logoalt Hacker News

chasilyesterday at 9:58 PM3 repliesview on HN

'Mythos “broke into almost all of our classified systems, not in weeks, but in hours.”'

Is Mythos a significant danger?

The curl experience does not suggest that hysteria is warranted, but this gives me pause.


Replies

maxall4yesterday at 10:16 PM

Or, alternatively, it may suggest that the NSA’s classified systems are not very secure, which seems at least as possible: they may rely on requiring physical access to these systems to even attempt to penetrate them.

nlyesterday at 11:47 PM

Curl is such a small utility, and the effect of any single problem is limited.

Mythos's great strength was finding multiple vulnerabilities and chaining them together to break a whole system.

Look at it like this: It found one confirmed, minor vulnerability in Curl (but I don't think they have said what it was?). In another system that used Curl it's possible it could have exploited that vulnerability to chain to another, bigger vulnerability that was normally inaccessible.

That's how systems get broken.

enraged_camelyesterday at 10:57 PM

>> The curl experience does not suggest that hysteria is warranted, but this gives me pause.

What about the Firefox experience?

Or are we conveniently ignoring things that don't confirm conclusions we've already reached?

show 2 replies