Earlier quoted context omitted.
What about Libreboot? Doesn't that allow booting x86 without binary blobs?
They still need some parts of blobs to configure/initialize the system and that “some” now means full MINIX kernel along its userland
NSA Owns Everything (2015)
81–90 of 265 posts
Re: NSA Owns Everything (2015)
#82Earlier quoted context omitted.
Yes, very old hardware that's no longer on the market. I don't consider that a solution. Eventually that pool of hardware dries up.
It's easy to find x200 etc. used. Flashing is another story.
Re: NSA Owns Everything (2015)
#83The question is, with all of these companies performing IR, why didn't they see mass exfiltration and C2?
I think the article lays out largely correct claims.
I personally would imagine (2) and (5) to be the most significant.
Regarding (2), it is so hard during an incident to know exactly what is attacker behavior and what isn't, to know that it's all the same attacker, etc. It isn't so uncommon to go digging into an incident only to find some unrelated malware - and in fact many companies find out they're owned from their pentesters.
With regards to (5), defenders have frankly been to slow to evolve. The people investigating these attacks likely only have a rudimentary understanding of TCP/IP, have virtually no ability to read or write code, and mostly are trained to build and enforce policy. The idea that they can catch even basic attackers in realtime is a joke, that they are to also be tasked with catching the NSA is just a depressing, hard to swallow reality.
Attackers are out here building up toolchains from scratch - anyone who isn't doing that is called a script kiddy. And yet defenders who can't build a single thing, who can only throw tools at a problem, are the standard. Attackers are flat out better than defenders - they work smarter, they have better capabilities, and defenders don't even seen to care en masse.
As Alex Stamos said (paraphrasing), most companies aren't even "playing the game", and it's a select few that even know what game to play - not even that they're playing well, but at least they showed up to the right ballpark (I'm butchering his statement). The vast majority of companies employee outdated models of security and incident response is probably the least mature, with devops pushing more and more infrastructure and product security engineers over IT admins.
No doubt that NSA's scale allowing novel forms of exfil like passive collection also played a major part.
What a sad state.
Having taken VC money to try to improve the situation I do always laugh when thinkst talks about that :) but much respect!
Re: NSA Owns Everything (2015)
#84Earlier quoted context omitted.
Exactly. The other emphasized question, while less sexy and less quotable, is a much more accurate representation of the question TFA tries to answer: > If the NSA was owning everything in sight (and by all accounts they have) then how is it that nobody ever spotted them? It’s sad that people routinely find the first disagreeable thing in any submission then derail the whole discussion based on an out-of-context misr…
While that practice is common, this article does say >The purpose of this post isn’t to discuss the legality of the NSA's actions or the morality of the leaks, what we are trying to answer is: "Why did we never see it coming?" They clearly made it the central theme. With enough context what they are saying makes sense, but that phrase is so often used to describe how people predicted something without evidence. I'm s…
That's really the only thing it means. It certainly doesn't mean "why did we never see it happening" (those words mean that) or "why didn't we identify the perpetrator".
Edit: for example I saw the downvote coming, because some people here love downvoting simple factual statements, but I don't know who did it, because why would they want to admit it.
Re: NSA Owns Everything (2015)
#85One thing I'm curious is what's the source of energy behind all this. NSA failed to stop many important accidents (9/11, covid) .. Is it a survival bias and they're still keeping people safe without saying it or is it some finance/intelligence blackhole spinning due to some political quicksand ?
Their mission has become “collect it all”, but I think they (and a lot of commentators and even everyday people) can’t really imagine what a large percentage of intelligence is useless noise, deliberately wrong (such as counterintelligence but they don’t realise), just plain wrong (like most intel gathered from torture - people will say literally anything they think you want to hear), correct but misinterpreted, etc.. And it’s extremely hard to meaningfully sort through that much information. I expect they do expend a lot of effort trying to combat this, but historically I don’t believe they’re very good at it, and I’m sceptical machine learning and things like that is really going to help that much.
And then just watching the wrong people. Take the Boston bombing, for instance. There are reports that the key focus of groups like the DHS at the time in that area were the Occupy Boston protests, so the bombing happened even though the FBI had been tipped off about one of the bombers from Russian intelligence services. Then things like the NZ mosque attack, where this far-right wing white supremacist came from Australia and murdered a bunch of people. At the time, the media where I am in Australia was reporting FUD campaigns from Australian security agencies about ISIS and Islamic terrorism, radicalisation etc., so I imagine that’s where the focus was and he slipped through.
This goes way back throughout history. Just think of the massive amount of wasted resources surveilling suspected “communists and homosexuals” back in the day. Here they had agents actually infiltrating university communist groups. The groups got up to extremely dangerous things like going to protests - great use of millions of dollars of surveillance...
Re: NSA Owns Everything (2015)
#86Earlier quoted context omitted.
Exactly. The other emphasized question, while less sexy and less quotable, is a much more accurate representation of the question TFA tries to answer: > If the NSA was owning everything in sight (and by all accounts they have) then how is it that nobody ever spotted them? It’s sad that people routinely find the first disagreeable thing in any submission then derail the whole discussion based on an out-of-context misr…
While that practice is common, this article does say >The purpose of this post isn’t to discuss the legality of the NSA's actions or the morality of the leaks, what we are trying to answer is: "Why did we never see it coming?" They clearly made it the central theme. With enough context what they are saying makes sense, but that phrase is so often used to describe how people predicted something without evidence. I'm s…
All of the talk of how some people on HN totally for real knew the NSA was hacking people is irrelevant and a total distraction from the far more interesting question of why we needed a leaker to confirm it.
Re: NSA Owns Everything (2015)
#87Earlier quoted context omitted.
>Many people saw it coming. This article is asking how the NSA managed a hacking empire leaving practically no evidence. Many people correctly assumed it was happening, they just couldn't prove much. "Why did we never see it coming?" Is a poor way of phrasing their premise, but it's not false.
Exactly. The other emphasized question, while less sexy and less quotable, is a much more accurate representation of the question TFA tries to answer: > If the NSA was owning everything in sight (and by all accounts they have) then how is it that nobody ever spotted them? It’s sad that people routinely find the first disagreeable thing in any submission then derail the whole discussion based on an out-of-context misr…
I think this should rather say "nobody ever came forward". I'm sure there always were enough pieces of evidence even if scattered and nobody had the whole picture. But the ones who were close enough to put together some of it and get an idea had no incentive to open their mouths.
Coming forward with enough evidence was likely close to impossible until a decade or two ago. The ones who have such comprehensive evidence also have some "incentive" to keep quiet. Up to the proverbial "terminated with extreme prejudice" option, which I'm sure must have been employed given the sensitivity of the topic. Or perhaps risking being labelled a terrorist which would likely lead to even worse outcomes. When the efforts were escalated after 9/11 so were the security measures and the "incentives".
And coming forward with just shreds of evidence of something like this will only get you labelled a nut, enemy of the state, shill, etc.
Snowden and a few others did it at great personal cost and I'm sure they now serve as an example for others to not do it. Look around even today, people see the world in black and white and if you're not with them, you're against them, and they will treat you as such.
Re: NSA Owns Everything (2015)
#88Earlier quoted context omitted.
There were others before snowden, like: James bamford https://media.ccc.de/v/31c3_-_6600_-_en_-_saal_2_-_201412281... What snowden did was provide independently verifiable content and details of their activities. His leaks were outdates by half a decade by the time they were public too. Everyone sort of accepted the IC will do shady stuff to stop terrorists after 9/11 because "american lives" so it was a solid conspi…
If the tools are there, they will be used for evil. When you can surveil and blackmail the entire world, including your political taskmasters, what sort of person will that role attract?
Re: NSA Owns Everything (2015)
#89I remember how the public was shocked in Germany in 2013 about the revelations. What we learned was way beyond what everybody thought possible. One of the most important figures discussing the implications for our democracy and the impact on our behaviour in light of the knowledge that we have no privacy at all was the editor of the German newspaper FAZ: Frank Schirrmacher. Unfortunately he died in 2014, very young,…
I am still being labelled as a conspiracy theory nutcase whenever I talk about this subject to people.
I just go with a bit of ridicule. Something like: It is not that sophisticated, educated, wealthy and influential people in power could get together and have some kind of plan. If they did it couldn't possibly escape your attention but if it did it wouldn't be interesting enough for you to talk about.
Or maybe it isn't that. Maybe the quality of government depends entirely on the citizens? If you think drag net spying is a good idea is a yes/no question. If you don't care means yes which in turn means they should be doing it. Same goes for enriching themselves at your expense. I mean if you approve of it?? Or is not caring and approving not the same thing?
Re: NSA Owns Everything (2015)
#90An observation: The exfiltration protocol described in the "misdirection" section has "Dated: 24 Feb 98" in the bottom right corner. That it's being regarded as reasonably novel is a good measure of just how broken the collective security discussion is. Just as broken as the PGP situation, thinking about it; in which case everything is operating as intended... moving on...
Context? I remember that Snowden regarded PGP as a usable defence against his former bosses.