Live data from Hacker News

Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

nytimes.com

71–80 of 84 posts

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#71
post #10

So, basically, it looks like there's a reasonable probability that this guy isn't the leaker. I know that if I wanted to actually blow the whistle on somebody like the NSA, I would make sure to plant the evidence on somebody else to give them a juicy target to latch onto.

With all sorts of current issues, I wouldn't be surprised if the poor guy was the fall guy. Heck, the guy was part of an elite team for NSA and at some point you have take your work home so you could finish it after dinner or over the weekend. Given the circumstances the story doesn't add up looking at it from software perspective to the least.

If he was the one (with full proof) trying to sell secrets then I won't blink twice.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#72

> F.B.I. agents on the case, advised by N.S.A. technical experts, do not believe Mr. Martin is fully cooperating, the officials say. He has spoken mainly through his lawyers, James Wyda and Deborah Boardman of the federal public defender’s office in Baltimore. It sounds like they're just mad that he didn't confess immediately, instead of doing the smart thing of having professional handle everything. Do they really e…

Yes. Because in many cases, suspects don't properly exercise their rights, and they usually end up acting to their own detriment.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#73

As far as I'm concerned, the NSA are the enemy - so props to anybody who can poke a stick in their eye. I just hope this guy doesn't wind up in Guantanamo for the rest of his life.

Uhm, per his story, he was working for "the enemy" and took his work home so he could get better at it. Shouldn't you be angry at someone so diligently working to harm you?

Well, I don't think we really know what happened yet, but yes, you have a good point IF that is the case. I have to admit, I let my own biases creep in and was probably assuming he leaked the stuff intentionally.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#74
post #7

As far as I'm concerned, the NSA are the enemy - so props to anybody who can poke a stick in their eye. I just hope this guy doesn't wind up in Guantanamo for the rest of his life.

What is interesting to me is that even super security gurus at NSA can't contain their most sensitive data (well, maybe tools aren't highest level?). At some point I think we need a better security strategy than trying to stop data from leaving, and more about how to make sure data is useless outside of its domain. edit: I say that now in retrospect that security and freedoms of data seem always at odds. DRM being a…

I think it's dependent on what the data is. We still haven't seen the JFK files... I'm guessing they were smart enough to only keep physical copies of that.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#75

Earlier quoted context omitted.

What I find astonishing is that these machines have working USB ports at all. And even if there are some external media connections like DVD burner or USB, wouldn't it make sense to at least hardwire them to some tamper-resistant logging device that protocols who used them at which time?

I'm certain I remember hearing about the military at least filling USB ports with epoxy at one point after the Manning leaks.

This has been SOP in certain places for a long time.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#76

Earlier quoted context omitted.

Yes. They're the FBI. They're not used to people exercising their rights.

The 2 FBI people I've known, both had law degrees..

Lots of people have degrees and still make mistakes, or push a personal/company motive that isn't inline with their training at school.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#77

> "F.B.I. agents on the case, advised by N.S.A. technical experts, do not believe Mr. Martin is fully cooperating, the officials say. He has spoken mainly through his lawyers" As is his right and what every sensible entirely innocent individual in his position should be doing. If the government (at any level from civic to federal to international) arrests you for any crime with serious charges, it is ABSOLUTELY the m…

It's not clear (to me) whether the "through his lawyers" comment is intending to convey the reason the FBI doesn't believe he's cooperating. It could just as likely be setting up the next sentence which says the lawyers declined to comment.

If the "through his lawyers" comment was explaining the FBI's level of belief, it should have been stated more explicitly. I kind of doubt it though -- local law enforcement might be suspicious of someone who lawyers up, for the FBI, it must be pretty much standard (or at least not unusual).

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#78

Earlier quoted context omitted.

I contract for many large state and federal agencies. For better or worse, contractors are easier to hire and fire for the federal government. That gives them more budgetary flexibility. You can also hire people and companies that specialize in the specifics of the project quickly through established contracting channels with established reputations. Contractors are also able to legally bypass red tape and bureaucrac…

Don't they have random searches? when I went to HMGCC for an interview (at Hanslope Park) a couple of years back there was a sign up saying that you could be searched on entry and exit.

Ever hear a plastic Wal-Mart shopping bag referred to as a "cloaking device"? Also, in some places, items that are banned when referred to by their proper names are allowed when they are instead called "contractor equipment".

The problem is that the level of control required for actual security prevents people from being able to do their jobs effectively. And if no one can get anything done, there's nothing to secure. So this leads to an environment where everything is oversecured by default, and bypassing the nominal level of security is simple, easy, and commonplace--sometimes even expected.

For instance, you don't have local administrator access on your workstation. But you have Visual Studio and its debugger, and can compile and run any source you can type in. You also have physical access to the machine, with its 5.25" removable-media drive. It becomes faster and easier to reimplement an unzip utility from a printed spec than to get 7zip installed on your machine. And the hand-rolled utility probably has a larger exposed attack surface than the open source program.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#79
post #53

The fundamental flaw is employing contractors.. Governments should be doing all things they are responsible for in house. Contracting anything out costs in terms of added security risk and in profits a contractor will want.

Former DoD contractor here. Contracting is a description of legal contracts and payment flows, independent of security arrangements. I sat in the same SCIF as my directly employed colleagues, and the same security officer was in charge of our site and everything I did at the site. My employer's security officer had to handle getting my clearance and forwarding the paperwork to my site's security officer. It's not lik…

Except they would get Columbus Day and MLK Day as paid holidays, while you had to sit at home and eat a PTO day, because the work site cannot be used with no government employees there, and your company doesn't coordinate its holiday schedule for on-site employees.

And then they would have some morale event (read: party/picnic) on base, and they could go to it while on the clock, while you were nominally invited, but if you attended it would have to be off the clock.

Then the funding for your project is interrupted. They get furloughed, and will probably be repaid later when the funding is restored, but you just get straight-up laid off, and have to find a new job with zero notice.

But at least you got paid more. That almost makes the crap treatment worthwhile.

Re: Trove of Stolen Data Is Said to Include Top-Secret U.S. Hacking Tools

#80

Earlier quoted context omitted.

I think that's because most of the people doing the work are contractors. Not because of some notion of contractors being less secure/loyal/honest/organized than gov employees. For one federal organization I work for literally everyone I work with and talk to at all levels seems to be a contractor except for a couple people. the ratio is at least 20:1 contractors to federal employees. As for why this is, it's mostly…

I agree, I never meant to imply that I thought contractors were less loyal. I appreciate the depth of your responses and hope I haven't given offense. There are just so many of them that it projects the attack surface of the DoD out; now you can attack contractors which aren't as tightly regulated, and they might hire people to, say, build their website that aren't even cleared. So now I can steal some web dev's cred…

No offense taken. And yes external contractors can pose additional security vulnerabilities since they are not always under the same security policies on their own machines. I know that some departments are changing things so all work must be performed on government equipment with government source control on internal networks. If my client does this I will definitely quit. I am already pretty burned out on the work (their policy is all internal projects must be in cold fusion)
Post reply on HN