Live data from Hacker News

Hacking Team, Computer Vulnerabilities, and the NSA

schneier.com

21–30 of 75 posts

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#21

Schneier apparently doesn't even know what the NSA stands for (National Security Administration ?) and yet seems it's safe to assume that they had infiltrated Hacking Team, and then proceeds to make a whole bunch of judgements and follow-on assumptions based off that first baseless assumption all while pandering to his userbase. Well done, Bruce.

I don't think a little typo ("Administration") weakens his argument. I think this post is more of a thought experiment than a serious analysis of what most likely happened.

Though I agree that over the past few years, Schneier's posts have been less substantial in analysis and contain more "thought experiments". I enjoyed his blog way more when it was restricted to the subject he has expertise in, i.e. cryptography.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#22

Schneier apparently doesn't even know what the NSA stands for (National Security Administration ?) and yet seems it's safe to assume that they had infiltrated Hacking Team, and then proceeds to make a whole bunch of judgements and follow-on assumptions based off that first baseless assumption all while pandering to his userbase. Well done, Bruce.

I don't think a little typo ("Administration") weakens his argument. I think this post is more of a thought experiment than a serious analysis of what most likely happened. Though I agree that over the past few years, Schneier's posts have been less substantial in analysis and contain more "thought experiments". I enjoyed his blog way more when it was restricted to the subject he has expertise in, i.e. cryptography.

I don't really think he was going the thought experiment route. He seems to genuinely believe what he writes. For example:

"The NSA was most likely able to penetrate Hacking Team's network and steal the same data. The agency probably did it years ago."

Nothing too ambiguous about that assertion.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#23

Schneier didn't discuss what is IMO the biggest reason for NSA not to report vulnerabilities: it's "pissing into the wind", it's futile. When 10 vulnerabilities are reported and fixed, 11 new ones are quickly found. The vulnerabilities are overwhelming us. Back around the year 2000 Microsoft was being beaten up for all the vulnerabilities in their software. So in 2002 Bill Gates announced "Trustworthy Computing".[1][…

Definitely agree.

In terms of raw "national security" net gain, it's likely it would be more useful if kept secret and used offensively than if it was revealed and patched. Vulnerabilities are dime a dozen. Patching one zero day says nothing of the 10 more that are floating around at any given time.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#24
post #5

Earlier quoted context omitted.

I think it's a fairly safe bet that they did, and I'll explain why I believe this. 1. The NSA has access to more info on both good crypto and broken crypto 2. Hacking Team's software & infrastructure were clearly vulnerable, otherwise they wouldn't have been hacked 3. Leaked docs show that NSA hacks everyone they possibly can, to get as much information as they possibly can. It's really not a big leap to assume that…

> But just so I can understand what you're saying, why do you think it's a big assumption? Are you serious? Because there's no proof or mention of it anywhere. You're making an assumption based on literally nothing more than "well obviously, based on what I've read on the Internet, they could have done it so they must have". You're bending facts to fit a worldview, something I'm sure you yourself detest elsewhere in…

There's no proof or mention that they didn't. There never will be, ever. Yet we have to make decisions, even in the absence of evidence pro or con. Given that they don't disclose "wittingly" what they do, given their mission, and given what appears to be their interpretation of their mission as revealed by Snowden and others, we have to assume the "worst" within the realm of possibility.

They did it, until they show me otherwise.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#25
post #13

There's a fourth reason NSA wouldn't have tipped off every vendor impacted by HT exploits: because they have no business breaking into commercial vulnerability research teams networks, grabbing their exploits, and burning them. It is in fact probably unlawful for them to do so (those actions having as they do an impact on US F-500 companies that use --- for better or worse --- tools from companies like HT to evaluate…

Is it still a reason when the NSA clearly don't care whether they break the law?

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#26

Schneier apparently doesn't even know what the NSA stands for (National Security Administration ?) and yet seems it's safe to assume that they had infiltrated Hacking Team, and then proceeds to make a whole bunch of judgements and follow-on assumptions based off that first baseless assumption all while pandering to his userbase. Well done, Bruce.

Says "NullCharacter", the respected authority on all matters security.

Teach us more.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#27
post #16
post #6

Earlier quoted context omitted.

Thanks for this, I agree it makes sense that they would have, I was just a bit disappointed that Bruce didn't enumerate any of this in his post. In fairness, all of this stuff is probably "duh" to him, and his normal audience, but it's not so obvious to everyone. Here's another thought: what if the NSA hacked Hacking Team, and they were also the ones to release all the data publicly. Re: #3 – do you have any links to…

For whatever it's worth: I do not believe --- and this is an opinion I think is shared by lots of people in my field --- that Scheier has any special insight into the software and network exploitation capabilities of NSA. Schneier is a writer first, then a policy guy next, then an academic/standards-group cryptographer. Information security is a huge field with lots of subfields, and nobody specializes in all of them…

Didn't Schneier have access to the Snowden docs, though?

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#28
post #24

Earlier quoted context omitted.

> But just so I can understand what you're saying, why do you think it's a big assumption? Are you serious? Because there's no proof or mention of it anywhere. You're making an assumption based on literally nothing more than "well obviously, based on what I've read on the Internet, they could have done it so they must have". You're bending facts to fit a worldview, something I'm sure you yourself detest elsewhere in…

There's no proof or mention that they didn't. There never will be, ever. Yet we have to make decisions, even in the absence of evidence pro or con. Given that they don't disclose "wittingly" what they do, given their mission, and given what appears to be their interpretation of their mission as revealed by Snowden and others, we have to assume the "worst" within the realm of possibility. They did it, until they show…

This is another point: the NSA really wants everyone to think they can, and have penetrated everything. It bolsters their image if people make these assumptions. This is one of the reasons I try not to assume the worst, especially when that's what they want you to do :)

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#29

It would be interesting to know if the NSA has explicit special access or has infiltrated the bug reporting programs for important vendors. Are browser bugs or iphone bugs important enough that the NSA has some guy in Apple or Firefox feeding them bug reports on the side?

Bugzilla was recently owned by an unnamed, unknown source, giving that source access to many zero day browser exploits for what was apparently many months. So yes, someone is doing this.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#30

Schneier apparently doesn't even know what the NSA stands for (National Security Administration ?) and yet seems it's safe to assume that they had infiltrated Hacking Team, and then proceeds to make a whole bunch of judgements and follow-on assumptions based off that first baseless assumption all while pandering to his userbase. Well done, Bruce.

Says "NullCharacter", the respected authority on all matters security. Teach us more.

I definitely never claimed to be anything more than someone who thinks making bullshit assumptions based on other bullshit assumptions is, well, bullshit.
Post reply on HN