Live data from Hacker News

NSA Owns Everything (2015)

blog.thinkst.com

41–50 of 265 posts

Re: NSA Owns Everything (2015)

#41
post #5

The basic premise is false. > "Why did we never see it coming?" Many people saw it coming. I was warning about the possibility of dragnet surveillance, the existence of ECHELON, the use of the American security apparatus to steal trade secrets, the surveillance of non-American politicians, et al... For many, many years before Snowden. And I'm just some rando on the internet who follows the mainstream news! We were ca…

> We were called Conspiracy Theorists...

It was a theory that there was a conspiracy. The issue is that people dismiss conspiracy theories out of hand - even when the theory is backed by means, motive and incentives.

"This power is being used to influence the political process in the US" is still a conspiracy theory and will likely turn out to be true as well one day - because again the people involved have means, motive and incentives. But incentives based predictions are a bit subjective and most people don't seem to believe that incentives overrule character.

Re: NSA Owns Everything (2015)

#42

Yet somehow Russian / China are hacking the US left and right. If the NSA is so good, then at some point dont they have the responsibility to actively defend?

From the article, attacking is much cheaper than defense. If they were splitting their budget evenly between the two you wouldnl still hear about the US being hacked constantly.

Even if they were 100% successful in stopping hackers we would still hear about the US being hacked constantly. It's propaganda.

Re: NSA Owns Everything (2015)

#43
post #18

2. You thought they were someone else Attribution in the cyberspace is still pretty shaky, even though there have been some high profile accusations flying around lately. Sometimes you see links being drawn to GRU on the basis of things like some executable having a compile time matching to a Russian time zone or a file being last modified by a user called "Dmitry." Seeing as the IC cyber business is already murky as…

> I think only the PLA plays with slightly more open cards, mostly because they just don't give a damn about being caught.

This tactic was invented by the KGB. It's not that they don't care, it's that if it looks like you did it, and there was no apparent attempt to conceal that it was you, then it actually seems more like you were framed by someone else and you didn't do it. In other words, the truth acts like its own disinformation campaign because people often assume the real criminal would try to conceal themselves.

Re: NSA Owns Everything (2015)

#44
post #13
post #6

Earlier quoted context omitted.

How does "running fully free software" helps alleviate "compromised x86"?

If you're running fully free software, you're not running x86, since it can't boot without backdoored binary blobs.

All modern ARMs have ROM block containing undocumented booting sequence.

Re: NSA Owns Everything (2015)

#45
post #20
post #4

Earlier quoted context omitted.

More scary is how people in tech circles still call you paranoid when you call Intel ME/AMD PSP a backdoor. >We are also always open for ideas but our focus is on firmware, BIOS, BUS or driver level attacks. Anyone on WiFi AC or up are backdoored right now by NSA. All of them are compromised, no doubt in my mind. All the LTE. All the x86 hardware on the market. All of it. If you aren't running fully free software, yo…

I can’t wait for those ME/PSP program to become declassified, because I have zero doubt it’s an op and someone’s going to do it. It’ll be exciting just as A-12/SR-71 docs!

They will never be declassified.

Re: NSA Owns Everything (2015)

#46
post #32

The hiding of the malicious code in arm processors of ssds and in the BIOS seem like this is mainly targeted at people running their own hardware. Does this mean running in a public cloud might actually be more secure? Or do we just have to assume that the NSA has their hardware in place in any cloud provider and that there actually is no security possible in the cloud?

> Does this mean running in a public cloud might actually be more secure?

Yes with two conditions: 1. your public cloud is run by an Amazon, Google, Microsoft-type company (FANMAG) 2. You trust the company to lean on rule of law.

1. Very few providers have the capability and desire to put the work into supply chain security, things like OpenTitan, etc.

2. They might hand over your data in response to warrant, but their systems are designed to prevent covert extraction of data. The company should have a track-record of pushing back against overly broad warrants.

Re: NSA Owns Everything (2015)

#47
post #5

The basic premise is false. > "Why did we never see it coming?" Many people saw it coming. I was warning about the possibility of dragnet surveillance, the existence of ECHELON, the use of the American security apparatus to steal trade secrets, the surveillance of non-American politicians, et al... For many, many years before Snowden. And I'm just some rando on the internet who follows the mainstream news! We were ca…

> The basic premise is false.

>> "Why did we never see it coming?"

You were never taught it in a rote fashion.

Fact is all intelligence services are heavily into their science and control. Its not just computer hacking they are into, they use psychology, medicine and finance to control the population. They have evolved the techniques first used and developed by successive religions since at least as far back as the ancient Sumerians.

Solomon Asch and his conformity experiments https://www.youtube.com/watch?v=TYIh4MkcfJA which continue to evolve to this day, is a useful tool for keeping people out of trouble, otherwise to quote an ancient religious expression "The devil makes work for idle hands to do" and who wants to go backwards in the Maslow's Hierarchy of needs?

So just like some people do not want to believe that God doesnt exist, some people do not want to believe their country's security services are spying on them 24/7 since the day they were born, hence why the hierarchical structure of society, currently called democracy, but included Royal governance and religious governance in the past, is still the leading way to operate in plain sight after more than 10,000 years of society. Maybe I should be called Mustapha Mond ;-)

Re: NSA Owns Everything (2015)

#49
post #35

Earlier quoted context omitted.

Snowden docs have been available for years. ShadowBrokers. Just this week a 20GB dump of private Intel source was dumped with backdoors included. It is beyond a reasonable doubt that x86 hardware has NSA backdoors in it. You're now sitting on a time bomb. Remember when the NSA tools were dumped with their secret Windows exploits? WannaCry? North Korea picked that up and launched ransomware attacks. That's the sort of…

I don't remember WiFi or CPU backdoors in Snowden, ShadowBrokers, or Intel 2020. Unless by "backdoor" you just mean NSA holds zero days on various important technologies, which is reasonably likely given EternalBlue. Is that what you mean?

They don't need 0days when they can just easily corrupt the standards process. They've been doing it everywhere.

The Wifi Alliance has made some heinously bad choices that if you attributed to incompetence simply make no sense, they treat anyone who questions them with disdain and shoots down attempts to fix the mess they make. WPA3 was hilariously broken a month after getting rolled out.

Re: NSA Owns Everything (2015)

#50
I think the intelligence community made a bit of a joke of themselves honestly. Especially on the topic of electoral manipulation. They deserve it.

Although there was large political influence, it really doesn't shine a good light on them and their capabilities or more probable what they make of them.

That said, I think restricting their abilities is the way forward, otherwise you just get a new form of a cold war, which in hindsight was just stupid. Their current capabilities cannot be justified with security concerns and if so, they should at least be able to fix the IT of prominent political actors.

They scared the right people to get privileges to data that is formally protected in most western countries. So not only do they do a bad job, they are also criminals.

Post reply on HN