Live data from Hacker News

Spy agency ducks questions about 'back doors' in tech products

reuters.com

41–50 of 272 posts

Re: Spy agency ducks questions about 'back doors' in tech products

#42
post #35

Earlier quoted context omitted.

> Disconnect from the internet and nobody is getting in, including the NSA. Oh boy. That's some serious delusion in 2020. Wireless cards and higher end network interface cards are independent computers. Your processor has another processor (Intel ME and others) in it. Baseband Management Controllers are also independent computers on their own right. With closed firmware and wireless capabilities, you can never know w…

Stuxnet is interesting. Apparently, the US and Israeli agents threw away a number of USB devices around target facilities. What do you do when you find a USB stick? Well, eventually someone working in an air gapped facility picked up one and used it inside. The NSA apparently perfectly aligned 4 zeros days in Siemens and Microsoft products to spread the malware from USB into the Iranian LAN (shared printers, industri…

Its more nuanced than that. Didn't read the book completely but read a long report. What I remember:

- They got exact hardware details and topology of the centrifuges somehow.

- They've stolen Realtek's driver signing keys.

- The virus looks like a simple worm which can infect other USB devices and doesn't unpack beyond a certain point if it can't find the SCADA equipment and the correct device ID & topology (It's like a homing cruise missile which looks like an RC plane from distance until it finds its target).

It's possibly the most sophisticated hacking campaign when social and technical aspects combined.

Re: Spy agency ducks questions about 'back doors' in tech products

#43
post #12

Earlier quoted context omitted.

Quote from Wyden in the article >Secret encryption back doors are a threat to national security and the safety of our families – it’s only a matter of time before foreign hackers or criminals exploit them in ways that undermine American national security

In other words: NSA paved the way for foreign hackers and criminals...

And likewise, foreign hackers and criminals may have paved the way for the NSA - which is considered a foreign hacker and criminal in other jurisdictions.

Re: Spy agency ducks questions about 'back doors' in tech products

#45
Wyden is great.

The big issue with backdoors, is that it's only a matter of time, before they become "front doors."

Presented for your approval. Imagine, if you will, a software engineer; probably based in the US, that writes a backdoor into equipment used to manage a banking transaction network. This is a fairly natural place to have it, as "follow the money" is a classic forensic technique.

Of course, access to this network could net nefarious (probably non-state) actors a lot of money.

Said software engineer suddenly quits and buys a Bugatti.

The back door is now a front door, and it's baked into some hardware that can't easily be changed, as no one trusts the patches, now.

Re: Spy agency ducks questions about 'back doors' in tech products

#46
post #38

Earlier quoted context omitted.

The first rule of fight club is you do not talk about fight club. If a chip company was placing back doors into their products, I doubt it would be something they would talk about around the water cooler. However, if a back door was implemented on this level, if some one broke rule #1 and rule #2 of fight club, then I don't see how it would be able to be kept quite after that.

So we only believe people who claim something is happening with no proof ... because anyone who doesn't see it happening just isn't in the special circle of folks doing it?

what are you on about? if nobody in the know talks, how does anyone find out about it? if people are talking about it, then anyone with any know-how will start to investigate. if you choose to believe something someone tells you with no proof, then that's on you. claiming we do the same thing is a broad brush that i'm not getting painted on by thank you very much

Re: Spy agency ducks questions about 'back doors' in tech products

#47
post #15
post #5

"The tactics drew widespread attention starting in 2013, when Snowden leaked documents referencing these practices." So this is what Snowden has done: he "drew widespread attention to these tactics". Before Snowden they would call you "paranoid" if you would allow yourself to mention it. Today they can not call you paranoid anymore. And yes, it has hurt US industry reputation. Many don't trust Intel processors and Ci…

It has always been true that any computer connected to the internet could be accessed by an unauthorized party, even before the leaks. Disconnect from the internet and nobody is getting in, including the NSA.

Have you heard of Stuxnet?

Re: Spy agency ducks questions about 'back doors' in tech products

#48

Is anyone actually surprised of a "we can neither confirm nor deny" type of answer coming from intelligence agencies?

Yes. After the Snowden leaks and Shadowbrokers/Vault7/WannaCry disasters, the agencies put a lot of effort into reassuring the public that US technology was trustworthy. This included things like making public the Vulnerabilities Equities Process [1], and other work to restore trust in cryptographic standards agencies like NIST [2]. It also included more public engagement with industry to report serious vulnerabiliti…

Couldn't they just have said "no we have no backdoors"? NSA would look good, Congress would look good for asking the tough questions. When eventually new evidence comes to light that they do have backdoors, they have the choice then between continuing to deny deny deny, or pointing to national security interests.

Re: Spy agency ducks questions about 'back doors' in tech products

#49
post #22

Earlier quoted context omitted.

a little interdiction while that new airgapped laptop is shipped to you and they got you, even though you never connected to a network

Exactly what have they got, if you never connect it to a network afterward, either? A key-log that never makes it back to them? (I’m presuming here that the laptop is openable, and that you will do so and physically remove any wi-fi M.2 card from it — and associated antennae — since you won’t be using it. There might be some sort of extra surface-mount snooper chip left onboard that could replicate the same function…

You might not understand the depth to which you can be exploited. They will simply let you use your laptop and switch your USB cable, which has a built in 6ft antenna.

https://en.m.wikipedia.org/wiki/File:NSA_COTTONMOUTH-I.jpg

Re: Spy agency ducks questions about 'back doors' in tech products

#50

Earlier quoted context omitted.

or rather they're not getting in _or_ out. they might already be in. as long as both in _and_ out are disconnected, you're set.

A 2g or 3g module is If the NSA has enough of an interest to be intercepting your packages, they're not going to shy away at adding in a transmitter or two of their own preference.

Quite considerably less. This one from Adafruit (hardly the cheapest supplier) is $30 and has GPS built in too: https://www.adafruit.com/product/2637
Post reply on HN