Also, we decided to detect it.
German Chaos Computer Club analyzes and releases government malware
11–20 of 67 posts
Re: German Chaos Computer Club analyzes and releases government malware
#12I think it's also possible that some of those safeguard provisions were left out of the software so that in case the malware was detected, it could have been attributed to standard hacker groups as opposed to German government organizations who play within a specific set of rules and regulations. Obviously, this plan failed and it has been identified as government-sponsored malware.
A standard hacker group would have working safeguards in order to remain in control. Nobody wants his carefully created botnet taken over by someone else.
Re: German Chaos Computer Club analyzes and releases government malware
#13I wonder how they were able to make sure that it's the german government behind this. I've read the whole analysis but nothing really hinted at it. Binaries not signed + no knowledge of how the infection is done + server in the USA which they said they didn't penetrate to look what's behind it. I'm not doubting them, it would just be very interesting.
there was a big public discussion about the government trojaner in germany. they government also has to report how often it is used. so you can be sure thats the work of some government part.
Re: German Chaos Computer Club analyzes and releases government malware
#14I wonder how they were able to make sure that it's the german government behind this. I've read the whole analysis but nothing really hinted at it. Binaries not signed + no knowledge of how the infection is done + server in the USA which they said they didn't penetrate to look what's behind it. I'm not doubting them, it would just be very interesting.
The first paragraph: > Dem Chaos Computer Club (CCC) wurde Schadsoftware zugespielt, deren Besitzer begründeten Anlaß zu der Vermutung hatten, daß es sich möglicherweise um einen „Bundestrojaner“ handeln könnte. Einen dieser Trojaner und dessen Funktionen beschreibt dieses Dokument, die anderen Versionen werden teilweise vergleichend hinzugezogen. Translates to: > The Chaos Computer Club (CCC) received malware, whose…
I'm not saying it unlikely to be the federal trojan but if they had real proof, that would be so much bigger and could really damage the surveillance efforts.
Re: German Chaos Computer Club analyzes and releases government malware
#15Re: German Chaos Computer Club analyzes and releases government malware
#16Earlier quoted context omitted.
A standard hacker group would have working safeguards in order to remain in control. Nobody wants his carefully created botnet taken over by someone else.
Obviously each group would try, but that doesn't guarantee perfect success every time. Afterall, if every botnet were perfect, then they would never be discovered by researchers and taken down by authorities.
Especially the latter can be impossible to do legally if you don't manage to shut down however is controlling it.
In any case this doesn't matter because the government would have to put these safe guards in place. They cannot not implement them simply because someone might suspect the government behind it if it is detected.
Re: German Chaos Computer Club analyzes and releases government malware
#17Earlier quoted context omitted.
A standard hacker group would have working safeguards in order to remain in control. Nobody wants his carefully created botnet taken over by someone else.
Obviously each group would try, but that doesn't guarantee perfect success every time. Afterall, if every botnet were perfect, then they would never be discovered by researchers and taken down by authorities.
They rarely are.
Re: German Chaos Computer Club analyzes and releases government malware
#18And it's things like that that will make even more people vote the Pirate Party. Luckily the German public is by and large opposed to surveillance. (for historical reasons)
http://www.infratest-dimap.de/umfragen-analysen/bundesweit/s...
However I don't really think that the German public is strongly opposed to surveillance, especially since the media tried making a big deal out of the few incidences where some assholes decided to beat up people on the Munich and Berlin subways lately.
Re: German Chaos Computer Club analyzes and releases government malware
#19Our take on this case: http://www.f-secure.com/weblog/archives/00002249.html Also, we decided to detect it.
How generous...
Re: German Chaos Computer Club analyzes and releases government malware
#20The press release and the analysis are unfortunately poorly written and make it appear as if a couple of overeager teenagers wrote this, although their conclusion is accurate given the information given in the analysis. Releasing the binaries alone to back up such a statement might be good enough for the hacker community but if you want to persuade the public you need to be more professional in your choice of words.…