Earlier quoted context omitted.
but literally the most important when you need to attack air gapped machine
No, it's not the most important. The most important was clearly obtaining the PLC zero days to infect the physical machines. It's unclear to me why you choose to be so explicitly obtuse but in any case, for your own personal edification, feel free to read some details on how it went down - [0] https://www.wikiwand.com/en/Stuxnet [1] https://www.wired.com/2014/11/countdown-to-zero-day-stuxnet/ [1] https://www.hsdl.org…
Ghidra: A software reverse engineering suite of tools developed by the NSA
131–140 of 147 posts
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#132Earlier quoted context omitted.
Yeah this is bullshit. There is no demonstrated NSA proof setup. If they haven’t broken in to something, they aren’t telling us about it.
Assuming that time travel is impossible, NSA can't break into something that does not exist anymore. Hence the idea when facing such adversary is to provide them a constantly moving target. Although NSA might be able to break any full disc encryption given enough time, they aren't able to decrypt something that no longer exists. This principle isn't scalable to every computer system out there and will definitely go a…
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#133Earlier quoted context omitted.
Assuming that time travel is impossible, NSA can't break into something that does not exist anymore. Hence the idea when facing such adversary is to provide them a constantly moving target. Although NSA might be able to break any full disc encryption given enough time, they aren't able to decrypt something that no longer exists. This principle isn't scalable to every computer system out there and will definitely go a…
This ignores the obvious. What parts are not changing with a distro hop? Are those parts vulnerable to the NSA? I believe due to what was made public, that they do have that capability. I would suggest more research. If you are actually changing distros every month, that seems like a very manual process, with many points to use an insecure config. I think your time could be better spent hardening a current system. An…
The threat modeling that you see in this thread is laughable. Nobody has infinite resources, not even NSA. They can't throw all their capability at you alone. In fact they are not even interested in any one individual. They might be interested in some groups of people like "terrorist leadership" but even in that case they don't have the need to hack all people matching that group. So at every step of the decision making process there is a cost benefit analysis. And in the end NSA will only hack some terrorist leaders, the ones deemed sufficiently significant but not any more risky then is necessary.
The amount of meetings and paperwork required for carrying out offensive action is significant and everyone involved is very risk averse. Getting superiors to sign up for an operation against an individual capable of detecting attack and thus risking attribution would only be possible if the proposed techniques can be shown to be extraordinarily stealthy. That requires replicating the system in the lab and rigorously testing methodology beforehand.
Yeah, it is hard to protect organizations from nation states. Because all sufficiently complex systems have bugs and given long enough time persistent attackers will find & exploit these bugs. But that's because organizations have other real-world priorities besides fighting NSA. These organizations can't change protocols overnight and replace core systems just for fun of it.
Individuals actually have an advantage here because they can rotate systems at will and have much higher control over their personal lives than any CEO/CTO/CISO has over their organization. As a result, yes you can raise the cost of an attack against you high enough that NSA won't bother hacking you - either because there are other people who are less protected but hacking them would fulfill the same objective or because your ass gets handed to another agency which is able to present more cost-effective solution.
Your link demonstrates this dichotomy between options that NSA has available for hacking organizations vs individuals. Individuals rarely have well documented procurement processes available for third party auditing you know.
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#134Earlier quoted context omitted.
Assuming that time travel is impossible, NSA can't break into something that does not exist anymore. Hence the idea when facing such adversary is to provide them a constantly moving target. Although NSA might be able to break any full disc encryption given enough time, they aren't able to decrypt something that no longer exists. This principle isn't scalable to every computer system out there and will definitely go a…
You sir have no clue what you talking about, a payload geter in your ssd-firmware survives your distro-hop and can adapt to every OS (if your information is worth the work). And an encrypted disk...on man i stop arguing, it's obvious that you really don't have a clue.
I'm not advocating for installing a fresh OS on an exploited hardware and calling it a day, no matter how hard you try to present my words this way.
The point is to keep any single environment around only for a short period of time so that adversaries don't have enough time for replicating your systems and crafting a targeted exploit chain.
It is not meant to be the only line of defense. You would still harden every system you own, putting particular focus on tamper & intrusion detection (including retrospective analysis).
Couple that with strong compartmentalization (e.g. using different hardware for different purposes, Qubes OS style virtualization approaches) and defense in depth (exploit mitigations, traffic anonymization).
Here, I have spelled it out for you. Feel free to outline how you would approach attacking such individual adversary, even with NSA level team at your disposal. Silent assumptions being that 1) if person's physical location is known, CIA is a cheaper option than NSA and 2) failed offensive operation leaving attributable evidence is considered by NSA worse than missed opportunity.
Please, stop low effort ad hominem attacks.
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#135Earlier quoted context omitted.
You have be wearing multiple tinfoil hats if you think NSA released DeepBlue as some sort of black flag OP
>NSA released DeepBlue as some sort of black flag OP EternalBlue...and it was a part of the shadow broker package, but that was just one occasion, Snowden is one of the other. One must probably wear a Tar-hat to think that this is impossible.
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#136Earlier quoted context omitted.
You sir have no clue what you talking about, a payload geter in your ssd-firmware survives your distro-hop and can adapt to every OS (if your information is worth the work). And an encrypted disk...on man i stop arguing, it's obvious that you really don't have a clue.
You just keep talking straight past my points without even trying to understand them. Why bother writing answers at all? I'm not advocating for installing a fresh OS on an exploited hardware and calling it a day, no matter how hard you try to present my words this way. The point is to keep any single environment around only for a short period of time so that adversaries don't have enough time for replicating your sys…
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#137Earlier quoted context omitted.
You sir have no clue what you talking about, a payload geter in your ssd-firmware survives your distro-hop and can adapt to every OS (if your information is worth the work). And an encrypted disk...on man i stop arguing, it's obvious that you really don't have a clue.
You just keep talking straight past my points without even trying to understand them. Why bother writing answers at all? I'm not advocating for installing a fresh OS on an exploited hardware and calling it a day, no matter how hard you try to present my words this way. The point is to keep any single environment around only for a short period of time so that adversaries don't have enough time for replicating your sys…
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#138Earlier quoted context omitted.
This ignores the obvious. What parts are not changing with a distro hop? Are those parts vulnerable to the NSA? I believe due to what was made public, that they do have that capability. I would suggest more research. If you are actually changing distros every month, that seems like a very manual process, with many points to use an insecure config. I think your time could be better spent hardening a current system. An…
You pose the questions but do not answer them. Assuming distros are selected purposefully you do get quite a lot of variability. Recompiling the kernel with different hardening options alone makes many exploits impractical. The threat modeling that you see in this thread is laughable. Nobody has infinite resources, not even NSA. They can't throw all their capability at you alone. In fact they are not even interested…
I literally answer directly after the questions. Read for comprehension.
I can tell you with 100% certainty that your assumptions are 100% wrong. Interpret that statement as you may and update your threat model accordingly.
Re: Ghidra: A software reverse engineering suite of tools developed by the NSA
#139It is open source software and it can reverse engineer programs from a lot of different systems. Some people may be worried about installing a piece of software on their computer that comes from the NSA. I don't think that there are real reasons to worry. One of the tasks of the NSA is defending against cyber attacks. Having more people with good tools helps the defense. Also, you can be pretty certain that some secu…
I don't think there is anything fishy here, although I don't think the NSA can just install anything on my computer, even if I were based in the US. There is a lot of bluffing when it comes to cyber security. Still it might be quite a useful tool.