Live data from Hacker News

Spy agency ducks questions about 'back doors' in tech products

reuters.com

61–70 of 272 posts

Re: Spy agency ducks questions about 'back doors' in tech products

#61
post #15

Earlier quoted context omitted.

It has always been true that any computer connected to the internet could be accessed by an unauthorized party, even before the leaks. Disconnect from the internet and nobody is getting in, including the NSA.

> Disconnect from the internet and nobody is getting in, including the NSA. Oh boy. That's some serious delusion in 2020. Wireless cards and higher end network interface cards are independent computers. Your processor has another processor (Intel ME and others) in it. Baseband Management Controllers are also independent computers on their own right. With closed firmware and wireless capabilities, you can never know w…

> - Your Intel system runs a special version of Minix on its Management Engine. A version of Minix customized for Intel by its original developer

Not on all systems. It's neutralized and disabled on my Librem 15: https://puri.sm/learn/intel-me/.

Re: Spy agency ducks questions about 'back doors' in tech products

#62
post #29

>Three former senior intelligence agency figures told Reuters that the NSA now requires that before a back door is sought, the agency must weigh the potential fallout and arrange for some kind of warning if the back door gets discovered and manipulated by adversaries. Meaning that before, they were free to plant as many back doors as they pleased without any concern for the consequences. And even now, they just need…

"Meaning that before, they were free to plant as many back doors as they pleased without any concern for the consequences." Kinda. There apparently is some approval process and such but I'm not sure everyone at he agency was able to make such requests in the first place... I'm with your gist, I'm just not sure we know how widespread it really was. I'm not inclined to agree that it must have been ultra widespread.

We know that just one of the NSA's related programs, Bullrun, had a budget of $250 million a year from 2011. And by their own admission this gave them access to "vast amounts of encrypted Internet data which have up till now been discarded are now exploitable". Further, their reports mention much more activity that Snowden did not have clearance for.

We don't know the full extent of their activities, but it clearly far surpassed what should be tolerable.

Re: Spy agency ducks questions about 'back doors' in tech products

#64
post #35

Earlier quoted context omitted.

Stuxnet is interesting. Apparently, the US and Israeli agents threw away a number of USB devices around target facilities. What do you do when you find a USB stick? Well, eventually someone working in an air gapped facility picked up one and used it inside. The NSA apparently perfectly aligned 4 zeros days in Siemens and Microsoft products to spread the malware from USB into the Iranian LAN (shared printers, industri…

Its more nuanced than that. Didn't read the book completely but read a long report. What I remember: - They got exact hardware details and topology of the centrifuges somehow. - They've stolen Realtek's driver signing keys. - The virus looks like a simple worm which can infect other USB devices and doesn't unpack beyond a certain point if it can't find the SCADA equipment and the correct device ID & topology (It's li…

> It's possibly the most sophisticated hacking campaign when social and technical aspects combined.

It’s the most sophisticated one _we know of_

Re: Spy agency ducks questions about 'back doors' in tech products

#65
post #15

Earlier quoted context omitted.

It has always been true that any computer connected to the internet could be accessed by an unauthorized party, even before the leaks. Disconnect from the internet and nobody is getting in, including the NSA.

> Disconnect from the internet and nobody is getting in, including the NSA. Oh boy. That's some serious delusion in 2020. Wireless cards and higher end network interface cards are independent computers. Your processor has another processor (Intel ME and others) in it. Baseband Management Controllers are also independent computers on their own right. With closed firmware and wireless capabilities, you can never know w…

Here's a hobby-grade GSM modem dev board you can add to any 'offline' device for $40.

https://www.adafruit.com/product/1946

Re: Spy agency ducks questions about 'back doors' in tech products

#66
post #31

Earlier quoted context omitted.

Hope you have your bluetooth also turned off

And your mic and speaker. And the light sensors while you're at it. All can be used for exfiltration.

And never use USB devices (see: BadUSB).

Re: Spy agency ducks questions about 'back doors' in tech products

#67
post #36
post #12

Earlier quoted context omitted.

In other words: NSA paved the way for foreign hackers and criminals...

It's certainly possible, but I suspect just traditional bugs and poor software is more likely the cause for such events. Software / hardware industry is PLENTY good at paving the way all on its own.

The article presents an example where we basically know that it happened with Juniper Networks.

As you say, the hardware/software industries have enough difficulties with security acting on their own. They don't need the NSA purposely making more holes.

Re: Spy agency ducks questions about 'back doors' in tech products

#68

Earlier quoted context omitted.

They totally still call you paranoid. Snowden unfortunately meant nothing to the general technology consumer mass. They're more than happy to defend tooth and nail their jails. See Discord or Zoom as prime current examples. It is ridiculous that he had to go through this just for people to shake their shoulders and keep on, except for the few that already were inclined to care.

Look, my estimation of "general technology consumer mass" is incredibly low, but I promise you nearly every American adult knows who Edward Snowden is and probably has at least a vague idea of what he was trying to communicate. I agree that many — maybe even most — people don't understand the issue very well, but I think it did have a pretty large impact at the time and since.

They don't know who he is. American adults are uninformed about most issues and will just parrot what they're told to believe in. Mass media paints him as a bad person so that's his public image.

Re: Spy agency ducks questions about 'back doors' in tech products

#69
post #56

Operate under the assumption that government is reading all of your text messages, internet history, payment history, and phone calls. Then when you need privacy, enhance as needed. Even if privacy technologies like VPN or Tor are compromised, the government is less likely to reveal in order to keep the fact they can do it secret. Good luck out there! It's an unfair and scary world, once you try to do anything non-co…

No, you should try to have privacy at all times. Otherwise those who really need it will be in the minority and easily hacked.

Re: Spy agency ducks questions about 'back doors' in tech products

#70
post #15

Earlier quoted context omitted.

It has always been true that any computer connected to the internet could be accessed by an unauthorized party, even before the leaks. Disconnect from the internet and nobody is getting in, including the NSA.

> Disconnect from the internet and nobody is getting in, including the NSA. Oh boy. That's some serious delusion in 2020. Wireless cards and higher end network interface cards are independent computers. Your processor has another processor (Intel ME and others) in it. Baseband Management Controllers are also independent computers on their own right. With closed firmware and wireless capabilities, you can never know w…

Fine, make a Faraday cage around the PC. Are you happy now?
Post reply on HN