Live data from Hacker News

Spies Jumped from One Network to Another via Wi-Fi in an Unprecedented Hack

wired.com

31–40 of 63 posts

Re: Spies Jumped from One Network to Another via Wi-Fi in an Unprecedented Hack

#31
post #23

Earlier quoted context omitted.

If you can't secure computers against state attackers, then you have to stop using computers and to simply talk in places where there are not phones, computers etc. If you're afraid about directional microphones out in the woods there are countermeasures for that too, but security is very possible even against the very most well-funded attackers. Furthermore, I don't think even internet-connected secure computers are…

I read once that when America refurbishes an embassy somewhere in the world they bring in their own construction company. Otherwise you end up with mics in the walls. Used to think the Chinese were paranoid with their bans on iPhones and Tesla's...

iPhones and Teslas would be overkill anyway: https://www.cryptomuseum.com/covert/bugs/thing/

Re: Spies Jumped from One Network to Another via Wi-Fi in an Unprecedented Hack

#32
post #23

Earlier quoted context omitted.

If you can't secure computers against state attackers, then you have to stop using computers and to simply talk in places where there are not phones, computers etc. If you're afraid about directional microphones out in the woods there are countermeasures for that too, but security is very possible even against the very most well-funded attackers. Furthermore, I don't think even internet-connected secure computers are…

I read once that when America refurbishes an embassy somewhere in the world they bring in their own construction company. Otherwise you end up with mics in the walls. Used to think the Chinese were paranoid with their bans on iPhones and Tesla's...

Kind of. They’re required (or agree to?) to use local labor at least in part, but there American companies that manage the construction. My grandfather (a U.S. citizen) does security inspections for embassy construction, verifying that it’s built to plan, that all materials are traceable to point of origin, etc.

Re: Spies Jumped from One Network to Another via Wi-Fi in an Unprecedented Hack

#33
post #26
post #16

Earlier quoted context omitted.

Right, hostapd. It has the radius functionality builtin you'd need for proper wifi enterprise functionality

Getting hostapd to work is ass in itself.

Yes, but much easier than with a full radius server

Re: Spies Jumped from One Network to Another via Wi-Fi in an Unprecedented Hack

#35

Earlier quoted context omitted.

Lots of espionage and surveillance within government and contractors. Lots of body shop contractors are fake people anyway. Pretty easy to imagine placing a compromised person in a low sensitivity area, then moving laterally.

But why you hire consultants to solve core security problems? Furthermore, surely it would just be one guy who knows OS and FPGA stuff and another guy to check it? What I'm arguing for is that a sensible solution to security problems is to avoid complexity, so that things can be obviously secure. Carefully defined interfaces designed to be clear, impossible to misinterpret and which are designed to be parsed and impl…

You don’t.

You hire them for other lower priority roles, but they are inside the firewall. Most large organizations have an immature zero trust environment.

Look at the Microsoft PKI breach. The adversary was able to compromise certificate services in a corporate dev environment and parlay that in accessing US government mailboxes in a supposedly isolated cloud tenant. Microsoft has a world class security practice. The average Fortune 1000 is toast.

Re: Spies Jumped from One Network to Another via Wi-Fi in an Unprecedented Hack

#36
post #33
post #26

Earlier quoted context omitted.

Getting hostapd to work is ass in itself.

Yes, but much easier than with a full radius server

FWIW one can front-end OpenLDAP or AD with Radius. Once the translation layer is in place then it's more about teaching IT how to manage particular fields in LDAP/AD.

Re: Spies Jumped from One Network to Another via Wi-Fi in an Unprecedented Hack

#37

Earlier quoted context omitted.

But why you hire consultants to solve core security problems? Furthermore, surely it would just be one guy who knows OS and FPGA stuff and another guy to check it? What I'm arguing for is that a sensible solution to security problems is to avoid complexity, so that things can be obviously secure. Carefully defined interfaces designed to be clear, impossible to misinterpret and which are designed to be parsed and impl…

You don’t. You hire them for other lower priority roles, but they are inside the firewall. Most large organizations have an immature zero trust environment. Look at the Microsoft PKI breach. The adversary was able to compromise certificate services in a corporate dev environment and parlay that in accessing US government mailboxes in a supposedly isolated cloud tenant. Microsoft has a world class security practice. T…

Microsoft PKI was because they were not doing world class security practice. For some reason, consumer environment could sign corporate environment logins. Also, they acquired some company and instead of issuing them new hardware to ensure it wasn't compromised, they just let them onto their network.

When you read the report, it was very clear that Microsoft wasn't doing "World Class Security Practice", they were taking shortcuts like everyone else does.

Re: Spies Jumped from One Network to Another via Wi-Fi in an Unprecedented Hack

#38
post #20

Earlier quoted context omitted.

You say criminals, but I think you meant intelligence agencies

A distinction without a difference.

In this context, the difference is that intelligence agencies have a bigger budget: the cited hack does not show that an ordinary criminal budget would be sufficient.

Re: Spies Jumped from One Network to Another via Wi-Fi in an Unprecedented Hack

#39
post #2

If your threat model includes nation states, you are outgunned. A nation state can probably buy the building across the street if that's the value of hacking your system. Of course there are almost certainly cheaper options,but that's the level of time and budget you are up against...teams of motivated and well resourced experienced professionals working against you full time.

> A nation state can probably buy the building across the street if that's the value of hacking your system.

So make them spend that money.

Or, more likely, convince them to refocus on a cheaper target.

Re: Spies Jumped from One Network to Another via Wi-Fi in an Unprecedented Hack

#40
post #33

Earlier quoted context omitted.

Yes, but much easier than with a full radius server

FWIW one can front-end OpenLDAP or AD with Radius. Once the translation layer is in place then it's more about teaching IT how to manage particular fields in LDAP/AD.

From repo at start of thread: screenshots for adding router users and managing network segments, https://apps.apple.com/us/app/secure-programmable-router/id6.... Router image runs Linux and hostapd.
Post reply on HN