Live data from Hacker News

German Chaos Computer Club analyzes and releases government malware

ccc.de

11–20 of 67 posts

Re: German Chaos Computer Club analyzes and releases government malware

#12
post #10
post #8

I think it's also possible that some of those safeguard provisions were left out of the software so that in case the malware was detected, it could have been attributed to standard hacker groups as opposed to German government organizations who play within a specific set of rules and regulations. Obviously, this plan failed and it has been identified as government-sponsored malware.

A standard hacker group would have working safeguards in order to remain in control. Nobody wants his carefully created botnet taken over by someone else.

Obviously each group would try, but that doesn't guarantee perfect success every time. Afterall, if every botnet were perfect, then they would never be discovered by researchers and taken down by authorities.

Re: German Chaos Computer Club analyzes and releases government malware

#13
post #5

I wonder how they were able to make sure that it's the german government behind this. I've read the whole analysis but nothing really hinted at it. Binaries not signed + no knowledge of how the infection is done + server in the USA which they said they didn't penetrate to look what's behind it. I'm not doubting them, it would just be very interesting.

there was a big public discussion about the government trojaner in germany. they government also has to report how often it is used. so you can be sure thats the work of some government part.

I can't follow your logic. I know about the discussion and the statistic reports but how does that proof that this every-day-trojan actually is controlled by the government?

Re: German Chaos Computer Club analyzes and releases government malware

#14
post #7
post #5

I wonder how they were able to make sure that it's the german government behind this. I've read the whole analysis but nothing really hinted at it. Binaries not signed + no knowledge of how the infection is done + server in the USA which they said they didn't penetrate to look what's behind it. I'm not doubting them, it would just be very interesting.

The first paragraph: > Dem Chaos Computer Club (CCC) wurde Schadsoftware zugespielt, deren Besitzer begründeten Anlaß zu der Vermutung hatten, daß es sich möglicherweise um einen „Bundestrojaner“ handeln könnte. Einen dieser Trojaner und dessen Funktionen beschreibt dieses Dokument, die anderen Versionen werden teilweise vergleichend hinzugezogen. Translates to: > The Chaos Computer Club (CCC) received malware, whose…

Yea. So they got it from people who believe it might be the federal trojan. No proof.

I'm not saying it unlikely to be the federal trojan but if they had real proof, that would be so much bigger and could really damage the surveillance efforts.

Re: German Chaos Computer Club analyzes and releases government malware

#16
post #12
post #10

Earlier quoted context omitted.

A standard hacker group would have working safeguards in order to remain in control. Nobody wants his carefully created botnet taken over by someone else.

Obviously each group would try, but that doesn't guarantee perfect success every time. Afterall, if every botnet were perfect, then they would never be discovered by researchers and taken down by authorities.

There is a significant difference between identification of a botnet and listening into communication, controlling it or even taking it down.

Especially the latter can be impossible to do legally if you don't manage to shut down however is controlling it.

In any case this doesn't matter because the government would have to put these safe guards in place. They cannot not implement them simply because someone might suspect the government behind it if it is detected.

Re: German Chaos Computer Club analyzes and releases government malware

#17
post #12
post #10

Earlier quoted context omitted.

A standard hacker group would have working safeguards in order to remain in control. Nobody wants his carefully created botnet taken over by someone else.

Obviously each group would try, but that doesn't guarantee perfect success every time. Afterall, if every botnet were perfect, then they would never be discovered by researchers and taken down by authorities.

Afterall, if every botnet were perfect, then they would never be discovered by researchers and taken down by authorities.

They rarely are.

Re: German Chaos Computer Club analyzes and releases government malware

#18
post #2

And it's things like that that will make even more people vote the Pirate Party. Luckily the German public is by and large opposed to surveillance. (for historical reasons)

The latest surveys show the Pirate Party at about 8% while the FDP (the smaller one of the governing parties which got 14.6% in the state elections in 2011) is at 3%

http://www.infratest-dimap.de/umfragen-analysen/bundesweit/s...

However I don't really think that the German public is strongly opposed to surveillance, especially since the media tried making a big deal out of the few incidences where some assholes decided to beat up people on the Munich and Berlin subways lately.

Re: German Chaos Computer Club analyzes and releases government malware

#20
post #9

The press release and the analysis are unfortunately poorly written and make it appear as if a couple of overeager teenagers wrote this, although their conclusion is accurate given the information given in the analysis. Releasing the binaries alone to back up such a statement might be good enough for the hacker community but if you want to persuade the public you need to be more professional in your choice of words.…

Here are the binaries: http://www.ccc.de/system/uploads/77/original/0zapftis-releas...
Post reply on HN