Live data from Hacker News

How the NSA Plans to Infect “Millions” of Computers with Malware

firstlook.org

141–150 of 182 posts

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#141
post #85

Earlier quoted context omitted.

Feel free to cite the document that shows Microsoft delaying fixes for NSA.

Do your own homework, you know how to use Google - so go use it .. a simple query "Microsoft collaborates with NSA" turns up enough reading material .. of course, unless you don't want it to be so easy to enlighten yourself on the issue, in which case no document is going to convince you of your position.

I love seeing Tptacek being proven wrong as much as the rest of us; but this is just weak.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#142
post #55
post #27

Earlier quoted context omitted.

Firstly, your "founding fathers" - ha now there's a joke. Do you think anyone respects those amendments? Nope. If they thought that, you wouldn't be stocked up with weapons. And we all know how effective that technology is at ending all those pesky terrorists with their zip guns and IEDs...

Don't be defeatist. A key problem I see, that I used to have, and learned from my mistake, is that the checks and balances system works . Yes, you see the executive branch overstepping its bounds. Lots of people getting picked up. However, the judicial branch is finding the charges untenable. It's not easy nor automatic, and costs a lot of time and research and arguing, but those amendments are still pretty damn stro…

..you mean realist?

also, Brennan was sworn in on the consitutions without the bill of rights

http://www.theguardian.com/world/us-news-blog/2013/mar/08/jo...

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#143
post #141

Earlier quoted context omitted.

Do your own homework, you know how to use Google - so go use it .. a simple query "Microsoft collaborates with NSA" turns up enough reading material .. of course, unless you don't want it to be so easy to enlighten yourself on the issue, in which case no document is going to convince you of your position.

I love seeing Tptacek being proven wrong as much as the rest of us; but this is just weak.

I have no idea who Tptacek is, but - is it really so hard to pay attention? Microsoft collaborates with the NSA. Its in the docs, its been news for months.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#144
post #141

Earlier quoted context omitted.

I love seeing Tptacek being proven wrong as much as the rest of us; but this is just weak.

I have no idea who Tptacek is, but - is it really so hard to pay attention? Microsoft collaborates with the NSA. Its in the docs, its been news for months.

For something so obviously well known you seem to have difficulty providing evidence of your specific allegation (microsoft giving NSA advance notice of unpatched zero days.)

I don't doubt it happens, so much as I expect extraordinary claims be backed with extraordinary evidence.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#145
post #126

Earlier quoted context omitted.

> I, for one, continue to be excited about our drone overlords. Genuine question: why do hackers and obviously smart persons believe in this cargo-cult "founding fathers" concept? As if some guidelines set by some 18th century guys are the be all end all in running a state or even mean much after centuries of "interpretation" and changing conditions (including technology). Case in point 1: most of the things people n…

One of the values of a constitutional democracy is supposed to be that it reduces the impact of the "tyranny of the majority" . That is to say, that it reduces the likelihood that a simple majority of people will trivially be able to oppress minority populations. This works by setting up a base set of rules that cannot be violated even if a majority of people in the democracy want to. In order to change or amend thes…

Since you seem to have thought about this quite a bit, do you happen to know something you think works better?

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#146
post #141

Earlier quoted context omitted.

I love seeing Tptacek being proven wrong as much as the rest of us; but this is just weak.

I have no idea who Tptacek is, but - is it really so hard to pay attention? Microsoft collaborates with the NSA. Its in the docs, its been news for months.

I'm a little slow, my Googling skills suck, and I've been living under a rock for... let's just say "months". Can you spoon-feed me the exact article, line, and phrase where you got this idea that Microsoft delays fixing vulnerabilities at the NSA's behest?

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#147
post #90
post #70

Earlier quoted context omitted.

In the UK, we did manage to get the identity cards scheme killed and all the data collected destroyed . Admittedly it was still in the pilot stage. The key to effective political action is getting all the other existing politically active groups to realise that they don't want to do politics under surveillance either. Everyone from the NRA to the NAACP should oppose this. Talk about guns on the internet? It's trivial…

Offtopic, but I've always been surprised there wasn't more uproar over the passage of the Real ID Act. Basically a sneaky way to turn your state-issued driver license into a national ID card.

Could it happen? Sure, but the State would have to agree to it. I am pretty sure the majority would not do that. Now, a State to State registry would likely happen.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#148
post #6

Remember, Microsoft is part of this plot, even if they have "plausible deniability". Microsoft is giving NSA access to lists of vulnerabilities Windows has many months before Microsoft even begins to work on a fix. They are in effect helping NSA break into many computers, even if they are up to date. http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t... Every single one of these vulnerabilities could be see…

And this is why I'm glad my main OS is linux. Not impossible for NSA to get in but a lot more difficult.

I don't think it's hard at all for the NSA to hack your Linux install if you were manually targetted.

* The NSA probably has a few 0day exploits for typical Linux software ready. Remember that most critical servers use Linux and the NSA would love to get access to them.

* Even though you are tech-savvy and install most software from repositories, you probably will run some code which comes from a potentially compromisable source. This includes: Any kind of random "utility script", any installer that downloads data from the Internet, and any download of software from unencrypted HTTP.

* If you were savvy enough to protect yourself, they could even get someone to come to your house and install some backdoor to your system. Also, I guess the correlation between the people who take paranoid-level anti-hacking measures and people who they want to surveill is pretty high, so as unlikely as this may sound, I don't believe it's this impossible.

My particular take on it:

* Assume that everything you do on your regular install, whatever it is, may be compromissed and/or surveilled right now.

* If you want to do something anonymously, download TAILS. Check the integrity of the image with PGP and some other, random source. Burn it to a non-modifiable media and watermark it.

* If you want to store data securely, use something like TrueCrypt (TAILS includes it, though it's disabled by default). Use whole drive encryption. Do NEVER connect any unencrypted storage media in the same session you mount your volume unless you plan to wipe it immediately later. Do NEVER connect to the Internet in the same session you mount the volume. (If you want to send some of your encrypted volume data to the Internet, make a temporary partition to hold it. Put the data to it while offline, send it, then wipe it).

* If your unencrypted partitions have ever contained unencrypted data or you slip, consider them "tainted". You need to wipe them. (NOTE: SDDs and USB thumb drives are hard to securely erase. Either use at least 3 random whole-drive passes, or physically destroy them).

Yes, I'm a paranoid.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#149
post #125

Earlier quoted context omitted.

Hasn't there been enough evidence that the system the founding fathers built in has been compromised to the point of irrelevance? What you have today is an illusion of the freedom and the "equal and impartial justice under the law". http://www.popehat.com/2013/12/23/burn-the-fucking-system-to...

You're probably right. I think the Feinstein/CIA spying episode currently unfolding shows that the intelligence services have flipped the fuckit bit, and they don't even try to make it look like they're subject to Congressional oversight. They do still say they're subject, which I guess is something; they just don't try hard anymore to hide what they do .

> They do still say they're subject, which I guess is something

Nope, it's meaningless. What else are they going to say?

"It's exactly what it looks like! We just don't give a fuck about you or your rights, and in fact, we're an important part of the police state springing up all around you. When you're thinking of rebelling, remember we know where you live, where you are, and pretty much everything else about you! Stay in line, peasant!"

That would be fairly accurate, but they're not going to say it. Doesn't the propaganda just keep going anyway, even in North-Korea?

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#150
post #82

All of this sounds like excellent operational technology. I don't understand all the outrage here. If you sit down and ask yourself, "What kind of technology would I build if I wanted to infiltrate government/military networks of technologically sophisticated adversaries?", this is basically what you'd end up with. This is exactly the sort of thing I would expect the NSA to spend their time on.

I don't think the majority of people are outraged that a spy organisation spies. The things that have got most people rattled are:

a) The breadth of the spying, including many, many innocent people.

b) The long-term storage of data, likewise.

c) Deliberate weakening of security standards we all rely upon.

d) The fact it's all happening without democratic debate.

If instead of the above, they threw innocent people's data away, targeted their intrusions, engaged with the democratic mechanisms, and used their expertise to improve internet security, a lot of people would be much happier.

Post reply on HN