Live data from Hacker News

Did this Tor developer become a victim of NSA's laptop interception program?

privacysos.org

141–150 of 169 posts

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#141

Earlier quoted context omitted.

> You were anomalously naive. Now that type of thinking I find naive.

If you had to break the last 20 years into three time periods: (!) "post Snowden", (2) "post-9/11", and (3) "post PGP", sensitivity to government surveillance would rank 1-3-2. The NSA was a bigger deal in the 1990s than it was in the 2000s, even after the AT&T "Room 101" disclosure.

Technically, Room 641a. But, otherwise, spot-on.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#142
post #108
post #92

The amount of apologetic in this thread is hilarious. Do you all expect to see "SECRET NSA WAREHOUSE" on the packing slip?

Apparently, they do. Until Snowden releases something along the lines of "List with 1.500 gadgets that Amazon released that were bugged". Then suddenly we'll be like " Oh Jeez, I thought but it but I never really believed... ". The thing is "Would the NSA wanna bug a TOR developer's computer"? and the answer is "Damn, sure!". So it's not as far fetched as many here believe imho - and NO there are not many better ways…

Exactly. This is why many people in tech weren't that surprised by Snowden's leaks and were slightly relieved just to see all the suspicions verified. But most people seem to need a powerpoint explicitly stating what's going on before they believe it. Prior leaks from NSA defectors without hard proof had almost no recognition by the public. Even full in-depth exclusives from Washington Post didn't seem to affect people.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#143
post #31

Earlier quoted context omitted.

Oh, I like this game. Let's play again: WHICH IS MORE LIKELY?! * The world's largest online retailer that does $54M in sales per day has a bug in its procurement system that randomly transposes tracking codes. ORRRRRRRR! * The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviousl…

I don't understand. Richard's point doesn't depend on an Amazon bug that transposes tracking codes. But your point does depend on the NSA redirecting packages to Alexandria in such a way that anyone who checked their order status would notice.

No, he's saying that anyone who checked their order status shouldn't notice (by design), but maybe that part of the process failed this time.

Also, that failure might be technical or intentional. As I mentioned on another subthread, it's always possible this was "accidentally" exposed by an employee working at the merchant or postal service. The program would require their cooperation. After all, we first learned about the telco spying because telco employees spoke up.

As for whether it's conceivable that NSA would target a Tor developer? A few months they were spying on our close friends and allies simply because they could. If that same mindset were applied to the intercept program, then this isn't impossible to imagine. Just because the NSA and administration has finally recognized their overreach and has started backpedalling doesn't mean these programs change overnight.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#145
post #143
post #31

Earlier quoted context omitted.

I don't understand. Richard's point doesn't depend on an Amazon bug that transposes tracking codes. But your point does depend on the NSA redirecting packages to Alexandria in such a way that anyone who checked their order status would notice.

No, he's saying that anyone who checked their order status shouldn't notice (by design), but maybe that part of the process failed this time. Also, that failure might be technical or intentional. As I mentioned on another subthread, it's always possible this was "accidentally" exposed by an employee working at the merchant or postal service. The program would require their cooperation. After all, we first learned abo…

It is difficult to predict NSA actions, but opportunistically putting up inexpensive surveillance on all Tor users and nodes seems like a reasonable thing to do. As a developer she is a Tor user and also probably operates a few Tor nodes [for debugging and testing purposes]. So she would be in that group. I think this is plausible. I doubt that NSA would specifically target a Tor developer in US, without court order, as this would probably be illegal. [Although subverting some Tor developers, especially ones who build Tor binaries would be useful.]

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#146

I don't get the "installing malware" part. Every PC comes with malware already installed by most manufacturers. (Yes, if I have to spend time removing bloated stuff it's malware, I don't care if it's an "antivirus demo" or something like that) Now, if it's a hardware detail, this is more interesting.

(Yes, if I have to spend time removing bloated stuff it's malware, I don't care if it's an "antivirus demo" or something like that)

I don't like this, there is a reason there are different terms.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#147

Why would the NSA fuck with a TOR developer, when the federal government contributes a great deal of TOR code and actually runs exit nodes as a matter of research?

because it is two different divisions of the government that don't get along. And while the NSA may have the power to fuck with a Civilian TOR dev, if they were to start hacking Navy Intelligence they would get in a world of trouble.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#148
post #89

Earlier quoted context omitted.

Oh, I like this game. Let's play again: WHICH IS MORE LIKELY?! * The world's largest online retailer that does $54M in sales per day has a bug in its procurement system that randomly transposes tracking codes. ORRRRRRRR! * The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviousl…

The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviously high value target. A few comments: • This "low-level operative" was a system administrator who used social engineering to obtain other people's authentication credentials and gain access to material to which he wasn't aut…

All good points, and I'd second that Andrea is unlikely to be a "high value target" [BTW, curious, who is building and releasing Tor binaries and Tor dependencies binaries?]. Still, as a developer she is a Tor user and it is possible that NSA opportunistically targets all Tor users. And even if not, I'm still finding it distasteful that NSA can legally intercept post and put up dragnet surveillance. It feels like they are using legal loopholes too. Not fair.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#149
post #122

Earlier quoted context omitted.

> Internally, the keyboard and TrackPoint speak PS/2. While they could log keystrokes to an on-board chip and transmit keystrokes via radio, there aren't any especially interesting things the NSA can do to her laptop via a modified keyboard. They certainly won't be rooting it that way. This is a joke, right? A keyboard and a keylogger would give you everything you need to root a computer.

My point was that the modified keyboard alone couldn't do it. It's not a FireWire device that can read/write things from/to memory however it pleases, insta-pwning a computer as soon as it's connected (unless something like VT-d is being used to contain DMA transfers). It's not even a USB device that could abuse some poorly written driver to gain access. If a hypothetical modified keyboard is logging keystrokes, some…

What would you need DMA for?

Here's a fun thought exercise for you, since my first reply didn't spark one. Imagine you're an evil keyboard. What evil could you accomplish? Hint: you don't even need your own radio, the computer's already got one.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#150
post #136
post #122

Earlier quoted context omitted.

My point was that the modified keyboard alone couldn't do it. It's not a FireWire device that can read/write things from/to memory however it pleases, insta-pwning a computer as soon as it's connected (unless something like VT-d is being used to contain DMA transfers). It's not even a USB device that could abuse some poorly written driver to gain access. If a hypothetical modified keyboard is logging keystrokes, some…

Devil's advocate: you don't necessarily need all the data - the keystrokes are plenty valuable information on their own. Alternatively, such a keyboard could try to do something clever when a shell is focused, although it's risky.

You don't need a shell to be focused to run commands.
Post reply on HN