Live data from Hacker News

Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

nytimes.com

41–50 of 84 posts

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#41
post #7

As far as I'm concerned, the NSA are the enemy - so props to anybody who can poke a stick in their eye. I just hope this guy doesn't wind up in Guantanamo for the rest of his life.

What is interesting to me is that even super security gurus at NSA can't contain their most sensitive data (well, maybe tools aren't highest level?). At some point I think we need a better security strategy than trying to stop data from leaving, and more about how to make sure data is useless outside of its domain. edit: I say that now in retrospect that security and freedoms of data seem always at odds. DRM being a…

> and more about how to make sure data is useless outside of its domain.

This explains why most enterprise applications and platforms are a nightmare to work with. This class is called "UserView" oh but you see comrade it actually does not have any view or user, in fact its sole purpose is to be compiled and thrown away - nevermind the JIRA issues for bugs in it. Everything is "business logic" "business specific", noone who hasnt been at the place for 3-5 years can understand that this is not actulaly what it says it is.

This kind of feature was called before JCR, "Just for Curious Russians".

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#42

Earlier quoted context omitted.

I contract for many large state and federal agencies. For better or worse, contractors are easier to hire and fire for the federal government. That gives them more budgetary flexibility. You can also hire people and companies that specialize in the specifics of the project quickly through established contracting channels with established reputations. Contractors are also able to legally bypass red tape and bureaucrac…

What I find astonishing is that these machines have working USB ports at all. And even if there are some external media connections like DVD burner or USB, wouldn't it make sense to at least hardwire them to some tamper-resistant logging device that protocols who used them at which time?

You have to trust your employees at some point. If he was writing code he also could have written back doors to access and download it from somewhere else.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#43

> He always thought of himself like a James Bond-type person, wanting to save the world from computer evil Maybe the NSA needs less James Bond characters and more engineers.

So? your not really making sense here "engineers" may well think that working for the good of the state is more ethical than working on an improved algo for google/facebook to monetize peoples private data.

Good of the State or good of the oligarchs? That is the question!

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#44
> F.B.I. agents on the case, advised by N.S.A. technical experts, do not believe Mr. Martin is fully cooperating, the officials say. He has spoken mainly through his lawyers, James Wyda and Deborah Boardman of the federal public defender’s office in Baltimore.

It sounds like they're just mad that he didn't confess immediately, instead of doing the smart thing of having professional handle everything. Do they really expect someone to cooperate gladly when repercussions could be severe?

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#45
post #26

Earlier quoted context omitted.

DRM is surprisingly security oriented, if you think about it,the premise of DRM is not trusting the user, which is more extreme than most security models (allow the user root/admin access to the OS is anithetical to not trusting the user).

DRM is more about who has the keys , than security itself.

Modern computer security is all about who has the keys.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#46
> "F.B.I. agents on the case, advised by N.S.A. technical experts, do not believe Mr. Martin is fully cooperating, the officials say. He has spoken mainly through his lawyers"

As is his right and what every sensible entirely innocent individual in his position should be doing. If the government (at any level from civic to federal to international) arrests you for any crime with serious charges, it is ABSOLUTELY the most prudent thing to communicate solely through your lawyers.

There is too great of a risk of being convicted due to doubt and natural human inconsistency otherwise.

For anyone that doubts how even the most innocent person can be convicted for not heeding this advice, there is a hilarious and content-dense lecture on the subject: https://www.youtube.com/watch?v=ZGgKLgVNfAo

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#47
post #23

It seems like contractors are a massive attack surface for the DoD. I do wonder why they gave a clearance to someone who was apparently a hoarder. If collecting things that interest you in a compulsory manner doesn't suggest to you that this person might be abused by foreign powers, but marijuana use does, your secrets will flow like water.

The government has all sorts of pay guidelines on what people can make, which makes it near impossible for them to retain talent. Most of the NSA guys I know put in 18 or so months, then go to Booz Allen and get contracted right back to the department they left at 4x the pay (one guy even got his same desk back). Every time someone points out the "why'd they give a clearance to X person" argument, I point out that th…

It's roughly 5 million people. The number fluctuates, but way more than 1 million people have US government issued security clearances.

http://www.defenseone.com/business/2015/04/number-security-c...

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#48

Earlier quoted context omitted.

not where I work. Also, random could mean once every 10 years. I use a laptop and take it home every night. Unless they banned users from taking everything with them (phones keychains etc) there's not much a random search would accomplish.

I know people who worked at places where taking a phone into work with a camera in was verboten. And for high security places why on earth would they allow people to work on laptops that are taken home every night an obvious security risk.

Apple are well known for being ridiculously paranoid about products being leaked before their announcement, so much so that at one point they put eye-height frosting (not the cake type) on the glass walls to stop people accidentally looking in to the factory floor.

My bag was checked once in the 5 weeks I worked there - on the way in. The passwords I created for their new servers (containing metrics from the factory's build and test processes) was at one point walking around Cork in their admin's wallet. I used my own laptop (because OSX bleugh) plugged straight into their corporate lan.

But they did have a room which was out of bounds.

Nobody gets security right, however "high security" they think they are.

Oh and let's not get started on what the MoD thinks it's achieving in its immigration office.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#49
post #26

Earlier quoted context omitted.

DRM is surprisingly security oriented, if you think about it,the premise of DRM is not trusting the user, which is more extreme than most security models (allow the user root/admin access to the OS is anithetical to not trusting the user).

It's funny. People get all excited about homomorphic encryption, which is basically DRM with a mathematical proof.

Because it works both ways. I can send my data to a server and have it do things to it without ever actually knowing it. You can't let me watch a video without letting me watch a video.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#50

> F.B.I. agents on the case, advised by N.S.A. technical experts, do not believe Mr. Martin is fully cooperating, the officials say. He has spoken mainly through his lawyers, James Wyda and Deborah Boardman of the federal public defender’s office in Baltimore. It sounds like they're just mad that he didn't confess immediately, instead of doing the smart thing of having professional handle everything. Do they really e…

Yes. They're the FBI. They're not used to people exercising their rights.
Post reply on HN