Live data from Hacker News

How the NSA Plans to Infect “Millions” of Computers with Malware

firstlook.org

31–40 of 182 posts

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#31

Earlier quoted context omitted.

Actually its been remarkably effective in other countries, have you been reading the news? Our own soldiers have not been terribly effective at pacifying unrest, and the locals have nothing but rifles etc.

It's kind of interesting to think about. Remember the hullabaloo just after the Boston bomber lit off the bomb but wasn't caught yet? Imagine all of that societal rage focused on a small group of people who have started an armed conflict and killed a few policemen, and you can imagine how quickly that group will be annihilated.

Yeah, you suppose one person - easy to find and contain. But a diffuse population of unrest? Impossible.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#32
> By concealing its malware within what looks like an ordinary Facebook page, the NSA is able to hack into the targeted computer and covertly siphon out data from its hard drive. A top-secret animation demonstrates the tactic in action.

Can anyone explain why they need to conceal it as a Facebook server? Why is that essential to infecting your computer? Why can't it just send you the malware, and then redirect you to the real Facebook (since their mission is accomplished anyway)?

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#33
post #7

Remember, Microsoft is part of this plot, even if they have "plausible deniability". Microsoft is giving NSA access to lists of vulnerabilities Windows has many months before Microsoft even begins to work on a fix. They are in effect helping NSA break into many computers, even if they are up to date. http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t... Every single one of these vulnerabilities could be see…

This. Very frustrating as I work with a Microsoft-oriented company at the moment. Any mention of this to their architectural team results in nothing short of "mwuhahaha you're talking shit". There is some weird universal trust there that really makes no sense at all. To add insult to injury they don't log, don't have an IDS and don't have a clue stick to hit themselves with. Their funeral!

MS's program to provide information on upcoming security issues to large customers isn't anything sinister. It's an obvious step to achieve a better overall security by allowing larger users to mitigate damage before a patch is available.

You can spin it as a secret NSA-program, but I don't think that's very useful as this program does legitimately help a ton of users.

(Not that it really would excuse things, but I'd be very surprised if intelligence agencies don't have people inside companies like Microsoft anyways.)

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#34
post #27

Earlier quoted context omitted.

Luckily, our founding fathers built in a way to achieve the same effects as a revolution without any violence. If you were to start an armed insurrection, the government would be totally justified in ending you. Not a smart decision given today's level of technology. It was through sheer luck that the American revolution worked at all: the British commanders were so incredibly incompetent that they checkmated themsel…

Firstly, your "founding fathers" - ha now there's a joke. Do you think anyone respects those amendments? Nope. If they thought that, you wouldn't be stocked up with weapons. And we all know how effective that technology is at ending all those pesky terrorists with their zip guns and IEDs...

And we all know how effective that technology is at ending all those pesky terrorists with their zip guns and IEDs...

Those people have been indoctrinated since birth to see us as evil invaders. Some of their religions have baked in the idea that it's good to die in order to kill invaders. And we've sometimes acted like an evil invader. (See Blackwater atrocities, etc.) It's an invalid comparison because our population isn't motivated in the same way.

It's easy to become disheartened with the current state of affairs, but history has shown that ignoring reality doesn't work. Setting aside the question of ethics, the reality is that an armed revolution in America probably can't happen. And besides, there are plenty of other options to explore.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#35
post #13
post #5

After a while all these news items about the NSA and GCHQ can seem a bit too much, but not if we take a step back and really understand the enormity of it all. The NSA and its cohorts set up fake Facebook websites, spoof security certificates, secretly record webcam streams, vacuum up everything they can lay their hands on etc. Meanwhile the CIA coolly wipes hundreds of documents from the machines of those who are in…

Yes it's called a revolution at which point we storm the bases and burn the data centres and monitoring stations to the ground. But, as Huxley was so keen to point out, that's not going to happen when people are staring at Honey Boo Boo and Hollyoaks.

Let's say we do that and then what? The NSA/GCHQ decides to build a fully decentralized spy network. Millions of nodes connected all over the place; a botnet of spying. Sound familiar?

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#36
post #7

Remember, Microsoft is part of this plot, even if they have "plausible deniability". Microsoft is giving NSA access to lists of vulnerabilities Windows has many months before Microsoft even begins to work on a fix. They are in effect helping NSA break into many computers, even if they are up to date. http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t... Every single one of these vulnerabilities could be see…

This. Very frustrating as I work with a Microsoft-oriented company at the moment. Any mention of this to their architectural team results in nothing short of "mwuhahaha you're talking shit". There is some weird universal trust there that really makes no sense at all. To add insult to injury they don't log, don't have an IDS and don't have a clue stick to hit themselves with. Their funeral!

Probably because they don't care about any of that. They probably care about releasing products and making clients happy.

Also, mwuhahaha you're talking shit.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#37

Prediction: If this goes on long enough, NSA (and other entities) will accidentally create Skynet.

That won't happen, because SkyNet is already created. It's their management infrastructure. This proves once more management is evil. (this post is false)

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#38
post #6

Remember, Microsoft is part of this plot, even if they have "plausible deniability". Microsoft is giving NSA access to lists of vulnerabilities Windows has many months before Microsoft even begins to work on a fix. They are in effect helping NSA break into many computers, even if they are up to date. http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t... Every single one of these vulnerabilities could be see…

And this is why I'm glad my main OS is linux. Not impossible for NSA to get in but a lot more difficult.

While Linux is probably slightly harder for a sophisticated attacker (and a lot harder for a unsophisticated one), a lot of your protection probably comes from the fact that they spend most of their time targeting the 98% of the desktop software base- that isn't Linux. Of course maybe their server oriented efforts make this moot.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#39
post #22

Earlier quoted context omitted.

> I use Ubuntu, take that NSA! You're cute.

Close... It's Arch though.

So the only thing the NSA has to do is hack/convince/rendition/break-into-house a single person who holds a package signing key, and then they can MITM your pacman updater and have you as well.

And there's enough people with such a key to choose from: https://www.archlinux.org/master-keys/.

(I run Arch as well, but I have no such illusions of security.)

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#40
post #5

After a while all these news items about the NSA and GCHQ can seem a bit too much, but not if we take a step back and really understand the enormity of it all. The NSA and its cohorts set up fake Facebook websites, spoof security certificates, secretly record webcam streams, vacuum up everything they can lay their hands on etc. Meanwhile the CIA coolly wipes hundreds of documents from the machines of those who are in…

Yes, it is possible. Stop being defeatist, you're doing NSA/GCHQ propaganda for them for free.

>for free

How do you know r0h1n is doing this for free?

Post reply on HN