222 karma · joined March 19, 2016
The filthy rich do enjoy this ego-feeding narrative that it was all just talent and hard work that gave them a disproportionate slice of the world's wealth, but it's not borne out by the facts.
Unfortunately the DOS program it was being used to remote was highly picky on the hardware being used, and would refuse to communicate with the PLC if the PC was too new. Due to the harsh environment of the plant, we'd go through two or three computers per year. So there was a lot of digging around for old hardware until we realised it would run reliably in DOSBox with a suitable CPU speed set.
After that, our use case for TINY was no more, and we just used a VNC server for Windows. Saved a great deal of site to site travel and plant downtime while it was set up though.
The damage to signals intelligence capabilities, through the leaking of classified documents, was deliberately and maliciously done through the actions of Snowden himself, most likely in response to a bruised ego.
In contrast, the engineers involved in the Challenger shuttle did their very best to try to avert disaster - albeit to no avail - through their selfless adherence to professional ethics and engineering safety concerns.
The two scenarios couldn't be more different really.
> Snowden would later publicly claim that his "breaking point" - the final impetus for his unauthorised downloads and disclosures of troves of classified material - was March 2013 congressional testimony by Director of National Intelligence James Clapper.
> But only a few weeks after his conflict with NSA managers, on July 12, 2012 - eight months before Director Clapper's testimony - Snowden began the unauthorized, mass downloading of information from NSA networks.
Given that Snowden claimed his motivation was seeing Clapper "lie on oath", there's some irony in seeing Snowden caught in a lie about this claim, as at that point not only had he already downloaded and exfiltrated much of what he later leaked, but had already been in contact with Greenwald and Poitras for two to three months.
Also interesting is how well the accounts of his work behaviour match up with these posts from an HN user earlier this year, who claimed insider knowledge: https://news.ycombinator.com/threads?id=buttcoin
It's akin to the phone companies logging each number called. This isn't as intrusive as people are making it out to be.
Like yours, sounds like the same sort of thing as these Airtop machines.
We don't yet know if this was being widely exploited (versus being a niche exploit used by an APT, for example), but it will be now either way.
> The Windows vulnerability is a local privilege escalation in the Windows kernel that can be used as a security sandbox escape. It can be triggered via the win32k.sys system call NtSetWindowLongPtr() for the index GWLP_ID on a window handle with GWL_STYLE set to WS_CHILD.
Which is enough information for someone to write an exploit from scratch.
If they'd just said there is a win32k.sys vulnerability and advised users to make sure Flash is up to date, this would have been fine.
There's no good reason for Google not to respect coordinated disclosure here. Making an arbitrarily tight deadline their policy isn't protecting users.
I'd expect AV vendors to already have signatures for this given that it's being actively exploited, which means there must be malware samples to know this.
I don't see the problem with ignoring the hosts file, if that is indeed what is happening. It's not really intended as a blocking mechanism.