Live data from Hacker News

Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

nytimes.com

61–70 of 84 posts

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#61

Earlier quoted context omitted.

Yes. They're the FBI. They're not used to people exercising their rights.

The 2 FBI people I've known, both had law degrees..

So does James Comey and he's a complete idiot.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#62
post #11

The Shadow Brokers are still active online. https://www.reddit.com/r/DarkNetMarkets/comments/57le5u/thes... However nothing in the message proves that it was written recently.

Have any of you checked if the same secret key was used to sign the original and this message?

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#63

It seems like contractors are a massive attack surface for the DoD. I do wonder why they gave a clearance to someone who was apparently a hoarder. If collecting things that interest you in a compulsory manner doesn't suggest to you that this person might be abused by foreign powers, but marijuana use does, your secrets will flow like water.

collecting things that interest you in a compulsory manner vs marijuana use

The key difference to the government is hording can be perfectly legal while marijuana use requires you to participate in the black market.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#64

Earlier quoted context omitted.

not where I work. Also, random could mean once every 10 years. I use a laptop and take it home every night. Unless they banned users from taking everything with them (phones keychains etc) there's not much a random search would accomplish.

I know people who worked at places where taking a phone into work with a camera in was verboten. And for high security places why on earth would they allow people to work on laptops that are taken home every night an obvious security risk.

Indeed. I worked in a secure environment for about 4-5 years, and we couldn't bring our cellphone (of any type) or any other electronics/storage devices/etc. into work. In fact, while working there I had surgery that required me to lug around a medical device 24/7 for a while. And because the device had an exposed USB port, I wasn't allowed to return to work until after I no longer needed it. That took roughly 1 month.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#65

Earlier quoted context omitted.

The 2 FBI people I've known, both had law degrees..

So does James Comey and he's a complete idiot.

That extraordinary claim requires extraordinary evidence. Can I assume you are also a lawyer?

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#66

Earlier quoted context omitted.

As an outsider looking in, it seems like there have been a lot of DLEs due to contractors though. Theres the obvious example of Snowden, but also the QinetiQ breach ( https://www.bloomberg.com/news/articles/2013-05-01/china-cyb... ). Moonlit Maze might be a counterexample.

I think that's because most of the people doing the work are contractors. Not because of some notion of contractors being less secure/loyal/honest/organized than gov employees. For one federal organization I work for literally everyone I work with and talk to at all levels seems to be a contractor except for a couple people. the ratio is at least 20:1 contractors to federal employees. As for why this is, it's mostly…

I agree, I never meant to imply that I thought contractors were less loyal. I appreciate the depth of your responses and hope I haven't given offense.

There are just so many of them that it projects the attack surface of the DoD out; now you can attack contractors which aren't as tightly regulated, and they might hire people to, say, build their website that aren't even cleared. So now I can steal some web dev's credentials and pivot towards classified networks.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#67

It seems like contractors are a massive attack surface for the DoD. I do wonder why they gave a clearance to someone who was apparently a hoarder. If collecting things that interest you in a compulsory manner doesn't suggest to you that this person might be abused by foreign powers, but marijuana use does, your secrets will flow like water.

collecting things that interest you in a compulsory manner vs marijuana use The key difference to the government is hording can be perfectly legal while marijuana use requires you to participate in the black market.

Which is a pretty flimsy reason to believe an adversary might find leverage against you. But hoarding is a force multiplier in the adversary's favor.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#68

Earlier quoted context omitted.

Yes. They're the FBI. They're not used to people exercising their rights.

The 2 FBI people I've known, both had law degrees..

I didn't say they don't know the law, though.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#70

Earlier quoted context omitted.

So does James Comey and he's a complete idiot.

That extraordinary claim requires extraordinary evidence. Can I assume you are also a lawyer?

Extraordinary claims don't require more evidence than other claims. A more accurate statement would be, "claims I'm skeptical of will require convincing evidence for me to be swayed." The "extraordinary" part makes this razor less useful, as if there were more than one category of evidence and one of them simply wasn't good enough for you.

Comey continues to advocate for backdoors in order to stop ISIS from being able to radicalize marginalized people within the US without them being able to listen. However, there are two obvious problems with this.

1. Why don't you just reach out to the marginalized yourself? Spend that $1M you paid to break into an iPhone on combatting Islamphobia and ISIS will have a tougher job.

2. What is to stop ISIS from using software written outside the US, or software they write themselves, or versions of software older than the mandated backdoors, or open-source software, or... on and on and on. His plan transparently will not work. To quote Schneier, "His problem isn't encryption, it's general purpose computers and a global market for software."

That is stupid.

Post reply on HN