145 points by linolevan 1 day ago | 82 comments | View on ycombinator
dbetteridge about 21 hours ago |
londons_explore about 13 hours ago |
"We're releasing hacking tools to allow others to break into poorly secured computer systems... But we are doing it with good intentions so it won't be illegal right??"
tialaramex about 9 hours ago |
I couldn't immediately figure out here whether we're talking
0. Microsoft's supported products default enable this worthless "authentication" feature
1. Microsoft's supported products provide such a feature behind a UI that's not clearly marked "Danger: Do not stare into laser with remaining eye"
2: Microsoft does still support this, behind some Registry nonsense most users do not understand and once enabled it doesn't turn on the "I am a toxic waste dump, leave by nearest exit" warning signs on affected machines
3: Microsoft doesn't support this at all but some 3rd party commercial stuff does and customers really do love their crusty archaic 3rd party garbage
4: But this long abandoned SCO machine we've kept on life support for twenty years!
5: What does "supported" mean? Windows NT is scary, we're still on Windows 98 here.
archi42 about 19 hours ago |
observationist about 23 hours ago |
However, it's most likely to be used by governments, with legacy servers that are finicky, with filesharing set up that's impacted other computers configured for compatibility, or legacy ancient network gear or printers.
I wonder who they're pushing around, and what the motivation is?
Sytten about 19 hours ago |
nubskr about 13 hours ago |
themafia about 20 hours ago |
davidkellis about 22 hours ago |
BrandoElFollito about 22 hours ago |
They decided to not fix the vulns (either directly by not patching, or indirectly by not investing in cybersecurity). So exploiting them is somehow an act of mercy. They may not know they have a problem and they have an opportunity to learn.
Let's just hope they will have white or gray-ish hats teaching the lesson
1970-01-01 about 23 hours ago |
TacticalCoder about 23 hours ago |
But we are in two-thousand-twenty-FUCKING-six.
It's unbelievable. Just plain unbelievable.
ubuntulover2011 about 24 hours ago |
postepowanieadm about 23 hours ago |
aunty_helen about 23 hours ago |
Great, so someone with half a motherboard can break this hash
bflesch about 22 hours ago |
Was it a success? Is Mandiant a cash cow or was it basically an acquihire?
The big "contact mandiant" button next to the post feels a bit like trying to stay relevant and acquire more customers.
schmuckonwheels about 23 hours ago |
Amazing that this is still around and causing someone enough of a headache to justify spending money on.
Also amazing what a teenager with lots of free time and a bootable Linux usb can get up to.