Live data from Hacker News

Gmail security warnings for suspected state-sponsored attacks

googleonlinesecurity.blogspot.com

101–110 of 123 posts

Re: Gmail security warnings for suspected state-sponsored attacks

#101
post #30

Earlier quoted context omitted.

Google is a huge multinational, operating on the internet, which is (at least historically) devoid of specific jurisdictions. They could, at the expense of profits, sidestep this issue - but they don't. Unfortunately the US is trying to deny that, with less and less success, but that's where we're at today. I just think it's shitty of them to make such a noise about non-US state-sponsored surveillance, but remain rel…

How could Google sidestep compliance with US laws? They are incorporated in the US, are they not?

I imagine in ways analogous to how they avoid paying US taxes, even though they are incorporated in the US.

Re: Gmail security warnings for suspected state-sponsored attacks

#102

Earlier quoted context omitted.

> USA reading your mail: Business as usual. According to the first paragraph of the article you linked: "NSLs can only request non-content information, such as transactional records, phone numbers dialed or email addresses mailed to and from." According to the sample NSL from the article you linked: "We are not directing that you provide, and you should not provide, information pursuant to this letter that would disc…

I'm a privacy researcher, specifically focusing on government access to data held by Internet companies. Google, your employer, will not confirm, on the record, what they will or will not disclose when they get an NSL. The NSL statute does not authorize the disclosure of transactional records. 18 USC 2709(b)(1) states that the government can only get "the name, address, length of service, and local and long distance…

I'm not a privacy researcher, but my guess is this is probably less "they won't answer because all your worst fears are true" and more "they won't answer because they don't want to narrow their future options and political maneuvers".

Re: Gmail security warnings for suspected state-sponsored attacks

#103
post #63

Earlier quoted context omitted.

> Dissent in China will get you a prison sentence or worse. Dissent in America will get your karma modded down. I think Julian Assange, Bradley Manning, and Dmitry Sklyarov may disagree with you.

Sklyarov - charges dropped. Manning - U.S. soldier deliberately mishandled diplomatic cables. Assange - I'm aware of no official charges or actions by the U.S.

What about the unofficial actions?

Re: Gmail security warnings for suspected state-sponsored attacks

#104
post #89

Earlier quoted context omitted.

From a wired article: http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/al... "Before yottabytes of data from the deep web and elsewhere can begin piling up inside the servers of the NSA’s new center, they must be collected. To better accomplish that, the agency has undergone the largest building boom in its history, including installing secret electronic monitoring rooms in major US telecom facilities. Contr…

NSA ability to sniff traffic at major telecom exchanges is real. NSA ability to break $cipher or $hash based on the hearsay journalism involving an interview of (ex-)NSA employees (who would certainly be barred from talking about any real non-public attacks) is not real [1]. It's possible the NSA is setting up real systems that will brute force or factor or find collisions for known borderline algorithms/keysizes. Ma…

I heard a story somewhere that public key cryptography was known to the NSA long before the 70s. Maybe they are 30 years ahead in cryptographic number theory? Maybe prime factorization isn't actually hard? Maybe...

Re: Gmail security warnings for suspected state-sponsored attacks

#105
People that have received this warning so far:

* @gesa, Obama campaign web developer says an infosec staff member got one: https://twitter.com/gesa/status/210184075149979649

* @dandrezner, international relations professor: https://twitter.com/dandrezner/status/210103984881549312

* @TomLasseter, Bejing Bureau Chief for McClatchy Newspapers: https://twitter.com/tomlasseter/status/210210259019640835

* @JeffreyCarr, CEO of Taia Global and author of Inside Cyber Warfare: https://twitter.com/jeffreycarr/status/210227611912257537

* @snowfl0w, malware analyst for Contagio Dump: https://twitter.com/snowfl0w/status/210207958376779776

* @w7voa, Voice of America Bureau Chief covering Korea and Japan: https://twitter.com/w7voa/status/210194791479250946

* @marcambinder, national security reporter for The Atlantic and GQ: https://twitter.com/marcambinder/status/210184141180911617

* @DDysart, web developer?: https://twitter.com/DDysart/status/210183540535590912

This is not looking good... some people on this list have gone and installed Google 2FA after realizing their computer might be compromised. Enabling two-factor auth WILL NOT resolve this issue if your computer has been compromised. If you get this warning, you need to bring your computer to someone with real security expertise and have it checked out. Strongly consider cleanly reinstalling your OS, then enable two-factor authentication.

EDIT: Here's the message that Google is giving to people that have been affected: http://support.google.com/mail/bin/answer.py?hl=en&ctx=m...

It looks like they're detecting exploit code sitting in people's accounts, mostly in the form of PDF and Office docs and inside RARs. This might explain why snowfl0w is on the list, since he handles a lot of this stuff daily and some of it likely goes through his e-mail (on purpose). It's unclear if this means that your account was successfully compromised. It's more likely that it means someone is attempting to get into your account.

Re: Gmail security warnings for suspected state-sponsored attacks

#106
I personally don't care if it's an individual attack or a state sponsored attack. An individual can be sponsored by a state after the fact. With the price of 0day vulns as high as it is, it's quite likely that "states" are playing the field as much as "traditional" attackers. Drawing a line between the 2 is treating a grey area as black and white.

Re: Gmail security warnings for suspected state-sponsored attacks

#107
post #63

Earlier quoted context omitted.

> Dissent in China will get you a prison sentence or worse. Dissent in America will get your karma modded down. I think Julian Assange, Bradley Manning, and Dmitry Sklyarov may disagree with you.

Sklyarov - charges dropped. Manning - U.S. soldier deliberately mishandled diplomatic cables. Assange - I'm aware of no official charges or actions by the U.S.

http://www.youtube.com/watch_popup?v=7n2m-X7OIuY#t=2m00s

Try and keep your head out of the main stream media's asshole.

Re: Gmail security warnings for suspected state-sponsored attacks

#108
post #21

Too bad they are legally prohibited from doing this when the state-sponsored attack is a PATRIOT NSL from the US government. http://en.wikipedia.org/wiki/National_security_letter China reading your mail: Big red flag. USA reading your mail: Business as usual.

> USA reading your mail: Business as usual. According to the first paragraph of the article you linked: "NSLs can only request non-content information, such as transactional records, phone numbers dialed or email addresses mailed to and from." According to the sample NSL from the article you linked: "We are not directing that you provide, and you should not provide, information pursuant to this letter that would disc…

http://www.wired.com/threatlevel/2007/06/librarians-desc/

Does reading your library records count... How do you know the same hasn't been done with your email? You don't. Because it's secret. Is this an open society? A free society?

Re: Gmail security warnings for suspected state-sponsored attacks

#109

Earlier quoted context omitted.

NSA ability to sniff traffic at major telecom exchanges is real. NSA ability to break $cipher or $hash based on the hearsay journalism involving an interview of (ex-)NSA employees (who would certainly be barred from talking about any real non-public attacks) is not real [1]. It's possible the NSA is setting up real systems that will brute force or factor or find collisions for known borderline algorithms/keysizes. Ma…

I heard a story somewhere that public key cryptography was known to the NSA long before the 70s. Maybe they are 30 years ahead in cryptographic number theory? Maybe prime factorization isn't actually hard? Maybe...

What was essentially RSA was known to Britain's GCHQ (Government Communications Headquarters) in 1973. Is this what you were thinking of? Rivest, Shamir and Adleman rediscovered it in 1977.
Post reply on HN