Live data from Hacker News

NSA Owns Everything (2015)

blog.thinkst.com

31–40 of 265 posts

Re: NSA Owns Everything (2015)

#31

Yet somehow Russian / China are hacking the US left and right. If the NSA is so good, then at some point dont they have the responsibility to actively defend?

You are hearing those hacking news essentially from the same mouths calling Snowden a traitor and denying that we are under massive surveillance net, which only get worse over time. I do believe that scale of those hacks and their impact is greatly exaggerated to justify further power creep.

Re: NSA Owns Everything (2015)

#32
The hiding of the malicious code in arm processors of ssds and in the BIOS seem like this is mainly targeted at people running their own hardware.

Does this mean running in a public cloud might actually be more secure? Or do we just have to assume that the NSA has their hardware in place in any cloud provider and that there actually is no security possible in the cloud?

Re: NSA Owns Everything (2015)

#33
post #8
post #5

The basic premise is false. > "Why did we never see it coming?" Many people saw it coming. I was warning about the possibility of dragnet surveillance, the existence of ECHELON, the use of the American security apparatus to steal trade secrets, the surveillance of non-American politicians, et al... For many, many years before Snowden. And I'm just some rando on the internet who follows the mainstream news! We were ca…

There were others before snowden, like: James bamford https://media.ccc.de/v/31c3_-_6600_-_en_-_saal_2_-_201412281... What snowden did was provide independently verifiable content and details of their activities. His leaks were outdates by half a decade by the time they were public too. Everyone sort of accepted the IC will do shady stuff to stop terrorists after 9/11 because "american lives" so it was a solid conspi…

Puzzle Palace is from 1982. Everyone knew overseas cables were tapped and many peers joked about big brother listening on their long distance domestic calls.

Like life, technology always finds a way. Much of the talk back in the day was not based on reality because it was not based on what tech could practically do. The compute and storage weren’t there.

But it was pretty obvious by the late aughts that all the pieces for panopticon were coming together nicely. Tech finds a way.

Re: NSA Owns Everything (2015)

#35
post #4

Earlier quoted context omitted.

More scary is how people in tech circles still call you paranoid when you call Intel ME/AMD PSP a backdoor. >We are also always open for ideas but our focus is on firmware, BIOS, BUS or driver level attacks. Anyone on WiFi AC or up are backdoored right now by NSA. All of them are compromised, no doubt in my mind. All the LTE. All the x86 hardware on the market. All of it. If you aren't running fully free software, yo…

Can you provide some evidence for these claims?

Snowden docs have been available for years. ShadowBrokers. Just this week a 20GB dump of private Intel source was dumped with backdoors included. It is beyond a reasonable doubt that x86 hardware has NSA backdoors in it. You're now sitting on a time bomb.

Remember when the NSA tools were dumped with their secret Windows exploits? WannaCry? North Korea picked that up and launched ransomware attacks. That's the sort of thing that's going to happen again with the newly published Intel backdoors. Just wait and see. Tim Cook is 100% vindicated this week about not adding intentional iPhone backdoors.

Re: NSA Owns Everything (2015)

#36
post #32

The hiding of the malicious code in arm processors of ssds and in the BIOS seem like this is mainly targeted at people running their own hardware. Does this mean running in a public cloud might actually be more secure? Or do we just have to assume that the NSA has their hardware in place in any cloud provider and that there actually is no security possible in the cloud?

Why on Earth would public cloud be more secure? If the NSA has dedicated rack space in AT&T switching facilities, what makes you think they don't have offices at Microsoft, Amazon, Cloudflare, etc?

https://en.wikipedia.org/wiki/Room_641A

Re: NSA Owns Everything (2015)

#37
post #35

Earlier quoted context omitted.

Can you provide some evidence for these claims?

Snowden docs have been available for years. ShadowBrokers. Just this week a 20GB dump of private Intel source was dumped with backdoors included. It is beyond a reasonable doubt that x86 hardware has NSA backdoors in it. You're now sitting on a time bomb. Remember when the NSA tools were dumped with their secret Windows exploits? WannaCry? North Korea picked that up and launched ransomware attacks. That's the sort of…

I don't remember WiFi or CPU backdoors in Snowden, ShadowBrokers, or Intel 2020. Unless by "backdoor" you just mean NSA holds zero days on various important technologies, which is reasonably likely given EternalBlue. Is that what you mean?

Re: NSA Owns Everything (2015)

#38
post #32

The hiding of the malicious code in arm processors of ssds and in the BIOS seem like this is mainly targeted at people running their own hardware. Does this mean running in a public cloud might actually be more secure? Or do we just have to assume that the NSA has their hardware in place in any cloud provider and that there actually is no security possible in the cloud?

> Does this mean running in a public cloud might actually be more secure?

If that public Cloud is from an American company: obviously no. And whether you prefer some Chinese intelligence service having access to your data probably depends on what you want to do.

Re: NSA Owns Everything (2015)

#39
post #25
post #19

Earlier quoted context omitted.

What about Libreboot? Doesn't that allow booting x86 without binary blobs?

Yes, very old hardware that's no longer on the market. I don't consider that a solution. Eventually that pool of hardware dries up.

https://libreboot.org/suppliers.html

Re: NSA Owns Everything (2015)

#40
An observation:

The exfiltration protocol described in the "misdirection" section has "Dated: 24 Feb 98" in the bottom right corner.

That it's being regarded as reasonably novel is a good measure of just how broken the collective security discussion is.

Just as broken as the PGP situation, thinking about it; in which case everything is operating as intended... moving on...

Post reply on HN