Did this Tor developer become a victim of NSA's laptop interception program?
121–130 of 169 posts
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#122Earlier quoted context omitted.
The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviously high value target. A few comments: • This "low-level operative" was a system administrator who used social engineering to obtain other people's authentication credentials and gain access to material to which he wasn't aut…
> Internally, the keyboard and TrackPoint speak PS/2. While they could log keystrokes to an on-board chip and transmit keystrokes via radio, there aren't any especially interesting things the NSA can do to her laptop via a modified keyboard. They certainly won't be rooting it that way. This is a joke, right? A keyboard and a keylogger would give you everything you need to root a computer.
If a hypothetical modified keyboard is logging keystrokes, someone has to eventually retrieve it to get the logged data. If it's transmitting keystrokes via radio, someone has to be nearby to capture them and then steal the laptop to get at its (presumably encrypted) data.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#123Earlier quoted context omitted.
> No we did not. The disdain with which you discard my memories of that time is... interesting. Invent distrust? Of course not. However, I and my colleagues (as I recall), at the time just did not take the threat of government surveillance seriously. Did I trust the government? Yes. Yes I did. I'm Dutch. We have a childlike faith in our government. Being spied on by the government was something that happened on the o…
You weren't just naive. You were anomalously naive. It's funny you should mention PGP: the 1990s were the time of the crypto-wars, which were in part sparked by PGP. Remember "this t-shirt is a munition"? You couldn't even sell products with crypto in them without jumping through hoops.
Now that type of thinking I find naive.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#124Earlier quoted context omitted.
> Further, there isn't much in the way of intelligence presence in Alexandria. ARE YOU SERIOUS? Come. On.
Would you care to refute that instead of just shouting? Like, point out something that contradicts it? Because I can't think of any, and I lived in Alexandria for seven years.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#125When I read the headline, and the comments here before reading the article, I was expecting to see tracking data that went from the seller to the buyer with a mysterious stop near the NSA. Then I read the article. The tacking data shows a delivery to a destination near the NSA. Does anyone here seriously think that the mechanism the NSA uses if they want to tamper with a laptop on the way to simply change the destina…
No that doesn't pass the giggle test. If it has anything at all to do with the NSA, it's a blunder.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#126Re: Did this Tor developer become a victim of NSA's laptop interception program?
#127HEY, KIDS! Do YOU know what time it is?! [wild audience applause] THAT'S RIGHT, it's time for WHICH IS MORE LIKELY? ! [intro music] Today on Which is More Likely? , we're looking at a replacement Lenovo Thinkpad keyboard that was shipped to Alexandria, Virginia, instead of Seattle, Washington. What a blunder! [slide whistle sound effect] Now put your thinking caps on and ponder, WHICH IS MORE LIKELY? ! • The largest…
Oh, I like this game. Let's play again: WHICH IS MORE LIKELY?! * The world's largest online retailer that does $54M in sales per day has a bug in its procurement system that randomly transposes tracking codes. ORRRRRRRR! * The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviousl…
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#128Earlier quoted context omitted.
Would you care to refute that instead of just shouting? Like, point out something that contradicts it? Because I can't think of any, and I lived in Alexandria for seven years.
NSA HQ, Ft Meade is 30 miles from Alexandria, Va.
Re: Did this Tor developer become a victim of NSA's laptop interception program?
#129Earlier quoted context omitted.
At this point aren't we all just guessing? Reading this thread I'm surprised how strongly many folks I respect (like you - viva FQ&A!) are insisting this could not be an NSA screw up. The truth is we don't know, so why rush to conclusions (even benign conclusions) instead of waiting to learn more? And imagine if you were Andrea and you develop software that dissidents around the world depend on with their life, while…
Yes, we are all just guessing. And I think you misunderstand. I am not arguing that it "could not be" the NSA. And I haven't see anyone say that. I am simply arguing that it is extremely unlikely. It's a guess, yes, but it's an informed guess. It's a matter of looking at probabilities and seeing what's more likely. Shippers screw up all the time. Packages make crazy detours because somebody tossed a box in the wrong…
Like you, I'm also a big proponent of Occam's razor. (Having been a med student, you don't know how many times I heard that "think horses not zebras" analogy from attendings.) I guess it just comes down to the degree of faith each of us has in the NSA and their corporate partners. Some of us are more willing to doubt their actions and/or believe it's possible they could screw up this way. But at this point we can only wait and see if we learn anything more in the coming days -- though probably not. One would hope the NSA is competent enough to cover this up, even if it was their screw up.
Added: BTW, there is another explanation that no one has mentioned. Leaving the Alexandria issue aside, the NSA interception program obviously relies on participation from one or more corporate partners. And just as we've seen at the telcos, it's reasonable to assume that there are staff at those partners who aren't particularly enthusiastic about the program. So it's possible someone decided to "accidentally" bypass/skip an important step that would have obscured this. It's not a huge leap to imagine a motivated techie realizing that this particular delivery would be an ideal opportunity to direct a lot of attention to the interception program -- if they felt compelled to take the risk. I'm definitely not saying this is the (or even a) likely possibility, but it's probably the only way we'll ever know if it was in fact the NSA.