Live data from Hacker News

German Chaos Computer Club analyzes and releases government malware

ccc.de

61–67 of 67 posts

Re: German Chaos Computer Club analyzes and releases government malware

#61
The chancellor's press secretary denies that this malware is the Bundestrojaner, claiming that it has never been used by the BKA, the federal crime investigation department [1].

From the wording of the tweet I assume that instead some LKA (crime investigation departments on the state level) had been using the malware.

[1] http://twitter.com/#!/RegSprecher/status/123056930888491008

Re: German Chaos Computer Club analyzes and releases government malware

#63
post #29
post #14

Earlier quoted context omitted.

Yea. So they got it from people who believe it might be the federal trojan. No proof. I'm not saying it unlikely to be the federal trojan but if they had real proof, that would be so much bigger and could really damage the surveillance efforts.

We have no reason to suspect CCC's findings, but we can't confirm that this trojan was written by the German government. As far as we see, the only party that could confirm that would be the German government itself. [1] I guess they are right. However, the features implemented in this trojan horse (Skype wiretapping, taking screenshots, keylogging, etc.) certainly look like it is to be used for general wiretapping/e…

Hilarious, using forensics tools to recover snooping and forensics tools.

Re: German Chaos Computer Club analyzes and releases government malware

#64
post #21
post #19

Earlier quoted context omitted.

> Also, we decided to detect it. How generous...

Unfortunately as time goes on this might be not as free-will a decision. The right of law enforcement to breach our computers for the 'good of the public' will probably only get worse.

It's already there for many unsuspecting users. You have to root your iPhone to begin to investigate what might be spying, let alone stopping it, and Apple is doing their best to make the phone unrootable. Soon it won't be (practically) possible.

And not just Apple, they're just one of the first with effective lock-in, and market-share.

Soon having programming/debugging tools could be ample evidence of intent to criminally (the only way) access a computing device.

Re: German Chaos Computer Club analyzes and releases government malware

#65
post #15

F-Secure will detect the malware according to their blog post: http://www.f-secure.com/weblog/archives/00002249.html

The wording of their "backdoor policy" is ambiguous: http://www.f-secure.com/virus-info/bdtp.shtml "F-Secure Corporation would like to make known that we will not leave such backdoors to our F-Secure Anti-Virus products, regardless of the source of such tools. We have to draw a line with every sample we get regarding whether to detect it or not. This decision-making is influenced only by technical factors, and nothin…

What about, then, when EU law requires them to leave an explicit backdoor?

Transparency is a top priority, otherwise we're approaching a high-tech East Germany. The group I least trust snooping on the world is the government (ie, above the law).

Re: German Chaos Computer Club analyzes and releases government malware

#66
post #29
post #14

Earlier quoted context omitted.

Yea. So they got it from people who believe it might be the federal trojan. No proof. I'm not saying it unlikely to be the federal trojan but if they had real proof, that would be so much bigger and could really damage the surveillance efforts.

We have no reason to suspect CCC's findings, but we can't confirm that this trojan was written by the German government. As far as we see, the only party that could confirm that would be the German government itself. [1] I guess they are right. However, the features implemented in this trojan horse (Skype wiretapping, taking screenshots, keylogging, etc.) certainly look like it is to be used for general wiretapping/e…

In the meantime, several federal states have admitted to using this software. The software analyzed by the CCC had evidently been used by the Bavarian police.

Re: German Chaos Computer Club analyzes and releases government malware

#67
post #29
post #14

Earlier quoted context omitted.

Yea. So they got it from people who believe it might be the federal trojan. No proof. I'm not saying it unlikely to be the federal trojan but if they had real proof, that would be so much bigger and could really damage the surveillance efforts.

We have no reason to suspect CCC's findings, but we can't confirm that this trojan was written by the German government. As far as we see, the only party that could confirm that would be the German government itself. [1] I guess they are right. However, the features implemented in this trojan horse (Skype wiretapping, taking screenshots, keylogging, etc.) certainly look like it is to be used for general wiretapping/e…

[deleted]
Post reply on HN