HEY, KIDS! Do YOU know what time it is?! [wild audience applause] THAT'S RIGHT, it's time for WHICH IS MORE LIKELY? ! [intro music] Today on Which is More Likely? , we're looking at a replacement Lenovo Thinkpad keyboard that was shipped to Alexandria, Virginia, instead of Seattle, Washington. What a blunder! [slide whistle sound effect] Now put your thinking caps on and ponder, WHICH IS MORE LIKELY? ! • The largest…
Your tone and the overall lack of tact in your post is very off putting. Which is a shame as you have a marginally good point to make.
Did this Tor developer become a victim of NSA's laptop interception program?
101–110 of 169 posts
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#102Earlier quoted context omitted.
You're using public sources of information to refute theories of where a highly-secret and officially-denied program might operate. That makes no sense. Whatever office, department, or contractor does the NSA's package intercepts, all public sources will describe it as something innocent and unrelated.
The guy I responded to is using that some information to try to support the theories. Either the info is good, or it's not. I have no particular objection to saying, "this stuff would be secret so of course there would be no information on it". Oddly, nobody has actually tried that. However, that still goes back to the point I raised: why Alexandria? It's not particularly convenient to the NSA. It's not convenient to…
There's no point in debating speculations beyond that because we don't have any information for or against.
It's just me stating "hey, it's possible" and refuting your suggestion that there isn't anything in Alexandria that could cause concern. I'm only answering a question you asked.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#103You only phrase your headline as a question if the answer is No, but you really want it to be Yes.
It fits. The answer is almost certainly No (an honest mistake is far more likely, and nefarious activity wouldn't look like this anyway), and you can tell from the way they write (e.g. vastly exaggerating the import of the tracking info) that they deeply want this to be true.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#104Just googling for "funny delivery tracking route" for example will give you things like:
- 4 times over the ocean - http://i696.photobucket.com/albums/vv325/oneupmanship34/Fg0e...
- let's send it to Canada, 3 times - http://i30.photobucket.com/albums/c325/duffer987/UPSFTD_zps6...
- Germany, HK, Germany, HK, ... - http://laforge.gnumonks.org/fun/dhl-hk-leipzig-hk-leipzig-hk...
Getting a strange route within one country is probably an improvement compared to those...
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#105Earlier quoted context omitted.
I'll have to be explicit since this seems hard to understand: You're the NSA. Who do you trust more: A) (Perhaps the) CTO of a defense contractor that only works for you that you've had a 20 year working relationship with? B) The bright eyed young scientists working for that contractor in a building 3000 miles away? Or put another way, despite the Snowden leak, I'll bet you any amount of money that the NSA is still i…
You're right, it is pretty hard to understand. In one paragraph, you seem to be saying that the NSA wouldn't trust the employees of contractors. In the next paragraph, you tell me that the NSA is still "really fucking tight" with Booz Allen. These two ideas seem completely contradictory. But I think you might be suggesting that the NSA has given up on the low-level employees, and is now having the executives of these…
Not executives specifically but somebody trusted. That's more likely to be in the building where administration is done than anywhere else. Also you want to separate research from implementation. Your narrow refusal to even consider that there might be an interesting place for an agency to ship a laptop component to in Alexandria has taken this exercise way further than it needs to be to demonstrate the point.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#106The obvious explanation here is that the USPS fucked up. As the tweet says, you'd think the NSA program would be more subtle. Further, there isn't much in the way of intelligence presence in Alexandria. So what's more likely: that the NSA does this program in a secret location that's still right next to all the non-secret stuff, and they can't cover up the tracking data, or that the USPS accidentally sent a package t…
At this point aren't we all just guessing? Reading this thread I'm surprised how strongly many folks I respect (like you - viva FQ&A!) are insisting this could not be an NSA screw up. The truth is we don't know, so why rush to conclusions (even benign conclusions) instead of waiting to learn more? And imagine if you were Andrea and you develop software that dissidents around the world depend on with their life, while…
And I think you misunderstand. I am not arguing that it "could not be" the NSA. And I haven't see anyone say that. I am simply arguing that it is extremely unlikely.
It's a guess, yes, but it's an informed guess. It's a matter of looking at probabilities and seeing what's more likely. Shippers screw up all the time. Packages make crazy detours because somebody tossed a box in the wrong truck. A label falls off and a mixup occurs. Somebody typos a tracking number.
On the other hand, for this to be the NSA, several unlikely things would have to be true:
1. The NSA would need to be intercepting computer equipment destined for certain people and modifying it to spy on them.
2. The NSA would need to be targeting the person in question for this program.
3. The NSA would need to have set up this program in such a boneheaded way that it shows up on a package tracker. (If I were in charge of this program, I'd just set it up in FedEx's sorting facility in Memphis and then ensure all the relevant equipment uses FedEx. Simple, fast, and no chance of the target finding out.)
4. The NSA would need to have set up this program in Alexandria, even though it has little to recommend it for such a thing.
Now, we know that #1 is actually true. So that's one requirement fulfilled, out of several. But what about the rest?
I'm somewhat skeptical on #2. It's possible, but it seems unlikely. Why would the NSA target Tor developers? The security of Tor falls apart in the presence of an adversary that is able to monitor the entire internet, because you can just correlate traffic that enters with traffic that exits. The NSA can presumably monitor enough of the internet to defeat Tor right now. So why bother spying on Tor developers? It's possible as a belt-and-suspenders maneuver, but this person just doesn't strike me as a likely target.
I'm really skeptical on #3. It's about as believable as having the FBI spy on me by parking a van outside my house that says "Flowers By Irene". It's possible, but really unlikely.
And #4 doesn't make a whole lot of sense to me. Again, possible, but unlikely.
So we have one thing that's true, and then several other things that are individually unlikely, and combine to be really unlikely. It looks to me that people are committing the basic fallacy of thinking that the truth of #1, since it's unlikely, somehow makes the rest more likely too.
It comes down to this: is it a screwup by USPS or Amazon or a third-party reseller, or is it the NSA screwing up royally while trying to plant a bug? In the absence of evidence, we are stuck guessing, but we can guess intelligently by realizing that one is vastly more likely than the others.
"When you hear hoofbeats, think of horses not zebras."
That doesn't mean zebras are impossible. But it means you should prefer the more obvious explanation unless there's evidence to the contrary.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#107Then I read the article. The tacking data shows a delivery to a destination near the NSA.
Does anyone here seriously think that the mechanism the NSA uses if they want to tamper with a laptop on the way to simply change the destination address to be the NSA? And that no one has noticed this before?
If they are intercepting and modifying domestic shipments, the mechanism would be something that is executed AT the shipping carrier facilities or possibly during the final delivery, and would be completely transparent to outside observers, including both the sender and the receiver of the package.
Watch the "Modern Marvels" episode on package delivery for a look at how the automated package movement systems work at the major hubs, and you'll see how a package could be diverted for special treatment and then re-inserted into the system transparently, with most workers at the facility having no idea something special is going on.
The best chance at detecting this from outside would probably be to look at next day delivery orders on items that would be the most time consuming to modify, to see if those are more likely to miss their delivery deadline. The idea is that with such a tight schedule, the chances are higher than an interception will blow the delivery schedule. For items ordered with two day or longer shipment, the delay in modifying the item could be made up by upgrading it to one day delivery in the system when it is re-inserted. That's why observing one day delivery items is the best bet.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#108The amount of apologetic in this thread is hilarious. Do you all expect to see "SECRET NSA WAREHOUSE" on the packing slip?
The thing is "Would the NSA wanna bug a TOR developer's computer"? and the answer is "Damn, sure!".
So it's not as far fetched as many here believe imho - and NO there are not many better ways than this, I can't think of any.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#109Earlier quoted context omitted.
You're right, it is pretty hard to understand. In one paragraph, you seem to be saying that the NSA wouldn't trust the employees of contractors. In the next paragraph, you tell me that the NSA is still "really fucking tight" with Booz Allen. These two ideas seem completely contradictory. But I think you might be suggesting that the NSA has given up on the low-level employees, and is now having the executives of these…
You think along the narrowest lines of anyone of anyone I've ever held a conversation with. Not executives specifically but somebody trusted. That's more likely to be in the building where administration is done than anywhere else. Also you want to separate research from implementation. Your narrow refusal to even consider that there might be an interesting place for an agency to ship a laptop component to in Alexand…
For example, I live a couple of miles from the headquarters of Exxon Mobil. Yet it's about the last place I'd look if I wanted to find a trustworthy person to drill an oil well or build a gas pipeline.
Also, I'm not refusing to consider that Alexandria might be a viable destination for this. I merely think it's unlikely, especially compared to the "military and intelligence belt" language used in the post.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#110Earlier quoted context omitted.
It fits. The answer is almost certainly No (an honest mistake is far more likely, and nefarious activity wouldn't look like this anyway), and you can tell from the way they write (e.g. vastly exaggerating the import of the tracking info) that they deeply want this to be true.
Clearly, absence of evidence is evidence of conspiracy, and evidence to the contrary is propaganda. It's the only way to know for sure.