Live data from Hacker News

Security Breach and Spilled Secrets Have Shaken the N.S.A.

nytimes.com

181–190 of 193 posts

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#181
post #174
post #161

Earlier quoted context omitted.

Who says attackers must use home or small office connections? Why can't the data be exfiltrated to a top tier data center with excellent peering?

But consumer/corporate demand for bandwidth is what should ultimately drive increase in data center bandwidth. Another point is defeating monitoring. I am sure the NSA (or Google/Facebook) could not notice 1GB of upload, but I like to think that uploading 1PB of data would make all sorts of red lights flash in they network security control room.

I'm with you that copying all of Google's data is unlikely. It's a serious project for Google itself to significantly move around its own data internally. My point is that very extensive, damaging information could amount to a mere 100TB subset of it and it's not implausible that could be copied in a day at 10 gig/s. To obvious? How about 100 hosts each pulling 100 meg/s? That's feasible right now. When you really get down to it the datasets I fear being leaked the most are a lot smaller than that.

Most bandwidth is used sending many copies of the same content. Attackers aren't going to be interested in downloading the popular video 100 million times, they're just going to grab the logs which are nowhere near that size, and although large it's not implausible that even the best security teams wouldn't notice until it's too late.

There is no hard rule that the leaks need to come from the same central database either. That is unlikely considering the fact that large scale services are already, and necessarily, distributed. Imagine thousands of attacker hosts receiving from thousands of compromised hosts.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#182
post #133
post #83

Great. I hope this continues. The more the NSA has problems, the better off the rest of the rest of us are. It's unlikely the institution is even lawful--its practices certainly aren't. At the very least, it proves that the government cannot itself keep secrets, so it really needs to shut up about trying to put backdoors into software when it can't protect its own most vital software assets from leaking. I guarantee…

There are plenty of vital secrets that haven't leaked for decades. Why do you exclude those examples from your reasoning?

Name one.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#183

Earlier quoted context omitted.

But it's not patriotic to give NSA tools to the Russians, to hurt the ability of the NSA to spy on Russia.

Who gave NSA tools to the Russians?

Presumably, a traitor within the NSA or a contractor.

See: https://medium.com/@thegrugq/the-great-cyber-game-commentary...

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#184

Earlier quoted context omitted.

Public school systems tend to pay well for people who majored in early elementary education, music, kinesiology, etc. But this isn't the same demographic that would work at NSA.

My mom has a master's in education, and after 30 years across two public school systems, she's finally broken $40k salary. Where do you live that public school systems pay well?

In Cincinnati, not a particularly HCOL place, with 30 years and a master's she would have made $77k.

https://www.nctq.org/districtPolicy/contractDatabase/distric...

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#185
post #44

Living in Maryland, I've met several young people who put in a few years at the agency (including TAO) who then left for industry. Millenials don't care about a government pension, especially when you're in a windowless SCIF hacking Perl. The US Government as a whole has a massive talent retention problem. Only the mediocre will stay at NSA / CIA now and we'll probably see more of these leaks / hacks.

There’s a massive pay disparity between public and private, and those currently in power want to keep it that way and eat away even more at gov functions. That combined without a clear rallying call for public service (like the Cold War or collective pride) are a recipe for disaster.

I have relatives who are all steeped in public service hoo-ha because they attended a small, private college that upholds that as a primary value. I personally think they have taken it too far: Public service was traditionally not a career path and should not be looked upon as such. You do your service for a couple of years, then you go back to private enterprise. Career public servants are bureaucrats, have become a very negative voting bloc, and need to be reined in if for no other reason than public service pensions have brought this whole entire nation to the brink of collapse.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#186

Earlier quoted context omitted.

He had that access as he had been working for first the CIA, then the NSA, for five years before he decided to become a whistleblower.

If you go read his story in detail you'll see that he held various jobs, but he applied for a transfer to become a sysadmin specifically (a job downgrade ) because he was collecting info to leak by that point, and knew he could access more if he had admin privs.q

I have read his story in detail, he hadn't been a systems admin for a few years when he decided to began copying documents. There wasn't a demotion, he had the same title at two departments. And his decision to become a whistleblower came from what he saw at the new department.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#187
post #149

Earlier quoted context omitted.

The point is that the debt can increase forever since we got off gold.

This isn’t necessarily hard or bad, though. If I take $100 and loan it to my neigbor, the debt appears from nowhere. Heck, theoretically, he could loan it right back under different terms and create more debt. Debt isn’t necessarily bad—the fear is you’re builidng on jenga blocks, not that some guy is going to show up with a wrench.

In this case we are talking about government debt though. Congress does have some control over it with "appropriations" I think.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#188

Earlier quoted context omitted.

Wasn't Perl created for the NSA? At least that's a story I heard. The official JPL reason is a cover. Or maybe it was created for both. Or neither. Shrug. Just googled it.. Here's a quote from Larry: [...] the NSA project Perl was (indirectly) written to support. http://www.linuxjournal.com/article/3394 Another one from his 2005 State of the Onion: > You might say that Perl grew out of the Cold War. I've often told t…

It was for the high-assurance BLACKER VPN: https://en.wikipedia.org/wiki/Blacker_(security) Here's the source on that: http://cahighways.org/wordpress/?p=5460 Another notable aspect of that was it used an early secure kernel, GEMSOS, that is still marketed by Aesec but probably in legacy mode in bad way. It did resist penetration during NSA certification and time on market far as what data I have says. http://aesec.c…

Great links, thanks.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#189

Earlier quoted context omitted.

A quick google finds its a compromise worthy of the laundry file "We settled on the name ‘operator’ to designate an operational member of the unit (as opposed to a member of the support staff) due to some legal and political situations. We couldn’t use ‘operative’ because that name had certain espionage connotations from the CIA. The term ‘agent’ had some legal issues. An agent carries a legal commission to perform c…

this sounds more like a joke about government bureaucracy than anything. it seems much more likely that it's simply derived from 'special operations'.

I have worked for an ex civil service bureaucracy and names and grades still had serious social and prestige

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#190

Earlier quoted context omitted.

Maybe, maybe not. NSA hacking tools can't necessarily be kept privately within their network, because they have to be used to attack targets across the Internet -- they have to be deployed. By comparison, the data that the NSA collects can presumably be sucked into their airgapped network, where data has a way in but no way out.

Data has to be accessable to be of any use.

Has Snowden or any whistleblower given any indication as to whether such networks are air-gapped, accessible from the internet, etc?
Post reply on HN