Why did anyone need this challenge in the first place? Couldn't someone have justed ASKED a good exploit developer what they would do and what the impact is? No, I guess we're all up for wasting people's time and creating potential false negatives.
HN user
bitsteak
https://twitter.com/8bitsteak https://github.com/bitsteak
What in this article associates USAID with the intel community? The fact that they both use technology?
Ask any random person what they think of when you say "hacker." PROTIP: it's not your typical employee of some random consumer web startup, working 12 hour days and pounding redbull. It's someone who bypasses technical security controls through mastery of the underlying technology.
NSA collects intelligence from people so that US policymakers make informed decisions (like about Russia invading Crimea or how badly Malaysia is lying to the world), same as every other intel agency does for their home country. Big difference is that NSA won't give their analysis to private companies. In many countries, things like State-Owned Enterprises blur the things and economic espionage is widespread.
Why anyone would voluntarily MITM their own data and hand ALL of it over to a single company (and a single point of failure) is totally beyond me. It's a market failure that services like these continue to exist.
“When they deploy malware on systems,” Hypponen says, “they potentially create new vulnerabilities in these systems, making them more vulnerable for attacks by third parties.”
Really, how does that work Mikko? You don't even have a copy of any malware to make that statement.
All the hyperbole about how this is somehow unique is really getting old. Exploit kit authors have had shitty PHP web applications that accomplish the same task for ages: manage thousands of bots by grouping them together with a point and click management interface. It sounds like, prior to TURBINE, NSA had a single person tasked to oversee every action taken by hand, which is kind of inefficient if you ask me, so it stands to reason they would try to manage that process with technology.
How do you cool yourself First Look when you're reporting on this in 2014? Jeez.
Playing devil's advocate here. What harm was done by this? Was it really deserving of a news article and, further, a post on Hacker News? Now, maybe if there is a company out there working to replace or revolutionize passwords... otherwise I just don't see the point of this story.
just wanted to say it's great seeing security integrated into such a product from the start!
"Physicists and computer scientists have long speculated about whether the NSA’s efforts are more advanced than those of the best civilian labs. Although the full extent of the agency’s research remains unknown, ___the documents provided by Snowden suggest that the NSA is no closer to success than others in the scientific community.___"
Nothing to see here but false outrage and surprise, move along.
That's a pretty amazing hyperbole from kaepora (twitter description of incident vs actual e-mail response from Apple). And later, Apple accepted the fix: https://github.com/cryptocat/cryptocat/issues/542#issuecomme...
Kaepora is so full of himself, I'm not sure how anyone takes what he says or the apps he writes seriously. Glad that people are putting stock in more consistent developers these days (http://tobtu.com/decryptocat.php).
Tough talk from someone who can't even be bothered to use PGP. There are lots of people doing real good out there, like Moxie Marlinspike with BitHub, the kickstarter audit of TrueCrypt, and work in the CAB forum and the W3C on SSL and browser security. Glenn is just a talking head at this point, someone who ferried a few hard drives from point A to point B. He shouldn't be respected as someone who knows squat about the subject matter.
Scumbag Hacker News: Admires spies only after they're dead.