Live data from Hacker News

Equation Group Cyber Weapons Auction

theshadowbrokers.tumblr.com

111–120 of 151 posts

Re: Equation Group Cyber Weapons Auction

#111
post #9

The structure of this auction is amazing! 1. All bids are paid up front, and you never get your money back, even if you aren't the highest bidder. So if people bid $50, $70, and $100, they collect $220. 2. No one can verify what is actualy up for sale before the auction. 3. There is no way for the world to know that they actualy delivered the goods after the auction. 4. There is no way for the highest bidder to know…

Not to mention the complete insults to anyone who would want to buy it. A government would handle this by trying to chase down the autioneers. If they wanted the data, they would buy it from Kaspersky, assuming it's real.

It would be reasonable to assume that the data in the auction contains as-of-yet undiscovered exploits. this also makes sense when you consider we will not likely know who walks away with this.

Re: Equation Group Cyber Weapons Auction

#112

Isn't this obviously a hoax? The screenshots are not at all what I would expect -- python files? shell scripts? in the face of esoteric pieces of C software like stuxnet? Add on the fact that the author of the readme is clearly writing in an exaggerated Russian / East European accent, with such wild claims and mystery surrounding the terms of the auction...I would suspect joke or alternate reality game more quickly t…

> Add on the fact that the author of the readme is clearly writing in an exaggerated Russian / East European accent, with such wild claims and mystery surrounding the terms of the auction...I would suspect joke or alternate reality game more quickly than a hack of Equation Group.

Without any spelling mistakes.

Re: Equation Group Cyber Weapons Auction

#113

The preview contains old working exploits. They should release some post-snowden compilable source if they want a little more legitimacy. Python files the russian government picked off a compromised server a few years ago are not interesting. Code shared by snowden with someone who had bad opsec is interesting but not as interesting as what they claim this is.

I didn't catch any reporting about any malware code that Snowden retrieved, can you link me to those new stories?

I remember an config file regarding the XKeyscore tool, but nothing else.

Re: Equation Group Cyber Weapons Auction

#114
post #104
post #9

The structure of this auction is amazing! 1. All bids are paid up front, and you never get your money back, even if you aren't the highest bidder. So if people bid $50, $70, and $100, they collect $220. 2. No one can verify what is actualy up for sale before the auction. 3. There is no way for the world to know that they actualy delivered the goods after the auction. 4. There is no way for the highest bidder to know…

It makes sense if they know they've released information that the person who this was leaked from can absolutely verify it's legitimacy, and wants to keep it secret at all costs while also maximizing return.

Correct! This is why they are doing it this way.

Re: Equation Group Cyber Weapons Auction

#118
post #2

Interesting discussions happening on Twitter, eg https://twitter.com/thegrugq . Looks like this could be at least somewhat legit.

The grugq tweets should always be read with the understanding/context that he sells bugs to the Feds. He is not an impartial observer on the topic of nation-state malware.

Re: Equation Group Cyber Weapons Auction

#119
post #9

The structure of this auction is amazing! 1. All bids are paid up front, and you never get your money back, even if you aren't the highest bidder. So if people bid $50, $70, and $100, they collect $220. 2. No one can verify what is actualy up for sale before the auction. 3. There is no way for the world to know that they actualy delivered the goods after the auction. 4. There is no way for the highest bidder to know…

THIS:

https://blockchain.info/address/19BY2XCgbDe6WtTVbTyzM9eR3LYr...

Re: Equation Group Cyber Weapons Auction

#120
post #31

Earlier quoted context omitted.

If this leak is real, it points to one of two things. Either it isn't the NSA and is a company or some quasi-governmental group - owing to the fact that any of this shit the NSA makes would be on JWICS terminals and absolutely not accessible to the internet, or it means there's a leak from the NSA that dumped these files and has decided to sell them. I'd lean more towards the former.

The command and control ("listening posts" in intelligence community parlance) for even NSA implants has to be on the public internet so the victims can phone home. This stuff could be from one of those servers.

Is that necessarily true for NSA et al.? I don't see why the target couldn't just send the data towards an arbitrary destination, and that data be collected by NSA via a passive tap. Commands could be sent using a QUANTUM-style technique (packet injection with spoofed origin)
Post reply on HN