Live data from Hacker News

NSA infected 50,000 computer networks with malicious software

nrc.nl

71–80 of 96 posts

Re: NSA infected 50,000 computer networks with malicious software

#71

Earlier quoted context omitted.

What does illegal mean in the context of government? The government decides what's illegal. If you want to declare some government's action illegal, you need to find a bigger government to impose their laws on the little government.

If you live in a nation of laws, i.e. some form of functioning democracy, the people decide what is legal through their representatives, and this can change gradually as attitudes shift. The government is supposed to be an instrument of the people, not the other way around.

I assume the parent is talking about the USG spying on or murdering other not-US people, in which case the people of the US have more or less decided that's what they want.

Re: NSA infected 50,000 computer networks with malicious software

#72
post #28
post #18

Earlier quoted context omitted.

>But it is intellectually dishonest to pretend that people are just now discovering that NSA was breaking into computers around the world. That is literally the charter of the NSA. It's why they exist at all. You're presenting a red herring here, tptacek. Any third grader who played played Splinter Cell would say, "No duh!" But the news isn't that the NSA is breaking into computers. The news is the scope of the intru…

> The news is the scope of the intrusions (installing malware on 50k computers), and of the motivations for the behavior. GCHQ have said for at least 15 years that their mission is to monitor all communications, world wide, at frequencies from DC to light. They've said that they provide intelligence for their customers, who are the Ministry of Defence and other parts of government. (MI5, MI6, etc). > It's about globa…

GCHQ have said for at least 15 years that their mission is to monitor all communications, world wide, at frequencies from DC to light

That's a truly appalling aspiration. If that is indeed their aspiration, which apparently it is (total information awareness, master the internet etc), we'd be safer with them shut down completely. Otherwise as more and more data becomes available online, they'd be in a position of absolute power over the populace (including those who are supposed to control their activities).

That's not keeping us safe, that is endangering the things they purport to defend.

Don't you find this aspiration frightening?

It's a grab that happened a decade or more ago.

Oh, that's ok then. Business as usual. Would you prefer people just didn't bother to discuss this topic, or do you have something to say about where the limits on this behaviour should be?

Re: NSA infected 50,000 computer networks with malicious software

#73
post #22
post #2

As an American, I feel like my country is actually putting me in long-term danger. The government is making America and Americans enemies of the entire world. If and when I ultimately have to feel the country, will I even be accepted into anywhere else? What if they are suspicious that I work for the NSA? Or what if they just decide to treat Americans the way the US treats would-be immigrants to the US now--no, you c…

>> As an American, I feel like my country is actually putting me in long-term danger. The government is making America and Americans enemies of the entire world. That has been happening since forever; it's just that the NSA stuff has made that fact visible to people who didn't see America's hypocrisy before. I mean, there are people who actually believe this ---> https://www.youtube.com/watch?v=p6HOcLWP-Ls

I don't want to take the time to watch that video, but I actually do think that 99% of hatred of America historically has been due to the moral inferiority of the haters.

For example, fundamentalist Islamists, and all those who wish to sympathize with them, are "right" to hate America. Socialists are right to hate America--the American constitution fundamentally stands for the opposite moral code, and American prosperity is evidence that the American morality is the right one.

That said, the GOP is opposed to that very morality, and the Democrat party even more-so, so the country is being rapidly destroyed from the inside (and has been on that path for almost 100 years, just accelerating or decelerating occasionally).

Re: NSA infected 50,000 computer networks with malicious software

#74

It's stories like this that make me wish we had the term "national security" as narrowly defined as the term "treason". I wouldn't be surprised if many of America's largest corporations most often present their corporate interests as national security interests when they are lobbying our politicians. Looking at that map, we need to be asking questions about where so many of those "implants" are located. I'm not surpr…

Not to excuse the actions, which I find deplorable. Isn't Brazil one of our major agricultural trading partners? Making the internal security interests of Brazil our security interests? If our food supply was cut by 1/3 during half the year, that could be a big issue.

> If our food supply was cut by 1/3 during half the year, that could be a big issue.

That would also be a massive issue for Brazil to lose their largest agricultural trading partner. It's a competitive marketplace. Their industry, law enforcement agencies, and courts are sufficiently incentivized to protect it, or risk losing it to other countries.

I'm amazed that people view the need for some World Police to control and monitor our economic interests abroad, when there has been no clear failure of markets or democratic processes at protecting them historically.

These rationalizations sound border-line schizophrenic and paranoid. With scenarios comparable to conspiracies theories.

Are there really economic threats that necessitate secret intelligence agencies intercepting private communications of citizens within friendly sovereign nations? And a threat to whom? The representative population? Or primarily the special interests of the government - from where these secret orders/intelligence are held, classified, and acted upon in secret?

Re: NSA infected 50,000 computer networks with malicious software

#75
post #28

Earlier quoted context omitted.

> The news is the scope of the intrusions (installing malware on 50k computers), and of the motivations for the behavior. GCHQ have said for at least 15 years that their mission is to monitor all communications, world wide, at frequencies from DC to light. They've said that they provide intelligence for their customers, who are the Ministry of Defence and other parts of government. (MI5, MI6, etc). > It's about globa…

GCHQ have said for at least 15 years that their mission is to monitor all communications, world wide, at frequencies from DC to light That's a truly appalling aspiration. If that is indeed their aspiration, which apparently it is (total information awareness, master the internet etc), we'd be safer with them shut down completely. Otherwise as more and more data becomes available online, they'd be in a position of abs…

> Would you prefer people just didn't bother to discuss this topic,

I would prefer that people stop saying that it's a modern development, or that there was no sign of it until Snowden leaked, or that it's some weird new thing. GCHQ at least has been open about their behaviour for years and years. ECHELON was discussed in EU parliament.

> do you have something to say about where the limits on this behaviour should be?

My view is tricky for me to explain, but I'll try.

1) GCHQ need to be allowed to do stuff. The limits should be clear, and defined by law.

2) GCHQ is a secret organisation, thus their oversight must be by people who keep secrets, but who are accountable to the public. GCHQ oversight failed, hard. I'm not sure what should happen. I hope that, in secret, someone is getting a kicking.

3) I don't care what GCHQ does to people who are not subjects of the UK (or whatever the hell England plus others is called now)

4) For UK subjects I would prefer that GCHQ does not collect meta data. I could be persuaded that they can collect targeted meta data, if they have suitable oversight. EG: They know that Bob is a terrorist-sympathiser. (Beyond just looking at a few YouTube videos - this would be things like sending money, fly-posting, fund raising, associating with other terrorists, etc.) GCHQ would apply for, and get, a warrant, and be allowed to collect meta data for that person. Warrants would require oversight, not just by the courts but by the oversight body.

5) For UK subjects I strongly prefer that GCHQ does not collect content data unless they get a warrant.

6) GCHQ claim to obey the law. I want oversight to be stronger, and I want some of the GCHQ choices to be challenged. I don't want weird interpretations of words to guide their behaviours. (EG: Clinton's "I did not have sexual relations" - well, a blow job is sexual to most people.)

Having said all that, I am a lot less bothered by GCHQ data slurping than I am by other potential privacy invasions.

GCHQ has a many petabyte dump of data but there's no impact on me unless they grep my name. (I'm aware that this is like me saying I'm not so bothered by police stop and search powers; me being white and rarely leaving the house means that I'm never stopped and searched.) Plenty of other organisations have my data, and we have many examples of them breaching confidentiality through corruption, incompetence, maliciousness, and so on. I said a bit more about that in this post. https://news.ycombinator.com/item?id=6767612

Re: NSA infected 50,000 computer networks with malicious software

#76

It's stories like this that make me wish we had the term "national security" as narrowly defined as the term "treason". I wouldn't be surprised if many of America's largest corporations most often present their corporate interests as national security interests when they are lobbying our politicians. Looking at that map, we need to be asking questions about where so many of those "implants" are located. I'm not surpr…

> It's stories like this that make me wish we had the term "national security" as narrowly defined as the term "treason".

The U.S. Constitution has Article I, Section 8, Clause 1 that reads:

> The Congress shall have Power To lay and collect Taxes, Duties, Imposts and Excises, to pay the Debts and provide for the common Defence and general Welfare of the United States;

People on the political left seem to favor a broad interpretation of the powers that "general welfare" gives to the federal government. Why isn't there a similar acceptance of the broad powers that "common defense" grants the federal government in the same clause?

Re: NSA infected 50,000 computer networks with malicious software

#77
post #50
post #32

Earlier quoted context omitted.

I don't think I've seen him defend their actions, just explain them. I, for one, appreciate it. He is in a sphere that I am not in, and were I to guess whether or not this was well-known behavior, I would have guessed not. And, apparently, I would have been wrong. So I thank tptacek for sharing what he knows that I don't know. That is, after all, why I come here.

Don't you think that he's being a little inflammatory with statements this? But it is intellectually dishonest to pretend that people are just now discovering that NSA was breaking into computers around the world. By your own admission, you are just now discovering that the NSA was breaking into computers around the world.

^wrong assumptions. You're assuming he didn't know already. Why would one make a statement like that if one didn't know beforehand?

Re: NSA infected 50,000 computer networks with malicious software

#78
post #10
post #4

What would happen if NSA mistakenly targets a nuclear reactor, and a bug in the malicious software caused a meltdown. Is that a declaration of war, similar to a US launching a nuke? Would US be liable, and under what jurisdiction? Could the US President be put under Interpool arrest warrant, charged as an terrorist? Sabotage, especially when the target can not be fully verified, is a dangerous game. IP addresses are…

Yes, that seems pretty simple: if NSA hacking caused a nuclear disaster, that would be an act of war. And?

> And?

Like during the cold war, the world was a button press from global collapse.

It is not a good thing that random act of sabotage against targets which the attacker can't and won't verify is happening with such indifference to consequences. As citizens, we should react with more than "And?".

Re: NSA infected 50,000 computer networks with malicious software

#79
post #54
post #53

Earlier quoted context omitted.

> We don't need the Snowden disclosures to know this; it has for 15 years been the worst kept secret in computer security. Just 1 year before, people would deny such thing occured and treat you like a conspiracy theorist, including here on HN. > But it is intellectually dishonest to pretend that people are just now discovering that A, the "we knew it all along so it's ok" defense -- with the "and furthermore, you sho…

> "and furthermore, you should be ashamed for pretending to have learned about it just now" You are wrong. People have been saying for as long as email has existed that it is not private and that anyone can read it. People have been warning that if you have something secret you must not put it online, or that you must use sensible encryption carefully if you do so. Risk assessment has always been part of online secur…

It's news to my mother. Half of the UK and US government are saying it's news to them. The world's press seems to think it qualifies as news.

Re: NSA infected 50,000 computer networks with malicious software

#80
post #54

Earlier quoted context omitted.

> "and furthermore, you should be ashamed for pretending to have learned about it just now" You are wrong. People have been saying for as long as email has existed that it is not private and that anyone can read it. People have been warning that if you have something secret you must not put it online, or that you must use sensible encryption carefully if you do so. Risk assessment has always been part of online secur…

It's news to my mother. Half of the UK and US government are saying it's news to them. The world's press seems to think it qualifies as news.

> It's news to my mother.

2001, in mainstream UK newspaper http://www.theguardian.com/world/2001/may/30/eu.politics4

> the European Parliament warned EU citizens of the threat to their privacy from Echelon, a global eavesdropping network run by the US National Security Agency in cooperation with Britain, Canada, Australia and New Zealand. As we reported on Saturday, it concluded that the primary purpose of the system is to "intercept private and commercial communications". It urged individuals and businesses to use codes to protect their communications.

> Half of the UK and US government are saying it's news to them

1999, from the website of this secret agency https://web.archive.org/web/19990428012157/http://www.gchq.g...

> GCHQ employs one of the largest long term bulk near line storage systems in the world. Data is stored in a number of locations on a variety of media, including magnetic tape, cartridges, recordable Compact Disc and optical storage technologies.

What did they think was being done with the largest long term storage system in the world?

> GCHQ has an interest in all aspects of modern telecommunications and uses a variety of systems designed to operate on all frequencies over which data can be transmitted.

I'll admit that the GCHQ FAQ got a bit slimier later on. See this page from 2004 https://web.archive.org/web/20040604234303/http://www.gchq.g...

> People sometimes think that we cannot be accountable because we do not disclose much about GCHQ's operations and methods.

> Nothing could be further from the truth.

> In fact, GCHQ is subject to very rigorous oversight both by Parliament and senior members of the judiciary, and works entirely within a legal framework which complies with the European Convention on Human Rights.

> Activities at GCHQ are underpinned by the Intelligence Services Act 1994 (amended most recently by the Anti-Terrorism, Crime and Security Act 2001) and the Regulation of Investigatory Powers Act 2000. The purposes for which interception may be permitted are set out explicitly in these Acts: national security, safeguarding economic wellbeing, and the prevention and detection of serious crime. Interception for other purposes is not lawful, and we do not do it.

But I've already condemned this kind of wording used to justify unjustifiable privacy violation.

EDIT: It's mildly interesting reading through the technology pages to see it iterating. They list Win3.1 in the early versions!

Post reply on HN