If you only work on your malware on weekdays, you might be a CIA hacker
1–10 of 25 posts
Re: If you only work on your malware on weekdays, you might be a CIA hacker
#2Article mostly talks about the validation that security companies got from recent leaks, when before it could only be based on update and domain registration times.
Kind of makes the US look silly with that oversight. Though even if they did fix themselves, it's not like you could change behavior on the old stuff.
Re: If you only work on your malware on weekdays, you might be a CIA hacker
#3That's actually pretty funny. Article mostly talks about the validation that security companies got from recent leaks, when before it could only be based on update and domain registration times. Kind of makes the US look silly with that oversight. Though even if they did fix themselves, it's not like you could change behavior on the old stuff.
I suspect it was largely accidental, though. Heck, there's been private entities I know who have ended up with tells that pinned them to timezones.
Re: If you only work on your malware on weekdays, you might be a CIA hacker
#4Still waiting for the day a leak is attributed to the French because of the length of lunch breaks inferred from timestamps.
Re: If you only work on your malware on weekdays, you might be a CIA hacker
#5That's actually pretty funny. Article mostly talks about the validation that security companies got from recent leaks, when before it could only be based on update and domain registration times. Kind of makes the US look silly with that oversight. Though even if they did fix themselves, it's not like you could change behavior on the old stuff.
It also might be on purpose -- if you have a signature, then unsigned things aren't you, right? I suspect it was largely accidental, though. Heck, there's been private entities I know who have ended up with tells that pinned them to timezones.
Re: If you only work on your malware on weekdays, you might be a CIA hacker
#6That's actually pretty funny. Article mostly talks about the validation that security companies got from recent leaks, when before it could only be based on update and domain registration times. Kind of makes the US look silly with that oversight. Though even if they did fix themselves, it's not like you could change behavior on the old stuff.
Re: If you only work on your malware on weekdays, you might be a CIA hacker
#7Re: If you only work on your malware on weekdays, you might be a CIA hacker
#8Now the CIA is going to claim that for national security reasons, they're going to have to hack American computers too.
Re: If you only work on your malware on weekdays, you might be a CIA hacker
#9Earlier quoted context omitted.
It also might be on purpose -- if you have a signature, then unsigned things aren't you, right? I suspect it was largely accidental, though. Heck, there's been private entities I know who have ended up with tells that pinned them to timezones.
Easy to do with e.g. postings to forums, including those about bitcoin...
There are just too many information leaks that can be used to track people back to regions, and I honestly don't care if people know I'm one of millions of people.
(Whoops, there goes another -- there's only 53 US metros above 1mil people and 34 above 2mil.)
Re: If you only work on your malware on weekdays, you might be a CIA hacker
#10Let's say the US uses French time zones and France uses US eastern time zones. You've discovered malware that for whatever reason has time stamps for US Eastern.
Is it really from the US or is it from France? How would you deduce such a fact? I posit it would be better to see who the malware is targeting: entities may be averse to targeting their own countries.