Live data from Hacker News

NSA Owns Everything (2015)

blog.thinkst.com

61–70 of 265 posts

Re: NSA Owns Everything (2015)

#61
post #14

Yet somehow Russian / China are hacking the US left and right. If the NSA is so good, then at some point dont they have the responsibility to actively defend?

But are they really though? Could well be a threat there but I want actual evidence when the threat bogeyman is invoked in the name of more power. I believed the WMD lie. I hope I have learned from that. If we believe the NSA then your question is exactly the right one to ask and has some obvious implications.

I think this might interest you:

https://en.wikipedia.org/wiki/Nayirah_testimony

So pretty much all of US's wars in Iraq has been based on lies.

Re: NSA Owns Everything (2015)

#62
post #44
post #13

Earlier quoted context omitted.

If you're running fully free software, you're not running x86, since it can't boot without backdoored binary blobs.

All modern ARMs have ROM block containing undocumented booting sequence.

You're wrong, but with such confidence! Here is a documented ARM booting sequence with fully free firmware,

https://stikonas.eu/wordpress/2019/09/15/blobless-boot-with-...

Re: NSA Owns Everything (2015)

#63
post #18

2. You thought they were someone else Attribution in the cyberspace is still pretty shaky, even though there have been some high profile accusations flying around lately. Sometimes you see links being drawn to GRU on the basis of things like some executable having a compile time matching to a Russian time zone or a file being last modified by a user called "Dmitry." Seeing as the IC cyber business is already murky as…

> I think only the PLA plays with slightly more open cards, mostly because they just don't give a damn about being caught. This tactic was invented by the KGB. It's not that they don't care, it's that if it looks like you did it, and there was no apparent attempt to conceal that it was you, then it actually seems more like you were framed by someone else and you didn't do it. In other words, the truth acts like its o…

I'm not sure your average Joe with no tech knowledge thinks that far. I'd say that most people that this sort of information at face value and don't bother to delve into it.

Re: NSA Owns Everything (2015)

#64
post #57

I remember how the public was shocked in Germany in 2013 about the revelations. What we learned was way beyond what everybody thought possible. One of the most important figures discussing the implications for our democracy and the impact on our behaviour in light of the knowledge that we have no privacy at all was the editor of the German newspaper FAZ: Frank Schirrmacher. Unfortunately he died in 2014, very young,…

I am still being labelled as a conspiracy theory nutcase whenever I talk about this subject to people.

Re: NSA Owns Everything (2015)

#65
post #32

The hiding of the malicious code in arm processors of ssds and in the BIOS seem like this is mainly targeted at people running their own hardware. Does this mean running in a public cloud might actually be more secure? Or do we just have to assume that the NSA has their hardware in place in any cloud provider and that there actually is no security possible in the cloud?

> Does this mean running in a public cloud might actually be more secure? If that public Cloud is from an American company: obviously no. And whether you prefer some Chinese intelligence service having access to your data probably depends on what you want to do.

Not just because of Intelligence services but also because of the CLOUD Act / Data Residency.

Re: NSA Owns Everything (2015)

#66

Earlier quoted context omitted.

I don't remember WiFi or CPU backdoors in Snowden, ShadowBrokers, or Intel 2020. Unless by "backdoor" you just mean NSA holds zero days on various important technologies, which is reasonably likely given EternalBlue. Is that what you mean?

They don't need 0days when they can just easily corrupt the standards process. They've been doing it everywhere. The Wifi Alliance has made some heinously bad choices that if you attributed to incompetence simply make no sense, they treat anyone who questions them with disdain and shoots down attempts to fix the mess they make. WPA3 was hilariously broken a month after getting rolled out.

TIL, any recommended reading on this?

Re: NSA Owns Everything (2015)

#67
One thing I'm curious is what's the source of energy behind all this. NSA failed to stop many important accidents (9/11, covid) .. Is it a survival bias and they're still keeping people safe without saying it or is it some finance/intelligence blackhole spinning due to some political quicksand ?

Re: NSA Owns Everything (2015)

#68

One thing I'm curious is what's the source of energy behind all this. NSA failed to stop many important accidents (9/11, covid) .. Is it a survival bias and they're still keeping people safe without saying it or is it some finance/intelligence blackhole spinning due to some political quicksand ?

In a society governed through secrets, we can never know what the sovereign is really doing in our name. This is the case with the USA today - it is not truly an open society, but one of layers .. and those with the 'special privilege' of having security clearances are desperate to maintain that socially high-class standing among themselves, so they wrap more and more secret agency around the issue so that the general public can never know, truly, what their sovereign is doing.

This allows immense corruption and profiteering. However, its not all just "ma' capitalism" - there are very strong indicators that a socialist superstate is being constructed within this society, which is parasitically feeding on the corpse of America today. Many consider the US military industrial complex the largest socialist organization that ever existed - it certainly crosses a lot of the boxes.

Re: NSA Owns Everything (2015)

#69
post #46
post #32

The hiding of the malicious code in arm processors of ssds and in the BIOS seem like this is mainly targeted at people running their own hardware. Does this mean running in a public cloud might actually be more secure? Or do we just have to assume that the NSA has their hardware in place in any cloud provider and that there actually is no security possible in the cloud?

> Does this mean running in a public cloud might actually be more secure? Yes with two conditions: 1. your public cloud is run by an Amazon, Google, Microsoft-type company (FANMAG) 2. You trust the company to lean on rule of law. 1. Very few providers have the capability and desire to put the work into supply chain security, things like OpenTitan, etc. 2. They might hand over your data in response to warrant, but the…

In practical terms this is wrong in my opinion. You want the small provider that flies under the radar. If there are ambitions to compromise the hardware supply chain, it is a bit late to act. But it is logistically impossible or at least very unlikely to compromise every provider.

But you actually can run software on compromised hardware that can provide end to end encryption irrelevant on how thoroughly the system spies on you if you can control its network traffic and construct crypt generation from basic arithmetic functions of the system in question.

Re: NSA Owns Everything (2015)

#70

Yet somehow Russian / China are hacking the US left and right. If the NSA is so good, then at some point dont they have the responsibility to actively defend?

I am still amazed how many people believed the Russian election manipulation story without any evidence. Especially large portions of the press should stand ashamed in a really, really dark corner.

In hindsight I believe the people selling penis enlargement were correct about the reasoning abilities of humanity...

Post reply on HN