Live data from Hacker News

How the NSA Plans to Infect “Millions” of Computers with Malware

firstlook.org

131–140 of 182 posts

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#131
post #5

After a while all these news items about the NSA and GCHQ can seem a bit too much, but not if we take a step back and really understand the enormity of it all. The NSA and its cohorts set up fake Facebook websites, spoof security certificates, secretly record webcam streams, vacuum up everything they can lay their hands on etc. Meanwhile the CIA coolly wipes hundreds of documents from the machines of those who are in…

One word for you: sedition. Its gonna happen.

" Sedition often includes subversion of a constitution ..." https://en.wikipedia.org/wiki/Sedition

Ah, so that's the NSA's game.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#132

>computer servers I've been seeing this pattern a lot in nontechnical news recently, and have always been baffled as to what other kind of server there is (short of some basic network service implemented purely in logic gates, I guess).

There are servers at restaurants.

also both in and on courts. :)

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#133
post #29
post #7

Earlier quoted context omitted.

This. Very frustrating as I work with a Microsoft-oriented company at the moment. Any mention of this to their architectural team results in nothing short of "mwuhahaha you're talking shit". There is some weird universal trust there that really makes no sense at all. To add insult to injury they don't log, don't have an IDS and don't have a clue stick to hit themselves with. Their funeral!

As if having an IDS would make a difference.

You're right - it wouldn't but at least it'd look like they gave a crap.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#134
That's strange. If ever I tried to build a botnet with millions of nodes I'd surely be thrown in prison for years at least. Probably decades. But if I've learned anything in my short time on this planet, it's to always commit your crimes behind the corporate or government veils. Preferably both.

Edit:

https://prod01-cdn02.cdn.firstlook.org/wp-uploads/2014/03/ha...

Mirror: http://i.imgur.com/JbLqxAY.jpg

Fuckin' hell. I think we can consider the internet more than owned. More like bent over and pounded.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#135
post #82

All of this sounds like excellent operational technology. I don't understand all the outrage here. If you sit down and ask yourself, "What kind of technology would I build if I wanted to infiltrate government/military networks of technologically sophisticated adversaries?", this is basically what you'd end up with. This is exactly the sort of thing I would expect the NSA to spend their time on.

Exactly. So much of the article is about capabilities with little context for how broadly it is applied. Even the "millions" in the title is just about the server capacity for managing the infected computers, and later they admit that the actual number of computers is an order of magnitude less.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#136

Earlier quoted context omitted.

Don't be so melodramatic. There are solutions. Also, they don't "vacuum up everything they can lay their hands on." According to this article, they exploit on the order of tens of thousands of systems and have a control system to pull data and recordings from targeted users.

If you combine this article with the dozens of others from the past ~year, the vacuum analogy is not at all hyperbolic.

Two NSA bulk collection programs have been outed: the NSA collects call log metadata to this day, and they used to collect email headers from unencrypted email deliveries entering or leaving the US until a few years ago. The remaining articles about NSA data collection have been about targeted programs.

Though I disagree with some of their methods, they are not vacuuming up everything they can get their hands on by a long shot, and spreading ggp's view distracts from solving the problems with what they are doing.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#137
post #85

Earlier quoted context omitted.

Nothing you've uttered refutes the point - that Microsoft hand over vulnerabilities to the NSA, and delay fixing them. Read the docs.

Feel free to cite the document that shows Microsoft delaying fixes for NSA.

Do your own homework, you know how to use Google - so go use it .. a simple query "Microsoft collaborates with NSA" turns up enough reading material .. of course, unless you don't want it to be so easy to enlighten yourself on the issue, in which case no document is going to convince you of your position.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#139
post #124

Earlier quoted context omitted.

It seems to me that they are sending out packets identifying themselves as facebook. If you're not using SSL this is expected to be possible. If you are using SSL to communicate with FB then it's likely that the NSA has the private keys for FB's SSL certificates.

Right, I think this is referring to a technique described in some of the earlier info releases, where the agency intercepts requests and send a fake response before the real one arrives, and ditching the real response. I'm not clear on the details - it may rely on spoofing the server's IP, falsifying DNS replies and/or manipulating data in transit. What interests me more, and what the above poster may be asking about…

Yup, your second paragraph nails it. But even then, it boarders on XSS or some hybrid injection attack which would rely on a vulnerability somewhere else up the stack. The way I understood a lot of this article, I'm lead to believe that their able to monitor/intercept a target's requests, imitate the web server and send replies which are so meticulously malformed that they are able to infect the target system.

Like I said in my post and which you echo in your third paragraph, it's one thing to trick users into downloading and running binaries or to exploit a plugin, but it's another thing to imagine malformed packets breaking the security of an entire system.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#140
Since they see everyone as a potential threat, taint their data so that everyone appears to be that threat. Millions of us could increase the signal-to-noise ratio in their collected data by using a bot to perform random human-like web searches and visits.

If 100 people are searching for , the government has actionable surveillance data. If 100 thousand or 10 million are searching for it in ways that are indistinguishable from a human, then that data becomes unreliable and is no longer actionable.

Adding email to this would strike a fatal blow. Someone could figure a way to create a secure layer to inform a client when a given email being sent was fake, and thus suppress it visually. Soon from the government perspective everyone would be cheating on their spouses and spouting extremist views and plotting this or that.

This would result in an increase in liberty by proving to the government that it should fear its people, if only because its sophisticated surveillance tools now confirm that all the people are evil.

Post reply on HN