Live data from Hacker News

Hacking Team, Computer Vulnerabilities, and the NSA

schneier.com

41–50 of 75 posts

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#41
post #39

Earlier quoted context omitted.

> But just so I can understand what you're saying, why do you think it's a big assumption? Are you serious? Because there's no proof or mention of it anywhere. You're making an assumption based on literally nothing more than "well obviously, based on what I've read on the Internet, they could have done it so they must have". You're bending facts to fit a worldview, something I'm sure you yourself detest elsewhere in…

It's an assumption, but I'm asking why it's a big assumption. We know that the NSA spied on Google, Yahoo, and Microsoft, and those are our own (US) companies. Hacking Team produced weaponized exploits/crypto/stuffs and sold it to US enemies and allies. Having read through the documents, I assert that it's a small / likely / reasonable assumption. It's literally the NSAs mission statement to defend the US against for…

Did the NSA spy on google or did they spy on information passing through googles network? How much "interesting" intelligence would likely be found on HT's network?

As for defense, they obviously didnt pass along what they found. If securing US networks was the reason for hacking, they completely failed to accomplish their goal.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#42
post #31
post #25

Earlier quoted context omitted.

Is it still a reason when the NSA clearly don't care whether they break the law?

You're missing the point. Behind the scenes? Sure. But Schneier is asking why NSA didn't break into HT and then burn all their exploits with the vendors. That's not a behind- the- scenes hack.

I'm pretty sure you're completely missing the point. Any time somebody suggests something is "against the law" in a discussion about the NSA practises we need to remind ourselves that they really don't care whether they break the law. They do it nakedly, in public, with live television coverage and there are no consequences.

The NSA is a criminal organisation. I don't say everything they do is crime or that is there sole raison d'etre just that they don't care about the rule of law. The law is something that they don't need to worry about at all.

Does anyone really dispute that? "I gave the least untruthful answer I could..." Lying under oath. No consequences for that crime or any other.

No respect for the rule of law.

Please don't miss that point, the rule of law is the point, it is a necessary condition for a civilized society and MOST ESPECIALLY the government needs to be bound by it.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#43
post #3

While I wouldn't put it past the NSA – why would we assume the NSA had infiltrated Hacking Team?

I think a US asset could have been targeted by their software. Or Hacking Team sold to a country with a bad standing in Israel.

Then the software becomes a direct threat to their agents/allies overseas and it needed to be neutralized. That is the kind of competition you do not want as a state actor.

I also think Gamma International was the victim of a foreign intelligence agency. I don't believe the privacy-minded hacker Robin Hood stories anymore.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#44
post #24

Earlier quoted context omitted.

> But just so I can understand what you're saying, why do you think it's a big assumption? Are you serious? Because there's no proof or mention of it anywhere. You're making an assumption based on literally nothing more than "well obviously, based on what I've read on the Internet, they could have done it so they must have". You're bending facts to fit a worldview, something I'm sure you yourself detest elsewhere in…

There's no proof or mention that they didn't. There never will be, ever. Yet we have to make decisions, even in the absence of evidence pro or con. Given that they don't disclose "wittingly" what they do, given their mission, and given what appears to be their interpretation of their mission as revealed by Snowden and others, we have to assume the "worst" within the realm of possibility. They did it, until they show…

Let's remove the hyperbole and call a spade a spade.

So, you want them to prove a negative? Just trying to be clear.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#45

Earlier quoted context omitted.

Haha wow. Schneier fan, are we? Did I touch a nerve? The hilarious thing is you don't even know who I am or what I do. You have no fucking clue. How dare someone think critically. Not on your watch.

No it's just funny when a random person on internet claims that they are better because they "think critically". My point is, you are not a special snowflake. You are one of 500M that think that they are smarter than others. You are not. Basically, you are just like a 4-year old begging for attention. You will get some, but unlike 4-year old, it will wane quickly. All the best!

Insulting people only serves to weaken your argument. BTW, your statements are an appeal to authority.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#46
post #18

Earlier quoted context omitted.

I salute your sentiment: the world would be better off without companies like HT. It is in fact probably unlawful for them to do so I realize that the patriotic employees of the NSA work within a legal framework, and seemingly pride themselves on doing so. But they haven't bothered to share that framework with the rest of us. So my first response was to snicker to myself, and that's unfair to you. Also, Hacking Team…

I tried to acknowledge that HT is jurisdictionally complex; they are probably allowed, under the same charter that allows CIA to conduct HUMINT missions, to attack Italian security companies (modulo treaties, I guess). The issue though is that those attacks have direct impact on US companies, who (again) may rely on HT products for "zero day pentesting" (among other things).

> they are probably allowed, under the same charter that allows CIA to conduct HUMINT missions, to attack Italian security companies

They are definitely not allowed, under the Constitution, to monitor everyone, but they do it anyway. You know this too.

So why do you discuss legislation as if it mattered to the NSA, when their actions show it clearly doesn't?

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#47
post #42
post #31

Earlier quoted context omitted.

You're missing the point. Behind the scenes? Sure. But Schneier is asking why NSA didn't break into HT and then burn all their exploits with the vendors. That's not a behind- the- scenes hack.

I'm pretty sure you're completely missing the point. Any time somebody suggests something is "against the law" in a discussion about the NSA practises we need to remind ourselves that they really don't care whether they break the law. They do it nakedly, in public, with live television coverage and there are no consequences. The NSA is a criminal organisation. I don't say everything they do is crime or that is there…

You're right to point out that the NSA doesn't give a fuck about the law, but..

> the rule of law is the point, it is a necessary condition for a civilized society and MOST ESPECIALLY the government needs to be bound by it

You seem to be overlooking the fact that the organization that makes the laws is, by definition, above them. The government is not bound by its own laws any more than a King or Emperor by his, back in the day.

The reason why you see crimes go unpunished is that people with political power and/or connections are effectively above the law.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#48
post #18

Earlier quoted context omitted.

I tried to acknowledge that HT is jurisdictionally complex; they are probably allowed, under the same charter that allows CIA to conduct HUMINT missions, to attack Italian security companies (modulo treaties, I guess). The issue though is that those attacks have direct impact on US companies, who (again) may rely on HT products for "zero day pentesting" (among other things).

> they are probably allowed, under the same charter that allows CIA to conduct HUMINT missions, to attack Italian security companies They are definitely not allowed , under the Constitution , to monitor everyone, but they do it anyway. You know this too. So why do you discuss legislation as if it mattered to the NSA, when their actions show it clearly doesn't?

The NSA consists of many parts. Some people within it breaking the law does not mean that laws don't matter there.

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#49
If you do not realize that we have always been monitored, usually without a legal vehicle, by government agancies, you are just too young. If you believe for one second that the NSA is more of a threat than the ultimate climate created by the aggregation of every set of data collected by ISPs, Cloud service providers, app makers, and social media, please start thinking and researching just a few more steps ahead. Attacks will be patched, the NSA will decrypt in real time until someone finds a way to embarras them. The natural growth of company driven data theft and distribution can only result in an environment with revoloutionary sceintific achievement and statistical analysis that poses unpresidented virtual and physical threats to individuals and groups. The simple fact is our users have been slowly trained to implement and act upon concepts and technology they do no understand. When a person that can hardly type can watch a video online with explicit instructions on how to hijack a cell phone, but easily use too much power and suspend service in an area, what do we really change when housese burn and heart attack victims die because they have no 911 service?

Re: Hacking Team, Computer Vulnerabilities, and the NSA

#50
post #39

Earlier quoted context omitted.

It's an assumption, but I'm asking why it's a big assumption. We know that the NSA spied on Google, Yahoo, and Microsoft, and those are our own (US) companies. Hacking Team produced weaponized exploits/crypto/stuffs and sold it to US enemies and allies. Having read through the documents, I assert that it's a small / likely / reasonable assumption. It's literally the NSAs mission statement to defend the US against for…

Did the NSA spy on google or did they spy on information passing through googles network? How much "interesting" intelligence would likely be found on HT's network? As for defense, they obviously didnt pass along what they found. If securing US networks was the reason for hacking, they completely failed to accomplish their goal.

I really think that's a distinction without a difference. For all intents and purposes, they spied on google. If you consider the fact that Google considers consumers to be more product than client, the distinction matters even less. But to your other point:

This is the NSA's mission statement:

      The National Security Agency/Central Security Service 
      (NSA/CSS) leads the U.S. Government in cryptology that 
      encompasses both Signals Intelligence (SIGINT) and 
      Information Assurance (IA) products and services, 
      and enables Computer Network Operations (CNO) in order 
      to gain a decision advantage for the Nation and our 
      allies under all circumstances.
And again, considering that HT sold weaponized crypto to non-allied countries, it's by definition "interesting" intelligence (in relation to the NSA).

Also, I'm quite sure that the language in that statement indicates more of an offensive role than defensive, since that's usually what "advantage" signifies.

Even if their purpose was defense, the way our Government is set up, it's defense of the government, not the governed, so you can't say with any confidence that they didn't patch internal systems that mattered to them.

Post reply on HN