Live data from Hacker News

Spy agency ducks questions about 'back doors' in tech products

reuters.com

111–120 of 272 posts

Re: Spy agency ducks questions about 'back doors' in tech products

#111

Earlier quoted context omitted.

They totally still call you paranoid. Snowden unfortunately meant nothing to the general technology consumer mass. They're more than happy to defend tooth and nail their jails. See Discord or Zoom as prime current examples. It is ridiculous that he had to go through this just for people to shake their shoulders and keep on, except for the few that already were inclined to care.

Look, my estimation of "general technology consumer mass" is incredibly low, but I promise you nearly every American adult knows who Edward Snowden is and probably has at least a vague idea of what he was trying to communicate. I agree that many — maybe even most — people don't understand the issue very well, but I think it did have a pretty large impact at the time and since.

>but I promise you nearly every American adult knows

If the next thing you are going to say is not "The current President of the United States", then sadly you are extremely mistaken because that's the only political fact you can confidently say that all Americans know (and even then, it's not 100%).

Source: A political science degree that I don't use, but this sad fact is well known.

Re: Spy agency ducks questions about 'back doors' in tech products

#112
post #82
post #37

Earlier quoted context omitted.

It's an interesting case of cognitive dissonance. Most will admit when pressed a bit that the CIA/NSA/FBI do not have our best interests at heart and are out of control. They have repeatedly lied under oath, lied to congress, lied to the public, run human experiments on unwitting citizens, collect data on all of us, etc with complete impunity. However many people somehow simultaneously hold the belief that these agen…

> Perhaps it's just too exhausting to consider the extent of corruption in the USA. Abolish the (secret) police? It's basically the same debate; people need to feel that the threat from the "protectors" is greater than the threat they are allegedly protecting against before something gets done. And, realistically, being spied on by the CIA is fairly low down the average person's list of problems. Even the citizens wh…

While the threat (expressed as P(harm)*harm) from XYAgency surveillance is low or medium, the unmitigated threat from the things their surveillance practices protect against - namely, terrorism - is also low. The mitigation effect is lower still.

Objectively, even in 2001 terrorism was a negligible risk compared to everyday risks, and subjectively, there hasn't been a major terrorist attack for years. The only reason mass surveillance exists is a rationale by the US state that "more power is good". This may apply to the US army, but not to the spies.

Also, like you say, once the american spies start to (pun intended) "Interfere in american elections", then the problem affects everybody with P=1. Personally I could live with it trump were the only candidate they work against, but if they do it to trump, they likely do it to others. (I see no evidence of interference or other abuse of collected data currently, but I think it's dangerous to give them the power to collect all this info that can in principle be abused for selective prosecution and/or blackmail).

Also, it affects not just politicians, but also corporate execs, who can be further pressured using the other means of the state, and who themselves have power the state can deputize.

A democracy should have the surveillance powers that are proportionate to the benefit from these powers and no more. There is a positive value in minimizing state surveillance power; this concept seems lost on america. (In fairness, it seems lost on conservative parties worldwide.)

Re: Spy agency ducks questions about 'back doors' in tech products

#113

Wyden is great. The big issue with backdoors, is that it's only a matter of time, before they become "front doors." Presented for your approval. Imagine, if you will, a software engineer; probably based in the US, that writes a backdoor into equipment used to manage a banking transaction network. This is a fairly natural place to have it, as "follow the money" is a classic forensic technique. Of course, access to thi…

  is that it's only a matter of time, before they become "front doors."
Look no further than Plaid banking service. They collect your banking login information. I guarantee there are blanket warrants to monitor accounts from multiple agencies.

Re: Spy agency ducks questions about 'back doors' in tech products

#114

Earlier quoted context omitted.

Maybe, but they do for sure listen to your calls. I used their software in a wireless provider. "She" was fascinating. She could understand any language, dialect, voice inflection, and so much more. No training required whatsoever. She listens to all international calls and flags phrases and key words.

They don't listen to your phone calls either. If they did, Snowden would have leaked it, and it would have been a bombshell revelation. If you have information otherwise, you should blow the whistle.

There is no whistle to blow. It is fairly well known that all international calls into or out of each country are monitored by bots using speech recognition by the related agency for each repsective country. This has been the case for a very long time. Before bots, there were listening stations with thousands of people monitoring calls. There would be nothing for Snowden to leak in that regard. The only place this has been taboo is when the NSA is doing it within the country. They too use bots, as there is no way you could hire enough people to listen to the calls. Only flagged calls are listened to by people.

Re: Spy agency ducks questions about 'back doors' in tech products

#116
post #5

"The tactics drew widespread attention starting in 2013, when Snowden leaked documents referencing these practices." So this is what Snowden has done: he "drew widespread attention to these tactics". Before Snowden they would call you "paranoid" if you would allow yourself to mention it. Today they can not call you paranoid anymore. And yes, it has hurt US industry reputation. Many don't trust Intel processors and Ci…

> Many don't trust Intel processors and Cisco routers anymore That's Cisco's own fault given that there are rarely more than 6 months between critical firmware releases that either have some way of hardcoded backdoor account, remote code execution or other similar bugs.

It’s not Cisco’s fault if the NSA has compelled them to add those “bugs”

Re: Spy agency ducks questions about 'back doors' in tech products

#117
post #35

Earlier quoted context omitted.

Stuxnet is interesting. Apparently, the US and Israeli agents threw away a number of USB devices around target facilities. What do you do when you find a USB stick? Well, eventually someone working in an air gapped facility picked up one and used it inside. The NSA apparently perfectly aligned 4 zeros days in Siemens and Microsoft products to spread the malware from USB into the Iranian LAN (shared printers, industri…

Its more nuanced than that. Didn't read the book completely but read a long report. What I remember: - They got exact hardware details and topology of the centrifuges somehow. - They've stolen Realtek's driver signing keys. - The virus looks like a simple worm which can infect other USB devices and doesn't unpack beyond a certain point if it can't find the SCADA equipment and the correct device ID & topology (It's li…

Book?

Re: Spy agency ducks questions about 'back doors' in tech products

#118
post #89

Earlier quoted context omitted.

The best example of the Snowden fallout and the apathy around it was when John Oliver interviewed both Snowden and many people on the street. People on the street did not comprehend what NSA monitoring meant and did not care until John put it in terms they could understand. "So you are ok with the NSA seeing pictures and videos of your significant others junk you text (sext) back and forth?" "Oh, I would be furious i…

But that is not what the NSA monitoring meant. They do not get to see pictures of your SO's junk. They do know who you called and when but not tied to your name.

> They do know who you called and when but not tied to your name.

For a state-level actor (or the mobile provider itself or those other corporations to which it sells data for advertising purposes) to identify by name the human being who is the source of phone calls, is trivial in most countries today.

Re: Spy agency ducks questions about 'back doors' in tech products

#119

Earlier quoted context omitted.

I think it's clear that they are out of control, from the examples you list among others. The harder argument is that they're not doing it in our best interest. Without good visibility into their activities (which could very well inhibit those activities), it's hard to tell which of their activities are a net benefit to our country. My guess is that most Americans would expect that they sometimes do things that aren'…

> That second part is the primary reason why they aren't being wholesale shut down Two thoughts: 1) Even if most Americans decided they needed to be shut down, how would we enact that? It seems to me there are very few people who have that power, and even if a great majority of us wanted it, we have no way to enact it (and no way of knowing if it was actually enacted; we could be told it had been done, but that could…

> If they were actually shut down, what would the people who worked there do?

Prison time, like any other criminal enterprise.

Re: Spy agency ducks questions about 'back doors' in tech products

#120
post #35

Earlier quoted context omitted.

> Disconnect from the internet and nobody is getting in, including the NSA. Oh boy. That's some serious delusion in 2020. Wireless cards and higher end network interface cards are independent computers. Your processor has another processor (Intel ME and others) in it. Baseband Management Controllers are also independent computers on their own right. With closed firmware and wireless capabilities, you can never know w…

Stuxnet is interesting. Apparently, the US and Israeli agents threw away a number of USB devices around target facilities. What do you do when you find a USB stick? Well, eventually someone working in an air gapped facility picked up one and used it inside. The NSA apparently perfectly aligned 4 zeros days in Siemens and Microsoft products to spread the malware from USB into the Iranian LAN (shared printers, industri…

I agree. I'm sure the level of this organization operates at utilizes teams of their own vulnerability researchers to provide themselves with the ability to create new and novel zero-day exploits that are not-disclosed to the big players. This is Internet warfare.
Post reply on HN