For anyone who missed the warning a few days ago: https://blog.torproject.org/blog/possible-upcoming-attempts-...
“Warning: Do Not use my mirrors/services until I have reviewed the situation”
21–30 of 167 posts
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#22the chassis of the servers was opened and an unknown USB device was plugged in only 30-60 seconds before the connection was broken. In which country did this happen? As an European I expected the US/EU governments would keep their hands of Tor because dissidents use it in countries where US/EU want regime change.
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#23Interesting. It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. I've seen a 10x increase in various scripted attacks being attempted (patch early and often folks!) and a number of APT level compromises of systems either staging malware or deploying it (see the latest bulletin on the Afghan govern…
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#24Interesting. It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. I've seen a 10x increase in various scripted attacks being attempted (patch early and often folks!) and a number of APT level compromises of systems either staging malware or deploying it (see the latest bulletin on the Afghan govern…
Does ISIS really have the resources to carry out criminal computer activities? From what I understand, they are a group with limited technological advantage, and there is no way they could carry out a major attack on the Internet.
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#25Interesting. It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. I've seen a 10x increase in various scripted attacks being attempted (patch early and often folks!) and a number of APT level compromises of systems either staging malware or deploying it (see the latest bulletin on the Afghan govern…
It might have been a freudian slip or some kind of intuition, but when I was describing my life plans to my family, I said something along the lines of "I don't want to manage people, I want to stay on the front lines with the code." Except I don't want it to be scary, because I can't take anymore of that in my life. So what I really mean is "deploy knowledge bases" and that I choose to work in education. So I continue to stand on a soapbox of 'ethical coding' and I continue to request the ability to separate the responsibility of the developer from the technological applications to warfare. I just want to code difficult stuff, with intense mathematics and abstractions, and solve hard problems. I don't want people using that to hurt other people, and people who don't code don't seem to get that.
People wonder why I get depressed, and to a lot of people it probably looks super dumb and selfish, and I've lost a lot of friends over the years over things I couldn't really explain. People say I over-analyze things and that I think too much. Maybe I do, maybe I don't think enough. It's pretty easy for me to have these opinions when my life is stable.
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#26Wonder what shenanigans the USB device is up to. A bootable drive for flashing backdoored bios/hdd firmware or keylogging? Snapshotting the HDDs? 0day'ing the kernel USB stack?
Modifying anything before you have a complete forensic dump is a big no-no because you need to preserve evidence.
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#27Earlier quoted context omitted.
Does ISIS really have the resources to carry out criminal computer activities? From what I understand, they are a group with limited technological advantage, and there is no way they could carry out a major attack on the Internet.
(Note to ossreality, who also replied to this comment: you appear to be hellbanned.)
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#28Wonder what shenanigans the USB device is up to. A bootable drive for flashing backdoored bios/hdd firmware or keylogging? Snapshotting the HDDs? 0day'ing the kernel USB stack?
Probably just a USB stick with Second Look or a similar tool on it. Very first thing you do is dump the running memory on the system. Then you pull the drives, plug them into a write blocker, then image the drives. Modifying anything before you have a complete forensic dump is a big no-no because you need to preserve evidence.
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#29Interesting. It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. I've seen a 10x increase in various scripted attacks being attempted (patch early and often folks!) and a number of APT level compromises of systems either staging malware or deploying it (see the latest bulletin on the Afghan govern…
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#30Earlier quoted context omitted.
Probably just a USB stick with Second Look or a similar tool on it. Very first thing you do is dump the running memory on the system. Then you pull the drives, plug them into a write blocker, then image the drives. Modifying anything before you have a complete forensic dump is a big no-no because you need to preserve evidence.
Can you explain more? How do go about dumping memory?
Law enforcement also has additional undisclosed methods to avoid detection by systems.