Live data from Hacker News

“Warning: Do Not use my mirrors/services until I have reviewed the situation”

article.gmane.org

31–40 of 167 posts

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#31

Interesting. It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. I've seen a 10x increase in various scripted attacks being attempted (patch early and often folks!) and a number of APT level compromises of systems either staging malware or deploying it (see the latest bulletin on the Afghan govern…

> It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. It might have been a freudian slip or some kind of intuition, but when I was describing my life plans to my family, I said something along the lines of "I don't want to manage people, I want to stay on the front lines with the code." Except I d…

I've heard opinions along the lines of "thinking too much" countless of times, at first it was kind of depressing but later I've concluded that if you just like to think and analyze things in your mind (which is not so popular thing to do when you consider general population, sadly), people who voice such (negative, I'd say) comments didn't really think about this deeply. Over-analying can be a serious problem (consider some forms of OCD), but when you can somehow control it (but not constrain) it's ok to think as much as one like ;).

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#32
post #28
post #26

Earlier quoted context omitted.

Probably just a USB stick with Second Look or a similar tool on it. Very first thing you do is dump the running memory on the system. Then you pull the drives, plug them into a write blocker, then image the drives. Modifying anything before you have a complete forensic dump is a big no-no because you need to preserve evidence.

Can you explain more? How do go about dumping memory?

The specific tool they were mentioning is: https://secondlookforensics.com/

Interestingly enough, look who makes it.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#33

the chassis of the servers was opened and an unknown USB device was plugged in only 30-60 seconds before the connection was broken. In which country did this happen? As an European I expected the US/EU governments would keep their hands of Tor because dissidents use it in countries where US/EU want regime change.

Even on a more practical level, aren't all major hosting providers ones that follow standards where getting a USB drive onto a server would be extremely easy to trace back? Where was this guy keeping his servers?

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#34

Interesting. It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. I've seen a 10x increase in various scripted attacks being attempted (patch early and often folks!) and a number of APT level compromises of systems either staging malware or deploying it (see the latest bulletin on the Afghan govern…

When it hits hedge funds and private equity firms people will start caring.

Oh, the whole cyberwar situation is far from "hopeless". The truth is nobody to speak of has taken it seriously yet. Security is still mostly an afterthought, if that, almost everywhere you look. Even in nominally security-focused contexts. And much of the activity in places that really are security focused are built around an environment in which software must be assumed to basically be constructed out of styrofoam and radioactive waste, so they end up looking very restrictive in reaction to this reality.

I'm fairly convinced that if we all really tried we could secure things much better than they are today. The personal tripwire I've been watching for is when it finally becomes simply general knowledge that C is completely unsuitable to write security software in and C++ is pretty damned dangerous. (Many people know this, but a large contingent will still push back on that. Once we get serious about security, one of the things that will have to happen is C is going to have be evicted from its current privileged position.)

Lest I sound utopian, yes, this will require immense effort. My point is precisely that we've never really tried that level of effort yet, not that the effort will be low. There's no real reason that the Internet actually has to be made out of swiss cheese, but it will take a significant change of viewpoint before it will be resolved.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#35
post #13

How did these criminals penetrate the ISP? Is there security footage? It should be no trouble to identify the perpetrators and have them arrested if their pictures are posted online.

The criminals were probably carrying a warrant.

I laughed...and then I frowned.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#36
post #13

How did these criminals penetrate the ISP? Is there security footage? It should be no trouble to identify the perpetrators and have them arrested if their pictures are posted online.

The criminals were probably carrying a warrant.

If there was a warrant, we should be able to get that information, and act on it, and figure out how to avoid it in the future.

Which comes to an interesting situation: if this was acted upon by NSL, here there's proof something happened, so how does that get explained without breaking the gag order?

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#37

the chassis of the servers was opened and an unknown USB device was plugged in only 30-60 seconds before the connection was broken. In which country did this happen? As an European I expected the US/EU governments would keep their hands of Tor because dissidents use it in countries where US/EU want regime change.

Nederlands $ whois 77.95.229.11

WTF?! Since when do we backdoor hardware in The Netherlands without informing the owner?

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#38
post #26
post #15

Wonder what shenanigans the USB device is up to. A bootable drive for flashing backdoored bios/hdd firmware or keylogging? Snapshotting the HDDs? 0day'ing the kernel USB stack?

Probably just a USB stick with Second Look or a similar tool on it. Very first thing you do is dump the running memory on the system. Then you pull the drives, plug them into a write blocker, then image the drives. Modifying anything before you have a complete forensic dump is a big no-no because you need to preserve evidence.

Seeing how this is a targeted attack on an exit node specifically they're not going to be interested in dumping whats on the system for evidence. Even an idiot will know that someone running a TOR exit node isn't going to be a big fan of logging traffic in detail. Has to be an attempt to keep the node running but in a compromised state...

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#39

Interesting. It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. I've seen a 10x increase in various scripted attacks being attempted (patch early and often folks!) and a number of APT level compromises of systems either staging malware or deploying it (see the latest bulletin on the Afghan govern…

If the USB device from the article is doing anything along the lines of BadUSB or EFI compromise, then re-imaging your server won't accomplish much. https://trmm.net/EFI

Well that is not reassuring :-(. Particularly the part about it copying itself to other Thunderbolt devices.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#40
post #13

How did these criminals penetrate the ISP? Is there security footage? It should be no trouble to identify the perpetrators and have them arrested if their pictures are posted online.

The criminals were probably carrying a warrant.

Your comment is indicative of the crisis of legitimacy that has infected our governments, and most of the institutions of stability in our global society. It seems like a small thing; but once the perception that the forces of law and order are themselves lawless exceeds a certain critical threshold things begin to change rapidly. Indeed the United States itself came to be in the wake of the erosion of the legitimacy of Englands colonial government.

There won't be an announcement; but once that threshold is crossed events begin to move rapidly and forcefully and do not stop until a new arrangement of powers is found that society can scaffold itself upon. Who knows what will be the stable state of a world seeded with the idea of networks and knowledgable in their subversion and subornation.

Post reply on HN