Live data from Hacker News

How the NSA Plans to Infect “Millions” of Computers with Malware

firstlook.org

171–180 of 182 posts

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#171
post #163

Earlier quoted context omitted.

Reread the source documents. XKeystore isn't a data collection program. It is a system for retrieving data and metadata already collected through data collection programs like PRISM. I mentioned the Verizon program in my previous post. As I said, it is one of only two NSA domestic bulk collection programs that Snowden's documents have revealed, and it's the only one that is ongoing. * The Skype chat collection is tar…

You may have missed the fact that other "five eyes" intelligence agencies conduct broad sweep data collection on US citizens, which is usually then shared with US agencies (the GCHQ Webcam program mentioned notes that it isn't clear if that program is shared with the NSA, but it also notes NSA documents protocols for dealing with webcam footage). You'll note the NSA statement on this program was very carefully worked…

A suspicious person might think a lot of things. In this case, a suspicious person was actually in their document systems with access to all the program info and didn't leak anything to confirm those suspicions.

Pointing out that I already mentioned the call log collection doesn't make that collection any less of an issue, but that's not why I pointed it out. The context is earlier in the thread.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#172
post #20

Earlier quoted context omitted.

Revolution is a tool of limited usefulness, and violent ones very often put something back in that is just as bad as what they ejected (see also: the KGB).

It's more complicated than that. ----->[ good times ]---->[ hard times ] ---> [fascism] --\ ^ | \-------------------[revolution] Revolution merely starts the cycle again. We'll always end up with the KGB, Stasi, NSA, GCHQ, CIA etc so you have to deconstruct society regularly to flush it out. We're stuck in a pretty long loop at the moment just verging on hard times. Edit: the "good times" above is optional.

I don't know if history supports the assertion that [revolution] leads to [good times]. I mean maybe on average, and maybe in the long run. However it seems to me the suffering the original government caused is dwarfed by the suffering of a violent revolution. Also that things don't improve as much as expected after the revolution, and that it can just end up a worse government, or lead to more conflict.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#173

Earlier quoted context omitted.

Luckily, our founding fathers built in a way to achieve the same effects as a revolution without any violence. If you were to start an armed insurrection, the government would be totally justified in ending you. Not a smart decision given today's level of technology. It was through sheer luck that the American revolution worked at all: the British commanders were so incredibly incompetent that they checkmated themsel…

Hasn't there been enough evidence that the system the founding fathers built in has been compromised to the point of irrelevance? What you have today is an illusion of the freedom and the "equal and impartial justice under the law". http://www.popehat.com/2013/12/23/burn-the-fucking-system-to...

No, there isn't. Democracy might not be great, but it is orders of magnitude better than not-democracy. The main function of democracy is to keep true tyrants out of power, and it's very effective at that.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#174

Earlier quoted context omitted.

At the time when this was written, there was a clear distinction between times of peace and war. Nowadays, especially from the start of the "War on terror", this distinction has been artificially demolished; one of the consequences is that there is way more leverage to wark around laws (and to do many other nasty things).

I grant that funding for the War on Terror has taken place. But I also don't think that a real, formal declaration of war has been approved. So, is the USA at war or not? I suspect (but I'm only 52% certain) that we're not at war. The follow-on questions (after "are we at war or not?"): In what state are we? What are the legal ramifications of this half-at-war-state? Why hasn't the US Congress declared war since WW2?…

I wasn't referring to a formal state of war (although somebody pointed out that it may exist), but to an informal one.

Under a certain perspecive, paradoxically, an informal state of war is worse than a formal one, because it's more subtle - it goes under the radar.

There has been a big shift in mindset towards accepting offensive practices as normal, which would not be accepted in a clear state of peace, or at least, which would force a much stronger opposition.

Mass surveillance? It's accepted, we're at war. Unaccounted (mass) murder of foreign civilians? It's accepted, we're at war. Torturing suspects? It's accepted, we're at war.

Except, we're not at war.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#175

Earlier quoted context omitted.

Hasn't there been enough evidence that the system the founding fathers built in has been compromised to the point of irrelevance? What you have today is an illusion of the freedom and the "equal and impartial justice under the law". http://www.popehat.com/2013/12/23/burn-the-fucking-system-to...

No, there isn't. Democracy might not be great, but it is orders of magnitude better than not-democracy. The main function of democracy is to keep true tyrants out of power, and it's very effective at that.

I would call the system in UK, US more of an elected dictatorship than a democracy, as the politicians are not representing anyone other than their corporate buddies.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#176
post #95

>computer servers I've been seeing this pattern a lot in nontechnical news recently, and have always been baffled as to what other kind of server there is (short of some basic network service implemented purely in logic gates, I guess).

>> computer servers > I've been seeing this pattern a lot in nontechnical news recently, and have always been baffled as to what other kind of server there is ... In this fast-breaking story, the expression "computer servers" has joined "software program" and "underground tunnel" at the Department of Redundancy Department.

Don't forget putting your PIN number into an ATM machine.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#177

Earlier quoted context omitted.

My message is not a red herring. I did not make any conclusions of my own for you to debate. I was trying to add context (note that I replied to fit2rule, I wasn't challenging you). I quoted the Guardian and gave the reason there is no public Snowden document on the Microsoft NSA issue. Therefore, we don't know the specifics of their collaboration/cooperation. I do not dispute what you said about delayed patches, but…

No, that would not be considered a "vulnerability" in the sense used on this thread.

Is the user more - or less - vulnerable to an attack? You're quite the pedant, whoever you are ..

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#178

Earlier quoted context omitted.

No, that would not be considered a "vulnerability" in the sense used on this thread.

Is the user more - or less - vulnerable to an attack? You're quite the pedant, whoever you are ..

I'll happily accept this as an admission that you don't have a source to back up your original (extraordinary) claim. Thanks.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#179

> By concealing its malware within what looks like an ordinary Facebook page, the NSA is able to hack into the targeted computer and covertly siphon out data from its hard drive. A top-secret animation demonstrates the tactic in action. Can anyone explain why they need to conceal it as a Facebook server? Why is that essential to infecting your computer? Why can't it just send you the malware, and then redirect you to…

It sounds like they are going after a vulnerability in the browser. My guess would be that do a man-in-the-middle attack where they have a device that acts as a proxy so you get YOUR Facebook page, but with an exploit injected into the code.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#180
post #144

Earlier quoted context omitted.

I have no idea who Tptacek is, but - is it really so hard to pay attention? Microsoft collaborates with the NSA. Its in the docs, its been news for months.

For something so obviously well known you seem to have difficulty providing evidence of your specific allegation (microsoft giving NSA advance notice of unpatched zero days.) I don't doubt it happens, so much as I expect extraordinary claims be backed with extraordinary evidence.

Start your homework engine:

http://www.bloomberg.com/news/2013-06-14/u-s-agencies-said-t...

http://arstechnica.com/security/2013/06/nsa-gets-early-acces...

Post reply on HN