Live data from Hacker News

Security Breach and Spilled Secrets Have Shaken the N.S.A.

nytimes.com

141–150 of 193 posts

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#141
post #70

This is why friends don't let friends run Windows. It's not that hard.

More than one exploit released by the shadow brokers was specifically targeted at Linux/Unix/Cisco and other operating systems... Its naive to think that other operating systems are somehow invulnerable to nation-state attackers.

Yes but at least with open source software, you have a fighting chance of knowing what you're running.

What's the open source equivalent of DUAL_EC_DRBG or Kaspersky Anti-Virus?

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#142
post #17

One thing that is not talked about enough with NSA is that if they are capable of leaking some of their most sensitive and powerful tools, then they are also capable of leaking the most sensitive and private information they collect on people. Perhaps this has not yet happened, or perhaps it has (someone will no doubt point out any known incidents here if there are any) but the idea is unnerving. Maybe my wording is…

It doesnt even have to be leaked when they are sharing raw data with the Israelis, a country just as active in espionage against the US as China or Russia.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#143
post #42

Earlier quoted context omitted.

I love how he refers to himself as an "operator" - like he's going downrange with SEALs or some shit.

A quick google finds its a compromise worthy of the laundry file "We settled on the name ‘operator’ to designate an operational member of the unit (as opposed to a member of the support staff) due to some legal and political situations. We couldn’t use ‘operative’ because that name had certain espionage connotations from the CIA. The term ‘agent’ had some legal issues. An agent carries a legal commission to perform c…

this sounds more like a joke about government bureaucracy than anything. it seems much more likely that it's simply derived from 'special operations'.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#144

The biggest indictment of the NSA is the fact that there has been no visible internal dissent after Snowden regarding mass surveillance. Their willingness to overlook the constitution because it's inconvenient is a far bigger problem than leaks, IMO.

I don't think that from their perspective they are overlooking the constitution.

All of their "illegal" programs are duly authorized by executive orders and DOJ legal opinions and signed off on by the intelligence committees.

You or me may view those operations as illegal but they are following orders given by democratically elected officials and signed off on by every level of the judiciary.

Ultimately I don't think it is productive to scapegoat the intelligence community for what is fundamentally a breakdown in the rule of law and democratic process. They are participants in that, but so is every voter, and every politician, not to mention all the corporations that happily do their work for them in exchange for money or favors and then lie about it.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#145

Earlier quoted context omitted.

Federal pay sucks by design. If you want to work for .gov, you want state/local government. The Feds want to contract out for anything they can. So you work for Lockheed or whatever and get most of the attributes of government employment.

> Federal pay sucks by design. If you want to work for .gov, you want state/local government State and local government employees are paid well? Where? Which ones?

[deleted]

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#146

Earlier quoted context omitted.

Federal pay sucks by design. If you want to work for .gov, you want state/local government. The Feds want to contract out for anything they can. So you work for Lockheed or whatever and get most of the attributes of government employment.

> Federal pay sucks by design. If you want to work for .gov, you want state/local government State and local government employees are paid well? Where? Which ones?

Public school systems tend to pay well for people who majored in early elementary education, music, kinesiology, etc. But this isn't the same demographic that would work at NSA.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#147
AFAIK Jake Williams didn't get singled out because he only "wrote a blog post" about Shadow Brokers - it was because he was involved in a Twitter based dispute with Shadow Brokers.

Somebody created a fake Twitter account and were sending all sorts of tweets to the Shadow Brokers, someone who was either in the IC or formerly in the IC.

This is why the Shadow Brokers outed him in this post[0]

> TheShadowBrokers is having special invitation message for “doctor” person theshadowbrokers is meeting on Twitter. “Doctor” person is writing ugly tweets to theshadowbrokers not unusual but “doctor” person is living in Hawaii and is sounding knowledgeable about theequationgroup.

> Then “doctor” person is deleting ugly tweets, maybe too much drinking and tweeting? Is very strange, so theshadowbrokers is doing some digging. TheShadowBrokers is thinking “doctor” person is former EquationGroup developer who built many tools and hacked organization in China.

> TheShadowBrokers is thinking “doctor” person is co-founder of new security company and is having much venture capital.

It was easy for everyone on Twitter to figure out who he/she/they were referring to. I think this is important context - Shadow Brokers aren't just outing random operatives, they're flexing their access and abilities when being prompted to

I also wonder if this wasn't part of a plan to bring the Shadow Brokers out of their shell a little - coax them into revealing a little more about themselves than the usual document and software dumps - which would require the NSA to spend money to get a picture of what tools are available.

Jake says to the NYTimes that he isn't working with the NSA - but he'd also say this if he were working with the NSA to get a little more out of Shadow Brokers

I've never bought the theory that Shadow Brokers is Russia, or that it was Harold T Martin (or stolen from him). I think the Jake Williams incident lends further credibility to the theory that it is a former TAO or NSA employee.

The fake Russian style writing of the Shadow Brokers isn't ordinary bad English Russian (which has a number of characteristics that aren't reflected in how Shadow Brokers write). As the article mentions, there are also far too many cultural and infosec "inside baseball" references in the writing of Shadow Brokers for it to not be someone who is either familiar with the community or part of it.

I also don't recall Russian ops having OPSEC this good - to the point where they can't be identified or linked. The good OPSEC suggests the person/people behind the Shadow Brokers are familiar with what the NSA are capable of, and what they're not. Most Russian and Chinese ops are usually linked one way or another back to to them as they're less concerned about OPSEC as they have the operational advantage of not fearing arrest or extradition

Differences between SB and Fancy Bear or Russian ops: bad security practices (not locking down bitly) vs good, using clearnet domains[1] emails[3] vs steemit and onions, using VPNs rather than Tor, the use of Bitcoin vs Monero/Zcash, speaking only (broken) English vs either plain English or Russian[2], financial motive vs political motive, etc.

It feels like someone upset with the NSA, who knows the organization very well and is also motivated financially - but I wouldn't attribute greater than 50-60% certainty to any theory at the moment. If the Shadow Brokers go on to never be identified it would really be an incredible situation.

[0] https://steemit.com/shadowbrokers/@theshadowbrokers/theshado...

[1] https://www.secureworks.com/research/threat-group-4127-targe...

[2] https://www.fireeye.com/blog/threat-research/2014/10/apt28-a...

[3] https://www.threatconnect.com/blog/fancy-bear-anti-doping-ag...

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#148
post #111
post #37

Earlier quoted context omitted.

Agree, though the only thing that gives me any comfort (and it is the same with google, gmail, facebook, etc) is that the amount of data they collect is nearly impossible to ex filtrate because of its sheer size.

Once upon a time movies were too big to download, and now look.

Bandwidth has been increasing very slowly. And I think we will be stuck at 1gbit for a long time (and in many areas: if we ever reach it), just because there are no consumer use for higher bandwidth. Already 4k video resolution is a stretch, most people wouldn’t notice the difference to 1080p on a TV from they couch.

So there will be a need to upgrade wholesale bandwidth just because the internet keeps growing, people are already talking about next gen game consoles to be cloud based (ie the rendering to be made remotely) which will add more traffic. But not 5 orders of magnitude. The amount of data stored by the gmails and facebooks of this world are mind blowing.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#149
post #126

My favorite is how NSA is funded by government debt, which is their way of printing money. This is also true for the FBI too with the scare against encryption. One of the reasons we got off the gold standard decades ago was military spending.

Currency is just printed debt. What’s your point?

The point is that the debt can increase forever since we got off gold.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#150
post #3

> The agency regarded as the world’s leader in breaking into adversaries’ computer networks failed to protect its own. Those are two very different things. Focusing on one of them doesn't automatically benefit your efforts on the other.

NSA is also responsible for establishing computer security practices for the rest of the government to follow. That they don't eat their own dogfood is damning.

We should also keep in mind that finding an exploit or two is much easier than making sure that nothing on your network can be exploited. I wouldn't expect even the best in the world to be able to thwart all attacks.
Post reply on HN