HEY, KIDS! Do YOU know what time it is?! [wild audience applause] THAT'S RIGHT, it's time for WHICH IS MORE LIKELY? ! [intro music] Today on Which is More Likely? , we're looking at a replacement Lenovo Thinkpad keyboard that was shipped to Alexandria, Virginia, instead of Seattle, Washington. What a blunder! [slide whistle sound effect] Now put your thinking caps on and ponder, WHICH IS MORE LIKELY? ! • The largest…
Oh, I like this game. Let's play again: WHICH IS MORE LIKELY?! * The world's largest online retailer that does $54M in sales per day has a bug in its procurement system that randomly transposes tracking codes. ORRRRRRRR! * The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviousl…
Did this Tor developer become a victim of NSA's laptop interception program?
31–40 of 169 posts
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#32Earlier quoted context omitted.
But when that keyboard gets plugged into the motherboard of the laptop, it'll have an opportunity to install malware in the form of device drivers.
I don't believe HIDs have the ability to install arbitrary drivers. Windows will try to identify the device and locate the driver via Windows Update, or use a generic HID driver. Or the OEM may have preinstalled drivers. In any case, a malicious keyboard can simulate keypresses and pwn your machine that way. No evil driver needed.
Indeed: https://hakshop.myshopify.com/collections/usb-rubber-ducky/p...
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#33Earlier quoted context omitted.
The sad sad thing is, though, that in the '90s we made these jokes about surveillance cameras, internet taps, government-written-viruses, etc..etc... Seemed funny then, too.
No we did not. This is perhaps the most annoying meme to have come out of the Wikileaks and Snowden disclosures. Nobody working in technology laughed about dragnet surveillance or cryptanalysis capabilities or trojan horses. The 1990s was the era of Clipper and Echelon. People did not assume in the 1990s that the intelligence community was benign or disconnected. All you have to do is read _Applied Cryptography_ to s…
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#34Earlier quoted context omitted.
No we did not. This is perhaps the most annoying meme to have come out of the Wikileaks and Snowden disclosures. Nobody working in technology laughed about dragnet surveillance or cryptanalysis capabilities or trojan horses. The 1990s was the era of Clipper and Echelon. People did not assume in the 1990s that the intelligence community was benign or disconnected. All you have to do is read _Applied Cryptography_ to s…
[deleted]
If people were relying on television entertainers for informed political opinions in the '90s, they were already hopelessly lost.
It's hardly even 'back in the day' as you said. Network was released in theaters in 1976.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#35HEY, KIDS! Do YOU know what time it is?! [wild audience applause] THAT'S RIGHT, it's time for WHICH IS MORE LIKELY? ! [intro music] Today on Which is More Likely? , we're looking at a replacement Lenovo Thinkpad keyboard that was shipped to Alexandria, Virginia, instead of Seattle, Washington. What a blunder! [slide whistle sound effect] Now put your thinking caps on and ponder, WHICH IS MORE LIKELY? ! • The largest…
Oh, I like this game. Let's play again: WHICH IS MORE LIKELY?! * The world's largest online retailer that does $54M in sales per day has a bug in its procurement system that randomly transposes tracking codes. ORRRRRRRR! * The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviousl…
1. Amazon transposed a tracking code.
2. A third-party reseller transposed a tracking code.
3. USPS transposed a tracking code.
4. The tracking code is correct, but an error in USPS's backend showed tracking data for another shipment anyway.
5. The tracking code is correct, and the tracking data is correct, and the package went to Virginia because USPS screwed up.
I've personally seen #5, and none of the others are all that hard to believe.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#36HEY, KIDS! Do YOU know what time it is?! [wild audience applause] THAT'S RIGHT, it's time for WHICH IS MORE LIKELY? ! [intro music] Today on Which is More Likely? , we're looking at a replacement Lenovo Thinkpad keyboard that was shipped to Alexandria, Virginia, instead of Seattle, Washington. What a blunder! [slide whistle sound effect] Now put your thinking caps on and ponder, WHICH IS MORE LIKELY? ! • The largest…
Oh, I like this game. Let's play again: WHICH IS MORE LIKELY?! * The world's largest online retailer that does $54M in sales per day has a bug in its procurement system that randomly transposes tracking codes. ORRRRRRRR! * The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviousl…
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#37Earlier quoted context omitted.
Oh, I like this game. Let's play again: WHICH IS MORE LIKELY?! * The world's largest online retailer that does $54M in sales per day has a bug in its procurement system that randomly transposes tracking codes. ORRRRRRRR! * The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviousl…
I don't understand. Richard's point doesn't depend on an Amazon bug that transposes tracking codes. But your point does depend on the NSA redirecting packages to Alexandria in such a way that anyone who checked their order status would notice.
Part of this discussion seems based on a lack of understanding of the geography of the DC area. Alexandria is near these agencies, omg! But the fact is that there isn't much government in Alexandria. USPTO is there, and otherwise it's charming old houses, quirky shops, crappy strip malls, cookie-cutter suburbia, smallish high-rise apartments, railroad facilities, light industry, and other such similar things.
It's roughly like seeing your Mac get misdelivered to Richmond, CA and deciding that holy crap it's been intercepted by Apple on its way to me.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#38I don't get the "installing malware" part. Every PC comes with malware already installed by most manufacturers. (Yes, if I have to spend time removing bloated stuff it's malware, I don't care if it's an "antivirus demo" or something like that) Now, if it's a hardware detail, this is more interesting.
A few years ago we'd say this is all crazy conspiracy theory. Nowadays this this is just NSA's business as usual tactics [1].
[1] http://news.cnet.com/8301-1009_3-57616334-83/nsa-reportedly-...
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#39NSA contractor reveals mass surveillance on population
Independent journalists reporting on the topic has their home broken into
Independent article reports on NSA modifying laptops bound for "terrorists"
Tor developer notices laptop shipping traversing through the opposite direction
Tor developer is concerned and suspicious
The same people who didn't care about having their freedom to privacy breached claiming ITS CLEARLY A SHIPPING ERROR LOL.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#40Buy a new boxed computer with cash from a local supplier. I doubt the NSA has installed something on every single computer.
It may very well be that every single Linux system running on a recent or semi-recent CPU has a rdrand instruction returning a number "nullyfying" (from the NSA's point of view) the previous entropy sources XOR'ing.
You may call me "paranoid" but... Many people who were categorized as paranoids years ago turned out actually to be very, very far from the truth and not anywhere near paranoid enough.
I also remember a SNAFU years ago where a Windows version was compiled with some symbols left on and people started noticing variable named things like: "NSA_KEY". And, of course, lots of PR ensued and there was nothing to see and there were very reasonable explanation as to why there were NSA specific things in Windows.
Contrarily to you I believe it is very likely that most Windows and Apple OSes are backdoored by the NSA and I believe it's far from impossible that several piece of hardware are also backdoored.
I also think it's not impossible that several network cards have "kill switches" where a certain packet combination bricks the card . There have been weird reports out there from people seeing really strange things making such a possibility not science-fiction.