Live data from Hacker News

FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

wired.com

141–150 of 280 posts

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#141
post #73
post #51

Earlier quoted context omitted.

Air gapped with new hardware: "Since I started working with the Snowden documents, I bought a new computer that has never been connected to the internet. If I want to transfer a file, I encrypt the file on the secure computer and walk it over to my internet computer, using a USB stick. To decrypt something, I reverse the process. This might not be bulletproof, but it's pretty good." http://www.theguardian.com/world/2…

IF he was serious he would be burning CDs/DVDs instead of using a read-write USB stick. It is tedious, but blank media is cheap and there is precedent (that I'm sure Bruce is aware of): The DoD's own (classified) SIPRNet was infiltrated via a flash-drive based virus back in 2008. http://www.washingtonpost.com/wp-dyn/content/article/2010/08...

I kinda thought the same thing about flash-drive viruses, and why Bruce wasn't using CDs/DVDs instead. Then I realized if he was really serious, he wouldn't say what he's really using, and he'd have a USB honeypot plugged into his network-facing computer.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#142
post #4

I don't even know anymore. We're gonna have to raise the bar on what it means to be a "tinfoil hatter"; the original definition has become reality. "Trust no one! Suspect EVERYTHING!" , I can say today without sounding crazy. Also, remember this? http://www.linuxfoundation.org/news-media/blogs/browse/2011/... ....hmm, I wonder if....

> "Trust no one! Suspect EVERYTHING!", I can say today without sounding crazy.

It's really not that hard to say this seriously without wearing a tinfoil hat. I've been doing that since high school.

The key is thinking in terms of operations, rather than in terms of generic trust. You need to know what you're doing, maintain opsec and have a strong, realistic threat analysis. For me, the Snowden cascade hasn't changed anything: if someone can penetrate the USGov's defenses, then they can almost certainly penetrate mine.

And that has always been true.

The revelations are a matter of ideological trust--trust in whether or not someone agrees with you--, but the USGov has never had much of this kind of trust, not even at its founding, nor has it ever acquired it.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#143
post #137
post #111

Earlier quoted context omitted.

Public schools are far more significant than the media.

You could be right. Or it could be the exact opposite. Or something else. It doesn't matter. Fundamentally we do it to ourselves, because we're herd/pack/social animals. We shun anyone too different from the tribe, it's in our DNA. Because of that, we are highly evolved to fit in. Yeah, we're self aware and all that, we have choices, but what we generally choose to do is identify with some group and hate opposing gro…

In England and Wales, truancy is a criminal offence for parents.[6] Since 1998, a police officer of or above the rank of superintendent may direct that for a specified time in a specified area a police officer may remove a child believed to be absent from a school without authority to that school or to another designated place....

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#144
post #42
post #9

Misleading title - the FBI did not conduct a 'mass malware attack'

The FBI didn't conduct a 'mass malware attack' on the open web. It did, however, inject malicious code in Tor hidden services that were hosted in Freedom Hosting. How is that not a 'mass malware attack'?

[deleted]

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#145
post #4

I don't even know anymore. We're gonna have to raise the bar on what it means to be a "tinfoil hatter"; the original definition has become reality. "Trust no one! Suspect EVERYTHING!" , I can say today without sounding crazy. Also, remember this? http://www.linuxfoundation.org/news-media/blogs/browse/2011/... ....hmm, I wonder if....

"Trust no one! Suspect EVERYTHING!", I can say today without sounding crazy.

What's seemingly worse/more crazy is many of these materials date for 4-5 years ago (2008-09). If these data were public, it would have potenially casued huge behavioural shifts.

In that way, its reminiscent of 9-11 where the damage was done not on that day, but the years earlier when the bad guys were training in plain daylight.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#146
post #36

Earlier quoted context omitted.

Source and details would be welcome.

Read up on Sabu and the timeline of events between his initial arrest and the various Anonymous Operations. He's a narc, has admitted it and was very much involved in most of the operations. Coincidentally, most people in those operations were rolled on and his assistance has been used in their arrests/cases.

So this was referring to the Lulzsec attacks carried in the few months between Sabu's arrest and their demise.

I wouldn't call that "much of Annonymous".

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#147
post #132

Earlier quoted context omitted.

Someone else should step up and give a comprehensive overview, because I can only recount the timeline from memory, not provide sources. But iirc, Anonymous was a loose coalition of random people on the internet, some of which turned out to have some basic hacking skills. They weren't really taken seriously until they embarrassed HBGary. At that point, the FBI began investigating them. Anonymous changed their name to…

LulzSec was not Anonymous. While some of its membership may have overlapped, that doesn't really mean anything, because anyone can be a part of Anonymous, simply by carrying out acts in the group's name. Sabu forgot to activate TOR before logging into IRC just a single time, and the FBI was able to locate him. Sabu was the legal guardian of his siblings, and was pretty much told that he would never see them again if…

http://ask.fm/DoubleJake

That's the ask.fm profile of Topiary, the LulzSec leader that spent some time in prison. There's quite a few interesting answers regarding what LulzSec actually was and some of his opinions of Sabu.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#148
post #73
post #51

Earlier quoted context omitted.

Air gapped with new hardware: "Since I started working with the Snowden documents, I bought a new computer that has never been connected to the internet. If I want to transfer a file, I encrypt the file on the secure computer and walk it over to my internet computer, using a USB stick. To decrypt something, I reverse the process. This might not be bulletproof, but it's pretty good." http://www.theguardian.com/world/2…

IF he was serious he would be burning CDs/DVDs instead of using a read-write USB stick. It is tedious, but blank media is cheap and there is precedent (that I'm sure Bruce is aware of): The DoD's own (classified) SIPRNet was infiltrated via a flash-drive based virus back in 2008. http://www.washingtonpost.com/wp-dyn/content/article/2010/08...

Another approach might be to set up an old-fashioned serial link between the machines. It's easy enough to observe and audit all the traffic that passes through a serial cable.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#149
post #128
post #94

Earlier quoted context omitted.

Police "techniques" involve guns, tear gas, helicopters, etc. At any time the police could in theory fly to your house, launch tear gas into your windows, and shoot you in the head as you run out. And I don't know about you, but I'm not exactly worried about that happening to the point where I want to take guns, tear gas, and helicopters away from the police. This is the FBI taking down criminals engaging in a clear…

IANAL, but I'd be surprised if the police was allowed to raid me, launch tear gas through my window and shoot me in the head. Even with a warrant. I'm not worried about this happening, because it doesn't. If it did, I'm sure it would blow up into a huge scandal. I am worried about government agencies intercepting my traffic / communications because it does happen, it's really hard to find out unless you know what you…

> Even with a warrant. I'm not worried about this happening, because it doesn't.

Spend a little time in here: https://duckduckgo.com/?q=warrant+no+knock+raid+mistake&t=ca...

Or here: https://duckduckgo.com/?q=warrant++raid+mistake+death&t=cano...

Or here: http://www.newyorker.com/online/blogs/comment/2013/08/swat-t...

I'm still waiting for the scandal.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#150
post #14
post #4

I don't even know anymore. We're gonna have to raise the bar on what it means to be a "tinfoil hatter"; the original definition has become reality. "Trust no one! Suspect EVERYTHING!" , I can say today without sounding crazy. Also, remember this? http://www.linuxfoundation.org/news-media/blogs/browse/2011/... ....hmm, I wonder if....

Meanwhile the way Bruce Schneier is now using GPG is really only one conceptual leap away from full-blown Tinfoil Hat Linux usage: http://en.wikipedia.org/wiki/Tinfoil_Hat_Linux The difference between "tinfoil hatters" and reasonable people like Bruce Schneier now seems to be how concerned they are with their ability to destroy a harddrive, and TEMPEST.

You mean changing the number of "2048" to "4096"? I'm not sold on that being a meaningful improvement to his security, but even so, you realize that change costs him nothing, right? He needed to generate a new key... why not set it to 4096 bits? Everything he does with that key happens in human scale time --- even a 500ms per message delay wouldn't be noticeable.

So, some evocatively named Linux distro recommends the same key size, is what I understand you to be saying, and therefore... what? Aliens really did land at Roswell?

Post reply on HN