Live data from Hacker News

Security Breach and Spilled Secrets Have Shaken the N.S.A.

nytimes.com

171–180 of 193 posts

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#171
post #116

Earlier quoted context omitted.

I'm surprised this isn't used in privacy arguments more often. Every time governments and politicians suggest tracking everything we do for our safety with the assurance our data is safe, surely it's prudent to point out that if (arguably) the most secret and advanced cyber command in the world can't keep their weapons and secrets safe, what chance do you have?

"Don't worry. We are taking all precautions. It is 100% safe. Only a very few, select personell will have access to the data." They will just give the same bullshit answer as always. Sometimes throw in a new phrase ("24/7 guarded datacenter") to pretend they are not vulnerable to obvious risks.

You also forgot the part about how they always say, "Your data is safe, we can't get it without a court/judges approval." Which means from a FISA court. A closed, secret court no one hears about and no one is there to act as your advocate.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#172

Earlier quoted context omitted.

> Federal pay sucks by design. If you want to work for .gov, you want state/local government State and local government employees are paid well? Where? Which ones?

Public school systems tend to pay well for people who majored in early elementary education, music, kinesiology, etc. But this isn't the same demographic that would work at NSA.

My mom has a master's in education, and after 30 years across two public school systems, she's finally broken $40k salary. Where do you live that public school systems pay well?

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#173
post #149

Earlier quoted context omitted.

Currency is just printed debt. What’s your point?

The point is that the debt can increase forever since we got off gold.

This isn’t necessarily hard or bad, though. If I take $100 and loan it to my neigbor, the debt appears from nowhere. Heck, theoretically, he could loan it right back under different terms and create more debt. Debt isn’t necessarily bad—the fear is you’re builidng on jenga blocks, not that some guy is going to show up with a wrench.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#174
post #161
post #148

Earlier quoted context omitted.

Bandwidth has been increasing very slowly. And I think we will be stuck at 1gbit for a long time (and in many areas: if we ever reach it), just because there are no consumer use for higher bandwidth. Already 4k video resolution is a stretch, most people wouldn’t notice the difference to 1080p on a TV from they couch. So there will be a need to upgrade wholesale bandwidth just because the internet keeps growing, peopl…

Who says attackers must use home or small office connections? Why can't the data be exfiltrated to a top tier data center with excellent peering?

But consumer/corporate demand for bandwidth is what should ultimately drive increase in data center bandwidth.

Another point is defeating monitoring. I am sure the NSA (or Google/Facebook) could not notice 1GB of upload, but I like to think that uploading 1PB of data would make all sorts of red lights flash in they network security control room.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#175

Earlier quoted context omitted.

Yeah but Snowden had that level of access simply because he applied for the job, with the full intention of using it to do leaking.

He had that access as he had been working for first the CIA, then the NSA, for five years before he decided to become a whistleblower.

If you go read his story in detail you'll see that he held various jobs, but he applied for a transfer to become a sysadmin specifically (a job downgrade) because he was collecting info to leak by that point, and knew he could access more if he had admin privs.q

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#176

Earlier quoted context omitted.

Yeah? The Shadow Brokers themselves state flat out that they're former USG employees. The NY Times has - yet again - attempted to manipulate readers into believing the Brokers have admitted to being Russian, quoting something that is obviously a joke to try and do so. Here's what the Shadow Brokers themselves actually say about their origins: https://steemit.com/shadowbrokers/@theshadowbrokers/grammer-... TheShadowBr…

> Yeah? The Shadow Brokers themselves state flat out that they're former USG employees. But why would you take lying criminals at their word? TSB started out pretending to be criminals who wanted money, which nobody bought, and so they switched to pretending to be a Snowden/Assange caricature. The one objective that TSB has actually delivered on is attacking the NSA. Everything else is obfuscation.

Why would you not? You have no evidence they're lying, you're just assuming they are because you prefer the alternative explanations. You certainly have nothing to suggest they're Russian and there's plenty of reasons to believe that they're probably not.

TSB started out pretending to be criminals who wanted money, which nobody bought

Their attempt to auction the exploits was one of the most fascinating aspects of the whole tale because it was verifiably a failure - we don't have to take their word for it. They published a Bitcoin address and nobody sent them enough money to reach their min threshold, if I recall correctly. At least, I'm sure they were using Bitcoin with a static wallet address to do the sale.

so they switched to pretending to be a Snowden/Assange caricature.

TSB's personality has been consistent throughout. They aren't pretending to be a Snowden/Assange cariacture. Their writing makes it quite clear they seem to have a serious grudge or dislike for Snowden specifically.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#177
post #78
post #17

One thing that is not talked about enough with NSA is that if they are capable of leaking some of their most sensitive and powerful tools, then they are also capable of leaking the most sensitive and private information they collect on people. Perhaps this has not yet happened, or perhaps it has (someone will no doubt point out any known incidents here if there are any) but the idea is unnerving. Maybe my wording is…

The main point is that they can no longer say "trust us" with a straight face. If the politics of the last few decades has tried to teach us anything, it's that this is not true. No amount of shaming or obvious shortcomings will ever allow some people to bridge the reality/ideology-gaps in question. You don't see less lying as people are confronted with their lies, you're met with a hurricane of new lies, a Gish Gall…

What will change them is when we little people have finally had enough of their bullshit and do what we should already be doing which is putting a stop to it. Trump getting elected was the first big signal for them cut their shit out. But they won't listen--the dissonance and excuses being made around Trump tells you everything you need to know. The next step if they don't listen is going to be way uglier.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#178
post #44

Living in Maryland, I've met several young people who put in a few years at the agency (including TAO) who then left for industry. Millenials don't care about a government pension, especially when you're in a windowless SCIF hacking Perl. The US Government as a whole has a massive talent retention problem. Only the mediocre will stay at NSA / CIA now and we'll probably see more of these leaks / hacks.

I think they will still have a steady supply of talented people who consider themselves patriots and whose politics align with the NSA and CIAs stated missions. Just because their politics don't agree with yours doesn't necessarily make the 'mediocre' remember.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#179

Earlier quoted context omitted.

> Yeah? The Shadow Brokers themselves state flat out that they're former USG employees. But why would you take lying criminals at their word? TSB started out pretending to be criminals who wanted money, which nobody bought, and so they switched to pretending to be a Snowden/Assange caricature. The one objective that TSB has actually delivered on is attacking the NSA. Everything else is obfuscation.

Why would you not? You have no evidence they're lying, you're just assuming they are because you prefer the alternative explanations. You certainly have nothing to suggest they're Russian and there's plenty of reasons to believe that they're probably not. TSB started out pretending to be criminals who wanted money, which nobody bought Their attempt to auction the exploits was one of the most fascinating aspects of th…

> You certainly have nothing to suggest they're Russian

I don't think they are Russian. It makes no sense for a state actor like China or Russia to penetrate the NSA and then disclose it. When they disclose it they lose the ability to exploit it.

Even if the NSA had already closed all the holes, which we can guess they didn't because of Microsoft patching them after the leaks, a state level actor would still not show their hand because keeping your opponents in the dark is more disruptive to their operations, and showing your hand has the potential to reveal your own methods.

Whoever it is is specifically focused on attacking, disrupting and discrediting the NSA. They are not making money off it (even though the op has to be expensive) and they are not exploiting it for intelligence advantage.

I don't believe it is a Snowden type for the reasons I mentioned and because the op seems way too complex and long running for any individual or group to pull off for ideological reasons.

I would tend to believe that it is not a leaker or it was a one time leak to a third party who is now running the operation.

The NSA knows everyone who worked for them, and who had access to what, and I am sure they are watching every single one of those people so the only plausible way it could be a leaker is if the NSA can't connect the leaker to whatever individual(s) are running the online campaign.

The problem with a long running op like this is that all internet access can be traced back eventually. Every time you post online, even if you are going to really extraordinary measures, you are leaving a trail that will eventually converge on your location. That means you have to stay on the move. But travel is also observable and so moving all the time will eventually create a pattern that allows you to be identified.

It is some real Jason Bourne type shit.

It could just be some relatively crazy individual who is playing a high stakes game spy game for fun.

There are a couple of examples of criminals who engaged in robberies based on the movie Heat, which seems bizarre, but it happens.

http://en.wikipedia.org/wiki/North_Hollywood_shootout https://www.theguardian.com/world/2001/mar/24/gilestremlett

The European team that was obsessed with the movie and based their operations on it pulled off some of the biggest armed robberies in history.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#180

Earlier quoted context omitted.

Public school systems tend to pay well for people who majored in early elementary education, music, kinesiology, etc. But this isn't the same demographic that would work at NSA.

My mom has a master's in education, and after 30 years across two public school systems, she's finally broken $40k salary. Where do you live that public school systems pay well?

Presumably England, where 'public' schools are what would be termed 'private' or fee paying schools in the USA ;)
Post reply on HN