Live data from Hacker News

How the NSA Plans to Infect “Millions” of Computers with Malware

firstlook.org

161–170 of 182 posts

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#161

Earlier quoted context omitted.

Do your own homework, you know how to use Google - so go use it .. a simple query "Microsoft collaborates with NSA" turns up enough reading material .. of course, unless you don't want it to be so easy to enlighten yourself on the issue, in which case no document is going to convince you of your position.

These guys are focusing narrowly on your choice of words ("delay fixes"). It was outed by the Guardian that Microsoft actively circumvents the security of some major products (Outlook, Skype) for the NSA. The Guadrian never released the Snowden doc for Microsoft collaboration [0]. Therefore, we don't the specifics of how. We just know that Microsoft backdoors its products for the federal government without telling it…

No, you just introduced an entirely different concern than the one introduced by the thread. The root comment suggests that Microsoft arranges to provide NSA with vulnerabilities that they deliberately do not patch so as to maximize their value to NSA. There is no evidence that anything like this has ever happened.

Your message is a red herring; I could debate your conclusions, but what would be the point? I'm sure you've got 10 more red herrings up your sleeve.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#162

Earlier quoted context omitted.

At the time when this was written, there was a clear distinction between times of peace and war. Nowadays, especially from the start of the "War on terror", this distinction has been artificially demolished; one of the consequences is that there is way more leverage to wark around laws (and to do many other nasty things).

I grant that funding for the War on Terror has taken place. But I also don't think that a real, formal declaration of war has been approved. So, is the USA at war or not? I suspect (but I'm only 52% certain) that we're not at war. The follow-on questions (after "are we at war or not?"): In what state are we? What are the legal ramifications of this half-at-war-state? Why hasn't the US Congress declared war since WW2?…

The US is in a state of war, under the "Authorization for Use of Military Force Against Terrorists" act (2001).

In particular, Section 2(b)(1): SPECIFIC STATUTORY AUTHORIZATION- Consistent with section 8(a)(1) of the War Powers Resolution, the Congress declares that this section is intended to constitute specific statutory authorization within the meaning of section 5(b) of the War Powers Resolution.

This has been tested under law[1]. Notably, that the US was in a state of war wasn't even considered worth arguing, just if that state of war provided justification for indefinite detention.

[1] http://en.wikipedia.org/wiki/Hedges_v._Obama

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#163

Earlier quoted context omitted.

> The remaining articles about NSA data collection have been about targeted programs. Cut the crap. * XKeyscore: NSA tool collects 'nearly everything a user does on the internet' [1] * NSA collecting phone records of millions of Verizon customers daily [2] * NSA taps Skype chats, newly published Snowden leaks confirm [3] * NSA collects millions of text messages daily in 'untargeted' global sweep [4] * Optic Nerve: mi…

Reread the source documents. XKeystore isn't a data collection program. It is a system for retrieving data and metadata already collected through data collection programs like PRISM. I mentioned the Verizon program in my previous post. As I said, it is one of only two NSA domestic bulk collection programs that Snowden's documents have revealed, and it's the only one that is ongoing. * The Skype chat collection is tar…

You may have missed the fact that other "five eyes" intelligence agencies conduct broad sweep data collection on US citizens, which is usually then shared with US agencies (the GCHQ Webcam program mentioned notes that it isn't clear if that program is shared with the NSA, but it also notes NSA documents protocols for dealing with webcam footage).

You'll note the NSA statement on this program was very carefully worked:

The NSA declined to respond to specific queries about its access to the Optic Nerve system, the presence of US citizens' data in such systems, or whether the NSA has similar bulk-collection programs.

However, NSA spokeswoman Vanee Vines said the agency did not ask foreign partners such as GCHQ to collect intelligence the agency could not legally collect itself.

A suspicious person might wonder why the spokesperson said the NSA "did not ask foreign partners" for intelligence it could not legally collect itself. Perhaps it is because they don't need to ask? We already know that intelligence sharing between the five eyes is very open (eg GCHQ used XKeystore to run the Yahoo program somehow), so it seems likely that the NSA has access to GCHQ intelligence on US citizens without asking for it.

I'm not entirely sure why your acknowledgement of the phone metadata tapping program makes it less of an issue, either!

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#164

Earlier quoted context omitted.

These guys are focusing narrowly on your choice of words ("delay fixes"). It was outed by the Guardian that Microsoft actively circumvents the security of some major products (Outlook, Skype) for the NSA. The Guadrian never released the Snowden doc for Microsoft collaboration [0]. Therefore, we don't the specifics of how. We just know that Microsoft backdoors its products for the federal government without telling it…

No, you just introduced an entirely different concern than the one introduced by the thread. The root comment suggests that Microsoft arranges to provide NSA with vulnerabilities that they deliberately do not patch so as to maximize their value to NSA. There is no evidence that anything like this has ever happened. Your message is a red herring; I could debate your conclusions, but what would be the point? I'm sure y…

My message is not a red herring. I did not make any conclusions of my own for you to debate. I was trying to add context (note that I replied to fit2rule, I wasn't challenging you). I quoted the Guardian and gave the reason there is no public Snowden document on the Microsoft NSA issue. Therefore, we don't know the specifics of their collaboration/cooperation. I do not dispute what you said about delayed patches, but it is meaningless without that context.

To be fair, there is not much daylight between: 'The root comment suggests that Microsoft arranges to provide NSA with vulnerabilities that they deliberately do not patch' and what the Guardian reported about Outlook. At least to me, but I'm not a security expert. Is it not considered a 'vulnerability' if Microsoft hands over the keys so to speak?

Also on a side note, it is rude to call me out like you did. I don't have herrings up my sleeves. I don't care about internet points. I just wanted to contribute more information to the discussion.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#165

Earlier quoted context omitted.

No, you just introduced an entirely different concern than the one introduced by the thread. The root comment suggests that Microsoft arranges to provide NSA with vulnerabilities that they deliberately do not patch so as to maximize their value to NSA. There is no evidence that anything like this has ever happened. Your message is a red herring; I could debate your conclusions, but what would be the point? I'm sure y…

My message is not a red herring. I did not make any conclusions of my own for you to debate. I was trying to add context (note that I replied to fit2rule, I wasn't challenging you). I quoted the Guardian and gave the reason there is no public Snowden document on the Microsoft NSA issue. Therefore, we don't know the specifics of their collaboration/cooperation. I do not dispute what you said about delayed patches, but…

No, that would not be considered a "vulnerability" in the sense used on this thread.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#166

Earlier quoted context omitted.

Luckily, our founding fathers built in a way to achieve the same effects as a revolution without any violence. If you were to start an armed insurrection, the government would be totally justified in ending you. Not a smart decision given today's level of technology. It was through sheer luck that the American revolution worked at all: the British commanders were so incredibly incompetent that they checkmated themsel…

> I, for one, continue to be excited about our drone overlords. Genuine question: why do hackers and obviously smart persons believe in this cargo-cult "founding fathers" concept? As if some guidelines set by some 18th century guys are the be all end all in running a state or even mean much after centuries of "interpretation" and changing conditions (including technology). Case in point 1: most of the things people n…

I think belief in the "founding fathers" comes down to a faith in systems design or the idea that there exists in theory a system which some sufficiently brilliant folks may devise which addresses the enduring human problem of "how do we all live together and get along" in some optimal way. The American system bequeathed to us by the so called founding fathers and refined over more than two centuries was an experiment that its participants and sponsors have largely portrayed as ideal, or at least flawed but superior to others, and always improving.

When a "geek" or systemically-thinking person wakes up politically, having realized that much is going deeply wrong, the first thing he or she is likely to do is to consult the founding documents which most of us were taught in civics class or for our various merit badges comprise the guide and inspiration for our civil governance. Seeing obvious departures from the design, it is not hard to seize onto the idea that to correct things we merely need to return to the design and follow the rules. Indeed that might improve things.

The difficulty of the various struggles to implement substantial changes is hardly an indictment of the system laid out by the founding fathers. Conservatism is the rule. It is wise to temper the passions of the people for radical changes which they may press to address temporary needs. The ultimate success of campaigns to extend suffrage, abolish child labor, end slavery and segregation, and even to rollback prohibition testify to the effectiveness of the system devised. It presumably worked as intended in those instances. It failed to prevent a war between the states, the death of 600,000 men, and much other injustice in more recent times.

One can find much wisdom and value in the writings, thinking and dialog that went on at the founding of the United States and surely a measure of nonsense too. It seems clear however leaders of that time sought to grapple with the problems of governance and cooperation sincerely and with a great deal of intellect and ability. They treated these issues as matters of vital importance in a way that seems quaint and removed from our decadent era -- that is unless you live in one of the many countries lacking material comforts, safety and political stability.

The problems they sought to address have not changed much since then. Human beings are what they are, technology not withstanding.

America is and remains an experiment on many levels. Ben Franklin's remark coming out of the constitutional convention about "A republic, madam, if you can keep it" is relevant today. This surveillance business could be the end of it. So could imperial overstretch and fiscal profligacy precipitating a collapse. Its also possible that the very different demographics of the country two and a half centuries after its founding render it simply ungovernable in the way or fashion imagined by the founders.

With particular regard to the Constitution and its merits, I believe I paraphrase Lysander Spooner in saying, it either has failed to prevent tyranny or in fact provides for it. If it is so, then the verdict would be the same either way. I am not certain I have better proposition but I do not have a blind faith that in order to cure our ills all we need to do is exhibit greater fidelity to the Constitution.

https://en.wikipedia.org/wiki/No_Treason

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#167
post #57
post #44

The NSA, breaking into US computers, is violating the Third Amendment, in my opinion. No Soldier shall, in time of peace be quartered in any house, without the consent of the Owner, nor in time of war, but in a manner to be prescribed by law.

Interesting angle. Perhaps if research were to show that "soldier" could be more broadly interpreted to mean "agent of security," you could really get some momentum going for this line of though. After all, we aren't required to keep other pieces of security enforcement in our homes, such as turrets on the roof controlled by the government. Keep it up.

There is a "War on terror" going on, as governments are very keen to point out all the time.

Who fights wars on behalf of their governments...

Ok, reasoning is a bit simplistic and technically inaccurate depending on your definition of "war" (congress approved etc.) but I do like hoisting by own petards.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#168
post #28

Earlier quoted context omitted.

No. None of this is accurate. Microsoft gets information about vulnerabilities from the same sources as everyone else. They outspend every other software vendor by something like 4:1 on outside software security consultants. If they are in a privileged position regarding WinAPI software vulnerabilities at all, it is a marginally privileged position. No security person working at Microsoft would tell you they were con…

Nothing you've uttered refutes the point - that Microsoft hand over vulnerabilities to the NSA, and delay fixing them. Read the docs.

You read the docs. http://technet.microsoft.com/en-us/security/dn467918

This is a publicly disclosed, publicly available program. Implying that it's somehow a government conspiracy is lying.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#169
post #85

Earlier quoted context omitted.

Nothing you've uttered refutes the point - that Microsoft hand over vulnerabilities to the NSA, and delay fixing them. Read the docs.

Feel free to cite the document that shows Microsoft delaying fixes for NSA.

The only official response from Microsoft that I can find is in reply to a question from Bloomberg [1] on this question. Frank Shaw, lead communications for Microsoft, responded by email to the question that, according to Bloomberg, information regarding 0day or other exploits are provided to a number of government agencies as an "early start", prior to public announcement.

The original email text is unavailable as far as I can see. It of course makes perfect sense that, at least under certain circumstances, and this was the sense of limit inferable from the email, that government agencies should be given the opportunity to assess whether the item being notified about has some security implication.

The claim is made by Bloomberg, by reference to "two unnamed government officials", that Microsoft is aware that such information might be applied for reasons not primarily connected to domestic defensive security. But this is only an unsubstantiated assertion.

The number of potential exploits that are known only to Microsoft at the time of notification to those agencies would be, at a lazy guess, somewhat proportional to their exploit assessment man hours, compared to the overall exploit discovery effort. I would think that would be the much smaller proportion.

1. http://mobile.bloomberg.com/news/2013-06-14/u-s-agencies-sai...

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#170
When I was in middle/highschool -- late 90's-03 -- using a mix of home-made tools, scripts I tweaked, some trojans I hex edited to make work for me...I had almost all of my schools home computers logging into an IRC room where I could use them to DoS attack and easily knock off (especially before few had broadband) anyone -- all my infected IRC clients could also upload, often around firewall/virus protection varying degrees of other trojans that let me print on their computers, watch them on webcams, open their cd-roms... I was young, told most people and really didn't abuse it: and finally learned 'hackers make things, crackers break things' -- but the point is: yes this isn't a surprise, and in many cases the sophistication is not even too deep, but ya like many said: we need this to keep being published so the open community as a whole can understand, and circumvent if need be.
Post reply on HN