Live data from Hacker News

Canada's 'secret spy agency' is releasing a malware-fighting tool to the public

cbc.ca

41–50 of 83 posts

Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public

#41

Earlier quoted context omitted.

CSIS likes very much to not be in the news. They seem to actively work to stay unknown. I've heard, but cannot verify, that they are the only government agency that is not required to have a "Government of Canada dept X" sign outside their buildings. They do have them outside some buildings, but not all buildings.

It's kind of what I like about them. Now quiz time. Who's heard of JTF2?

Their "secret" base was a short drive from where I grew up. Every local knew what it was. But they are still the most badass dudes.

Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public

#42
post #21
post #15

Billangual README!

Its a Canadian government rule that even URLs have to be bilingual. eg You can't have http://host.ca/news (with bilingual text on the page) it has to be http://host.ca/news_nouvelles This is only for fed government sites.

je ne savais pas !

Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public

#44
post #10
post #3

The main repo seems to be here: https://bitbucket.org/cse-assemblyline/assemblyline/src Released under the MIT license with crown copyright. Looks like a plain ol' Flask application. I don't know what I was expecting from the government. Maybe more Microsoft and more Oracle, more "enterprise". And the git history goes back ten months with an initial commit of December 21, 2016. I'm actually surprised to learn that CS…

It's probably safer to assume CSE/CSIS would use open-source tools than stuff from MSFT/ORCL.

Especially because, unlike the NSA, they can't send legally-enforceable secret letters telling MSFT and ORCL what to do.

Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public

#45
post #10
post #3

The main repo seems to be here: https://bitbucket.org/cse-assemblyline/assemblyline/src Released under the MIT license with crown copyright. Looks like a plain ol' Flask application. I don't know what I was expecting from the government. Maybe more Microsoft and more Oracle, more "enterprise". And the git history goes back ten months with an initial commit of December 21, 2016. I'm actually surprised to learn that CS…

It's probably safer to assume CSE/CSIS would use open-source tools than stuff from MSFT/ORCL.

Anecdotal, but I was in an Oracle University training course last year with someone who confirmed, in an indirect and vague way, that he worked for the CSE. We were training on Oracle Database 12. He had plenty of "real world scenario" questions.

Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public

#46
post #41

Earlier quoted context omitted.

It's kind of what I like about them. Now quiz time. Who's heard of JTF2?

Their "secret" base was a short drive from where I grew up. Every local knew what it was. But they are still the most badass dudes.

My brother's (not JTF2) told me stories about their training/graduation exercises. Intense is a little too mild a word.

Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public

#48

This is the first major commit where they pulled in the existing codebase almost a year ago: https://bitbucket.org/cse-assemblyline/assemblyline/commits/... Couple interesting bits: 1. Bcrypt looks trusted. I guessed as much given that I've seen it used in other GC projects that were "Protected B" (think Revenue Canada / similar). 2. It doesn't look like they enabled HSTS by default until a couple months later in the…

Lol. I don't know if you clicked the username, but it's appropriate: https://bitbucket.org/sgaron-cse/

Yeah, of course, haha :)

Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public

#49

Earlier quoted context omitted.

https://www.cse-cst.gc.ca/en/about-apropos/faq

Suspect the Citation needed was referring to "They're good at their jobs."

Well we do know they successfully hacked the Brazilian government in the interests of private oil companies? That's something isn't it?

> CSEC had been meeting with the heads of our country’s largest energy companies and debriefing them on all the secrets they’ve stolen from Brazil’s mining and energy ministries.

https://www.vice.com/en_ca/article/5gqkwq/the-canadian-gover...

Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public

#50
post #21
post #15

Billangual README!

Its a Canadian government rule that even URLs have to be bilingual. eg You can't have http://host.ca/news (with bilingual text on the page) it has to be http://host.ca/news_nouvelles This is only for fed government sites.

I'm surprised there isn't a separate copy of all the code in French, or at least the code comments
Post reply on HN