Hah a PDF! Nice try, folks...
Assuming they have a zero day vulnerability in acrobat (or other PDF readers), they wouldn't risk losing it by uploading a file with an exploit, using their own name, and in a wide distribution. When the GCHQ wants to hack you, it won't be on GitHub. It will be a file served specifically to your computer, with content relevant specifically for you, from someone you trust and don't suspect.
GCHQ's Boiling Frogs paper on software development
31–40 of 85 posts
Re: GCHQ's Boiling Frogs paper on software development
#32http://imgur.com/a/pbazB Contents of this PDF, page by page, in JPGs.
Re: GCHQ's Boiling Frogs paper on software development
#33Re: GCHQ's Boiling Frogs paper on software development
#34Earlier quoted context omitted.
It's OK - Github converts it to HTML. However, GCHQ could politely ask the NSA to force Github to give them the usernames and IP addresses that viewed the repo. Maybe use Tor?
I don't understand why everybody assumes GCHQ and NSA are completely inept amateurs. Getting a list of usernames and IP addresses from GitHub would have an insane signal to noise ratio - after all, there are plenty of perfectly legitimate reasons to want to read this document. It's much easier to go to HN and grab the usernames and IPs of people you can see taking a rebellious position in discussions about these orga…
Or you could assume that they have that information already. Which I deem highly likely - private repos are a must-target for any intelligence service out there.
Re: GCHQ's Boiling Frogs paper on software development
#35http://imgur.com/a/pbazB Contents of this PDF, page by page, in JPGs.
Re: GCHQ's Boiling Frogs paper on software development
#36Re: GCHQ's Boiling Frogs paper on software development
#37Re: GCHQ's Boiling Frogs paper on software development
#38Re: GCHQ's Boiling Frogs paper on software development
#39Earlier quoted context omitted.
It's OK - Github converts it to HTML. However, GCHQ could politely ask the NSA to force Github to give them the usernames and IP addresses that viewed the repo. Maybe use Tor?
I don't understand why everybody assumes GCHQ and NSA are completely inept amateurs. Getting a list of usernames and IP addresses from GitHub would have an insane signal to noise ratio - after all, there are plenty of perfectly legitimate reasons to want to read this document. It's much easier to go to HN and grab the usernames and IPs of people you can see taking a rebellious position in discussions about these orga…
Assuming anyone is inept is inept, since even the inept get lucky.
Re: GCHQ's Boiling Frogs paper on software development
#40I like how all the members of that GitHub organisation have secret usernames: https://github.com/orgs/GovernmentCommunicationsHeadquarters...