Live data from Hacker News

NSA Owns Everything (2015)

blog.thinkst.com

211–220 of 265 posts

Re: NSA Owns Everything (2015)

#211
post #8

Earlier quoted context omitted.

There were others before snowden, like: James bamford https://media.ccc.de/v/31c3_-_6600_-_en_-_saal_2_-_201412281... What snowden did was provide independently verifiable content and details of their activities. His leaks were outdates by half a decade by the time they were public too. Everyone sort of accepted the IC will do shady stuff to stop terrorists after 9/11 because "american lives" so it was a solid conspi…

If the tools are there, they will be used for evil. When you can surveil and blackmail the entire world, including your political taskmasters, what sort of person will that role attract?

> If the tools are there, they will be used for evil.

I use a stronger (more specific) form of that heuristic that seems to hold up well in practice:

If something evil is within technological possibility, and there is economic gain to be had from doing it, someone will end up doing it.

(Note, by "within technological possibility" I don't mean "there are COTS tools available for doing that", but closer to "physics doesn't prohibit it, and we have a good grasp on how it could be done in theory".)

I actually first figured out this phrasing of my intuition during Snowden revelations, to explain to myself why my initial reaction was a complete lack of surprise.

Re: NSA Owns Everything (2015)

#212
It's still amazing to me that the mainstream media is insisting that incumbent politicians and power players weren't spying on their rivals using the full strength and force of the American intelligence community.

This isn't a red vs blue issue here. It's about whether or not we're going to allow the powerful to pick and choose election winners.

Re: NSA Owns Everything (2015)

#213
post #46

Earlier quoted context omitted.

> Does this mean running in a public cloud might actually be more secure? Yes with two conditions: 1. your public cloud is run by an Amazon, Google, Microsoft-type company (FANMAG) 2. You trust the company to lean on rule of law. 1. Very few providers have the capability and desire to put the work into supply chain security, things like OpenTitan, etc. 2. They might hand over your data in response to warrant, but the…

In practical terms this is wrong in my opinion. You want the small provider that flies under the radar. If there are ambitions to compromise the hardware supply chain, it is a bit late to act. But it is logistically impossible or at least very unlikely to compromise every provider. But you actually can run software on compromised hardware that can provide end to end encryption irrelevant on how thoroughly the system…

Small providers often don't have the resources or skills to properly cover their bases and get hit by random BS. They may not be targeted today, but they will get hit by random badness.

Example of shared hosting providers not patching postfix fast enough or having a support person that chmodded the wrong thing on shared hosting server, customer with old wordpress install that was exploited to drop a webshell, etc.

> But you actually can run software on compromised hardware that can provide end to end encryption irrelevant on how thoroughly the system spies on you

Do you have any references? I'd like to read more.

If this were generally true, attempts to make trusted enclaves like Intel SGX (though flawed) would not need to exist.

Re: NSA Owns Everything (2015)

#214

I’m really interested in how low level the hacking is, specifically network card and hard disk firmware. Does anyone have breakdowns of how these work or copies seen in the wild? I particularly liked the bit in the article about hiding data in packets intended for other hosts and harvesting them through passive relays. Is there a way to detect this sort of thing? Is everything really compromised?

consider what info NSA has access to with it's stunning global passive adversary infrastructure. to you or me, developing exploit implants on a systematic scale targetting the firmwarw of every model of every harddrive of every vendor seems technically impossible to us outsiders.

but NSA has access to the emails, internal bug trackers and source code repos of the entire dev teams at all of those vendors. think how easy it would be to hack all firmware on an indistrial scale when you can cheat and read the blueprints?

NSA is the biggest cheater. i no longer consider them as being gods of cyberwar. rather, they merely tricked us all to believe NSA was not mass surveilling everyone, then we were blinded to the scale of what was really possible behind the curtain.

if we had the source code to the firmware of every hard drive, we could do exactly the same thing NSA did.

also, yes, do not ever trust a computer. remember the photo of David Miranda's macbook motherboard after his laptop was siezed when he was connecting to a flight in London and acting as the courier between Laura Poitras in Berlin and Greenwald in Brazil? the photo showed GCHQ melted like a dozen chip on his motherboards. when that photo came out, it was puzzling, because the Snowden leaks about NSA hacking firmwares had not yet leaked. in hindsight, now we know. NSA and FVEYs physically destroyed every chip that they could implant, out of fear that someone else could BADBIOS attack David's macbook and steal the Snowden cache.

Re: NSA Owns Everything (2015)

#215
post #5

The basic premise is false. > "Why did we never see it coming?" Many people saw it coming. I was warning about the possibility of dragnet surveillance, the existence of ECHELON, the use of the American security apparatus to steal trade secrets, the surveillance of non-American politicians, et al... For many, many years before Snowden. And I'm just some rando on the internet who follows the mainstream news! We were ca…

> The basic premise is false.

> We were called _Conspiracy Theorists_

Depends who "we" is. If "we" is people on HN, who are tuned in and more closely associated with this stuff, then yeah. _You are not_ just some rando on the internet who follows the mainstream news, you are tech literate and actively participating in a niche technology forum.

But if "we" is more a general term then the premise isn't false and I'd argue is still relatively true today. The general public is only starting to turn away from ideas like "I don't care if Google reads my emails, what are they going to do?" And that's only because ad suggestions have gotten too good, enough that they believe that Facebook is turning on their microphones. Obviously didn't learn from Target[0]. You're clearly aware of this because of your last sentence!

You can sit with your pride telling everyone that you were right all along and not crazy, or you can further the reach to the more generalized "we." The two options are not really inclusive.

[0] https://www.nytimes.com/2012/02/19/magazine/shopping-habits....

Re: NSA Owns Everything (2015)

#216
post #40

An observation: The exfiltration protocol described in the "misdirection" section has "Dated: 24 Feb 98" in the bottom right corner. That it's being regarded as reasonably novel is a good measure of just how broken the collective security discussion is. Just as broken as the PGP situation, thinking about it; in which case everything is operating as intended... moving on...

nice catch. that date of 1998 is a Big Fucking Deal. the Patriot Act was passed in October 2001. the narrative we have all be lead to believe is that NSA only ramped up domestic mass surveillance in 2001. but why would NSA have a protocol for exfil across passive sensor hops in 1998? passive exfil only works if you have sensors mirroring backbone traffic at all the biggest upstream meetme rooms. but NSA supposedly wasnt legally allowed to install Boeing Narus mirror routers at ISPs until 2001.

what this 1998 date means is that NSA TURMOIL--passive sensor ingest, had to exist PRIOR TO 2001.

this even screws Bill Binney's narrative that the system he designed--THINTHREAD, which he says would spy on all traffic without violating our privacy laws, was built in 1999-2000. THINTHREAD was ultimately canceled and Hayden chose STELLARWIND instead.

but this screencap show FASHIONCLEFT already existed in 1998. therefore NSA has been spying on the whole Internet for waaaay longer than the official narrative says.

i was one of those conspiracy theorists ranting on USENET about ECHELON back in 1998. turns out, we were RIGHT.

Re: NSA Owns Everything (2015)

#217

Earlier quoted context omitted.

> they had means, motive and opportunity They didn't have the legal right. > All it took was one person willing to burn their career to provide the proof. Snowden proved that the NSA does not vacuum everything up in the US and only vacuums everything in a few countries. You seem to be reading different documents from the ones that Snowden released.

Not having the legal right to do something does not count as evidence that it didn't happen.

Since there isn't any evidence that it did happen, the fact that it is illegal is a pretty good reason to believe that it didn't happen. When you consider that Snowden released a trove of internal documents not vetted by the secret keepers, and none of them show that it did happen (while many of those documents cite the law for why it should not happen), that provides further circumstantial evidence that it didn't happen.

Re: NSA Owns Everything (2015)

#218
post #29

Earlier quoted context omitted.

>Many people saw it coming. This article is asking how the NSA managed a hacking empire leaving practically no evidence. Many people correctly assumed it was happening, they just couldn't prove much. "Why did we never see it coming?" Is a poor way of phrasing their premise, but it's not false.

Exactly. The other emphasized question, while less sexy and less quotable, is a much more accurate representation of the question TFA tries to answer: > If the NSA was owning everything in sight (and by all accounts they have) then how is it that nobody ever spotted them? It’s sad that people routinely find the first disagreeable thing in any submission then derail the whole discussion based on an out-of-context misr…

> It’s sad that people routinely find the first disagreeable thing in any submission then derail the whole discussion based on an out-of-context misrepresentation of that.

It reminds me of that "CIA manual" that floats around about how to derail conversations and sew doubt when infuriating an organization (can't find link). About doing things like bringing up irrelevant information, highlighting less meaningful things, revisiting already solved problems, etc. I mean what did the GGP do besides say "_I_ knew about this, but you all called me a conspiracy theorist! Who's laughing now?" What good does such a statement do? Clearly they are following the CIA handbook and derailing the conversation! (I'm joking)

But I think it comes down to not wanting to read the entire article _AND_ process the information contained within. I think a lot of people read things for the words written and not for the meaning, and I find this odd.

Re: NSA Owns Everything (2015)

#219
post #5

The basic premise is false. > "Why did we never see it coming?" Many people saw it coming. I was warning about the possibility of dragnet surveillance, the existence of ECHELON, the use of the American security apparatus to steal trade secrets, the surveillance of non-American politicians, et al... For many, many years before Snowden. And I'm just some rando on the internet who follows the mainstream news! We were ca…

>Many people saw it coming. This article is asking how the NSA managed a hacking empire leaving practically no evidence. Many people correctly assumed it was happening, they just couldn't prove much. "Why did we never see it coming?" Is a poor way of phrasing their premise, but it's not false.

I don't see why the surprise, since the whole apparatus of the NSA is premised on being invisible.

Re: NSA Owns Everything (2015)

#220

One thing I'm curious is what's the source of energy behind all this. NSA failed to stop many important accidents (9/11, covid) .. Is it a survival bias and they're still keeping people safe without saying it or is it some finance/intelligence blackhole spinning due to some political quicksand ?

In a society governed through secrets, we can never know what the sovereign is really doing in our name. This is the case with the USA today - it is not truly an open society, but one of layers .. and those with the 'special privilege' of having security clearances are desperate to maintain that socially high-class standing among themselves, so they wrap more and more secret agency around the issue so that the genera…

Socialism is when the Government does stuff. Rich capitalists lobbying and corrupting the Government to give their private organizations more money is Socialism.

Socialism is destroying America!! Can't you see??!

Post reply on HN