Live data from Hacker News

Inside the Operating System Edward Snowden Used to Evade the NSA

wired.com

11–20 of 83 posts

Re: Inside the Operating System Edward Snowden Used to Evade the NSA

#12
It's worth noting that Tails doesn't make you impervious. Tails uses Tor, and Tor is vulnerable to NSA and GCHQ attacks. Specifically, they have the capability of deanonymizing individual targets. I hypothesize that this capability works by monitoring Tor traffic worldwide, then performing a timing correlation between an origin and an endpoint.

Here's an example: Let's say (for the sake of example please) that the NSA can passively monitor Google searches in realtime. Let's say you search for a phrase that sets off their monitor: something like "a Tor user has Googled for Snowden." They'd like to know who you are. How would they do that?

One way is to record the fact that from your home computer originated some Tor traffic at almost the same time the Google search took place.

It's unclear exactly how they deanonymize Tor users, but one piece of info that may corroborate my hypothesis is that in a Snowden screenshot, you can see the NSA has a tab called "Tor Events" in one of their tools.

The need for websites to load quickly is Tor's Achilles heel, because it enables timing correlation. The fact that few people use Tor exacerbates the problem.

Re: Inside the Operating System Edward Snowden Used to Evade the NSA

#13
Some alternatives: Whonix: (vm isolated or hardware device isolated, tor) https://www.whonix.org/ and Qubes OS: (sandboxing different processes, needs torVM to do tor things) http://qubes-os.org/trac

A nice comparison: https://www.whonix.org/wiki/Comparison_with_Others

Re: Inside the Operating System Edward Snowden Used to Evade the NSA

#14
post #9

Earlier quoted context omitted.

Yes, the BBC News at Ten told us that "the website Mumsnet has warned its 1.5 million users that their data may have been hacked as a result of the Heartbleed computer bug. It's the first time the virus has been found on a British website"

I have found the BBC's Technology reporting particularly irksome. Their website is filled with re-hashed press releases. I even re-wrote an article concerning turning urea into electricty for them to show what it could have been like if they had put half an hour's effort into it, naturally I didn't even get a response.

Of course not. They thought that you were taking the piss in a shocking way.

I did once mail a correction to a story about a new EU regulation which had been a high profile item across BBC News. It was quite a fundamental thing, and I got a short mail from a senior editor, thanking me and angrily lamenting that it wasn't a difficult thing for his reporter to check, state of journalists these days, etc etc. The story was changed.

--edit: make a bad pun worse.

Re: Inside the Operating System Edward Snowden Used to Evade the NSA

#15
You can hack SD cards actually unlike the article states, Bunny's blog post and presentation at Chaos Computer Congress mentions of this possibility. SD cards have microcontrollers and with enough resources their guess flash media can be subverted. Diversity of these controllers and variety of "proprietary" standards the way these flash controllers work however can be the entropy that makes SD controller hacking very unlikely - but you never know.

http://www.bunniestudios.com/blog/?p=3554

my 2c

Re: Inside the Operating System Edward Snowden Used to Evade the NSA

#17

The article suggests security because "all of the Tails code is open source, so it can be inspected by anyone worried about foul play." Yeah, that worked out well for openssl.

Yes it did. The heartbleed bug was found during an audit of the open source of openssl.

Re: Inside the Operating System Edward Snowden Used to Evade the NSA

#18

You can hack SD cards actually unlike the article states, Bunny's blog post and presentation at Chaos Computer Congress mentions of this possibility. SD cards have microcontrollers and with enough resources their guess flash media can be subverted. Diversity of these controllers and variety of "proprietary" standards the way these flash controllers work however can be the entropy that makes SD controller hacking very…

also, in your hdd controller(s) http://spritesmods.com/?art=hddhack.

same stuff, too many cpu everywhere, making protocols meaningless.

Re: Inside the Operating System Edward Snowden Used to Evade the NSA

#19
post #13

Some alternatives: Whonix: (vm isolated or hardware device isolated, tor) https://www.whonix.org/ and Qubes OS: (sandboxing different processes, needs torVM to do tor things) http://qubes-os.org/trac A nice comparison: https://www.whonix.org/wiki/Comparison_with_Others

This table is also interesting:

https://www.whonix.org/wiki/Comparison_with_Others#Attacks

Re: Inside the Operating System Edward Snowden Used to Evade the NSA

#20
post #4

Another Debian based boot-from-CD OS that used to be quite popular is Knoppix [1]. I remember that was a big thing in the times of Win98 viruses when people used it for system recovery. In Germany they distributed it as add-on to computer magazines. [1] https://en.wikipedia.org/wiki/Knoppix

Knoppix and Slax were my first foray into Linux as a teenager. The latter also introduced me to the terminal, in my quest force it to boot from a HDD... Many a partition died that week.
Post reply on HN