Live data from Hacker News

New NSA Leak Shows MITM Attacks Against Major Internet Services

schneier.com

31–40 of 149 posts

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#31
I'd say this is likely bullshit at least that it was done against a Brazilian company. Why take the risk of getting caught and burning your ability to do this when you can get the information from Google?

1) Chrome(and some plugins) pin's certificates and would notice a man in the middle attack(unless it was done with google's key). Sure, most corporate targets probably use IE, but if anyone uses chrome on or one of these plugins on the network, you've both alerted your target and exposed a presumably tightly guarded ability. Hell, if it get's reported, you've probably burned the ability. Of course, you might be able to filter out both the plugins and chrome, but it's a risk.

2) NSA could legitimately just ask for the company's emails from Google. Petrobras is a Brazilian company in Brazil staffed by Brazilians and as such a legally allowed target for Foreign Surveillance without either the NSA's twisted definitions of search and who is a US national. Google is legally required to hand over the information by the Foreign Intelligence Surveillance Amendment Act of 2008. Why authorize an operation that could reveal both the CA's you have in your pocket and you network penetration exploits?

As a side note, the cited slide looks nothing like anything else we have seen and lack security/ handling information (e.g the prominent TS/SCI/ORCON/NOFORN on the top of the prism slides).

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#33

I'd say this is likely bullshit at least that it was done against a Brazilian company. Why take the risk of getting caught and burning your ability to do this when you can get the information from Google? 1) Chrome(and some plugins) pin's certificates and would notice a man in the middle attack(unless it was done with google's key). Sure, most corporate targets probably use IE, but if anyone uses chrome on or one of…

There is no implied relation in the presentation between MITM attacks and the attack on Petrobras

They're merely on the same presentation describing attacks and targets

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#35

If this is true, and that NSA has been MITMing providers like Google, they are undermining the already shabby trust the US cloud-industry has attempted to build. I doubt Google and friends are very happy about that, since that's their one big basket where all the money comes in. NSA in their eagerness to do rampant spying on everyone have had quite some collateral. They have decided to compromise the one thing which…

> Right now we need to find out which (root?) CAs are compromised by the NSA.

Given that basically all CAs people actually use (even in Europe) are owned by US companies, I would estimate something close to 100% of them have cooperated with the NSA at some point. Obviously there are non-US CAs like China's CNNIC but most of them won't actually sell you a certificate.

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#37
post #36

Weird. This has been submitted in less than two hours, has 90 points, but it is at the bottom of the front page. Other stories from 6+ hours ago with less points are at the top.

This has been the case for nearly all NSA related stories in the past week. There is a lot of flagging going on. I'd be interested in a data dump of who is doing the flagging and getting an idea if it's an indicator that the HN community as a whole doesn't want these stories or if it's just a small, but vigilant subset.

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#38

Some firefox add-ons to help defend against mitm: Certificate Patrol (notifies you when certs change) https://addons.mozilla.org/en-us/firefox/addon/certificate-p... Force-TLS (force websites to always use HTTPS) https://addons.mozilla.org/en-us/firefox/addon/force-tls/ Perspectives (compare certs with peers to verify authenticity) https://addons.mozilla.org/en-us/firefox/addon/perspectives/

Also Monkeysphere and HTTPS Everywhere (which Force-TLS sounds similar to):

http://web.monkeysphere.info/download/ https://www.eff.org/https-everywhere

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#39

I'd say this is likely bullshit at least that it was done against a Brazilian company. Why take the risk of getting caught and burning your ability to do this when you can get the information from Google? 1) Chrome(and some plugins) pin's certificates and would notice a man in the middle attack(unless it was done with google's key). Sure, most corporate targets probably use IE, but if anyone uses chrome on or one of…

I believe Chrome only "pins" certain certificates and almost certainly doesn't pin every SSL certificate you may happen to come across -- this is what the EFF's Observatory[0] and browser plugins like Certificate Patrol[1] are for -- although I may very well be wrong on that.

Also, a March 2010 research paper by Christopher Soghoian and Sid Stamm "in which they present evidence that certificate authorities (CAs) may be cooperating with government agencies to help them spy undetected on 'secure' encrypted communications."[2]

More details on that from the EFF[3] but if we assume that the government can obtain Google's private keys then they could almost certainly carry this out undetected, IMO.

[0]: https://www.eff.org/observatory

[1]: https://addons.mozilla.org/en-US/firefox/addon/certificate-p...

[2]: http://files.cloudprivacy.net/ssl-mitm.pdf

[3]: https://www.eff.org/deeplinks/2010/03/researchers-reveal-lik...

Re: New NSA Leak Shows MITM Attacks Against Major Internet Services

#40

One more reason to not use any of the giant email providers like Yahoo, Google, and Hotmail.

You are the sole person responsible for the security of your communications. You simply cannot trust any third party to keep your communications secure. Public-key crypto goes a long way here.
Post reply on HN