Live data from Hacker News

FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

wired.com

171–180 of 280 posts

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#172
post #14

Earlier quoted context omitted.

Meanwhile the way Bruce Schneier is now using GPG is really only one conceptual leap away from full-blown Tinfoil Hat Linux usage: http://en.wikipedia.org/wiki/Tinfoil_Hat_Linux The difference between "tinfoil hatters" and reasonable people like Bruce Schneier now seems to be how concerned they are with their ability to destroy a harddrive, and TEMPEST.

Bruce Schneier is not a reasonable person about his own computer security any more than a virologist is a reasonable person over her own infectivity. He knows too much to be a reasonable person.

Surely a virologist can be considered more reasonable about related matters of personal than the general public (who cannot even be trusted to immunize themselves or their children, and cannot be trusted to trust modern medicine instead of roots some hippy pulled out of the ground behind their shed).

Bruce isn't a nutter. I don't think many people would actually argue otherwise.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#173
post #125

The use of malware in police enforcement is truly a unique event in society. At what other point in history has police distributed a completly illegal tool onto unsuspected and non-targeted civilians? It feels like a total unexplored area of liability laws, so I look with excitement to when the first lawsuit starts. Some people have compared malware with guns. This is to me a very bad comparison, since guns actually…

It's possible that installing malware on a machine could be legal if the police have a warrant to wiretap that specific machine. However, in this case, they indiscriminately pushed malware to thousands of users on that site, many of whom were probably not doing anything illegal. So how does this not violate the Fourth Amendment?

The Fourth Amendment says: "No Warrants shall issue, but upon probable cause, supported by Oath or affirmation, and particularly describing the place to be searched, and the persons or things to be seized."[1]

[1] https://en.wikipedia.org/wiki/Fourth_Amendment_to_the_United...

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#174
post #125

The use of malware in police enforcement is truly a unique event in society. At what other point in history has police distributed a completly illegal tool onto unsuspected and non-targeted civilians? It feels like a total unexplored area of liability laws, so I look with excitement to when the first lawsuit starts. Some people have compared malware with guns. This is to me a very bad comparison, since guns actually…

>At what other point in history has police distributed a >completly illegal tool onto unsuspected and non-targeted >civilians? For quite a while. Law enforcement have installed physical surveilance and tracking devices since as long as they have existed - and unsuspecting innocents have been caught on those tapes and recorders. It's also a question of whether those tools are illegal - there may be laws against them ,…

For a wiretap, they'd definitely need a warrant. And I think there was a recent court decision that says that police need a warrant to put a GPS tracker on someone's car. What they did here was to install malware on thousands of machines, without any probable cause to believe that any specific machine owner was involved with child porn. If I understand the law correctly, they would need to obtain a specific warrant for each machine they wanted to search.

Let's say that there was a store in a neighborhood that was known to sell child porn. No judge would sign a warrant that gave police permission to put a GPS device on every car in that neighborhood to track whether they ever visited that store (and they may have visited but bought only legal merchandise). So why is it different if you do it on the internet?

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#175
post #51

Earlier quoted context omitted.

Air gapped with new hardware: "Since I started working with the Snowden documents, I bought a new computer that has never been connected to the internet. If I want to transfer a file, I encrypt the file on the secure computer and walk it over to my internet computer, using a USB stick. To decrypt something, I reverse the process. This might not be bulletproof, but it's pretty good." http://www.theguardian.com/world/2…

He's not doing that because of concerns about PGP, just to be clear, but because his host computer isn't secure (none of ours are); he's doing basically the same thing as the people who run their browsers in a VM, or the same thing that security professionals tell business owners to do when they want to access their online banking.

What do you tell business owners to do when accessing their online banking?

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#176
post #175

Earlier quoted context omitted.

He's not doing that because of concerns about PGP, just to be clear, but because his host computer isn't secure (none of ours are); he's doing basically the same thing as the people who run their browsers in a VM, or the same thing that security professionals tell business owners to do when they want to access their online banking.

What do you tell business owners to do when accessing their online banking?

Use a machine that is used for absolutely nothing else.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#177
post #51

Earlier quoted context omitted.

the way Bruce Schneier is now using GPG Which way is that? Also, from your Tinfoil Hat Linux link, this idea is hilariously awesome: Keystroke monitoring — THL has gpggrid, a wrapper for GPG that lets you use a video game style character entry system instead of typing in your passphrase. Keystroke loggers get a set of grid points, not your passphrase. I wonder if it might be possible to implement that idea into other…

Air gapped with new hardware: "Since I started working with the Snowden documents, I bought a new computer that has never been connected to the internet. If I want to transfer a file, I encrypt the file on the secure computer and walk it over to my internet computer, using a USB stick. To decrypt something, I reverse the process. This might not be bulletproof, but it's pretty good." http://www.theguardian.com/world/2…

Given what we know about USB sticks, especially their use in Iran, you would have to be ABSOLUTELY FUCKING RETARDED to trust them.

Oh so he encrypted his files, and walked them between his stand alone and his internet machines. Yeah, okay this established the file's integrity, and that's just fantastic.

But what assurance does he have that the USB stick isn't getting infected on the internet machine, and then deploying stealth hacksaw services onto the standalone, to buffer and relay data and commands each time it jacks in?

I mean, that's exactly what Stuxnet was designed to fucking do.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#178
post #73

Earlier quoted context omitted.

IF he was serious he would be burning CDs/DVDs instead of using a read-write USB stick. It is tedious, but blank media is cheap and there is precedent (that I'm sure Bruce is aware of): The DoD's own (classified) SIPRNet was infiltrated via a flash-drive based virus back in 2008. http://www.washingtonpost.com/wp-dyn/content/article/2010/08...

SD cards have a physical switch you can flip for read-only.

Yeah and my old Intel 486 Gateway 2000 had a Turbo button. What's your point?

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#180
post #51

Earlier quoted context omitted.

the way Bruce Schneier is now using GPG Which way is that? Also, from your Tinfoil Hat Linux link, this idea is hilariously awesome: Keystroke monitoring — THL has gpggrid, a wrapper for GPG that lets you use a video game style character entry system instead of typing in your passphrase. Keystroke loggers get a set of grid points, not your passphrase. I wonder if it might be possible to implement that idea into other…

Air gapped with new hardware: "Since I started working with the Snowden documents, I bought a new computer that has never been connected to the internet. If I want to transfer a file, I encrypt the file on the secure computer and walk it over to my internet computer, using a USB stick. To decrypt something, I reverse the process. This might not be bulletproof, but it's pretty good." http://www.theguardian.com/world/2…

I see a new product. The air gap - a micro computer that takes simple commands, like mail, ftp and get, to serve as a simple go between layer for people who want this kind of privacy.

IMHO, the hard part would be creating the interface on the on the pc.

Post reply on HN