizens, not belonging to any particular "nation" (ie ethnicity basically) in particular. I don't see the point in distinguishing between states that are "nation" states or not in the 21st century, or think that it has a clear distinction.
- x0x0 5y ago> I don't think there is any way to be safe from this Apple could certainly do a lot more to protect their customers, and we generally let Apple off far too lightly here. For starters: using their enormous revenues to bid up the prices for these cracks. Writing better software, eg using well-known techniques to harden imessage. etc.
- Hackbraten 5y agoAlso they could treat their employees better so there’s less churn. Every newly-hired kernel engineer is bound to repeat the same technical mistakes that their predecessor made a decade ago.
- gitanovic 5y agoMight be a business model for a Kernel engineer: * Go work for Apple * Learn vulnerabilities * Resign * Sell vulnerabilities for cash on the dark market Edit: formatting
- UncleMeat 5y agoThis is sort of in the middle. NSO Group's exploits are surely expensive, but they are also not pinpointed. The states buying these exploits aren't spending the unlimited resources at their disposal to do the exploitation, it just costs them cash. This is one of the thing that likely promotes proliferation of this stuff, since it is so easy to pick another target. So I do think there is a level between these two where you can be defended against nation states that will use COTS-equivalent exploits against you even if you won't resist an active attempt by a full team targeting you very specifically. But doing this is hard as hell in the modern world, because so so so much of our device surfaces is riddled with memory errors.
- finiteseries 5y agoBasically, you’re either dealing with Mossad or not-Mossad. If your adversary is not-Mossad, then you’ll probably be fine if you pick a good password and don’t respond to emails from ChEaPestPAiNPi11s@ virus-basket.biz.ru. If your adversary is the Mossad, YOU’RE GONNA DIE AND THERE’S NOTHING THAT YOU CAN DO ABOUT IT. The Mossad is not intimidated by the fact that you employ https:// https://. If the Mossad wants your data, they’re going to use a drone to replace your cellphone with a piece of uranium that’s shaped like a cellphone, and when you die of tumors filled with tumors, they’re going to hold a press conference and say “It wasn’t us” as they wear t-shirts that say “IT WAS DEFINITELY US,” and then they’re going to buy all of your stuff at your estate sale so that they can directly look at the photos of your vacation instead of reading your insipid emails about them. In summary, https:// https:// and two dollars will get you a bus ticket to nowhere. Also, SANTA CLAUS ISN’T REAL. When it rains, it pours. [PDF] https://www.usenix.org/system/files/1401_08-12_mickens.pdf https://www.usenix.org/system/files/1401_08-12_mickens.pdf
- g8oz 5y agoI think this understates the threat of privatized hacking tools. Governments that can barely tie their shoelaces now have access to capabilities that only a few heavy hitters used to have. One example: In Mexico NSO software was used to target anti-obesity activists who were pushing for less soda pop consumption.
- fragmede 5y agoIt's a well known piece but it's from 2014 (or earlier), and the world was different back then.
- notdang 5y agoThe funny thing is that despite all of this high end, super secret, extremely sophisticated technology used against them, those activists won in the end.
- jahlove 5y agohttps://www.nytimes.com/2017/02/11/technology/hack-mexico-soda-tax-advocates.html https://www.nytimes.com/2017/02/11/technology/hack-mexico-so...
- TaylorAlexander 5y agoBut is this because computers fundamentally cannot be made secure, or due to backdoors and sloppy coding? I’ve heard BSD is pretty secure right? Couldn’t we make phones that secure if we didn’t bloat them with flashy new features every six months?