Wait, the GCHQ has a GitHub profile where they share a Graph Database engine. Interesting.
NSA has a linux distro https://en.wikipedia.org/wiki/Security-Enhanced_Linux
GCHQ's Boiling Frogs paper on software development
61–70 of 85 posts
Re: GCHQ's Boiling Frogs paper on software development
#62Earlier quoted context omitted.
It literally makes sense. Do you mean to say it is paranoid?
No. The origin of a PDF has no relation to the security or otherwise of the format.
If I view using pdf.js, then not only does the "format" need to be unsecure (whatever that means), but it would require a browser vulnerability that's exploitable through javascript.
At which point why go through the charade of a PDF at all?
Re: GCHQ's Boiling Frogs paper on software development
#63Earlier quoted context omitted.
That's a bit no-true-Scotsman? There's a history of PDF exploits that have made people wary. The exploits are delivered in the PDF, therefore some PDFs are 'unsafe'. (As other comments have said, we shouldn't take "omg gchq are going to serve me an exploit PDF" too seriously, but there have been incidents of security services using PDF exploits to spear-phish people) Edit: an example bank PDF exploit is mentioned in:…
That's true, only in the sense that all software ever published may have vulnerabilities, meaning there is no format which is 'safe'. That's fine, if that's your definition, but it's obviously useless for comparison.
Re: GCHQ's Boiling Frogs paper on software development
#64Earlier quoted context omitted.
(In case folks don't know, PNG better for text because JPG's compression introduces "ringing" artifacts around sharp edges, such as the black/white transition of text.) https://en.wikipedia.org/wiki/Ringing_artifacts
JPGs are also a lot safer as PDFs can ping remote resources using carefully hidden beacon images. Although that said, I sometimes use this to see who opened my files. I once left hundreds of these on a very popular cloud hosting provider (not naming names), and somebody working there was stupid to open the PDF on a machine connected to the internet, thereby proving abuse by employees and proving any random stranger c…
Re: GCHQ's Boiling Frogs paper on software development
#65https://virustotal.com/en/url/1ecad5426be630531d4e5c9d4091a0...
Re: GCHQ's Boiling Frogs paper on software development
#66I really doubt this PDF is infected with anything like people are suggesting, but why is it on here at all? It seems incredibly empty and buzzword-y to me, interspersed with such charming insights as "It can make good sense to use external suppliers." Lots of talk about "disruption". It reads... well, it reads exactly like what it is, a vacuous corporate "whitepaper".
Because GCHQ are having a PR drive and they have enough accounts here to up-vote it to the front page?
What would they gain? And if they really have an eye on HN, that would probably mean that NSA as well. If that is true, would it inhibit a community like HN to self-censor?
Re: GCHQ's Boiling Frogs paper on software development
#67Re: GCHQ's Boiling Frogs paper on software development
#68Earlier quoted context omitted.
Because GCHQ are having a PR drive and they have enough accounts here to up-vote it to the front page?
Would it really be a good investment for GCHQ to keep enough sockpuppet accounts on HN to upvote something like this to the front page? What would they gain? And if they really have an eye on HN, that would probably mean that NSA as well. If that is true, would it inhibit a community like HN to self-censor?
https://theintercept.com/2014/02/24/jtrig-manipulation/
What would they gain? Look at the slides, these are not normal people all working in a large circular building. What would Kennedy have gained from the Bay of Pigs crisis had it gone the other way? Group think is it's own force. Those slides are pretty disturbing IMHO as is pretty-much everything I've ever seen out of that org.
Re: GCHQ's Boiling Frogs paper on software development
#69Earlier quoted context omitted.
Because GCHQ are having a PR drive and they have enough accounts here to up-vote it to the front page?
Would it really be a good investment for GCHQ to keep enough sockpuppet accounts on HN to upvote something like this to the front page? What would they gain? And if they really have an eye on HN, that would probably mean that NSA as well. If that is true, would it inhibit a community like HN to self-censor?
Tech people being more willing to work there, being less opposed to their friends working there, being less likely to tell legislators that GCHQ is an embarrassment to their country or a threat to its values or future freedom.
Greater likelihood of tech companies being willing to cooperate with GCHQ requests or inquiries (whether for counterintelligence or espionage purposes).
Edit: Academic researchers being more willing to take research funding from GCHQ or collaborate with GCHQ on research projects.
Re: GCHQ's Boiling Frogs paper on software development
#70Earlier quoted context omitted.
Would it really be a good investment for GCHQ to keep enough sockpuppet accounts on HN to upvote something like this to the front page? What would they gain? And if they really have an eye on HN, that would probably mean that NSA as well. If that is true, would it inhibit a community like HN to self-censor?
There have been leaks from GCHQ on influencing internet forums. https://theintercept.com/2014/02/24/jtrig-manipulation/ What would they gain? Look at the slides, these are not normal people all working in a large circular building. What would Kennedy have gained from the Bay of Pigs crisis had it gone the other way? Group think is it's own force. Those slides are pretty disturbing IMHO as is pretty-much everything I'…
I mean I was aware that spooks were aware of forums and watching them and such, but I never thought that a forum like HN would be a target for them.
But I guess that after thinking for a bit HN could definitely be a valuable target. It's just hard for me to accept that a community I visit regularly could be under the influence of these organizations.
Scary thoughts.