What is so surprising here? The DOD is the largest funder of research grants in the US. Pretty much every university is doing research for a US agency from cyber security to lasers for missile defense. I find it very hard to believe that this is the firs time a university was conducting computer security research on live targets.
The DOD funds lasers, but it doesn't then has researchers fire them at random cars to test their effectiveness. I'm not actually sure this isn't sarcasm.
Why the Tor attack matters
21–30 of 77 posts
Re: Why the Tor attack matters
#22I don't really buy the comparison that what CERT did is similar to a university-sponsored DDoS. I think a better parallel is the Dan Egerstad case. He ran a Tor exit node and analyzed all the plaintext traffic leaving the exit nodes. He ended up collecting a ton of sensitive usernames and passwords. He tried to contact some of these people by e-mail but they ignored him. So he posted a bunch of these passwords on his…
If the SEI took money to, essentially, weaponize unpublished research, the issue is not one an IRB would have prevented. DoD contractors aren't bound by scientific codes of conduct. In light of that realization, the suggestion in this blog post is confusing.
(BTW, distancing CMU and the SEI is not meant as a defense of CMU -- close ties between public science and law enforcement/military R&D are as troubling as ever...)
Re: Why the Tor attack matters
#23The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Just because you are univesity researcher does not means you can take money and then attack some random company and say LOL JK just doing "Research". Universities have enormous computing power / resources available via various means to do research. Just because I have access to a thousand node cluster does not means I can…
The problem is that people are outraged that they attacked Tor when they should be outraged that they attacked Tor users. Given what the Tor project thinks to be, it needs smart people to poke it.
The CMU researchers are basically Sabu. Subhuman traitors to the hacker ethos.
Re: Why the Tor attack matters
#24I think we have to assume that if a government can hack it, they will try. Perhaps it's sad that a university will help them but I'd also to be assumed that they're going to be trying it in some way.
For example, it is equally a understood that almost any government could control/manipulate any press agency if they wanted to, or break down any door with a SWAT team.
The only difference here is that `cyber` did not exist nor is cleanly appliciable to laws wich limits this type of power - laws largely written in the 1800s. Additionally it largely happens in secret, attribution is difficult, and there is a serious knowledge gap from the general public and the type of operations being done.
Re: Why the Tor attack matters
#25Earlier quoted context omitted.
The problem is that people are outraged that they attacked Tor when they should be outraged that they attacked Tor users. Given what the Tor project thinks to be, it needs smart people to poke it.
Some of us are more outraged by the fact that they kowtowed to authority on the BlackHat presentation, and had a disclosure policy that favored the Feds over both the Tor project and the entire security community. The CMU researchers are basically Sabu. Subhuman traitors to the hacker ethos.
Re: Why the Tor attack matters
#26Earlier quoted context omitted.
The problem is that people are outraged that they attacked Tor when they should be outraged that they attacked Tor users. Given what the Tor project thinks to be, it needs smart people to poke it.
Some of us are more outraged by the fact that they kowtowed to authority on the BlackHat presentation, and had a disclosure policy that favored the Feds over both the Tor project and the entire security community. The CMU researchers are basically Sabu. Subhuman traitors to the hacker ethos.
Re: Why the Tor attack matters
#27The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Just because you are univesity researcher does not means you can take money and then attack some random company and say LOL JK just doing "Research". Universities have enormous computing power / resources available via various means to do research. Just because I have access to a thousand node cluster does not means I can…
Re: Why the Tor attack matters
#28The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Just because you are univesity researcher does not means you can take money and then attack some random company and say LOL JK just doing "Research". Universities have enormous computing power / resources available via various means to do research. Just because I have access to a thousand node cluster does not means I can…
The problem is that people are outraged that they attacked Tor when they should be outraged that they attacked Tor users. Given what the Tor project thinks to be, it needs smart people to poke it.
Re: Why the Tor attack matters
#29The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Just because you are univesity researcher does not means you can take money and then attack some random company and say LOL JK just doing "Research". Universities have enormous computing power / resources available via various means to do research. Just because I have access to a thousand node cluster does not means I can…
This is perhaps the most unnecessarily rude comment to be at the top of a hacker news thread in some time. Let's all remember that disagreeing with someone doesn't mean being glib or mean.
Re: Why the Tor attack matters
#30The response by Patio11 regarding how this was acceptable penetration testing was beyond stupid. Just because you are univesity researcher does not means you can take money and then attack some random company and say LOL JK just doing "Research". Universities have enormous computing power / resources available via various means to do research. Just because I have access to a thousand node cluster does not means I can…
This is perhaps the most unnecessarily rude comment to be at the top of a hacker news thread in some time. Let's all remember that disagreeing with someone doesn't mean being glib or mean.
Unlike some stupid bingo card creator or bubble driven recruiting startup. Academic research is a serious business, there is a reason why it is looked in positive light and a lot of things which otherwise are not allowed, are acceptable when done as research. And for it to stay that way scrutiny of research conduct is essential.