this post was submitted on 29 Mar 2024
        
      
      672 points (99.0% liked)
      Technology
    76258 readers
  
      
      4128 users here now
      This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
        founded 2 years ago
      
      MODERATORS
      
    you are viewing a single comment's thread
view the rest of the comments
    view the rest of the comments
Ah sorry, english is not my native language so I'm not sure I fully got what you meant, your point was that they stopped inserting backdoors and instead concentrated on getting access by finding vulnerabilities ?
Basically two points, they stopped inserting backdoors and their backdoors seem to have only ever been to show them what's going on (so this just doesn't look like them to me).
I didn't really comment on "what they do now" as much. I think they do continue to spy, finding preexisting vulnerabilities is definitely one way to spy. I wouldn't be surprised if they report the worst ones in NATO systems to be repaired and keep the others for themselves.
They also tap into weak points like Google and Apple's notification services where things aren't end to end encrypted to gather information. I believe this was revealed recently.
Snowden I recall saying the modern NSA is more interested in metadata than what's actually in the message as well.
In general, I think they still do some shady stuff, but I don't think they do shady stuff that risks compromising a system. This exploit is quite literally a system compromise as (if I understand it correctly) it allows bypassing sshd authentication.