Live data from Hacker News

Your USB cable, the spy: Inside the NSA’s catalog of surveillance magic

arstechnica.com

11–20 of 32 posts

Re: Your USB cable, the spy: Inside the NSA’s catalog of surveillance magic

#11
IrateMonk is especially troubling - it installs itself on hard disk firmware, and supports all the major manufacturers: Western Digital, Seagate, Samsung etc. Now that it's known to exist, it's just a matter of time until some enterprising malware author will do the same...

Re: Your USB cable, the spy: Inside the NSA’s catalog of surveillance magic

#12

IrateMonk is especially troubling - it installs itself on hard disk firmware, and supports all the major manufacturers: Western Digital, Seagate, Samsung etc. Now that it's known to exist, it's just a matter of time until some enterprising malware author will do the same...

The callsigns have been there for a long time - only two or three weeks ago there was some guy who ran Linux on his harddrive. Literally. I think even the #badBIOS affair might have had its roots in a NSA black op gone bad... and nothing's off the radar anymore, these days.

Honestly, I wouldn't be surprised if there's a leak of a satellite with microwave/RF radar able to penetrate and fry electronic equipment in a centimetre-fine location.

Re: Your USB cable, the spy: Inside the NSA’s catalog of surveillance magic

#13
post #10

Unlike Snowden's disclosures of mass surveillance, this is not whistleblowing. Mass surveillance, such as recording and correlating cell phone location data or searching all emails, is immoral and unconstitutional, and it's good that the extent of it was revealed. Doctored USB cables do not enable mass surveillance since they have to be physically delivered to specific subjects. Assuming they're delivered based on so…

Yes, this "list of techniques" revealed by the German newspaper Der Spiegel is another thing that will be someday used against Snowden in a U.S. court...

Reason I say that is because as long as we're operating under the assumption that the U.S. will have a branch of the government somewhere that is able to engage in cyber-conflict activities (offensive or defensive), those cyber conflicts will be dependent upon weapons with which to fight them.

Even those who are mistrustful of NSA ever looking at domestic data seem to at least be aware that U.S. networks are constantly under attack (e.g. the Aurora attack on Google, countless attacks on U.S. defense contractors), and that it might be good for the U.S. to have similar capability.

And now the list of secret (cyber-)weapons is out for the whole world to see.

Contrast what would happen if this was a top-secret military weapons program (like, say, a stealth helicopter). How would the spy who leaked it have been treated?

Re: Your USB cable, the spy: Inside the NSA’s catalog of surveillance magic

#14
>One BIOS attack, called SWAP, was developed by the NSA to attack a number of types of computers and operating systems by loading surveillance and control software at boot-up. SWAP uses the Host Protected Area on a computer’s hard drive to store the payload and installs it before the operating system boots.

Won't the much maligned UEFI Secure Boot in Windows 8 stop this?

Re: Your USB cable, the spy: Inside the NSA’s catalog of surveillance magic

#15

>One BIOS attack, called SWAP, was developed by the NSA to attack a number of types of computers and operating systems by loading surveillance and control software at boot-up. SWAP uses the Host Protected Area on a computer’s hard drive to store the payload and installs it before the operating system boots. Won't the much maligned UEFI Secure Boot in Windows 8 stop this?

Yes, unless NSA has access to MS's signing keys, which I won't be surprised if they do.

Re: Your USB cable, the spy: Inside the NSA’s catalog of surveillance magic

#16
post #13
post #10

Unlike Snowden's disclosures of mass surveillance, this is not whistleblowing. Mass surveillance, such as recording and correlating cell phone location data or searching all emails, is immoral and unconstitutional, and it's good that the extent of it was revealed. Doctored USB cables do not enable mass surveillance since they have to be physically delivered to specific subjects. Assuming they're delivered based on so…

Yes, this "list of techniques" revealed by the German newspaper Der Spiegel is another thing that will be someday used against Snowden in a U.S. court... Reason I say that is because as long as we're operating under the assumption that the U.S. will have a branch of the government somewhere that is able to engage in cyber-conflict activities (offensive or defensive), those cyber conflicts will be dependent upon weapo…

That's assuming that these documents were given to Appelbaum by Snowden or Poitras:

https://twitter.com/ggreenwald/status/417325532980580353

Reading between the lines of the 30C3 talk, and the fact that none of this is credited to Snowden by Der Spiegel, I'd say there is a chance that another "whistleblower" is out there.

Re: Your USB cable, the spy: Inside the NSA’s catalog of surveillance magic

#17
post #8

NSA surely attracts some top talent, do they pay that well?

GS pay scale tops out in the low six figures, so to get around that they go through firms like Snowden's Booz Allen Hamilton. Now that a comprehensive picture of mass surveillance has emerged, an ethically unbothered engineer would be wise to recognize his or her increasing scarcity when negotiating salary.

Re: Your USB cable, the spy: Inside the NSA’s catalog of surveillance magic

#18

Monkeycalandar? Candygram? The names are ridiculous. It's like the whole place is staffed by 12 year olds who loved the "Spy Kids" movies.

They're probably generated from random numbers so that they reveal no information about what they are naming.

Look up "PGP word list", for example.

Re: Your USB cable, the spy: Inside the NSA’s catalog of surveillance magic

#19

IrateMonk is especially troubling - it installs itself on hard disk firmware, and supports all the major manufacturers: Western Digital, Seagate, Samsung etc. Now that it's known to exist, it's just a matter of time until some enterprising malware author will do the same...

These attacks have all been well understood as possible within the security community for years. People have demonstrated firmware exploits at security conferences and things like Microsoft's secure boot were explicitly designed to prevent this kind of threat.

Put another way, if you found that an intelligence agency had cool lock-picking tech would it change anything? Maybe it's surprisingly fast, leaves fewer traces, etc. but … it's not exactly a secret that they're in this business and this kind of thing is far less troubling than wide-scale surveillance because it still requires explicitly targeting specific people.

Re: Your USB cable, the spy: Inside the NSA’s catalog of surveillance magic

#20
post #6
post #2

It's really quite hard to stop admiring the technical lengths the NSA has gone to to exceed their constitutional bounds - radar-powered devices for snooping is genius!

Do you really think that tailored custom devices for spying on particular people of interests exceeds their constitutional grounds? Would you object to the NSA or CIA planting bugs that record audio or video on targets of interest outside of the United States? Does that exceed their constitutional grounds? How about if they supplied these to law enforcement agencies which had valid search warrants? I have plenty of c…

> Do you really think that tailored custom devices for spying on particular people of interests exceeds their constitutional grounds?

Do you really think that an agency that practices unconstitutional mass surveillance (or unconstitutional anything) would never use these recently revealed capabilities unconstitutionally?

Post reply on HN