Live data from Hacker News

FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

wired.com

191–200 of 280 posts

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#191

Earlier quoted context omitted.

Just out of curiosity - assume you took a key of 8096 bits - and it is super long - could you then make a hash of the key which were shorter, and provide the hash, with instructions on how to reverse it, and then use the hash to produce the 8096 keylength with less digits between you and the recipient?

Are you asking whether you can compress an RSA key? Anyways: don't use 8192 bit keys. Whatever kills the 4096 bit keys is going to kill RSA along with them. Honestly, I think 4096 bits is also kind of a you're-kidding-yourself key length; if attacks on 2048 bit keys became tractable, RSA is probably in serious trouble.

Dude, Get your ass to SF so I can buy you the many beers I owe you!

I get truly excited when I see your replies, I'd love to banter in [inebriated] public! With that said, may I please make the humble request;

Yoou have contributed a shitload of awesome comments on the state f "who-the-fuck-are-we-kidding" with respect to encryption and privacy in light of what we actually know now related to the NSA....

Would you please create a post, in an Explain-Like-I-Am-Five-Years-Old manner on both the state of the capabilities of the NSA, the state of current encryption tech/methods we rely on, AND what the heck I, as and individual, could/can/should do about protecting myself.

---

I can speculate all day long about all sorts of things, but I am asking - given the NSA-Fatigue I suffer from - fr your help.

I WILL PAY YOU FOR THIS SERVICE; Set the price at $20 for the best recommendation. Crowd-source your network of people who have enough info to contribute to the recommendation...

Aside from smashing my machines and cancelling my power utility, I have no clue how to regain privacy at this point.

Then we will drink, and e Merry, Pippin and Sam!

EDIT: Tawny Port May be responsible for this post.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#193
post #73

Earlier quoted context omitted.

IF he was serious he would be burning CDs/DVDs instead of using a read-write USB stick. It is tedious, but blank media is cheap and there is precedent (that I'm sure Bruce is aware of): The DoD's own (classified) SIPRNet was infiltrated via a flash-drive based virus back in 2008. http://www.washingtonpost.com/wp-dyn/content/article/2010/08...

SD cards have a physical switch you can flip for read-only.

The SD card switch is actually read by an external physical sensor (a tiny button like the write-protect buttons inside of ancient 3.5" floppy drives), at least on most SD cards. I had an SD card whose switch wasn't quite thick enough to trigger the writability sensor of an SD card reader, so I had to wrap it in tape.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#194
post #125

The use of malware in police enforcement is truly a unique event in society. At what other point in history has police distributed a completly illegal tool onto unsuspected and non-targeted civilians? It feels like a total unexplored area of liability laws, so I look with excitement to when the first lawsuit starts. Some people have compared malware with guns. This is to me a very bad comparison, since guns actually…

I think the most troubling aspect of this case is that the FBI modified the computers systems before Ireland seized them as evidence. It seems absurd that law enforcement can effectively tamper with evidence before it is secured, then use that tainted evidence as part of a prosecution.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#195
post #118
post #15

Earlier quoted context omitted.

It wouldn't be particularly easier to do it that way than just submitting your subversive code normally. Either way your change would need to be "underhanded" such that anybody viewing it wouldn't suspect anything. In fact, trying to slip it in under the radar like that would actually just increase the chances of getting caught, because then it becomes something that isn't suppose to be there instead of merely someth…

If you can come up with a backdoor that requires the non-obvious interaction of multiple parts of the kernel (or parts of the kernel and certain user-space actions) then it would be reasonable to break up the necessary changes and slip each one in as a part of a larger demonstrable improvement to each specific subsystem. For example (completely hypothetical), you could create a race condition in the kernel's page all…

That reminds me of a story I read about how the satellite companies foiled carders by slowly building up a new decryption system out of apparent garbage released across a long string of updates. I don't dare to search for it though, so I don't have a link.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#196
post #51

Earlier quoted context omitted.

Air gapped with new hardware: "Since I started working with the Snowden documents, I bought a new computer that has never been connected to the internet. If I want to transfer a file, I encrypt the file on the secure computer and walk it over to my internet computer, using a USB stick. To decrypt something, I reverse the process. This might not be bulletproof, but it's pretty good." http://www.theguardian.com/world/2…

Given what we know about USB sticks, especially their use in Iran, you would have to be ABSOLUTELY FUCKING RETARDED to trust them. Oh so he encrypted his files, and walked them between his stand alone and his internet machines. Yeah, okay this established the file's integrity, and that's just fantastic. But what assurance does he have that the USB stick isn't getting infected on the internet machine, and then deployi…

I wish you'd made your point more gracefully, because then it would've been taken seriously. I had the exact same concern about him using USB sticks.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#197

Earlier quoted context omitted.

Use a machine that is used for absolutely nothing else.

How many of them actually do?

Germany's best-selling PC magazine c't periodically distributes "Bankix" on their CD.

It's a Linux live system (with permanent storage on a USB stick) geared specifically towards online banking.

I believe that quite a few people actually use it.

Of course the hardware is the same, but you get a clean single purpose software system.

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#198
post #51

Earlier quoted context omitted.

Air gapped with new hardware: "Since I started working with the Snowden documents, I bought a new computer that has never been connected to the internet. If I want to transfer a file, I encrypt the file on the secure computer and walk it over to my internet computer, using a USB stick. To decrypt something, I reverse the process. This might not be bulletproof, but it's pretty good." http://www.theguardian.com/world/2…

I see a new product. The air gap - a micro computer that takes simple commands, like mail, ftp and get, to serve as a simple go between layer for people who want this kind of privacy. IMHO, the hard part would be creating the interface on the on the pc.

The new product I see is 100% open hardware (in addition to open-source software). All the way down to the chip.

This should be the new market: Companies inviting the whole world to inspect their hardware (in addition to firmware, software).

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#199

Earlier quoted context omitted.

From your link: But his FBI handlers said he was "brilliant, but lazy": they discovered him selling stolen credit card details on Facebook, and traced him to his home when he used an unguarded internet connection to go on the 2600.com site, which is popular with young and old hackers. Is 2600.com a honeypot for the FBI? How'd Sabu expose himself by merely visiting that site?

>Is 2600.com a honeypot for the FBI? How'd Sabu expose himself by merely visiting that site? i guess they just ran the query in the NSA's internet traffic meta-info database.

Speaking of which, there's publicly available security software that can (try to) identify original sources of phrases, identify links between websites and who said what first, etc. One example: http://www.paterva.com/web6/products/maltego.php

Re: FBI Admits It Controlled Tor Servers Behind Mass Malware Attack

#200
post #51

Earlier quoted context omitted.

the way Bruce Schneier is now using GPG Which way is that? Also, from your Tinfoil Hat Linux link, this idea is hilariously awesome: Keystroke monitoring — THL has gpggrid, a wrapper for GPG that lets you use a video game style character entry system instead of typing in your passphrase. Keystroke loggers get a set of grid points, not your passphrase. I wonder if it might be possible to implement that idea into other…

Air gapped with new hardware: "Since I started working with the Snowden documents, I bought a new computer that has never been connected to the internet. If I want to transfer a file, I encrypt the file on the secure computer and walk it over to my internet computer, using a USB stick. To decrypt something, I reverse the process. This might not be bulletproof, but it's pretty good." http://www.theguardian.com/world/2…

Stuxnet jumped an air gap.
Post reply on HN