Live data from Hacker News

Signs of a Creepy Government Conspiracy at Standing Rock

cracked.com

21–30 of 88 posts

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#21

I've seen this particular article before and despite me being fairly liberal, seems kind of lazy for journalism. It's a bunch of heresay with no conclusion, but clearly wants to draw the reader's opinion. The author admits that they aren't a place with an investigation budget and "someone else" should look into it. This damages the story - which seems likely to be happening to some degree - to the point where it is c…

""That seems plausible. DDoS on a phone by making the bandwidth burn power."

That's not what is happening. IMSI catchers are well known to ask their victim handsets to transmit at full power - which your phone almost never has to do normally.

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#22
post #6

Earlier quoted context omitted.

Without HSTS and cert pinning they don't even get as far as TLS.

If they've connected to Gmail before they would have received HSTS headers. So I'm not sure what you are suggesting? Could you elaborate on how you think GSM cipher downgrades lead to stolen Gmail credentials? edit: Furthermore Chrome/Firefox implement HSTS preload lists on which gmail.com is included. [0][1] [0] https://cs.chromium.org/chromium/src/net/http/transport_secu... [1] https://blog.mozilla.org/security/201…

The article said people were reporting that Gmail accounts have been hacked in an environment where malicious Wifi APs are prevalent. Your post said that report "sounds suspiciously false."

My reply contended that it's possible. A device running something other than a recent version of a modern browser is entirely susceptible to connection to Gmail over a non-TLS pipe or TLS to a MITM, especially when that device is using a fake Wifi AP.

Citing that the state of the art in browser technology exists does not change that point.

Do you agree it's possible the claim is true?

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#23

I've seen this particular article before and despite me being fairly liberal, seems kind of lazy for journalism. It's a bunch of heresay with no conclusion, but clearly wants to draw the reader's opinion. The author admits that they aren't a place with an investigation budget and "someone else" should look into it. This damages the story - which seems likely to be happening to some degree - to the point where it is c…

>> Camera apps were opened out of nowhere >Pretty unlikely

I thought the same thing, that this is pretty unlikely. But then, most of my personal experience is with iOS, which is pretty well buttoned down. With Android on the other hand, all bets are off. We can't even talk about the security of Android sensibly because there are so many old and unpatched versions out there. So from that perspective, maybe it's not as far fetched as it sounds.

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#24
If some or all of this is real -- someone in the command chain above these resources needs to reshape their thinking and fast! Talk about a quick way to radicalize individuals against the society in which they are embedded:

- Visitors from all over the country come to a welcoming self-supporting nature camp with friendly people behaving peacefully and protesting the destruction of nature for profit

- Apply violence to those people

- Attempt to disrupt these people's ability to communicate about their experience

That kind of visceral experience is the stuff of which revolutions are made. Lately I can't stop thinking about this quote from JFK:

Those who make peaceful revolution impossible will make violent revolution inevitable

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#25

Invalid SSL cert on the site. > There were even reports of people's Gmail accounts being hacked. This sounds suspiciously false - even if they are phones were forced to downgrade to A5/1 this should have no effect on TLS.

I don't know. Are you assuming that the Android phones at the camp are updated with the latest Android versions and security patches?

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#26
post #19

Earlier quoted context omitted.

They could just as easily be jamming cell signals.

There's no way they would stoop that low. They can just as easily block service with a stingray and avoid causing interference for everything other than the target. There's also the issue that a jammer will also block 911 calls so I don't really see why the FBI or any domestic law enforcement would want a simple jammer instead of using a stingray to selectively block service. There's really only downsides to it when…

"There's no way they would stoop that low."

I'm not sure you are familiar with the history of the police state. Just when you think they won't go below a certain bar, then do. Why do you think, when performing any other manner of illegal and unconstitutional things, they wouldn't add one more to the list, especially when there seems to be no repercussions?

I'm also reminded of occupy wall street, in which is was found out after the fact that:

"Banks sat down with FBI officials to pool information about OWS protesters harvested by private security; plans to crush Occupy events, planned for a month down the road, were made by the FBI – and offered to the representatives of the same organizations that the protests would target; and even threats of the assassination of OWS leaders by sniper fire..." - Revealed: how the FBI coordinated the crackdown on Occupy - Naomi Wolf

Much later we even found out the CIA had some involvement, and that's an organization which is not supposed to operate domestically! So, I think you are being naive in putting the abuse of zero-day cell exploits past them, especially when it might not even be the police forces themselves, any number of three-letters could just be seeing this as a good realistic training exercise to test out their latest toys.

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#27
post #22

Earlier quoted context omitted.

If they've connected to Gmail before they would have received HSTS headers. So I'm not sure what you are suggesting? Could you elaborate on how you think GSM cipher downgrades lead to stolen Gmail credentials? edit: Furthermore Chrome/Firefox implement HSTS preload lists on which gmail.com is included. [0][1] [0] https://cs.chromium.org/chromium/src/net/http/transport_secu... [1] https://blog.mozilla.org/security/201…

The article said people were reporting that Gmail accounts have been hacked in an environment where malicious Wifi APs are prevalent. Your post said that report "sounds suspiciously false." My reply contended that it's possible. A device running something other than a recent version of a modern browser is entirely susceptible to connection to Gmail over a non-TLS pipe or TLS to a MITM, especially when that device is…

> Citing that the state of the art in browser technology exists does not change that point.

> Do you agree it's possible the claim is true?

HSTS preload lists are not new (the Mozilla blog I referenced above is dated 2012).

> The article said people were reporting that Gmail accounts have been hacked in an environment where malicious Wifi APs are prevalent. Your post said that report "sounds suspiciously false."

If it's a case of 'technically illiterate user entered gmail credentials on a wifi-login page' than that can happen on literally any wifi-AP. I'm saying that the claim that phones are being forced to connect to fake base-stations mounted on Cessna's (which is possible) is not at all substantiated by reports of people's Gmail accounts being hacked, the later just sounds like lazy journalism as another commenter has pointed out.

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#28

I've seen this particular article before and despite me being fairly liberal, seems kind of lazy for journalism. It's a bunch of heresay with no conclusion, but clearly wants to draw the reader's opinion. The author admits that they aren't a place with an investigation budget and "someone else" should look into it. This damages the story - which seems likely to be happening to some degree - to the point where it is c…

Unless you have access to a mobile phone's baseband source code, you cannot really trust anything about its level of security.

This was discussed on HN a while back and comes up quite often:

https://news.ycombinator.com/item?id=10905643

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#29
post #20
post #10

In other strange news, Cracked is on the front page of HN.

Maybe they're going the way of Buzzfeed

It's... less good for Hacker News that click-baity article titls are getting more upvotes. This story was reported 3 times in the last 2 days...

https://hn.algolia.com/?query=standing%20rock&sort=byDate&pr...

Re: Signs of a Creepy Government Conspiracy at Standing Rock

#30
post #21

I've seen this particular article before and despite me being fairly liberal, seems kind of lazy for journalism. It's a bunch of heresay with no conclusion, but clearly wants to draw the reader's opinion. The author admits that they aren't a place with an investigation budget and "someone else" should look into it. This damages the story - which seems likely to be happening to some degree - to the point where it is c…

""That seems plausible. DDoS on a phone by making the bandwidth burn power." That's not what is happening. IMSI catchers are well known to ask their victim handsets to transmit at full power - which your phone almost never has to do normally.

This is a typo - I meant baseband.
Post reply on HN