Live data from Hacker News

Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

lite.cnn.io

81–88 of 88 posts

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#81

Earlier quoted context omitted.

I suspect it was the ISPs who made the decision, not the manufacturers. Removing the common excuse of "my network is open, who knows who did it!" for torrenting may be the reason. Another could be to make open/easily accessible networks rarer as they started selling Wi-Fi via the provided routers.

could be ISPs trying to improve user security generally to prevent lots of their customers becoming DDOS zombies resulting in more contention & customer complaints.

That's highly unlikely as we've recently learned from "Internet Chemotherapy": https://news.ycombinator.com/item?id=15946095

ISPs are unfortunately the problem, not the solution.

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#82
post #68

Earlier quoted context omitted.

Thanks, but all credit goes back to HN for turning me onto cnn.io in the first place.

TIL I needed this. -- do you use any other text based sites?

I don’t, sorry. I’d certainly upvote and appreciate someone who put together a list of good ones though.

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#83
post #68

Earlier quoted context omitted.

Thanks, but all credit goes back to HN for turning me onto cnn.io in the first place.

TIL I needed this. -- do you use any other text based sites?

NPR also has a text only version:

http://text.npr.org

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#84

Earlier quoted context omitted.

> the CIA this is why anything sensitive is air gapped and inside a SCIF... but good luck getting everyone to adhere to that all of the time. it's a hard problem to solve when people want things to "just work".

True. Also, the problem with air gaps is that people come to depend on them. According to documents about stuxnet and the Snowden leaks, the CIA has said that air gaps have never stopped them, so why should we think that it's any different? Also, many places people think are air gapped aren't any more. Think smart lightbulbs and bluetooth worms. A hacked android device that gets too close to the perimeter can infect…

>What's the baud on opening and closing vents and reading it from space satellites?

Here's an example where researchers used a scanner in an office building to exfiltrate data from the network. Malware on the network activates the scanner in a certain pattern, which lights up the room. The difference in lighting is recorded using a drone outside across the parking lot:

https://www.bankinfosecurity.com/black-hat-europe-beware-air...

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#85
post #44
post #43

Earlier quoted context omitted.

I can't even imagine what the purpose of this sort of honeypot would be. What a waste of money that would be. It's so absurd an idea that I would laugh at it if I didn't know how much money was spent and wasted by the federal government. Really the only way to explain it is this sort of thing. "Let's set up a whole fake parking lot, hire people to come and go in it, get a bunch of fake license plates, buy a bunch of…

You could probably save on reusing the video footage of another parking lot, instead of using actors.

"You could probably save on reusing the video footage of another parking lot, instead of using actors."

Live or recorded video footage from somewhere else can be spotted as fake (car license plates, distant shop signs, different weather conditions, etc) and recorded footage will also eventually wrap around revealing it's recorded. It all depends on what they need to accomplish.

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#86

Earlier quoted context omitted.

This is not necessarily the case for organizations that have special hiring authorities and/or contract dollars for use rapidly.

If a hacker reports themself to the CIA, its the government who gets involved, not a contractor.

Right, and they can offer specific "cyber" related competitive authority positions to that person, or ask them to come on board as a 1099 or via an existing contract vehicle where they implicitly instruct a company to bring the person on as a subcontractor. Or, you know, just dump a pile of money on them as a single outlay. I'm sure there are plenty of options created specifically for this scenario.

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#87
post #40

Are there any actually secure ip cameras? Somehow I don't think this is a badge of honor for the "romanian hackers". They probably just scanned for default passwords and known vulnerabilities.

How is that not hacking? Many hackers use known exploits to break into systems.

Who said it's not hacking? However, it's on the "unskilled labor" side of hacking.

Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras

#88

Earlier quoted context omitted.

> This is the problem with cyber security: Even if you're the most knowledgeable organization on earth you still fuck it up. Any one person can fuck up any one thing and if it isn't part of your predetermined threat vector analysis then it gets through and you lose everything. It isn't just cyber security but surveillance infrastructure in general. If you cultivate a large group of surveillance assets (even people) w…

I disagree with your conclusion, but I think your comment has a ton of truth to it. It's like that meme with the smiling black guy: "You can't write any bugs if you don't write any code." But the truth is that all the infrastructure for surveillance is going to be built anyway, if not by us then by our enemies or private industry. It's better to accept that it is going to be built and use our resources as best we can…

> But the truth is that all the infrastructure for surveillance is going to be built anyway, if not by us then by our enemies or private industry. It's better to accept that it is going to be built and use our resources as best we can to protect the world.

Of course. And then you attack _their_ surveillance infrastructure and take the fruit of their investments periodically.

Attacking surveillance infrastructure (tbh) seems more productive than building it.

Post reply on HN