Live data from Hacker News

GNU hackers discover HACIENDA government surveillance

fsf.org

61–70 of 83 posts

Re: GNU hackers discover HACIENDA government surveillance

#61

Earlier quoted context omitted.

> as in the calls for "deregulation" which seldom favor the average Joe Can you give an example of deregulation that doesn't favor the average Joe? I can't think of one.

Deregulation in the sense of removing price controls and barriers to entry is typically good for everyone, examples include airlines and craft beer brewing. Deregulation in the sense of stripping very specific regulations designed to prevent exploitation are typically good for the owners of capital and bad for everyone else. Examples include the Depository Institutions Deregulation and Monetary Control Act (Led to Sa…

I see what you and shiven mean. I agree those partial deregulations are bad. I say partial because that's not what I usually mean by "deregulation". "Stripping very specific regulations" is just that, just another law being passed, that flips some switch on or off.

When I asked for examples I thought we were talking about total deregulation (I previously thought deregulation was a binary thing - either something is regulated or it isn't at all) but I see it is used in other senses (although it is a bit perplexing to me).

> Some of those scenarios could have been prevented if more facets had been deregulated

Exactly this.

Re: GNU hackers discover HACIENDA government surveillance

#62
post #51
post #47

Earlier quoted context omitted.

Personally while I thought that while Aaron Swartz was guilty of something, the charges DAs were pressing for were disgustingly and flagrantly incommensurate, and I was distressed at the abuse of government power. I didn't really follow the Jeremy Hammond case, can't speak to it. I don't really have a problem with penalties for computing crimes, but I firmly believe that the punishment should be commensurate with the…

> The commonality with NSA and with Swartz is that you have heavy-handed authority figures flagrantly abusing their power with impunity. Read csandreasen's comment: https://news.ycombinator.com/item?id=8205642 Whatever else NSA's been doing, it hasn't been "with impunity", it's been in coordination with allied intelligence agencies (including the German BND that was spying on Turkey, Kerry, and Clinton...), and as Sn…

> NSA isn't hacking citizen's computers, except maybe for citizens in non-Five Eyes countries.

So just the majority of the world population.

Re: GNU hackers discover HACIENDA government surveillance

#63
post #39
post #6

Disturbingly, the HACIENDA system actually hijacks civilian computers to do some of its dirty work, allowing it to leach computing resources and cover its tracks. Yeah, that is disturbing, and it should be made illegal.

How disturbing and/or illegal should it be? I mean, I'm game to make it illegal if it's not already, and it probably already is illegal in the countries where that would be going on. But when I advocated the viewpoint that unauthorized access to computers was illegal and disturbing back with Aaron Swartz, that viewpoint didn't seem as popular at Hacker News for some reason. Likewise when Jeremy Hammond admitted to ha…

Should we not hold the government to a higher standard than random individuals?

Re: GNU hackers discover HACIENDA government surveillance

#64
post #13

Earlier quoted context omitted.

If you have access to a few routers, you could probably generate a good list of valid ipv6 addresses.

Isn't the local network block always at least a /64 or /80 or so? Thus even knowing which blocks are handed out means you still have an IPv4-Internet-sized task for each one.

I was more thinking logging every ip that goes through the router; I think that which blocks are given out is public information.

Re: GNU hackers discover HACIENDA government surveillance

#65
post #43
post #34

Earlier quoted context omitted.

I disagree. I don't see where blockfinder is actually reaching out and pinging servers to see what's up where. blockfinder seems to be downloading well known data sources as to where IPs are. The project the government is being accused of doing is essentially running a distributed nmap along with geo information.

But Blockfinder is returning a full list of IPs of which you could perform nmap scans upon. That's one step away from HACIENDA.

This gets even worse. I've heard Jacob has a computer with Internet access. Now that's like two steps away only from HACIENDA.

Terrifying.

Re: GNU hackers discover HACIENDA government surveillance

#66
post #34
post #31

Ironically Jacob Appelbaum, allegedly an investigative journalist who reported this issue, is responsible for this project on GitHub that does exactly the same thing: https://github.com/ioerror/blockfinder

I disagree. I don't see where blockfinder is actually reaching out and pinging servers to see what's up where. blockfinder seems to be downloading well known data sources as to where IPs are. The project the government is being accused of doing is essentially running a distributed nmap along with geo information.

Please, read the article that's referenced on GitHub:

"He beckons me over to one of his eight computers and presses several keys, activating Blockfinder. In less than 30 seconds, the program lists all of the Internet Protocol address allocations in the world — potentially giving him access to every computer connected to the Internet. Appelbaum decides to home in on Burma, a small country with one of the world's most repressive regimes. He types in Burma's two-letter country code: "mm," for Myanmar. Blockfinder instantly starts to spit out every IP address in Burma. Blockfinder informs Appelbaum that there are 12,284 IP addresses allocated to Burma, all of them distributed by government-run Internet-service providers. In Burma, as in many countries outside the United States, Internet access runs through the state. Appelbaum taps some keys and attempts to connect to every computer system in Burma. Only 118 of them respond. "That means almost every network in Burma is blocked from the outside world," he says. "All but 118 of them."

These 118 unfiltered computer systems could only belong to organizations and people to whom the government grants unfettered Internet access: trusted politicians, the upper echelons of state-run corporations, intelligence agencies.

"Now this," Appelbaum says, "is the good part."

He selects one of the 118 networks at random and tries to enter it. A window pops up asking for a password. Appelbaum throws back his head and screams with laughter — a gleeful, almost manic trill. The network runs on a router made by Cisco Systems and is riddled with vulnerabilities. Hacking into it will be trivial.

It's impossible to know what's on the other side of the password. The prime minister's personal e-mail account? The network server of the secret police? The military junta's central command? Whatever it is, it could soon be at Appelbaum's fingertips."

Re: GNU hackers discover HACIENDA government surveillance

#67
post #40
post #15

Earlier quoted context omitted.

For one, it's obviously quite good literature, of the "manifesto" style favored by modernist movements. Second, it makes perfect sense. It describes things seen in strolling around a city (Paris in this case), listing funny street names and shop titles. Plus some references to older art and poetry movements (namely dada and surealism), regarding their promise of a "fuller life" etc. Not sure what it has to do with TF…

Certainly not a room full of monkeys, but I'm having great difficulty trying to disprove the hypothesis that this wasn't just a Markov chain generator left to generate a few paragraphs.

Probably it's just like with Perl code. Can look like line noise to someone uninitiated, but if you know the syntax, operators etc you see that it's not and what it does.

For me, who know the surrelist and dadaist history references (and the place, so to speak, this text is coming from -- it's a plea from a bored existential youth for an "exciting" city and an exciting life) every line makes sense and has its place.

What I mean is, it's not absurdist -- like some dadaist poetry. He picked his words to convey a specific message, and the references and metaphors work in this context.

Re: GNU hackers discover HACIENDA government surveillance

#68
post #10

I can't really take much more of this... What is their goal?

Their goal for some time now[1] is to keep cash flowing through the military-industrial-complex. They obviously don't have any kind of focus on actual intelligence work, or they wouldn't be so bad at basic practices like compartmentalization[2]. Even the ways they could abuse their surveillance capabilities seem to be more of a "bonus". They could be much worse, but that would distract form their business of piping cash to their "contractor" friends.

Interestingly, the recent mess the EFF has been reporting on (Jewel v NSA) where they tried to retcon the public court record has - in the public court record - the DOJ lawyers delivering[3] and incredible Freuidan-slip. While arguing that basically nobody can ever have standing to challenge their Section 215 based activities, they mention this: (caps in original, emphasis mine)

    ALL THESE TERRIBLE DISCLOSURES THAT OCCURRED OVER THE PAST YEAR -- IN FACT,
    THIS IS THE ONE YEAR ANNIVERSARY -- DISCLOSURES THAT WE ARE CONVINCED THAT
    HAVE SERIOUSLY HARMED THE NATIONAL SECURITY OF THIS *COMPANY*, WE HAVE CONTINUED
    TO PROTECT THE IDENTITY OF PARTICULAR TELECOMMUNICATION CARRIERS THAT ARE
    ALLEGED TO HAVE ASSISTED THE NSA,
"national security of this company". wow.

[1] According to William Binny and others. This recent interview mentions it, as to many others.

http://www.dw.de/binney-the-nsas-main-motives-power-and-mone...

[2] For example, how the hell did Snowden even have access to that many sensitive docs? Even as a sysadmin, he didn't "need to know" a lot of that. They use to take that kind of practice deadly seriously.

[3] https://www.techdirt.com/articles/20140813/23203228207/unsea...

Re: GNU hackers discover HACIENDA government surveillance

#69
post #59

Earlier quoted context omitted.

I think the assaults on your sanity are likely more the result of sensationalized/incomplete reporting. The biggest issue I have with most of the Snowden reporting is that if the article doesn't outright jump to assumptions that aren't supported by the source material, they usually have unanswered questions and written in such a way that would cause the reader to jump to the worst possible conclusion. I'm not sure on…

Nothing is shown regarding any actual process for selecting hosts to use as relays, or any actual number of hosts that they hack into To quote parts of figure 18 in the Heise story: CSECS Operational Relay Box (ORB) ... subsequently used for exploits... 2/3 times a year, 1 day focused effort to acquire as many new ORBs as possible in as many non 5-Eyes countries as possible. I interpret this as "hack many hosts as po…

But it's still not a number - how many are actually being hacked in this manner? Hundreds? Thousands? Millions? Five? There's not enough context given to tell. That picture on slide 18 with all of the redactions just below the quote you cite shows 63 egg-shaped (or maybe "orb" shaped?) icons with various colored halos and warning symbols next to them. If I were to make an educated guess based on that slide, I'd guess that CSEC controls a total of 63 relays. If I only read the article, I'd assume several orders of magnitude more.

The point that I was trying to make in my earlier comment is that when we read an article like that we tend to instinctively ask more questions, and if the answers to our questions aren't there we tend to make assumptions. Depending on both our own biases and the biases of the author presenting the information, our assumptions are often way off the mark (in either direction).

Here's some questions I would pose to the authors of that article that aren't answered:

How many hosts are being hacked?

Who owns the hosts being hacked? Have the authors taken steps to inform the owners? If not, what is the reason they chose not to?

What are those hosts normally used for and by whom? What is the scale of the privacy implications associated with NSA/GCHQ/CSEC using this host?

What criteria are considered when they select a host to hack to use as a relay?

Re: GNU hackers discover HACIENDA government surveillance

#70
post #63
post #39

Earlier quoted context omitted.

How disturbing and/or illegal should it be? I mean, I'm game to make it illegal if it's not already, and it probably already is illegal in the countries where that would be going on. But when I advocated the viewpoint that unauthorized access to computers was illegal and disturbing back with Aaron Swartz, that viewpoint didn't seem as popular at Hacker News for some reason. Likewise when Jeremy Hammond admitted to ha…

Should we not hold the government to a higher standard than random individuals?

Not when we are outsourcing our intelligence collection to government.

Its the Government's responsibility to spy on our enemies, is it not?

Post reply on HN