Live data from Hacker News

Speaking out against government malware

ccc.de

1–10 of 11 posts

Re: Speaking out against government malware

#6
post #2

Forget Disclosure — Hackers Should Keep Security Holes to Themselves BY ANDREW AUERNHEIMER (weev) http://www.wired.com/opinion/2012/11/hacking-choice-and-disc...

What does that have to do with anything? Spam much?

An editorial from a few days ago that implores security researchers to not contribute zero days to governments that use them to invade our privacy has nothing to do with "Speaking out against government malware"?

Maybe the part of the puzzle that you're missing is that 90% of the zero day market is nation states buying.

Re: Speaking out against government malware

#7

It's nothing new for the CCC. Germany already has the Bundestrojaner ("Federal Trojan")

the CCC published an in-depth analysis of the so called bundestrojaner in which they for example proofed that many of the techniques jused are unconstitutional (for example intercepting skype calls).

I dont know if there is an english version of the paper (short english summary and link to the german paper here: http://ccc.de/en/updates/2011/staatstrojaner) but it was a very amusing read. Especially because it becomes clear very fast that from a technical standpoint, the software is horrible. Unencrypted communication with the remote, no auth or integrity checks and so on. Also, a lot of data is sent over a proxy in the US.

The results were published in various newspapers, among them the Frankfurter Allgemeine Zeitung (FAZ, a very big and well known newspaper) who printed one page of the trojans source code. The headline was something like: "You cant understand this language but this is what controls your everyday life".

Im very glad that we have an institution like the CCC here in germany. Its the closest you can get to a computer/tech/hacker lobby which argues from a very pragmatical point of view for example when it comes to things like voting machines.

edit: if you want to see the pages from the FAZ with the code, you can find it here (warning - big pdf): http://www.faz.net/dynamic/download/fas/FAS_09_10_2011_S41_S...

It's titled Anatomy of a digital vermin. The code is introduced with: "A text we dont understand but it nevertheless rules our lifes"

Re: Speaking out against government malware

#8
post #6

Earlier quoted context omitted.

What does that have to do with anything? Spam much?

An editorial from a few days ago that implores security researchers to not contribute zero days to governments that use them to invade our privacy has nothing to do with "Speaking out against government malware"? Maybe the part of the puzzle that you're missing is that 90% of the zero day market is nation states buying.

Nope it doesn't, since that speaking out would still be just as necessary, all of that nonwithstanding. If the police you pay for does stuff you don't want, the solution isn't to ask someone ELSE to not provide them with materials. This is not about hackers, this is about citizens, and not everything that has the word "malware" in it is automatically relevant. It's not complicated. No need to project your brainfart-ness onto me, either.

Re: Speaking out against government malware

#9
post #2

Forget Disclosure — Hackers Should Keep Security Holes to Themselves BY ANDREW AUERNHEIMER (weev) http://www.wired.com/opinion/2012/11/hacking-choice-and-disc...

What does that have to do with anything? Spam much?

Spamming moderation doesn't constitute an argument either, clowns.

Re: Speaking out against government malware

#10
post #2

Forget Disclosure — Hackers Should Keep Security Holes to Themselves BY ANDREW AUERNHEIMER (weev) http://www.wired.com/opinion/2012/11/hacking-choice-and-disc...

It is actually even more general than that, see www.schneier.com/blog/archives/2012/11/hacking_by_the.html
Post reply on HN