Live data from Hacker News

NSA infected 50,000 computer networks with malicious software

nrc.nl

81–90 of 96 posts

Re: NSA infected 50,000 computer networks with malicious software

#81
post #73
post #22

Earlier quoted context omitted.

>> As an American, I feel like my country is actually putting me in long-term danger. The government is making America and Americans enemies of the entire world. That has been happening since forever; it's just that the NSA stuff has made that fact visible to people who didn't see America's hypocrisy before. I mean, there are people who actually believe this ---> https://www.youtube.com/watch?v=p6HOcLWP-Ls

I don't want to take the time to watch that video, but I actually do think that 99% of hatred of America historically has been due to the moral inferiority of the haters. For example, fundamentalist Islamists, and all those who wish to sympathize with them, are " right " to hate America. Socialists are right to hate America--the American constitution fundamentally stands for the opposite moral code, and American pros…

Nope. The reason some people hate the US is because the country interferes (up to the point of overthrowing governments) with the entire world.

Yeah, it can be argued that there is some kind of problem with people more prone to hating than to actually dealing with the problem. But there is no excuse to think the reason that they target the US any other than them destroying their country.

Re: NSA infected 50,000 computer networks with malicious software

#82
post #75

Earlier quoted context omitted.

GCHQ have said for at least 15 years that their mission is to monitor all communications, world wide, at frequencies from DC to light That's a truly appalling aspiration. If that is indeed their aspiration, which apparently it is (total information awareness, master the internet etc), we'd be safer with them shut down completely. Otherwise as more and more data becomes available online, they'd be in a position of abs…

> Would you prefer people just didn't bother to discuss this topic, I would prefer that people stop saying that it's a modern development, or that there was no sign of it until Snowden leaked, or that it's some weird new thing. GCHQ at least has been open about their behaviour for years and years. ECHELON was discussed in EU parliament. > do you have something to say about where the limits on this behaviour should be…

Thanks for commenting. I do think this is a subject worth discussing until it is fixed.

GCHQ has a many petabyte dump of data but there's no impact on me unless they grep my name.

I'd disagree there - if GCHQ is collecting huge dumps of data, it doesn't have to be your data to affect you directly. For example if your MP or prime minister is deposed because of selective leaks of their data, that could easily affect your life in dramatic ways.

Re: NSA infected 50,000 computer networks with malicious software

#83
post #80

Earlier quoted context omitted.

It's news to my mother. Half of the UK and US government are saying it's news to them. The world's press seems to think it qualifies as news.

> It's news to my mother. 2001, in mainstream UK newspaper http://www.theguardian.com/world/2001/may/30/eu.politics4 > the European Parliament warned EU citizens of the threat to their privacy from Echelon, a global eavesdropping network run by the US National Security Agency in cooperation with Britain, Canada, Australia and New Zealand. As we reported on Saturday, it concluded that the primary purpose of the system…

It could maybe be described as hidden in plain sight. If you dug around there were pieces in the public domain that you could put together. But if you suggested this, you would have been dismissed as a tinfoil hatter by most people.

More to the point, the fact that it is a huge story in the news across the world proves that most people were simply unaware. So it doesn't mean much to say that this was already known when to most it wasn't. That could be taken to imply that there is nothing to see here and that people who are bringing it up are a little slow - which is simply disingenuous. The fact that my mother doesn't read every page of every newspaper doesn't mean she should be disenfranchised. And it also doesn't change the fact that many businesses are only now changing their behaviour and moving away from US companies and reconsidering architecture for IT projects and business operations.

Re: NSA infected 50,000 computer networks with malicious software

#84
post #58
post #3

We don't need the Snowden disclosures to know this; it has for 15 years been the worst kept secret in computer security. People from the various groups in NSA that do this work talk about having done it on Twitter. Some of the smartest people in vulnerability research came from stints in NSA. Be outraged that we're spying on your country if that makes you feel better, I guess. I'd rather nobody spied on each other ei…

May I suggest a different perspective: We did need the Snowden disclosures to know this, for some value of we. A lot of members here on HN appear to realize this for the first time, and this is obviously a computer-related community. Non-technical people, considering who to vote for next time, certainly needed the Snowden disclosures to know this. The press could have picked up this story from resumes, but didn't, so…

You might also reasonably ask why tptacek and friends weren't blowing the whistle as this is huge news to most.

Re: NSA infected 50,000 computer networks with malicious software

#86
post #12

Earlier quoted context omitted.

Has there ever been an NSA thread where you didn't take the opportunity to tell us why whatever the NSA has been doing is completely normal and expected?

Yes. For instance, I was not a believer in the NSA curve backdoors. Unfortunately for whatever innuendo you're trying to evoke here, I'm on pretty firm ground when I say that NSA sponsoring computer hacking is normal and expected. I say that because you can find it on people's fucking resumes.

Not many of the people commenting in this thread, to say nothing of the general population, are founders of security research firms. We may have seen noisy rumours of these things, and even noisier hints at their scope and extent, but we're not being personally mailed verifiable primary documents by first-party actors.

Re: NSA infected 50,000 computer networks with malicious software

#87
post #58

Earlier quoted context omitted.

May I suggest a different perspective: We did need the Snowden disclosures to know this, for some value of we. A lot of members here on HN appear to realize this for the first time, and this is obviously a computer-related community. Non-technical people, considering who to vote for next time, certainly needed the Snowden disclosures to know this. The press could have picked up this story from resumes, but didn't, so…

You might also reasonably ask why tptacek and friends weren't blowing the whistle as this is huge news to most.

I can't speak for tptacek. I don't know what he and his friends were doing.

But I've been telling people to encrypt everything, and to assume the government can read everything, for very many years.

Sure, I lack gravitas, but still. We were telling people about it.

A Google web search for Echelon before 1999 reveals many hits for the secret codename (as well as many not relevant hits)

https://www.google.co.uk/search?q=echelon&sa=X&ei=IXWRUpCGE8...

We successfully fought against idiotic ideas from government to control use of encryption (EG Clipper chip). We told you to use encryption. We told you they could listen. We told you they were listening.

What more could people have done?

http://webjcli.ncl.ac.uk/1997/issue1/akdeniz1.html#ukpolicy

Re: NSA infected 50,000 computer networks with malicious software

#88
post #80

Earlier quoted context omitted.

> It's news to my mother. 2001, in mainstream UK newspaper http://www.theguardian.com/world/2001/may/30/eu.politics4 > the European Parliament warned EU citizens of the threat to their privacy from Echelon, a global eavesdropping network run by the US National Security Agency in cooperation with Britain, Canada, Australia and New Zealand. As we reported on Saturday, it concluded that the primary purpose of the system…

It could maybe be described as hidden in plain sight. If you dug around there were pieces in the public domain that you could put together. But if you suggested this, you would have been dismissed as a tinfoil hatter by most people. More to the point, the fact that it is a huge story in the news across the world proves that most people were simply unaware. So it doesn't mean much to say that this was already known wh…

You're managing to change my mind.

I should say that I'm glad it's now being taken seriously by many people. I'm a bit worried about the number of toy crypto systems popping up. I'm frustrated that people still release apps that have over-broad privacy intrusions.

Re: NSA infected 50,000 computer networks with malicious software

#89
post #87

Earlier quoted context omitted.

You might also reasonably ask why tptacek and friends weren't blowing the whistle as this is huge news to most.

I can't speak for tptacek. I don't know what he and his friends were doing. But I've been telling people to encrypt everything, and to assume the government can read everything, for very many years. Sure, I lack gravitas, but still. We were telling people about it. A Google web search for Echelon before 1999 reveals many hits for the secret codename (as well as many not relevant hits) https://www.google.co.uk/search?…

I think there's a strong distinction between "the government can read everything unencrypted" and "the government has a horde of vulnerability researchers, and routinely infects huge numbers of computers with their code". For the sake of discussion, I will concede that the former was well-known. The latter, IMO, wasn't.

What more could people have done? Good question. Maybe try and contact investigative journalists, although I have had no luck doing that for an unrelated issue I feel strongly about (NBA game fixing).

Re: NSA infected 50,000 computer networks with malicious software

#90
post #2

As an American, I feel like my country is actually putting me in long-term danger. The government is making America and Americans enemies of the entire world. If and when I ultimately have to feel the country, will I even be accepted into anywhere else? What if they are suspicious that I work for the NSA? Or what if they just decide to treat Americans the way the US treats would-be immigrants to the US now--no, you c…

The danger is two-fold: firstly the USA is losing friends abroad, 'allies' are realising that at best they were slightly favoured underlings but never equals. At least this is explicit from the outset with China.

Secondly, America's power and influence is fading, slowly admittedly, but fading nonetheless. Like here in the UK your turn will come when you realise what it is like to be yesterday's bully boy. Ours came with the break up of Empire, yours may come when the world calls in your debts or builds walls to isolate your corrupt financial structures.

America was once admired and respected. Now it is increasingly like some blundering fat tourist in a brothel, people pretend to be nice to you because they want your money. But really, nobody is your friend.

Post reply on HN