Live data from Hacker News

Did this Tor developer become a victim of NSA's laptop interception program?

privacysos.org

11–20 of 169 posts

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#11
The obvious explanation here is that the USPS fucked up. As the tweet says, you'd think the NSA program would be more subtle. Further, there isn't much in the way of intelligence presence in Alexandria. So what's more likely: that the NSA does this program in a secret location that's still right next to all the non-secret stuff, and they can't cover up the tracking data, or that the USPS accidentally sent a package to the wrong place?

Edit: I want to emphasize how incredibly stupid the article is when analyzing the tracking data. Key quote:

"From Dulles, it moved another four times around the military and intelligence belt in suburban Washington DC, finally landing in Alexandria at 11:03 am on January 23."

First of all, there is nothing significant to Dulles. It's the largest airport in the area, and this makes it the arrival point for any packages coming in by air. 90% of my packages have a "Dulles, VA" tracking entry on them by the time they get to me.

Second, it didn't move "four times". It went from Dulles to a carrier facility in Alexandria, then it went out for delivery and got delivered. That's two moves. And how many times do you expect it to move? That's how air-based package delivery works. It goes to an airport. Then it goes to a local sorting facility. Then it goes out for delivery.

Third, the phrase "military and intelligence belt" is ridiculous. Especially so when the only two locations involved are Dulles and Alexandria, neither of which has much in the way of either military nor intelligence.

The article tries way too hard to make its case, and uses a great deal of purple prose to state what comes down to, "the package got delivered to Alexandria, VA which is close to a lot of government agencies". That would actually be more convincing than the insanity they wrote, although still not very convincing. But at least it would be honest.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#13
post #9

HEY, KIDS! Do YOU know what time it is?! [wild audience applause] THAT'S RIGHT, it's time for WHICH IS MORE LIKELY? ! [intro music] Today on Which is More Likely? , we're looking at a replacement Lenovo Thinkpad keyboard that was shipped to Alexandria, Virginia, instead of Seattle, Washington. What a blunder! [slide whistle sound effect] Now put your thinking caps on and ponder, WHICH IS MORE LIKELY? ! • The largest…

The sad sad thing is, though, that in the '90s we made these jokes about surveillance cameras, internet taps, government-written-viruses, etc..etc...

Seemed funny then, too.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#15

I don't get the "installing malware" part. Every PC comes with malware already installed by most manufacturers. (Yes, if I have to spend time removing bloated stuff it's malware, I don't care if it's an "antivirus demo" or something like that) Now, if it's a hardware detail, this is more interesting.

Not all malware can be removed the way you remove that antivirus demo. From the Der Spiegel article[1]:

> Take, for example, when they intercept shipping deliveries. If a target person, agency or company orders a new computer or related accessories, for example, TAO can divert the shipping delivery to its own secret workshops. The NSA calls this method interdiction. At these so-called "load stations," agents carefully open the package in order to load malware onto the electronics, or even install hardware components that can provide backdoor access for the intelligence agencies. All subsequent steps can then be conducted from the comfort of a remote computer.

Naturally, if they also load a keyboard logger or whatever, no amount of formatting that new laptop would help.

[1] http://www.spiegel.de/international/world/the-nsa-uses-power...

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#16
post #9

HEY, KIDS! Do YOU know what time it is?! [wild audience applause] THAT'S RIGHT, it's time for WHICH IS MORE LIKELY? ! [intro music] Today on Which is More Likely? , we're looking at a replacement Lenovo Thinkpad keyboard that was shipped to Alexandria, Virginia, instead of Seattle, Washington. What a blunder! [slide whistle sound effect] Now put your thinking caps on and ponder, WHICH IS MORE LIKELY? ! • The largest…

Your tone and the overall lack of tact in your post is very off putting. Which is a shame as you have a marginally good point to make.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#17
post #6
post #3

I'm a bit confused here. On the bottom right, it says that the package contained a replacement keyboard, and not an actual laptop.

But when that keyboard gets plugged into the motherboard of the laptop, it'll have an opportunity to install malware in the form of device drivers.

I don't believe HIDs have the ability to install arbitrary drivers. Windows will try to identify the device and locate the driver via Windows Update, or use a generic HID driver. Or the OEM may have preinstalled drivers.

In any case, a malicious keyboard can simulate keypresses and pwn your machine that way. No evil driver needed.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#18
post #9

HEY, KIDS! Do YOU know what time it is?! [wild audience applause] THAT'S RIGHT, it's time for WHICH IS MORE LIKELY? ! [intro music] Today on Which is More Likely? , we're looking at a replacement Lenovo Thinkpad keyboard that was shipped to Alexandria, Virginia, instead of Seattle, Washington. What a blunder! [slide whistle sound effect] Now put your thinking caps on and ponder, WHICH IS MORE LIKELY? ! • The largest…

Maybe this is Amazon/USPS's shipping version of the warrant canary? If Apple does it...

Imagine that we're not in the US for a second and that this were a journalist? Would your opinion of what happened change?

It would have to be a mis-delivery at least instead of a "wrong tracking number". How likely is it that Amazon would ship something from a CA warehouse and it take more than 2 days to get to Seattle? Also keep in mind that USPS does Saturday delivery.

Also, nice defense of the NSA, but keep in mind this is the same intelligence agency that gave pretty much unfettered document access to independent contractor Systems Administrators.

Post reply on HN