Live data from Hacker News

Thousands of computers now compromised with leaked NSA tools, researchers say

cyberscoop.com

151–160 of 173 posts

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#151

Earlier quoted context omitted.

The NSA is actually tasked with that mission: > NSA is concurrently charged with protection of U.S. government communications and information systems against penetration and network warfare. https://en.wikipedia.org/wiki/National_Security_Agency

Yes, government defense. Who protects the rest?

That actually overlaps with things like the power grid and ATC, for what it's worth. It's a little bigger than just "government computers".

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#152
post #90

Earlier quoted context omitted.

I don't think anyone worth a damn as far as this subject is concerned would have labeled you a conspiracy theorist. Anyone with an even passing knowledge of security assumed something of this nature was going on. It just logically follows, given the explosion of computers in every aspect of life, that the NSA would be doing this. Side note, what black image in a remote area of Utah? If you're talking about the Bluffd…

https://en.wikipedia.org/wiki/Utah_Data_Center I distinctly remember a point when it was not visible. That is how I discovered the plans to build a complex there years ago. This was probably remedied not long after we started catching wind. I'm sure it would not be difficult for Google, et al. to retroactively "fix" their public imagery data.

I wouldn't rule it out, but I'm left scratching my head as to the motivation why. I remember reading about said data center years ago, before they even broke ground. The location was known at that time, too. If the physical location was of such importance to censor it from satellite images, why then retroactively add those images back in?

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#153

Earlier quoted context omitted.

I cited Snowden's own documents. According to Snowden's documents, the NSA used email envelope metadata where at least one side was a foreigner to build a connection graph, similar to pen register metadata collection. It didn't look at the contents, which it would have to do in order to be wiretapping. That program (STELLARWIND, which operated behind the Internet companies' backs, not PRISM , which operated via court…

Citing Snowden's documents would involve actually giving me a link. I did not say PRISM was mass wiretapping but it is indeed part of the surveillance suite of NSA programs. I did not adequately explain myself in my original post, but I cleared things up afterwards and you are ignoring that completely. You have consistently been framing my arguments in a specific way so that you can attack them in a specific way. I a…

> Citing Snowden's documents would involve actually giving me a link.

I gave you a link to a slide diagramming PRISM and a link to the document describing the email envelope program that had shut down.

> I did not say PRISM was mass wiretapping but it is indeed part of the surveillance suite of NSA programs.

I understand you now concede that PRISM isn't the nefarious new-datacenter-requiring mass data collection you originally claimed it was, that the actual surveillance itself is carried out by the FBI, and that PRISM just enables the NSA to search the FBI's data collected on specific foreigners with a court order.

> I also don't understand why you think that the NSA was not mass wiretapping both of those telco's major junctions. It's a known thing.

If it's a "known thing," where is the evidence? None of your links claim that the NSA is mass wiretapping the telcos' major junctions. Mass wiretapping Americans would violate the Fourth Amendment (the ACLU successfully sued over phone metadata collection, and collecting voice content would be a much bigger issue), so if you have any evidence at all, present it or be prepared to be labeled a conspiracy theorist.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#154
post #56

> “Shodan has currently indexed more than 2 million IPs running a public SMB service on port 445. ..." OK, I understand SMB on LAN. But SMB on the Internet? Is that likely accidental?

Or a stupid way to make your data available on the go.

I did Google for "remote SMB". And your point was made in most of the top forum threads. But sure, people like the easy fix.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#155

It would be interesting (although I expect impossible) to figure out how many of those thousands were compromised by the NSA vs those compromised by people who got the tools through the leak. It was nice that Microsoft had already fixed a bunch of them (almost like they were told ahead of time they were coming). It is also interesting to read the outrage about the tools and the presentations on how to use them. If yo…

> It was nice that Microsoft had already fixed a bunch of them (almost like they were told ahead of time they were coming).

Hmmmm.

I wondered for a minute, then remembered that the leak was dropped, encrypted, onto torrent sites.

So there's your "it's out there". And you have a file size.

From there, well, Microsoft is yuuuuge, so it's entirely feasible that some nice person with connections to the leak in question could probably drop "well this and that was in it." From there it's not too much of a stretch to imagine a response team quietly forming to prioritize fixing everything "just in case".

It's entirely possible Microsoft ended up fixing more things than have been disclosed here - I vaguely recall the core leak involved hundreds of GBs of stuff, but that only a part of the data/code actually escaped. If that's true that's almost funny.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#156

I am worried about the firmware of Intel processors which I believe have had firmware since the mid-1990s or a bit later. Is this possible and are there tools "in the wild" that are capable of doing this? Does Intel do some sort of checksum to ensure that this cannot happen?

Not sure whether you're referring to CPU microcode or the OS in the management engine.

Microcode is remarkably tiny and heavily encrypted. I've never heard of anyone dropping hints as to what's in it, so if that's permeable at all I get the impression you'd probably have to have some rather nice friends to learn about it.

Regarding ME security, here's some interesting info I found a while ago: https://news.ycombinator.com/item?id=13782508

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#157

Earlier quoted context omitted.

Citing Snowden's documents would involve actually giving me a link. I did not say PRISM was mass wiretapping but it is indeed part of the surveillance suite of NSA programs. I did not adequately explain myself in my original post, but I cleared things up afterwards and you are ignoring that completely. You have consistently been framing my arguments in a specific way so that you can attack them in a specific way. I a…

> Citing Snowden's documents would involve actually giving me a link. I gave you a link to a slide diagramming PRISM and a link to the document describing the email envelope program that had shut down. > I did not say PRISM was mass wiretapping but it is indeed part of the surveillance suite of NSA programs. I understand you now concede that PRISM isn't the nefarious new-datacenter-requiring mass data collection you…

Here you are again, twisting my words! Amazing. No, I did not say anything like that about PRISM. I said exactly what I said-- that I was not clear enough in my original post, but I clarified myself immediately after in response to you. I wrote that original post in a hurry and did not take the time to read over it like I usually do. And I've already elaborated on how the NSA uses other agencies and businesses as tools for its surveillance, to avoid direct ownership of the information that they can request at any time. Again, STOP twisting my words to serve your narrative.

I gave you links, but I will humor you with another:

https://www.eff.org/nsa-spying

> . . . recently published FISA court order demanding Verizon turn over all customer phone records including who is talking to whom, when and for how long—to the NSA . . .

Oh look! FISA being used to demand all of verizon's phone records! All of them! And what are one of the programs that FISA feeds into? Oh yeah, that's right. PRISM. If you do not consider this to be a dragnet surveillance order, you are just lying to yourself. So there is yet another verifiable source highlighting the scope of PRISM.

here is the relevant court case:

https://www.eff.org/cases/first-unitarian-church-los-angeles...

Do I need to physically take you to Titanpointe to see it for yourself? Here is a link explaining what that is, I already posted it once but clearly you have not been following through and reading these links.

https://theintercept.com/2016/11/16/the-nsas-spy-hub-in-new-...

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#158

Earlier quoted context omitted.

A unreported zero day is a de facto backdoor. The chain you mentioned has similar flaws as the current strategy. Step 3 would be incredibly difficult. It would be similar to detecting a virus signature, which are easily circumvented. The second party can use trivial techniques to change the signature in a way that makes it incredibly difficult to detect. Many 0-days are built of of multiple bugs. A triple letter may…

> A unreported zero day is a de facto backdoor. This is not true. A backdoor indicates that Microsoft is aware of it (and/or colluded to put it in), but there is no evidence of that. I respect your disagreement with my thoughts on how they should handle 0-days, but re-defining "backdoor" does not seem helpful.

We can debate the meaning of words, but the goal of a backdoor from the perspective of the government is to gain access to a system. The effect of a backdoor is accomplished through a literal backdoor or a figurative backdoor by hoarding exploits, which both are a detriment of security.

By de facto, I was implying that they both accomplish the same things with almost the same list of pros and cons.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#159

Earlier quoted context omitted.

> A unreported zero day is a de facto backdoor. This is not true. A backdoor indicates that Microsoft is aware of it (and/or colluded to put it in), but there is no evidence of that. I respect your disagreement with my thoughts on how they should handle 0-days, but re-defining "backdoor" does not seem helpful.

We can debate the meaning of words, but the goal of a backdoor from the perspective of the government is to gain access to a system. The effect of a backdoor is accomplished through a literal backdoor or a figurative backdoor by hoarding exploits, which both are a detriment of security. By de facto, I was implying that they both accomplish the same things with almost the same list of pros and cons.

When I worked on jailbreaking tools for iOS devices, we routinely held onto multiple 0-days, waiting for a major iOS release to ensure compatibility.

While I know there may be reasons to disagree with that practice, I think it would be a major stretch to say that it meant iOS suddenly had a backdoor.

Re: Thousands of computers now compromised with leaked NSA tools, researchers say

#160

Earlier quoted context omitted.

We can debate the meaning of words, but the goal of a backdoor from the perspective of the government is to gain access to a system. The effect of a backdoor is accomplished through a literal backdoor or a figurative backdoor by hoarding exploits, which both are a detriment of security. By de facto, I was implying that they both accomplish the same things with almost the same list of pros and cons.

When I worked on jailbreaking tools for iOS devices, we routinely held onto multiple 0-days, waiting for a major iOS release to ensure compatibility. While I know there may be reasons to disagree with that practice, I think it would be a major stretch to say that it meant iOS suddenly had a backdoor.

I agree that it is not a true backdoor, but I am simply pointing out that the goal is accomplished by hoarding 0-days or creating an actual backdoor.

The 0-day you were not reporting gave you escalated access to iOS devices. If Apple had given you a backdoor, you would have had the exact same access to the device.

Not saying its the same thing, which is why I used "de facto". The government just wants the access. Regardless the hole is intentional or unintentional, if a hole exists, then overall security is weakened

Post reply on HN