Live data from Hacker News

Security Breach and Spilled Secrets Have Shaken the N.S.A.

nytimes.com

151–160 of 193 posts

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#151
post #147

AFAIK Jake Williams didn't get singled out because he only "wrote a blog post" about Shadow Brokers - it was because he was involved in a Twitter based dispute with Shadow Brokers. Somebody created a fake Twitter account and were sending all sorts of tweets to the Shadow Brokers, someone who was either in the IC or formerly in the IC. This is why the Shadow Brokers outed him in this post[0] > TheShadowBrokers is havi…

> I also don't recall Russian ops having OPSEC this good

Survival bias

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#152
post #17

One thing that is not talked about enough with NSA is that if they are capable of leaking some of their most sensitive and powerful tools, then they are also capable of leaking the most sensitive and private information they collect on people. Perhaps this has not yet happened, or perhaps it has (someone will no doubt point out any known incidents here if there are any) but the idea is unnerving. Maybe my wording is…

Maybe, maybe not. NSA hacking tools can't necessarily be kept privately within their network, because they have to be used to attack targets across the Internet -- they have to be deployed. By comparison, the data that the NSA collects can presumably be sucked into their airgapped network, where data has a way in but no way out.

Data has to be accessable to be of any use.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#154
post #151
post #147

AFAIK Jake Williams didn't get singled out because he only "wrote a blog post" about Shadow Brokers - it was because he was involved in a Twitter based dispute with Shadow Brokers. Somebody created a fake Twitter account and were sending all sorts of tweets to the Shadow Brokers, someone who was either in the IC or formerly in the IC. This is why the Shadow Brokers outed him in this post[0] > TheShadowBrokers is havi…

> I also don't recall Russian ops having OPSEC this good Survival bias

Yeah? The Shadow Brokers themselves state flat out that they're former USG employees. The NY Times has - yet again - attempted to manipulate readers into believing the Brokers have admitted to being Russian, quoting something that is obviously a joke to try and do so.

Here's what the Shadow Brokers themselves actually say about their origins:

https://steemit.com/shadowbrokers/@theshadowbrokers/grammer-...

TheShadowBrokers shaking heads at arrogant pretentiousness of grammar critics.

Liberal Ivory Tower Logical Fallacies:

A) Deliver Method of Content (Spelling/Grammer/Profanity) = Content is invalid

B) Only Explanation of Spelling/Grammar/Profanity = Inadequate Education

The ShadowBrokers is writing TRADOC, Position Pieces, White Papers, Wiki pages, etc for USG. If theshadowbrokers be using own voices, theshadowbrokers be writing peoples from prison or dead. TheShadowBrokers is practicing obfuscation as part of operational security (OPSEC). Is being a spy thing. Is being the difference between a contractor tech support guy posing as a infosec expert but living in exile in Russia (yes @snowden) and subject matter experts in Cyber Intelligence like theshadowbrokers. TheShadowBrokers has being operating in country for many months now and USG is still not having fucking clue. Guessing so called global surveillance is not being as good as @snowden is claiming?

Edit: the whole Steemit is really worth a read. The rants here are truly epic. It's just implausible that this is the work of a government - why would government employees spend so much time writing such long political rants on Steemit where approx ~nobody will ever see them except Q Branch and occasional journalists? It serves no obvious political or espionage related purpose. Whoever is writing these things seems to be someone who has a lot of hatred and anger for the political system and wants to get it out. It sounds a lot like the rantings of a lot of the self-proclaimed libertarians you find in the Bitcoin community:

is funny thing about being rich, powerful, and in control, it comes with dirty deeds and many skeletons. Violence begets violence but leaks, dumps, hacks brings evil and corruption into the light. No more secrets. Secrets Equal Control. Secrets between peoples, spouses, partners, friends, ok two peoples might be having some problems. But secrets between government and governed, governed is getting fucked. Secrets between corporations and peoples, peoples is getting fucked. Why do corporation deserved privacy? FUCK SCOTUS!!! CORPORATION ARE NOT PEOPLE YOU FUCKING OVER EDUCATED OVER THINKING CORRUPT RETARDS.

No more classifying bullshit. No more black budgets and black ops. If we can't be surviving and prospering without dirty little secrets, operating in full daylight, then maybe we don't deserving to being surviving. This being time to standing up. Standing up against more wars. Standing up to globalist controllers. Eliminating career politicians. Eliminating money and lobbyist. Policing corporate and special interest. Investing in ourselves. Investing in all our children.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#155
post #41

Earlier quoted context omitted.

It seems like those kinds of more removed scenarios point to a strategic void in compartmentalization. We (US, Soviet Union, etc) had this figured out in the 60s when we were primarily using human intel. [1] Except the danger that now, instead of walking out with rolls of film covering a few thousand pages, someone can take everything they have access to in My only explanation is all those long-won counter-intelligen…

I can assure you that 'taking' data off these systems is non-trivial -- Snowden was one of the few people with physical access and admin access. Attempting to access a large amount of info in 24H would also set off alarms. There is also no end to the pain-in-the-ass rules. But the gist of what you are saying is correct, a lot more interconnection, a lot more software, using standard (albeit locked down) desktop opera…

Yeah but Snowden had that level of access simply because he applied for the job, with the full intention of using it to do leaking.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#156
post #116
post #17

One thing that is not talked about enough with NSA is that if they are capable of leaking some of their most sensitive and powerful tools, then they are also capable of leaking the most sensitive and private information they collect on people. Perhaps this has not yet happened, or perhaps it has (someone will no doubt point out any known incidents here if there are any) but the idea is unnerving. Maybe my wording is…

I'm surprised this isn't used in privacy arguments more often. Every time governments and politicians suggest tracking everything we do for our safety with the assurance our data is safe, surely it's prudent to point out that if (arguably) the most secret and advanced cyber command in the world can't keep their weapons and secrets safe, what chance do you have?

"Don't worry. We are taking all precautions. It is 100% safe. Only a very few, select personell will have access to the data."

They will just give the same bullshit answer as always. Sometimes throw in a new phrase ("24/7 guarded datacenter") to pretend they are not vulnerable to obvious risks.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#157

Earlier quoted context omitted.

I disagree; it's a focus of their existence that appears to be abandoned by the NSA - and that's dearly needed right now. From the front page of nsa.gov: "Defending our Nation. Securing the Future." The second point from their What we do page - "Defends vital networks". In the opening paragraph of Wikipedia: "The NSA is also tasked with the protection of U.S. communications networks and information systems". Etc. For…

Yeah but think about it - imagine government employees shift their entire focus onto "securing US networks". What would they do, exactly? Build their own open-source chip designs from scratch? Because that's pretty much step one.

Do the same bug hunting they do now, but send all the exploits back to the vendors.

Do more work like SELinux.

There's lots they can do.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#158

Earlier quoted context omitted.

I can assure you that 'taking' data off these systems is non-trivial -- Snowden was one of the few people with physical access and admin access. Attempting to access a large amount of info in 24H would also set off alarms. There is also no end to the pain-in-the-ass rules. But the gist of what you are saying is correct, a lot more interconnection, a lot more software, using standard (albeit locked down) desktop opera…

Yeah but Snowden had that level of access simply because he applied for the job, with the full intention of using it to do leaking.

That he was selected for this job is a fault of Congress, for imposing caps on government employee numbers (and salaries), but not contractors, during the greatest period of SIGINT expansion in history (also authorised by Congress), and then outsource their vetting to the cheapest bidder. Oh, and have a President that creates a secret law for side stepping the Constitution.

Of course, given a defective Congress, what should the IC have done? Limit their use of computers? Stop sharing information? Encrypt everything on servers and decrypt client side via special hardware? Have someone watch the admins as if they are all wannabe traitors? Disperse honeypot systems and canary docs everywhere? Tripwire the heck out of every system? Fit explosive collars on systems administrators?

Well, all those things and more have now been contemplated. Everything except 'stop collecting'.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#159

The biggest indictment of the NSA is the fact that there has been no visible internal dissent after Snowden regarding mass surveillance. Their willingness to overlook the constitution because it's inconvenient is a far bigger problem than leaks, IMO.

I don't think that from their perspective they are overlooking the constitution. All of their "illegal" programs are duly authorized by executive orders and DOJ legal opinions and signed off on by the intelligence committees. You or me may view those operations as illegal but they are following orders given by democratically elected officials and signed off on by every level of the judiciary. Ultimately I don't think…

This is the correct answer.

The NSA doesn't spy on Americans.

If you look at the Snowden leaks, it talks of filters limiting access to collected data to foreign nationals and people contacting foreign nationals only, as per laws allowed under the US constitution.

Why would a TOP SECRET program have these filters if their operations were illegal?

Everything the NSA does is legal. It's now up to the public to accept that fact.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#160

Earlier quoted context omitted.

I can assure you that 'taking' data off these systems is non-trivial -- Snowden was one of the few people with physical access and admin access. Attempting to access a large amount of info in 24H would also set off alarms. There is also no end to the pain-in-the-ass rules. But the gist of what you are saying is correct, a lot more interconnection, a lot more software, using standard (albeit locked down) desktop opera…

Yeah but Snowden had that level of access simply because he applied for the job, with the full intention of using it to do leaking.

He had that access as he had been working for first the CIA, then the NSA, for five years before he decided to become a whistleblower.
Post reply on HN