Live data from Hacker News

How hackers abused satellites to stay under the radar (2015)

arstechnica.com

31–40 of 69 posts

Re: How hackers abused satellites to stay under the radar (2015)

#33
Dan Goodin has been writing articles about technology for many years now. How does he manage to keep doing so in such utterly incomprehensible fashion? I mean, I get that it's not intended for an audience of seasoned network engineers, but I don't see how it would leave a layman with a useful impression, either...

Re: How hackers abused satellites to stay under the radar (2015)

#34

Earlier quoted context omitted.

Not necessarily. I briefly pretended to be a criminal, mostly for fun. (Most readers will go "Uh huh" at this, but it was just a game.) Say you're developing the next Silk Road. Say you have perfect opsec, and you never reveal any personal info. What are your risks? The #1 risk is discovery of your physical location. Before every action, you must ask yourself: Will the next keystroke get me caught? It takes immense d…

- did you have a cellphone in your pocket? - where did you get the cash? - by talking about it you negated all the advantages you built up - if you walk into a store wearing a facemask you run the risk of being arrested or even shot because they assume you are robbing the store - you may have left fingerprints in the store - the cabdriver has seen your face and knows your home address, you should have walked to the s…

I'm not even GP but I think I can answer a lot of these. Are you maybe trying a little too hard to play devil's advocate?

- did you have a cellphone in your pocket?

After going through all of this, do you honestly think he forgot that detail?

- where did you get the cash?

That's a good question. Hopefully he withdrew a different amount of cash on a completely separate date, otherwise bank account and transactions surely could be linked.

- by talking about it you negated all the advantages you built up

He said he is only mentioning it now because he didn't actually go through with his plan i.e. he doesn't care.

- if you walk into a store wearing a facemask you run the risk of being arrested or even shot because they assume you are robbing the store

What country do you live in where you're shot for wearing a facemask? Holy shit.

- you may have left fingerprints in the store

Let's hope he wore gloves!

- the cabdriver has seen your face and knows your home address, you should have walked to the spot where you changed your clothes

Why does he know his home address? Taxis drive around in many cities. In most cities in Europe (regardless of size) there are taxis everywhere and also taxi parking spots, where there are usually a few taxis waiting.

- the clothes bought at the goodwill, did you pay cash for those too?

Is this a serious question? After all that other work and thinking the process through, why would he all of a sudden use a traceable ATM/credit-card?

- what happened to the clothes afterwards?

Hopefully burned. Or thrown away in a trash can far, far away. I would assume GP knows better than to throw them in his own trash.

- how did you summon the cab to your change location?

As mentioned above, taxis (in Europe at least) are everywhere. No need to summon. Just walk around for a few minutes.

- you're lucky that neither of the houses you changed next to had a dog

Why? Because the dog will bark? And? Dogs bark all the time, because there's a bird, a cat, leaves in the wind, etc.

Re: How hackers abused satellites to stay under the radar (2015)

#35
post #13

I don't get it. It is impossible to identify who receives the packets but TCP/IP requires an acknowledgement that the packets have been received before sending more packets. Surely the C&C could be tracked from this acknowledgement? Or were they using UDP?

UDP for everything would be workable and would remove the need for any sort of spoofing on the uplink.

Re: How hackers abused satellites to stay under the radar (2015)

#36

Earlier quoted context omitted.

- did you have a cellphone in your pocket? - where did you get the cash? - by talking about it you negated all the advantages you built up - if you walk into a store wearing a facemask you run the risk of being arrested or even shot because they assume you are robbing the store - you may have left fingerprints in the store - the cabdriver has seen your face and knows your home address, you should have walked to the s…

I'm not even GP but I think I can answer a lot of these. Are you maybe trying a little too hard to play devil's advocate? - did you have a cellphone in your pocket? After going through all of this, do you honestly think he forgot that detail? - where did you get the cash? That's a good question. Hopefully he withdrew a different amount of cash on a completely separate date, otherwise bank account and transactions sur…

I think the person you're replying to is more just poking at potential holes in the parent's post or pointing out common mistakes. I find the incredulousness that the parent would miss on a tiny detail rather odd, since it happens to people even with the best laid plans, or simple items we simply overlook. These would be pretty common and easy to forget task if you think in a mode of "in operation" versus "out of operation", and even if you are "in operation" all the time, mistakes still happen.

I've re-read the parent's post a few times and it doesn't sit quite right with me as being as secure as they make it out to be, at least not to the point that you can "[sleep] quite soundly knowing [your] location was untraceable even with government-level resources aimed at tracking us down."

Operating on two assumptions that the government was both interested in finding you and willing to spend resources, I think that the majority of the above is just security theatre. The transaction at the POS associates the pre-paid cards, the phones, and the pre-paid plans for the phone. Even if they don't buy data for the phone, if it's 3g enabled, as far as I know, this is easily traceable to some accuracy.

So even if the invidual isn't directly linked, a location, time, and purchase are all associated. This gets you CCTV of the store and a general build of the person, even if they're bundled up. From there, the blanket surveillance cameras are likely enough to get a general direction of where the individual went, and probably enough to think to check local taxis or ride shares, etc. Plus, activating the phone itself is a potential threat as there is some degree of tracking available via cell phone signals. [1]

Honestly, even if there's not a direct link, I think there's enough to get you in the ballpark for where to be looking if the assumptions about who is looking for you with what resources, and this even avoids having to use expensive and out-there methods and techniques; these are already used readily in day to day police business, and even by private corporations. Just look up stories about lost children at Disney World and see how fast they could find children with just cameras and staff on the ground during the 90's. It's even easier now with all the technology Disney includes in the experience, but with just CCTVs recording to tape, they usually had a resolution within an hour.

Seems to me it'd make more sense to just have a patsy do the errands for them and pass it along so that it goes from buyer through some agents ultimately to the user.

[1] https://en.wikipedia.org/wiki/Mobile_phone_tracking

Edit: Included the wiki link I forgot :p

Re: How hackers abused satellites to stay under the radar (2015)

#37
post #4

Ok, that is pretty interesting. I wonder if this will lead to an encrypted signal or deeper analysis of the uplink firewall logs. I would guess you would defeat this once you know the C&C is operating by doing traffic correlation on 'bad' connections (connections which should not exist given the failed TCP handshake). Presuming you have core router access at the ISPs then you would tell your sniffer to capture all tr…

Proper reverse path filtering would also work. The C&C servers should not be able to spoof the IP of the legitimate satellite internet user to reply to the eavsdropped packets. One day.

https://tools.ietf.org/html/rfc2827

Re: How hackers abused satellites to stay under the radar (2015)

#39

So this has to be some sort of state sponsored hacking right? I can't think of a non government group who would have the knowledge, money, or motivation to research this just to mask their origin when there are far simpler ways of receiving transactions (ie. bitcoin)

Not necessarily. I briefly pretended to be a criminal, mostly for fun. (Most readers will go "Uh huh" at this, but it was just a game.) Say you're developing the next Silk Road. Say you have perfect opsec, and you never reveal any personal info. What are your risks? The #1 risk is discovery of your physical location. Before every action, you must ask yourself: Will the next keystroke get me caught? It takes immense d…

Good post.

The only way to fight against drug cartels is to deal with the demand side.

As long as there is demand for an illegal product people will supply it. As long as there are illegal markets people will restort to using violence to resolve disputes, control the market etc.

Re: How hackers abused satellites to stay under the radar (2015)

#40
post #38

I don't understand how this allowed them to conceal their location. Surely whatever connection was being used to send commands could be traced back to the attackers. Could someone explain why this isn't the case?

The spoofed traffic theoretically could be traced back, but at the level of internet routing it would impose a huge cooperation and monitoring requirements on a number of networks. (As we can presume the origin network that's letting spoofed traffic onto the internet isn't going to notice, and/or would be uncooperative to someone investigating the source of the traffic.)

And that monitoring would have to have been active while the traffic spoofing was ongoing. If an ISP has confidence that incoming traffic is spoofed they'll just drop the packets instead of routing. So we're now talking about storing metadata on traffic for after-the-fact analysis, which could be prohibitively expensive considering the amount of traffic transiting networks, and has privacy implications.

Post reply on HN