Live data from Hacker News

Security Breach and Spilled Secrets Have Shaken the N.S.A.

nytimes.com

131–140 of 193 posts

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#131

Earlier quoted context omitted.

I disagree; it's a focus of their existence that appears to be abandoned by the NSA - and that's dearly needed right now. From the front page of nsa.gov: "Defending our Nation. Securing the Future." The second point from their What we do page - "Defends vital networks". In the opening paragraph of Wikipedia: "The NSA is also tasked with the protection of U.S. communications networks and information systems". Etc. For…

Yeah but think about it - imagine government employees shift their entire focus onto "securing US networks". What would they do, exactly? Build their own open-source chip designs from scratch? Because that's pretty much step one.

We are very far from trusted hardware. It's very easy to imagine what they would do - step one is helping American networks use the best practices - use open-source software, keep dependencies up-to-date, have bug bounties to find vulnerabilities in popular frameworks, etc.

Step two would be to consider some shared infrastructure, probably subcontracting with a cloud provider (AWS/Azure/GCP), hopefully multiple. Once we get to that step, then you can start considering things like Google's Titan (https://cloudplatform.googleblog.com/2017/08/Titan-in-depth-...). But there's a lot of low hanging fruit before we get there.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#132
post #41
post #29

Earlier quoted context omitted.

This was covered in a recent kaspersky paper[1], which I found in [2], where it is termed "fourth-party collection". The pdf gives a more complete description on page 2 (I found the increasing level of separation between collector and reciever to be almost comical) [1] https://cdn.securelist.com/files/2017/10/Guerrero-Saade-Raiu... [2] https://news.ycombinator.com/item?id=15663985

It seems like those kinds of more removed scenarios point to a strategic void in compartmentalization. We (US, Soviet Union, etc) had this figured out in the 60s when we were primarily using human intel. [1] Except the danger that now, instead of walking out with rolls of film covering a few thousand pages, someone can take everything they have access to in My only explanation is all those long-won counter-intelligen…

Under what basis do you assert that intelligence in the 60s was done primarily using human intelligence?

The full history of intelligence collection during the Cold War has not yet been fully declassified.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#133
post #83

Great. I hope this continues. The more the NSA has problems, the better off the rest of the rest of us are. It's unlikely the institution is even lawful--its practices certainly aren't. At the very least, it proves that the government cannot itself keep secrets, so it really needs to shut up about trying to put backdoors into software when it can't protect its own most vital software assets from leaking. I guarantee…

There are plenty of vital secrets that haven't leaked for decades. Why do you exclude those examples from your reasoning?

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#135
post #42

"Rendition Infosec" - give me a break, you were a peeping tom secret policeman, not a kidnapping secret policeman.

I love how he refers to himself as an "operator" - like he's going downrange with SEALs or some shit.

Yeah, his background was "paramedic" not a mathematician or programmer. So I wonder if his role was more like Script Kiddy on steroids than a brilliant programmer-hacker...

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#136

This is something I have been wondering about: how did both the CIA and NSA have their toolkits leaked within months of each other? Either one of these agencies suffering such a major security breach would be extraordinary but both at the same time is unprecedented.

I would guess that their cyber offensive operation computers, which if I were to design from a systems level their IT department probably is distinct from other parts of their network, is different than their intelligence gathering and storing methods because sources and methods are the most tightly held secrets of any intelligence agency. Plus you probably don't want your computers that you're using for offensive op…

A) this doesn’t require a rogue agent, just an insecure one. B) you just need the same attack to work twice; less extraordinary than an uncorrelated coincidence C) possibly some might have access to both. I think this is unlikely, but again, less unlikely than an uncorrelated coincidence.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#137
post #126

My favorite is how NSA is funded by government debt, which is their way of printing money. This is also true for the FBI too with the scare against encryption. One of the reasons we got off the gold standard decades ago was military spending.

Currency is just printed debt. What’s your point?

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#138
post #17

One thing that is not talked about enough with NSA is that if they are capable of leaking some of their most sensitive and powerful tools, then they are also capable of leaking the most sensitive and private information they collect on people. Perhaps this has not yet happened, or perhaps it has (someone will no doubt point out any known incidents here if there are any) but the idea is unnerving. Maybe my wording is…

And if it can happen to them, how much more likely will it happen to everyone else who has heaps of data about you?

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#139
"Antivirus is the ultimate back door," Blake Darche, a former N.S.A. operator and co-founder of Area 1 Security. "It provides consistent, reliable and remote access that can be used for any purpose, from launching a destructive attack to conducting espionage on thousands or even millions of users."

Humble opinion: s/Antivirus/Automatic updates/

Perhaps antivirus were in fact an early experiment to test the feasbility of automatic software updates.

I recall many years ago, pre-smartphone, users being advised to leave their computers online 24/7 "so antivirus could download updates". Yikes.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#140
post #98

Earlier quoted context omitted.

Exfiltration is a problem. It's more difficult to exfil terabytes of individual citizen dossiers than ~2GB of malware, implants, tools, scripts, etc from classified and possibly even SCIF environments. Or it could be more prosaic than that: Money. The market value of NSA tooling is likely far far higher than the threat assessments of Joe Blow Smith in Hoboken, NJ.

I don't think the concern is Joe Smith. The concern is high level people who can easily be blackmailed. Or even just someone who works in a classified setting. The value of blackmailing a few political elites is extremely powerful and profitable. Or even people in big companies like FAANG.

I don't think any blackmail would be effective at this point. When a man gets accused of molesting a teenager then gets elected to the Senate, I think the potential for blackmail has passed.
Post reply on HN