Live data from Hacker News

Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

nytimes.com

51–60 of 84 posts

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#51

Earlier quoted context omitted.

DRM is more about who has the keys , than security itself.

Modern computer security is all about who has the keys.

Just like a steel door, when somebody else has the keys, you are not secure - you are imprisoned.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#53

The fundamental flaw is employing contractors.. Governments should be doing all things they are responsible for in house. Contracting anything out costs in terms of added security risk and in profits a contractor will want.

Former DoD contractor here. Contracting is a description of legal contracts and payment flows, independent of security arrangements. I sat in the same SCIF as my directly employed colleagues, and the same security officer was in charge of our site and everything I did at the site. My employer's security officer had to handle getting my clearance and forwarding the paperwork to my site's security officer.

It's not like DoD contractors are doing classified work from home in their sleepwear. They're still subject to the same security procedures, and in fact the same security people are overseeing the contractors and direct employees.

I would still roll in before sunrise during what looked to be a beautiful day and work in a windowless chainsaw-resistant room with a steel door. I'd daydream of a nice sunny lunch break just like my direct employee colleagues, and be just as disappointed that it was raining when I exited isolation.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#54
post #26

Earlier quoted context omitted.

DRM is surprisingly security oriented, if you think about it,the premise of DRM is not trusting the user, which is more extreme than most security models (allow the user root/admin access to the OS is anithetical to not trusting the user).

DRM is more about who has the keys , than security itself.

Much of the base terminology of DRM comes from the military, and it involves the generals "back home" being able to trust that a computer out in the field, containing sensitive data, will not allow non-authorized personnel, never mind the enemy, to access said data.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#55
Question, did NYT break their website for noScript users or did I manage somehow to break the NYT website for myself? (I tested with chromium and no plugins and the website works there, but if I try to access it with FF and noScript, the articles only display a log-in form, even if I grant permissions to everything.)

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#56

Earlier quoted context omitted.

DRM is about neither security nor freedom.

But the more secure we make our devices, the more opportunities we create for them to be locked down. One person's security update is another's anti-jailbreak patch. Trusted computing can be used to protect against malware and to block users from saving Netflix streams.

I disagree with the notion of a computing system being “secure” in absolute terms, without reference to what the user wants to do with it. A system is secure if it's unlikely to compromise the integrity and/or privacy of information the user deems sensitive, which of course varies from one user to another.

Without reference to a specific user, all you can talk about is a computing system being restricted or unrestricted, and I don't want my computing devices to have restrictions imposed by someone other than myself.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#57
post #7

As far as I'm concerned, the NSA are the enemy - so props to anybody who can poke a stick in their eye. I just hope this guy doesn't wind up in Guantanamo for the rest of his life.

What is interesting to me is that even super security gurus at NSA can't contain their most sensitive data (well, maybe tools aren't highest level?). At some point I think we need a better security strategy than trying to stop data from leaving, and more about how to make sure data is useless outside of its domain. edit: I say that now in retrospect that security and freedoms of data seem always at odds. DRM being a…

I would like to see a massive effort in research and development of unbreakable encryption, privacy tools, and general security.

Everyone, the NSA, rest of our government, all governments, all citizens of the world, all businesses should be protected. If we just spent a small percentage of what we spend on endless wars for profit, then I think we could mostly reach these goals.

I would like to think that we could still catch and prosecute criminals, and I include terrorists when I say criminals, without violating rights to privacy and our general rights.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#58

> "F.B.I. agents on the case, advised by N.S.A. technical experts, do not believe Mr. Martin is fully cooperating, the officials say. He has spoken mainly through his lawyers" As is his right and what every sensible entirely innocent individual in his position should be doing. If the government (at any level from civic to federal to international) arrests you for any crime with serious charges, it is ABSOLUTELY the m…

100 percent agree. If you're speaking through your lawyer, you are cooperating. Never ever speak to law enforcement without a lawyer there to explain the law to you if you've been charged, or sometimes even if you're being questioned, about a crime.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#59

> F.B.I. agents on the case, advised by N.S.A. technical experts, do not believe Mr. Martin is fully cooperating, the officials say. He has spoken mainly through his lawyers, James Wyda and Deborah Boardman of the federal public defender’s office in Baltimore. It sounds like they're just mad that he didn't confess immediately, instead of doing the smart thing of having professional handle everything. Do they really e…

Yes. They're the FBI. They're not used to people exercising their rights.

The 2 FBI people I've known, both had law degrees..

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#60

Earlier quoted context omitted.

I contract for many large state and federal agencies. For better or worse, contractors are easier to hire and fire for the federal government. That gives them more budgetary flexibility. You can also hire people and companies that specialize in the specifics of the project quickly through established contracting channels with established reputations. Contractors are also able to legally bypass red tape and bureaucrac…

What I find astonishing is that these machines have working USB ports at all. And even if there are some external media connections like DVD burner or USB, wouldn't it make sense to at least hardwire them to some tamper-resistant logging device that protocols who used them at which time?

I'm certain I remember hearing about the military at least filling USB ports with epoxy at one point after the Manning leaks.
Post reply on HN