Live data from Hacker News

How the NSA Plans to Infect “Millions” of Computers with Malware

firstlook.org

81–90 of 182 posts

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#82
All of this sounds like excellent operational technology. I don't understand all the outrage here. If you sit down and ask yourself, "What kind of technology would I build if I wanted to infiltrate government/military networks of technologically sophisticated adversaries?", this is basically what you'd end up with. This is exactly the sort of thing I would expect the NSA to spend their time on.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#83
post #20

Earlier quoted context omitted.

Revolution is a tool of limited usefulness, and violent ones very often put something back in that is just as bad as what they ejected (see also: the KGB).

It's more complicated than that. ----->[ good times ]---->[ hard times ] ---> [fascism] --\ ^ | \-------------------[revolution] Revolution merely starts the cycle again. We'll always end up with the KGB, Stasi, NSA, GCHQ, CIA etc so you have to deconstruct society regularly to flush it out. We're stuck in a pretty long loop at the moment just verging on hard times. Edit: the "good times" above is optional.

I think you might want to add an intermediate state, of [ Possibly Very Bad Times ] as a possible consequence of revolution before returning to Good Times. It's not a quick fix, not a panacea.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#84

At some point, laptops, displays, and handheld devices started carrying built-in microphones and cameras as a feature. Perhaps the new feature is devices that don't have these things? To use a mic or camera, you'd explicitly have to plug it in and could physically unplug it later.

Better then, to have hardware switches similar to the iPhone lock switch.

I'd welcome that in general! Make the switch open up the camera app directly, and a similar one for the mics; binding it to your phone or recording app, depending on what you prefer.

Make each switch a LED which -if they are- signals ON-state as the screen is turned on or off.

Edit: And incoming call screen would have to reflect the mic being off, in which case flicking the switch would accept the call.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#85
post #28

Earlier quoted context omitted.

No. None of this is accurate. Microsoft gets information about vulnerabilities from the same sources as everyone else. They outspend every other software vendor by something like 4:1 on outside software security consultants. If they are in a privileged position regarding WinAPI software vulnerabilities at all, it is a marginally privileged position. No security person working at Microsoft would tell you they were con…

Nothing you've uttered refutes the point - that Microsoft hand over vulnerabilities to the NSA, and delay fixing them. Read the docs.

Feel free to cite the document that shows Microsoft delaying fixes for NSA.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#86
post #20

Earlier quoted context omitted.

It's more complicated than that. ----->[ good times ]---->[ hard times ] ---> [fascism] --\ ^ | \-------------------[revolution] Revolution merely starts the cycle again. We'll always end up with the KGB, Stasi, NSA, GCHQ, CIA etc so you have to deconstruct society regularly to flush it out. We're stuck in a pretty long loop at the moment just verging on hard times. Edit: the "good times" above is optional.

Luckily, our founding fathers built in a way to achieve the same effects as a revolution without any violence. If you were to start an armed insurrection, the government would be totally justified in ending you. Not a smart decision given today's level of technology. It was through sheer luck that the American revolution worked at all: the British commanders were so incredibly incompetent that they checkmated themsel…

George Washington was a British commander too, as a Colonel in the British Army.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#87
post #20

Earlier quoted context omitted.

Revolution is a tool of limited usefulness, and violent ones very often put something back in that is just as bad as what they ejected (see also: the KGB).

It's more complicated than that. ----->[ good times ]---->[ hard times ] ---> [fascism] --\ ^ | \-------------------[revolution] Revolution merely starts the cycle again. We'll always end up with the KGB, Stasi, NSA, GCHQ, CIA etc so you have to deconstruct society regularly to flush it out. We're stuck in a pretty long loop at the moment just verging on hard times. Edit: the "good times" above is optional.

There is a relevant theory on the topic: https://en.wikipedia.org/wiki/Strauss%E2%80%93Howe_generatio...

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#88
post #5

After a while all these news items about the NSA and GCHQ can seem a bit too much, but not if we take a step back and really understand the enormity of it all. The NSA and its cohorts set up fake Facebook websites, spoof security certificates, secretly record webcam streams, vacuum up everything they can lay their hands on etc. Meanwhile the CIA coolly wipes hundreds of documents from the machines of those who are in…

Don't be so melodramatic. There are solutions. Also, they don't "vacuum up everything they can lay their hands on." According to this article, they exploit on the order of tens of thousands of systems and have a control system to pull data and recordings from targeted users.

If you combine this article with the dozens of others from the past ~year, the vacuum analogy is not at all hyperbolic.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#89
Through all of the news articles and the analyses I have read, I still don't understand how exactly all of this works. I understand the MITM concept, but the Man-On-The-Side parts boggle m:

"When a target attempts to log in to the social media site, the NSA transmits malicious data packets that trick the target’s computer into thinking they are being sent from the real Facebook. By concealing its malware within what looks like an ordinary Facebook page, the NSA is able to hack into the targeted computer and covertly siphon out data from its hard drive."

Where is the security hole? My network card? OS? Browser? But then there are so many layers in there. Is it a specially malformed ICMP packet? Or is it a vulnerability in the OS's RPC functions? It's one thing to exploit a vulnerability in Java or Flash, but just using "malicious packets"?

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#90
post #70
post #5

After a while all these news items about the NSA and GCHQ can seem a bit too much, but not if we take a step back and really understand the enormity of it all. The NSA and its cohorts set up fake Facebook websites, spoof security certificates, secretly record webcam streams, vacuum up everything they can lay their hands on etc. Meanwhile the CIA coolly wipes hundreds of documents from the machines of those who are in…

In the UK, we did manage to get the identity cards scheme killed and all the data collected destroyed . Admittedly it was still in the pilot stage. The key to effective political action is getting all the other existing politically active groups to realise that they don't want to do politics under surveillance either. Everyone from the NRA to the NAACP should oppose this. Talk about guns on the internet? It's trivial…

Offtopic, but I've always been surprised there wasn't more uproar over the passage of the Real ID Act. Basically a sneaky way to turn your state-issued driver license into a national ID card.
Post reply on HN