Live data from Hacker News

The NSA Furby Documents

404media.co

21–30 of 129 posts

Re: The NSA Furby Documents

#21

Context: Furbys were the toy for a year or two, and were actively marketed as learning from speech, had an active mic, and did adjust their speech based on what they heard, "learning" to speak English from Furbish. [^1] It's not so different from the fundamental fear of Alexa/Assistant/microphones that's fairly well diffused now. Except the Furby actively claimed to learn how to speak based on your speech, and had a…

Of course some people really wanted to teach it to say new things, and figured out how to swap out the audio files (among other modifications): https://github.com/Jeija/bluefluff

Fun fact: If you mess up and need to reset the furby, the procedure is to turn it upside down and hold down the tongue while pulling the tail for ten seconds.

Re: The NSA Furby Documents

#23
post #15

Earlier quoted context omitted.

In any SCIF or SCIF-like office space, they're all prohibited. You leave your cell phone at the front door of the secured area. Internet access is via SIPRNet (for classified) or NIPRNet (non-classified, but secured). Phones are through dedicated secure switchboards. The above is common in the DC area (lots of DoD contractors).

My company infosec training actually advises you don't have voice assistants or cellphones in your work area. They even make light of it in the video: "I know it sounds crazy, but it's not". Google and Amazon as the biggest voice assistant makers are, of course, our competitors. But they are competitors to I would say most software companies in some fashion.

Knowing what exploits are like in the private/state sector that seems like a no-brainer if your threat model includes a well-funded attacker.

Re: The NSA Furby Documents

#24
post #17

Earlier quoted context omitted.

One of these fears is rational and based on things people know are in fact taking place. The other one is isn't, so drawing the parallel seems iffy. Maybe it's a little closer to the fear your phone is listening to you and that's how you get eerily targeted ads when browsing the web.

What makes the two fears fundamentally different?

One is the fear of the possible consequences of something you know - with a voice assistant, you know you are being recorded and the recordings are sent somewhere. 'Is furby spying on me' is a vague suspicion but it's not (for most people with the fear) based on any known facts about the furby.

Re: The NSA Furby Documents

#26
post #5

Whats gov policy around Alexas and like half the IOT market? My botvac even has a microphone. I'm sure it's "don't ever speak about outside of this room" sort of thing. I guess phone calls would be over a secure line. Are there secure cell phone towers/whatever? I'm curious how gov phones are hardened.

It's actually more restrictive than the sibling makes it sound. A SCIF can't have any radio-transmitting device, recording device, or storage media without special approval. Computers hooked up to classified networks can't have USB ports. Even medical devices are case by case. My wife requires hearing aids and needed them to be analyzed and approved by a security team before she could bring them in. Pacemakers require approval.

The phones and networks are hardened by being their own separate network from public networks. The lines are all buried and protected and utilize hardware-encrypted point to point tunnels to merge with public backbone fiber. I've told an anecdote here many times of working at a facility where AT&T contractors dug too close to a JWICS fiber cable and had an unmarked black SUV show up in minutes to confiscate all of their gear and question them.

Keep in mind the military has been encrypting radio traffic over hostile territory for a century, so they don't even necessarily require the lines themselves to be physically secure as long as the endpoint devices are. Encryption keys are loaded from hardware random number generators that are synced manually on some rotating basis determined by local command or national policy, depending on the intended reach of the comms device. The NSA has something called a key management infrastructure for the wide-area computer net that replaced the legacy system a few years ago that is similar to PKI, but keys are only issued in-person and stored on unnetworked hardware key loaders that are kept in locked arms rooms on military installations (or with deployed units). There is, of course, also a DoD and IC PKI so they can still use develop and use regular web applications and browsers, but it is also more restrictive than regular PKI. Everything requires client certs and mutual TLS and you need to be personally sponsored to get your personal certificates.

It's actually really cool the way the JWICS websites work because your client cert provides an identity that is linked to your sponsoring agency's clearance database and web apps automatically redact content on the server side that you are not cleared to see. It's possible I'm making up memories but I think I've seen at least a few cases where some applications can do this inside of a single page, but typically you get a denial for an entire application if you're not cleared for the highest level data it provides.

I almost hate to say it because it's antithetical to the Internet and Hacker News ethos, but it's a testament to how well networked applications could work with a central authority and no anonymity. You don't need passwords. Accounts are provisioned automatically. SSO is global to the entire network. You only need one identity. But no, your office can't have Alexa.

Re: The NSA Furby Documents

#27

The FOIA documents are up on archive.org now: https://archive.org/details/nsa-furby-memo/ I'm amused at page 8 of the listserve doc, in which someone points out that the ongoing discussion may at some point be released to the public under FOIA and to consider how it might look after showing up on the front page of a news site

It's interesting to see how quickly the norms around cybersecurity changed. In 1999 the NSA was worried about avoiding ridicule for banning simple electronics in secure areas. In 2010 Stuxnet was introduced via simple electronics into a secure area and set back the Iranian nuclear program by several years.

Some of the people receiving these furby emails were probably already conceiving of (or actively working on) Stuxnet-like capabilities. Maybe a future FOIA request will reveal several teams quietly emailing up the org chart to absolutely not relax the rule for furbies.

Re: The NSA Furby Documents

#28
post #15

Earlier quoted context omitted.

In any SCIF or SCIF-like office space, they're all prohibited. You leave your cell phone at the front door of the secured area. Internet access is via SIPRNet (for classified) or NIPRNet (non-classified, but secured). Phones are through dedicated secure switchboards. The above is common in the DC area (lots of DoD contractors).

My company infosec training actually advises you don't have voice assistants or cellphones in your work area. They even make light of it in the video: "I know it sounds crazy, but it's not". Google and Amazon as the biggest voice assistant makers are, of course, our competitors. But they are competitors to I would say most software companies in some fashion.

We have been told that so many times at work, but I know most snr people seem to leave them and their smart watches in listen mode as they occasionally go off in video calls.

Re: The NSA Furby Documents

#29

The FOIA documents are up on archive.org now: https://archive.org/details/nsa-furby-memo/ I'm amused at page 8 of the listserve doc, in which someone points out that the ongoing discussion may at some point be released to the public under FOIA and to consider how it might look after showing up on the front page of a news site

They wanted to avoid FURBYGATE. They avoided FURBYGATE. Sounds reasonable to me!
Post reply on HN