Live data from Hacker News

GNU hackers discover HACIENDA government surveillance

fsf.org

41–50 of 83 posts

Re: GNU hackers discover HACIENDA government surveillance

#41
post #22

Earlier quoted context omitted.

Gathering foreign intelligence. It's not like their overarching mission is a huge secret. http://www.nsa.gov/about/mission/index.shtml

At the expense of the sanity and security of those who the foreign intelligence is meant to protect? This is an obvious abuse with extreme existential consequences. Sort of reminds of this book I read as a kid: http://en.wikipedia.org/wiki/Momo_(novel)#Plot_summary

I think the assaults on your sanity are likely more the result of sensationalized/incomplete reporting. The biggest issue I have with most of the Snowden reporting is that if the article doesn't outright jump to assumptions that aren't supported by the source material, they usually have unanswered questions and written in such a way that would cause the reader to jump to the worst possible conclusion. I'm not sure on the entirety of what's actually going on, but the only hard facts I can gleam from the original article[1] are: 1) GCHQ has an nmap/zmap-like tool (not surprising) 2) the various intelligence agencies hack their targets (not surprising) 3) they apparently gain control of relays to obscure their tracks (potentially disconcerting, but makes sense...) 4) the only criteria that was discussed was the fact that the relays can't be located in Five-Eyes countries (Slide 18).

Bruce Schneier made a couple of observations on the slide decks[2]:

24 people were able to identify "a list of 3000+ potential ORBs" in 5-8 hours. The presentation does not go on to say whether all of those computers were actually infected.

...

The slides never say how many of the "potential ORBs" CSEC discovers or the computers that register positive in GCHQ's "Orb identification" are actually infected

Despite this, the article authors have no problem tossing in assertions not made in their source material, such as: "these spy agencies try to attack every possible system they can, presumably as it might provide access to further systems. Systems may be attacked simply because they might eventually create a path towards a valuable espionage target, even without actionable information indicating this will ever be the case." or "Thus, system and network administrators now face the threat of industrial espionage, sabotage and human rights violations created by nation-state ad- versaries indiscriminately attacking network infrastructure and breaking into services." Heck, as far as I can tell they apparently threw in Slide 9-16 (what appears to generic description of network hacking) solely so that they could include the phrase "The NSA presentation makes it clear that the agency embraces the mindset of criminals." (Neglecting to mention that the supposed "tools to support this criminal process" are a Wireshark dump of an ICMP ping response [Slide 14], what looks to be an FTP session labelled "Iraqi Ministry of Finance" showing an attempt at brute forcing the administrator account [Slide 15], and a screenshot of a freshly opened cmd.exe [Slide 16])

If the average person reads through this without looking at the text critically, they're going to walk away thinking "holy crap, they're hacking everyone!", which would indeed be terrifying. The problem is that the evidence needed to reach that conclusion isn't actually there. Nothing is shown regarding any actual process for selecting hosts to use as relays, or any actual number of hosts that they hack into. One commenter on the Schneier article[3] points out that they can't just indiscriminately gain control of hosts - the host isn't necessarily going to be reliable and the chances of them getting caught increase quickly as the number of hacked hosts increases. Nor do they mention if there is any effort to assess the potential political damage that may arise from the target selection. I'd be pretty pissed if I found out that my laptop was being covertly used to hack on their behalf, but on the other end of the scale I don't care if some random open SMTP server in Nigeria is being used by the NSA to spy on North Korea.

[1] http://www.heise.de/ct/artikel/NSA-GCHQ-The-HACIENDA-Program...

[2] https://www.schneier.com/blog/archives/2014/08/nsagchqcesc_i...

[3] https://www.schneier.com/blog/archives/2014/08/nsagchqcesc_i...

Re: GNU hackers discover HACIENDA government surveillance

#42
post #6

Disturbingly, the HACIENDA system actually hijacks civilian computers to do some of its dirty work, allowing it to leach computing resources and cover its tracks. Yeah, that is disturbing, and it should be made illegal.

I think it's already illegal.

Illegal they do right away. Unconstitutional takes a bit longer.

Re: GNU hackers discover HACIENDA government surveillance

#43
post #34
post #31

Ironically Jacob Appelbaum, allegedly an investigative journalist who reported this issue, is responsible for this project on GitHub that does exactly the same thing: https://github.com/ioerror/blockfinder

I disagree. I don't see where blockfinder is actually reaching out and pinging servers to see what's up where. blockfinder seems to be downloading well known data sources as to where IPs are. The project the government is being accused of doing is essentially running a distributed nmap along with geo information.

But Blockfinder is returning a full list of IPs of which you could perform nmap scans upon.

That's one step away from HACIENDA.

Re: GNU hackers discover HACIENDA government surveillance

#44
post #22

Earlier quoted context omitted.

At the expense of the sanity and security of those who the foreign intelligence is meant to protect? This is an obvious abuse with extreme existential consequences. Sort of reminds of this book I read as a kid: http://en.wikipedia.org/wiki/Momo_(novel)#Plot_summary

I think the assaults on your sanity are likely more the result of sensationalized/incomplete reporting. The biggest issue I have with most of the Snowden reporting is that if the article doesn't outright jump to assumptions that aren't supported by the source material, they usually have unanswered questions and written in such a way that would cause the reader to jump to the worst possible conclusion. I'm not sure on…

Thanks, this is the kind of response I was looking for. I was under the assumption, after reading a couple of articles that they were more or less hacking anything they could, and creating a network of vulnerable machines that could then be used as a relays.

I appreciate you taking the time to write this up - I will have to invest some time into going over these sources more carefully.

Re: GNU hackers discover HACIENDA government surveillance

#45

We are bored in the city, there is no longer any Temple of the Sun. Between the legs of the women walking by, the dadaists imagined a monkey wrench and the surrealists a crystal cup. That’s lost. We know how to read every promise in faces — the latest stage of morphology. The poetry of the billboards lasted twenty years. We are bored in the city, we really have to strain to still discover mysteries on the sidewalk bi…

Great post! Great link! What a writer! Some subsequent portions are really good: half a century earlier expression of Unabomber-style anti-technocratic sentiment imbued with the Parisian aesthetic. Dreams. Sunrise. Pre-brutalist architecture. Things society has almost forgotten, or banished to the Disneyland of yore... powered by travel selfies.

Re: GNU hackers discover HACIENDA government surveillance

#46
post #40
post #15

Earlier quoted context omitted.

For one, it's obviously quite good literature, of the "manifesto" style favored by modernist movements. Second, it makes perfect sense. It describes things seen in strolling around a city (Paris in this case), listing funny street names and shop titles. Plus some references to older art and poetry movements (namely dada and surealism), regarding their promise of a "fuller life" etc. Not sure what it has to do with TF…

Certainly not a room full of monkeys, but I'm having great difficulty trying to disprove the hypothesis that this wasn't just a Markov chain generator left to generate a few paragraphs.

In any case I guess the revelance of said paragraphs depends on what the Markov chain generator had been fed. Leaves me wondering if we are or can be, at times (and when), Markov chain generators.

Re: GNU hackers discover HACIENDA government surveillance

#47
post #39
post #6

Disturbingly, the HACIENDA system actually hijacks civilian computers to do some of its dirty work, allowing it to leach computing resources and cover its tracks. Yeah, that is disturbing, and it should be made illegal.

How disturbing and/or illegal should it be? I mean, I'm game to make it illegal if it's not already, and it probably already is illegal in the countries where that would be going on. But when I advocated the viewpoint that unauthorized access to computers was illegal and disturbing back with Aaron Swartz, that viewpoint didn't seem as popular at Hacker News for some reason. Likewise when Jeremy Hammond admitted to ha…

Personally while I thought that while Aaron Swartz was guilty of something, the charges DAs were pressing for were disgustingly and flagrantly incommensurate, and I was distressed at the abuse of government power.

I didn't really follow the Jeremy Hammond case, can't speak to it.

I don't really have a problem with penalties for computing crimes, but I firmly believe that the punishment should be commensurate with the crime.

The commonality with NSA and with Swartz is that you have heavy-handed authority figures flagrantly abusing their power with impunity. That's the part that I take issue with. Swartz was headed for a prison term and life as a felon for downloading a lot of documents he technically had legal access to (the issue was with the way he downloaded them). I don't think he didn't break any rules, but what he engaged in was in all respects a victimless crime. The NSA has abused its power in ways that are mind-boggling, lying to the Congress and continuing with illegal programs after being told to stop, abusing the privacy of the public in ways that have ramifications of such a scale that are hard to even sorted out, but nobody is seeing any justice for things that look like serious crimes. Nobody is even being charged with anything.

Comparing computing crimes of individuals vs. the government hacking citizen's computers and violating basic civil liberties is that the government engaging in the same act is doing something far more dangerous, harmful, and abusive, and the punishments should be far more severe, since the dangers from that abuse are far, far more serious, but instead they are non-existent.

Re: GNU hackers discover HACIENDA government surveillance

#48
I believe a civilian has portscanned the whole Internet before via the same thing: http://internetcensus2012.bitbucket.org/paper.html

I don't get all the fuss about portscanning is either - anything connected to the Internet will be subjected to packets sent to it because the Internet is public; if you don't want others, government or otherwise, to know that there's a machine present at an IP, then it should be your responsibility to configure it so it doesn't reply.

Re: GNU hackers discover HACIENDA government surveillance

#50

We are bored in the city, there is no longer any Temple of the Sun. Between the legs of the women walking by, the dadaists imagined a monkey wrench and the surrealists a crystal cup. That’s lost. We know how to read every promise in faces — the latest stage of morphology. The poetry of the billboards lasted twenty years. We are bored in the city, we really have to strain to still discover mysteries on the sidewalk bi…

http://en.wikipedia.org/wiki/Ivan_Chtcheglov

http://www.youtube.com/watch?v=2CQLAhNlbfQ
Post reply on HN