Live data from Hacker News

Hacking Team, Computer Vulnerabilities, and the NSA

schneier.com

1–10 of 75 posts

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#2
It would be interesting to know if the NSA has explicit special access or has infiltrated the bug reporting programs for important vendors. Are browser bugs or iphone bugs important enough that the NSA has some guy in Apple or Firefox feeding them bug reports on the side?

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#5
post #3

While I wouldn't put it past the NSA – why would we assume the NSA had infiltrated Hacking Team?

I think it's a fairly safe bet that they did, and I'll explain why I believe this.

1. The NSA has access to more info on both good crypto and broken crypto

2. Hacking Team's software & infrastructure were clearly vulnerable, otherwise they wouldn't have been hacked

3. Leaked docs show that NSA hacks everyone they possibly can, to get as much information as they possibly can.

It's really not a big leap to assume that NSA infiltrated Hacking Team's infrastructure, if anything I would think it's harder to believe they wouldn't have.

So if some Joe Schmoe broke into Hacking Team's system, I think it's pretty reasonable to assume that NSA did as well

But just so I can understand what you're saying, why do you think it's a big assumption?

Edit: Formating.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#6
post #5
post #3

While I wouldn't put it past the NSA – why would we assume the NSA had infiltrated Hacking Team?

I think it's a fairly safe bet that they did, and I'll explain why I believe this. 1. The NSA has access to more info on both good crypto and broken crypto 2. Hacking Team's software & infrastructure were clearly vulnerable, otherwise they wouldn't have been hacked 3. Leaked docs show that NSA hacks everyone they possibly can, to get as much information as they possibly can. It's really not a big leap to assume that…

Thanks for this, I agree it makes sense that they would have, I was just a bit disappointed that Bruce didn't enumerate any of this in his post. In fairness, all of this stuff is probably "duh" to him, and his normal audience, but it's not so obvious to everyone.

Here's another thought: what if the NSA hacked Hacking Team, and they were also the ones to release all the data publicly.

Re: #3 – do you have any links to that info? (I'm not challenging you to prove what you said, I'm just curious, if you don't have anything readily available, I'll Google search like a good Internet commenter :))

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#7

It would be interesting to know if the NSA has explicit special access or has infiltrated the bug reporting programs for important vendors. Are browser bugs or iphone bugs important enough that the NSA has some guy in Apple or Firefox feeding them bug reports on the side?

It would make sense for them to. Though, they would have to be quick to utilize the vulnerabilities before they got patched, unlike those found in-house.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#8
post #6
post #5

Earlier quoted context omitted.

I think it's a fairly safe bet that they did, and I'll explain why I believe this. 1. The NSA has access to more info on both good crypto and broken crypto 2. Hacking Team's software & infrastructure were clearly vulnerable, otherwise they wouldn't have been hacked 3. Leaked docs show that NSA hacks everyone they possibly can, to get as much information as they possibly can. It's really not a big leap to assume that…

Thanks for this, I agree it makes sense that they would have, I was just a bit disappointed that Bruce didn't enumerate any of this in his post. In fairness, all of this stuff is probably "duh" to him, and his normal audience, but it's not so obvious to everyone. Here's another thought: what if the NSA hacked Hacking Team, and they were also the ones to release all the data publicly. Re: #3 – do you have any links to…

I think it would be hard to go through everything, but off the top of my head:

https://snowdenarchive.cjfe.org/greenstone/collect/snowden1/...

Quote:

       For the past decade, NSA has lead an
       aggressive, multi-pronged effort to break widely
       used Internet encryption technologies

Their Motto:

      "We penetrate targets' defences."

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#9
post #6
post #5

Earlier quoted context omitted.

I think it's a fairly safe bet that they did, and I'll explain why I believe this. 1. The NSA has access to more info on both good crypto and broken crypto 2. Hacking Team's software & infrastructure were clearly vulnerable, otherwise they wouldn't have been hacked 3. Leaked docs show that NSA hacks everyone they possibly can, to get as much information as they possibly can. It's really not a big leap to assume that…

Thanks for this, I agree it makes sense that they would have, I was just a bit disappointed that Bruce didn't enumerate any of this in his post. In fairness, all of this stuff is probably "duh" to him, and his normal audience, but it's not so obvious to everyone. Here's another thought: what if the NSA hacked Hacking Team, and they were also the ones to release all the data publicly. Re: #3 – do you have any links to…

It is a bit odd that Schneier was stating it as an obvious fact despite no evidence. Of course, the NSA had and has great incentive to compromise them, as well as the ability to do so, but it's still an empty claim (even if it's probably a true one).

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#10
post #9
post #6

Earlier quoted context omitted.

Thanks for this, I agree it makes sense that they would have, I was just a bit disappointed that Bruce didn't enumerate any of this in his post. In fairness, all of this stuff is probably "duh" to him, and his normal audience, but it's not so obvious to everyone. Here's another thought: what if the NSA hacked Hacking Team, and they were also the ones to release all the data publicly. Re: #3 – do you have any links to…

It is a bit odd that Schneier was stating it as an obvious fact despite no evidence. Of course, the NSA had and has great incentive to compromise them, as well as the ability to do so, but it's still an empty claim (even if it's probably a true one).

Keep in mind also that I think he has access to more documents than we have. He made this statement a while back[1]:

      I am reviewing some of the documents Snowden has
      provided to the Guardian. Because of the delicate
      nature of this, I cannot comment on what I have seen. 
[1]http://www.technologyreview.com/news/519336/bruce-schneier-n...
Post reply on HN