Live data from Hacker News

Did this Tor developer become a victim of NSA's laptop interception program?

privacysos.org

151–160 of 169 posts

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#151
post #9

HEY, KIDS! Do YOU know what time it is?! [wild audience applause] THAT'S RIGHT, it's time for WHICH IS MORE LIKELY? ! [intro music] Today on Which is More Likely? , we're looking at a replacement Lenovo Thinkpad keyboard that was shipped to Alexandria, Virginia, instead of Seattle, Washington. What a blunder! [slide whistle sound effect] Now put your thinking caps on and ponder, WHICH IS MORE LIKELY? ! • The largest…

Oh, I like this game. Let's play again: WHICH IS MORE LIKELY?! * The world's largest online retailer that does $54M in sales per day has a bug in its procurement system that randomly transposes tracking codes. ORRRRRRRR! * The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviousl…

I work in e-commerce, we get bad/transposed tracking numbers entered into our systems all the freaking time.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#152
post #136
post #122

Earlier quoted context omitted.

My point was that the modified keyboard alone couldn't do it. It's not a FireWire device that can read/write things from/to memory however it pleases, insta-pwning a computer as soon as it's connected (unless something like VT-d is being used to contain DMA transfers). It's not even a USB device that could abuse some poorly written driver to gain access. If a hypothetical modified keyboard is logging keystrokes, some…

Devil's advocate: you don't necessarily need all the data - the keystrokes are plenty valuable information on their own. Alternatively, such a keyboard could try to do something clever when a shell is focused, although it's risky.

Right. Snag root or sudo password. Download rootkit. Execute.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#153
Really stupid move to post this on twitter before getting it. Should have just taken a screenshot then waited for it to show up. Then post the screenshot and have people analyze the keyboard.

By posting before getting the package, the NSA could see the Twitter post and give a non-modified one instead.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#154
post #122

Earlier quoted context omitted.

My point was that the modified keyboard alone couldn't do it. It's not a FireWire device that can read/write things from/to memory however it pleases, insta-pwning a computer as soon as it's connected (unless something like VT-d is being used to contain DMA transfers). It's not even a USB device that could abuse some poorly written driver to gain access. If a hypothetical modified keyboard is logging keystrokes, some…

What would you need DMA for? Here's a fun thought exercise for you, since my first reply didn't spark one. Imagine you're an evil keyboard. What evil could you accomplish? Hint: you don't even need your own radio, the computer's already got one.

Here's a nice example: http://www.blackhat.com/presentations/bh-usa-09/CHEN/BHUSA09...

"we describe how to tamper with a firmware upgrade to the Apple Aluminum Keyboard. We describe how an attacker can subvert an off-the-shelf keyboard by embedding into the firmware malicious code which allows a rootkit to survive a clean re-installation of the host operating system."

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#155
The real story here is a small segment of productive coders rightfully feel themselves focus of nation sized actors that threaten their work.

...

Also the large segment around them that still feel dismissive about their now confirmed fears.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#156
post #89

Earlier quoted context omitted.

Oh, I like this game. Let's play again: WHICH IS MORE LIKELY?! * The world's largest online retailer that does $54M in sales per day has a bug in its procurement system that randomly transposes tracking codes. ORRRRRRRR! * The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviousl…

The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviously high value target. A few comments: • This "low-level operative" was a system administrator who used social engineering to obtain other people's authentication credentials and gain access to material to which he wasn't aut…

[deleted]

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#157
post #136
post #122

Earlier quoted context omitted.

My point was that the modified keyboard alone couldn't do it. It's not a FireWire device that can read/write things from/to memory however it pleases, insta-pwning a computer as soon as it's connected (unless something like VT-d is being used to contain DMA transfers). It's not even a USB device that could abuse some poorly written driver to gain access. If a hypothetical modified keyboard is logging keystrokes, some…

Devil's advocate: you don't necessarily need all the data - the keystrokes are plenty valuable information on their own. Alternatively, such a keyboard could try to do something clever when a shell is focused, although it's risky.

Why when a shell is focused? Better to wait until the keyboard has been idle for some time, then send the keystrokes to open a shell, execute the needed commands, and close it afterward.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#158
post #132

Earlier quoted context omitted.

I would speculate that they might be interested in submitting a patch that compromises the Tor network in some subtle way that only they can exploit, and doing it in her name. Maybe added on to some other big change she submitted, in the hope that nobody will notice it. Seems the Tor project is using Git for all of their projects, so doing something like that would probably require pwning whatever system she's creati…

The Tor project was started by the US Navy, and receives 80% of its funding from the US Government. This is how you think they get them?

I don't really think that they're trying to break Tor like this. More of a thought experiment - to figure out the likelihood that this is part of an attempt to break Tor, run through the details of exactly how this would be part of such an attempt. It doesn't sound all that practical when you run though how it would work if it was. If they wanted to do it, you'd think they have better ways then a rather sloppy attempt to intercept a laptop keyboard shipment, if that's actually what this was, instead of an ordinary shipment screw-up.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#159
post #89

Earlier quoted context omitted.

Oh, I like this game. Let's play again: WHICH IS MORE LIKELY?! * The world's largest online retailer that does $54M in sales per day has a bug in its procurement system that randomly transposes tracking codes. ORRRRRRRR! * The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviousl…

The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviously high value target. A few comments: • This "low-level operative" was a system administrator who used social engineering to obtain other people's authentication credentials and gain access to material to which he wasn't aut…

That generated more response than I expected. I actually do agree that, on balance, it's somewhat more likely that it's just a benign glitch; I should have said that. What I was really taking issue with is the dismissiveness with you treated the suggestion that this might be an NSA attack. I was responding to what I saw as a slanted and unreasonable framing by doing the same thing from the other end.

So with less snark: I don't think it's exceedingly improbable at all, and whether ultimately it turns out to be the case or not, smugly guffawing the idea that the NSA may have used a trick like that isn't warranted. They really do intercept people's laptop shipments [1] to plant malware in them. They really do sneak tiny radio transmitters into end-user hardware. They really are trying to get backdoors into communication tools. I'll put it this way: if I worked on the kind of software Andrea works on, I would be seriously alarmed. Would you keep the keyboard?

On some specific points you made:

* That Snowden had access to other people's credentials seems like a serious operational shortcoming to me. The "low-level" part wasn't an attack on Snowden; the point is that a lot of people have that level of access. In general, the US intelligence apparatus makes a lot of well-publicized mistakes; I'm sure they make a great number of more subtle ones.

* On the NSA's shortcomings generally, I think this is actually nicely illustrative. Because a lot of the stuff Snowden revealed were things a lot of credible people already believed, based on things like weird locked server closets in telecom buildings and PRNGs that seemed fishy and pointless and heresay reports of requests for backdoor access to communication tools and so on. There was just little hard evidence before Snowden. And there won't be here either. So this is entirely consistent with the what the NSA was like in those decades where their programs "never saw the light of day".

* I think being a core Tor developer makes her high value target. It's hard to imagine the NSA wanting to subvert all the things it's subverted and not wanting to backdoor Tor. Keylogging her keyboard is a great way to do that, either by compromising her somehow, or by just stealing her credentials. So I don't follow the "it doesn't make any sense" line of thinking.

* That she's now tweeted about certainly makes it unlikely that, if the NSA has it, they'll go through with sending it bugged. But so?

Where I come out on this is that yes, it's probably nothing, but it should be treated with suspicion and carefulness, not laughed off because haha, what, do you think you're in a spy movie or something? Because, basically, we are.

[1] Yes, I know this is just the keyboard. I don't think that's a relevant difference.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#160
post #107

When I read the headline, and the comments here before reading the article, I was expecting to see tracking data that went from the seller to the buyer with a mysterious stop near the NSA. Then I read the article. The tacking data shows a delivery to a destination near the NSA. Does anyone here seriously think that the mechanism the NSA uses if they want to tamper with a laptop on the way to simply change the destina…

Genuinely curious about the Modern Marvels episode. Do you remember the exact name or season? I couldn't find it on iTunes.
Post reply on HN