Live data from Hacker News

How the NSA Plans to Infect “Millions” of Computers with Malware

firstlook.org

11–20 of 182 posts

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#12
post #3

“When they deploy malware on systems,” Hypponen says, “they potentially create new vulnerabilities in these systems, making them more vulnerable for attacks by third parties.” Really, how does that work Mikko? You don't even have a copy of any malware to make that statement. All the hyperbole about how this is somehow unique is really getting old. Exploit kit authors have had shitty PHP web applications that accompli…

> All the hyperbole about how this is somehow unique is really getting old.

The big news is that the most powerful people on the planet are now using the same script-kiddie techniques against the rest of the world, in secret, without oversight, on an industrial scale.

EDIT: Judging from your github account, you appear to be a developer working on a open-source whistleblower platform. Given that the NSA's efforts would likely be focused on the users applications such as yours, do you not find these revelations to be directly relevant to your goals in developing this software?

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#13
post #5

After a while all these news items about the NSA and GCHQ can seem a bit too much, but not if we take a step back and really understand the enormity of it all. The NSA and its cohorts set up fake Facebook websites, spoof security certificates, secretly record webcam streams, vacuum up everything they can lay their hands on etc. Meanwhile the CIA coolly wipes hundreds of documents from the machines of those who are in…

Yes it's called a revolution at which point we storm the bases and burn the data centres and monitoring stations to the ground.

But, as Huxley was so keen to point out, that's not going to happen when people are staring at Honey Boo Boo and Hollyoaks.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#14
post #5

After a while all these news items about the NSA and GCHQ can seem a bit too much, but not if we take a step back and really understand the enormity of it all. The NSA and its cohorts set up fake Facebook websites, spoof security certificates, secretly record webcam streams, vacuum up everything they can lay their hands on etc. Meanwhile the CIA coolly wipes hundreds of documents from the machines of those who are in…

Yes, it is possible. Stop being defeatist, you're doing NSA/GCHQ propaganda for them for free.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#15
post #3

“When they deploy malware on systems,” Hypponen says, “they potentially create new vulnerabilities in these systems, making them more vulnerable for attacks by third parties.” Really, how does that work Mikko? You don't even have a copy of any malware to make that statement. All the hyperbole about how this is somehow unique is really getting old. Exploit kit authors have had shitty PHP web applications that accompli…

Hypponen said "potentially" and it is an absolutely defensible statement. You go around poking holes in a system, don't be surprised if other people find the holes. You gonna trust the guy who hacked your machine to lock the door behind him on the way out?

>All the hyperbole about how this is somehow unique is really getting old.

The issue isn't that the spooks have developed some superweapon. The issue is that they've signaled intent and means to do mass espionage on citizens, not just at the network level, but at the machine level. This is as if your local law enforcement handed out burglars tools to all their officers so they could get into everyone's homes "to check for drugs". "Eh, burglars tools are nothing special" totally misses the point.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#16
post #3

“When they deploy malware on systems,” Hypponen says, “they potentially create new vulnerabilities in these systems, making them more vulnerable for attacks by third parties.” Really, how does that work Mikko? You don't even have a copy of any malware to make that statement. All the hyperbole about how this is somehow unique is really getting old. Exploit kit authors have had shitty PHP web applications that accompli…

Definition of the word 'potential' cited in the Oxford Dictionary.

"Having or showing the capacity to develop into something in the future"

Or alternatively

"Having possibility, capability, or power."

Or in Merrium-Webster:

"expressing possibility ; specifically : of, relating to, or constituting a verb phrase expressing possibility, liberty, or power by the use of an auxiliary with the infinitive of the verb (as in “it may rain”)"

I can see no difficulty in the authors expression of the idea of possibility.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#17
An implant plug-in named CAPTIVATEDAUDIENCE, for example, is used to take over a targeted computer’s microphone and record conversations taking place near the device. Another, GUMFISH, can covertly take over a computer’s webcam and snap photographs. FOGGYBOTTOM records logs of Internet browsing histories and collects login details and passwords used to access websites and email accounts. GROK is used to log keystrokes. And SALVAGERABBIT exfiltrates data from removable flash drives that connect to an infected computer.

Will all the conspiracy theorists come out of the woodwork, please. We need your help.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#18
post #13
post #5

After a while all these news items about the NSA and GCHQ can seem a bit too much, but not if we take a step back and really understand the enormity of it all. The NSA and its cohorts set up fake Facebook websites, spoof security certificates, secretly record webcam streams, vacuum up everything they can lay their hands on etc. Meanwhile the CIA coolly wipes hundreds of documents from the machines of those who are in…

Yes it's called a revolution at which point we storm the bases and burn the data centres and monitoring stations to the ground. But, as Huxley was so keen to point out, that's not going to happen when people are staring at Honey Boo Boo and Hollyoaks.

Revolution is a tool of limited usefulness, and violent ones very often put something back in that is just as bad as what they ejected (see also: the KGB).

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#19
post #17

An implant plug-in named CAPTIVATEDAUDIENCE, for example, is used to take over a targeted computer’s microphone and record conversations taking place near the device. Another, GUMFISH, can covertly take over a computer’s webcam and snap photographs. FOGGYBOTTOM records logs of Internet browsing histories and collects login details and passwords used to access websites and email accounts. GROK is used to log keystroke…

And I can't even keep Evolution from needing my password every few minutes.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#20
post #13

Earlier quoted context omitted.

Yes it's called a revolution at which point we storm the bases and burn the data centres and monitoring stations to the ground. But, as Huxley was so keen to point out, that's not going to happen when people are staring at Honey Boo Boo and Hollyoaks.

Revolution is a tool of limited usefulness, and violent ones very often put something back in that is just as bad as what they ejected (see also: the KGB).

It's more complicated than that.

   ----->[ good times ]---->[ hard times ] ---> [fascism] --\
      ^                                                     |
      \-------------------[revolution] 
Revolution merely starts the cycle again. We'll always end up with the KGB, Stasi, NSA, GCHQ, CIA etc so you have to deconstruct society regularly to flush it out.

We're stuck in a pretty long loop at the moment just verging on hard times.

Edit: the "good times" above is optional.

Post reply on HN