Live data from Hacker News

Signs of a Creepy Government Conspiracy at Standing Rock

cracked.com

11–20 of 88 posts

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#11
If everything in this story is true (and I see no reason to doubt it), then there is a 0-day being used here in the wild to hack gmail accounts for political purposes. There really need to be some security engineers (ideally Google security engineers) on-site investigating, both to identify and fix the exploits being used, and to establish their use later for legal purposes.

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#12
post #6

Earlier quoted context omitted.

Without HSTS and cert pinning they don't even get as far as TLS.

If they've connected to Gmail before they would have received HSTS headers. So I'm not sure what you are suggesting? Could you elaborate on how you think GSM cipher downgrades lead to stolen Gmail credentials? edit: Furthermore Chrome/Firefox implement HSTS preload lists on which gmail.com is included. [0][1] [0] https://cs.chromium.org/chromium/src/net/http/transport_secu... [1] https://blog.mozilla.org/security/201…

I can see something simple like redirecting random pages to a fake login page. The average person will fall for the simplest of attacks so it wouldn't surprise me to hear that they were just using a captive portal that asked for their Google account credentials to use wifi.

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#13
The tricky thing about stuff like this is that the majority of people at protests (and in the general population) are incredibly tech illiterate. They are easily exploitable, but also prone to misunderstanding what they're seeing when things go weird with their devices.

We know that hacking and spying on protestors happens, because there are FOIA (and similar state level public information act) requests that have revealed it. We also know there is collusion between private tech firms and the government at all levels that utilize questionable tactics (Stratfor leaks; Barrett Brown just got out of jail for covering this collusion as a journalist and Jeremy Hammond is still in jail for leaking it). So, something is certainly happening at Standing Rock. It is a protest against perhaps the most powerful interests in the world (oil and gas and international finance) so surely every tool available is being used against them.

So, this is probably half paranoia and half correct. It's hard to know which parts are correctly diagnosing the symptoms, however.

Also, some of the practices are likely unconstitutional, by most reasonable interpretations, but we long passed the point where the US government gave a damn about that when it comes to tech privacy.

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#14
I have a question:

At the beginning of the article they author mentions that there is no cell signal once you reach the camp.

Wouldn't a Cessna with a Stingray on board show up on your cell phone as a signal?

It was my understanding that the way the Stingrays works is that they broadcast a pilot signal just like a regular cell tower albeit a spoofed one.

Wouldn't you be able to see that your cell phone all of sudden has x bars signal when you hear or see the Cessna and then that signal would disappear when the Cessna leaves?

Cessnas are not that quiet and they aren't capable of flying that high to the point that you couldn't hear or see them right?

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#15
Relevant: Lack of a Cipher Status Indicator on Android has been an open issue since 2009 (https://code.google.com/p/android/issues/detail?id=5353)

There is also an open-source android app to detect fake base-stations: https://github.com/CellularPrivacy/Android-IMSI-Catcher-Dete...

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#16
I've seen this particular article before and despite me being fairly liberal, seems kind of lazy for journalism. It's a bunch of heresay with no conclusion, but clearly wants to draw the reader's opinion. The author admits that they aren't a place with an investigation budget and "someone else" should look into it. This damages the story - which seems likely to be happening to some degree - to the point where it is completely lost to someone who isn't fully aligned with the conclusion ahead of time.

I mean, a simple technical fact check of one paragraph that they could have enhanced by speaking with someone who understands these things:

> would talk about their cellphone signals cutting out just as drones circled above.

OK, plausible

> Mobiles would switch themselves off and on again -- not in pocket but in hand.

If they mean turn on and off, unlikely. Maybe rebooting via DDoS on the baseband, but we're jumping into suppositions and inventions here.

> Camera apps were opened out of nowhere

Pretty unlikely

> and batteries would drain by enormous percentages, killing the phones in minutes, rather than the steady decline of any device pinging back and forth searching for a signal

That seems plausible. DDoS on a phone by making the bandwidth burn power.

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#17

I have a question: At the beginning of the article they author mentions that there is no cell signal once you reach the camp. Wouldn't a Cessna with a Stingray on board show up on your cell phone as a signal? It was my understanding that the way the Stingrays works is that they broadcast a pilot signal just like a regular cell tower albeit a spoofed one. Wouldn't you be able to see that your cell phone all of sudden…

They could just as easily be jamming cell signals.

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#18
post #12

Earlier quoted context omitted.

If they've connected to Gmail before they would have received HSTS headers. So I'm not sure what you are suggesting? Could you elaborate on how you think GSM cipher downgrades lead to stolen Gmail credentials? edit: Furthermore Chrome/Firefox implement HSTS preload lists on which gmail.com is included. [0][1] [0] https://cs.chromium.org/chromium/src/net/http/transport_secu... [1] https://blog.mozilla.org/security/201…

I can see something simple like redirecting random pages to a fake login page. The average person will fall for the simplest of attacks so it wouldn't surprise me to hear that they were just using a captive portal that asked for their Google account credentials to use wifi.

This doesn't even seem that different from how gmail actually works -- before I stopped using it I was always astonished by the insane chain of redirects the browser is directed through before eventually seeing the login screen.

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#19

I have a question: At the beginning of the article they author mentions that there is no cell signal once you reach the camp. Wouldn't a Cessna with a Stingray on board show up on your cell phone as a signal? It was my understanding that the way the Stingrays works is that they broadcast a pilot signal just like a regular cell tower albeit a spoofed one. Wouldn't you be able to see that your cell phone all of sudden…

They could just as easily be jamming cell signals.

There's no way they would stoop that low. They can just as easily block service with a stingray and avoid causing interference for everything other than the target. There's also the issue that a jammer will also block 911 calls so I don't really see why the FBI or any domestic law enforcement would want a simple jammer instead of using a stingray to selectively block service. There's really only downsides to it when compared to using a cell site simulator.
Post reply on HN