Live data from Hacker News

GNU hackers discover HACIENDA government surveillance

fsf.org

51–60 of 83 posts

Re: GNU hackers discover HACIENDA government surveillance

#51
post #47
post #39

Earlier quoted context omitted.

How disturbing and/or illegal should it be? I mean, I'm game to make it illegal if it's not already, and it probably already is illegal in the countries where that would be going on. But when I advocated the viewpoint that unauthorized access to computers was illegal and disturbing back with Aaron Swartz, that viewpoint didn't seem as popular at Hacker News for some reason. Likewise when Jeremy Hammond admitted to ha…

Personally while I thought that while Aaron Swartz was guilty of something, the charges DAs were pressing for were disgustingly and flagrantly incommensurate, and I was distressed at the abuse of government power. I didn't really follow the Jeremy Hammond case, can't speak to it. I don't really have a problem with penalties for computing crimes, but I firmly believe that the punishment should be commensurate with the…

> The commonality with NSA and with Swartz is that you have heavy-handed authority figures flagrantly abusing their power with impunity.

Read csandreasen's comment: https://news.ycombinator.com/item?id=8205642

Whatever else NSA's been doing, it hasn't been "with impunity", it's been in coordination with allied intelligence agencies (including the German BND that was spying on Turkey, Kerry, and Clinton...), and as Snowden's own leaks demonstrate, a ton of oversight within and without NSA, the intelligence community, and the Executive branch itself.

Likewise with Swartz, it's not the prosecutors' fault that the evidence of what Swartz did was sufficient to cause a grand jury to indict on charges that could easily lead to a 1-2 year sentence (as admitted even by Jennifer Granick, no friend to the DOJ here).

> I don't think he didn't break any rules, but what he engaged in was in all respects a victimless crime.

Mapping the Internet is a victimless crime too. Hell, even hijacking computers to aid in proxying those port scans is a victimless crime. Spammers running botnets on Aunt Edna's Windows 98 box is a victimless crime, so I hope you have something better than that.

> Comparing computing crimes of individuals vs. the government hacking citizen's computers and violating basic civil liberties

Did you read the linked article? NSA isn't hacking citizen's computers, except maybe for citizens in non-Five Eyes countries. Likewise NSA wasn't the one who lied to Congress, but then I can't expect people to keep the agencies that most risk their civil liberties straight now can I? :)

And the tradeoff with "far more severe punishments" even for civil servants trying to stay within the law, is naturally "far less severe restrictions" on operation of those civil servants.

If the deal is "you can do whatever is right and proper, but screw up and you go to Leavenworth" then I'd argue that the civil liberties impact would be much more of a net negative. Putting restraints and oversight and restrictive policy and all the rest is much safer IMHO, but the tradeoff there is that when government agencies make a good-faith effort to stay within those restrictions (as even the Snowden leaks have indicated with regard to NSA) that you wouldn't expect heads to roll even if a court later disagrees.

Re: GNU hackers discover HACIENDA government surveillance

#52

We are bored in the city, there is no longer any Temple of the Sun. Between the legs of the women walking by, the dadaists imagined a monkey wrench and the surrealists a crystal cup. That’s lost. We know how to read every promise in faces — the latest stage of morphology. The poetry of the billboards lasted twenty years. We are bored in the city, we really have to strain to still discover mysteries on the sidewalk bi…

http://en.wikipedia.org/wiki/Ivan_Chtcheglov

And the original French version is here:

http://debordiana.chez.com/francais/is1.htm#formulaire

Re: GNU hackers discover HACIENDA government surveillance

#53
post #51
post #47

Earlier quoted context omitted.

Personally while I thought that while Aaron Swartz was guilty of something, the charges DAs were pressing for were disgustingly and flagrantly incommensurate, and I was distressed at the abuse of government power. I didn't really follow the Jeremy Hammond case, can't speak to it. I don't really have a problem with penalties for computing crimes, but I firmly believe that the punishment should be commensurate with the…

> The commonality with NSA and with Swartz is that you have heavy-handed authority figures flagrantly abusing their power with impunity. Read csandreasen's comment: https://news.ycombinator.com/item?id=8205642 Whatever else NSA's been doing, it hasn't been "with impunity", it's been in coordination with allied intelligence agencies (including the German BND that was spying on Turkey, Kerry, and Clinton...), and as Sn…

...it's not the prosecutors' fault that the evidence of what Swartz did was sufficient to cause a grand jury to indict...

...a ham sandwich.

Please, let's not pretend that anything happens in a grand jury that is not completely controlled by prosecutors.

Re: GNU hackers discover HACIENDA government surveillance

#54
post #13
post #8

Good luck port scanning ipv6 at random. I really hope all this some day is just some horrible chapter in a book that remembers how governments used to spy on their own citizens and how crazy that seems to everyone "now".

If you have access to a few routers, you could probably generate a good list of valid ipv6 addresses.

Isn't the local network block always at least a /64 or /80 or so? Thus even knowing which blocks are handed out means you still have an IPv4-Internet-sized task for each one.

Re: GNU hackers discover HACIENDA government surveillance

#55
post #51
post #47

Earlier quoted context omitted.

Personally while I thought that while Aaron Swartz was guilty of something, the charges DAs were pressing for were disgustingly and flagrantly incommensurate, and I was distressed at the abuse of government power. I didn't really follow the Jeremy Hammond case, can't speak to it. I don't really have a problem with penalties for computing crimes, but I firmly believe that the punishment should be commensurate with the…

> The commonality with NSA and with Swartz is that you have heavy-handed authority figures flagrantly abusing their power with impunity. Read csandreasen's comment: https://news.ycombinator.com/item?id=8205642 Whatever else NSA's been doing, it hasn't been "with impunity", it's been in coordination with allied intelligence agencies (including the German BND that was spying on Turkey, Kerry, and Clinton...), and as Sn…

"but the tradeoff there is that when government agencies make a good-faith effort to stay within those restrictions (as even the Snowden leaks have indicated with regard to NSA) that you wouldn't expect heads to roll even if a court later disagrees."

We must live in parallel universes, only bridged by a single message thread. Since in my universe your account of the NSA is a bizarro-world inversion of what we have here, I am pretty jealous of you getting to live there.

Re: GNU hackers discover HACIENDA government surveillance

#56
post #10

I can't really take much more of this... What is their goal?

Gathering foreign intelligence. It's not like their overarching mission is a huge secret. http://www.nsa.gov/about/mission/index.shtml

I find it quite amusing they don't roll with SSL/TLS on their website.

Re: GNU hackers discover HACIENDA government surveillance

#57

We are bored in the city, there is no longer any Temple of the Sun. Between the legs of the women walking by, the dadaists imagined a monkey wrench and the surrealists a crystal cup. That’s lost. We know how to read every promise in faces — the latest stage of morphology. The poetry of the billboards lasted twenty years. We are bored in the city, we really have to strain to still discover mysteries on the sidewalk bi…

I somehow doubt that GCHQ geeks read anti-modernist manifestos.

Depending on the age of the name pickers, I'd say they either went to the Hacienda nightclub at Manchester or saw 24 hours party people[1].

1: http://www.imdb.com/title/tt0274309/

Re: GNU hackers discover HACIENDA government surveillance

#58

I believe a civilian has portscanned the whole Internet before via the same thing: http://internetcensus2012.bitbucket.org/paper.html I don't get all the fuss about portscanning is either - anything connected to the Internet will be subjected to packets sent to it because the Internet is public; if you don't want others, government or otherwise, to know that there's a machine present at an IP, then it should be your…

There was a lot of noise when the Heise story was released with people concentrating on the use of nmap and saying that using nmap is not shocking.

For me the disturbing thing was the pipeline - nmap, fingerprint, identify weak systems and then compromise those systems. Those compromised systems are then used for further surveillance or attacks.

Before the Heise story, I naively believed that this sort of automated attack was only done by organised crime.

Re: GNU hackers discover HACIENDA government surveillance

#59
post #22

Earlier quoted context omitted.

At the expense of the sanity and security of those who the foreign intelligence is meant to protect? This is an obvious abuse with extreme existential consequences. Sort of reminds of this book I read as a kid: http://en.wikipedia.org/wiki/Momo_(novel)#Plot_summary

I think the assaults on your sanity are likely more the result of sensationalized/incomplete reporting. The biggest issue I have with most of the Snowden reporting is that if the article doesn't outright jump to assumptions that aren't supported by the source material, they usually have unanswered questions and written in such a way that would cause the reader to jump to the worst possible conclusion. I'm not sure on…

Nothing is shown regarding any actual process for selecting hosts to use as relays, or any actual number of hosts that they hack into

To quote parts of figure 18 in the Heise story:

CSECS Operational Relay Box (ORB) ... subsequently used for exploits... 2/3 times a year, 1 day focused effort to acquire as many new ORBs as possible in as many non 5-Eyes countries as possible.

I interpret this as "hack many hosts as possible in a given short timeframe".

Post reply on HN