Live data from Hacker News

“Warning: Do Not use my mirrors/services until I have reviewed the situation”

article.gmane.org

71–80 of 167 posts

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#71

Earlier quoted context omitted.

Nederlands $ whois 77.95.229.11

WTF?! Since when do we backdoor hardware in The Netherlands without informing the owner?

Hold off on the conclusion-jumping = 'possibly consistent with X' is a long way from 'proof of X'.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#72

the chassis of the servers was opened and an unknown USB device was plugged in only 30-60 seconds before the connection was broken. In which country did this happen? As an European I expected the US/EU governments would keep their hands of Tor because dissidents use it in countries where US/EU want regime change.

The US/EU governments run their own nodes. Why WOULDN'T they take down third parties that aren't willing to give them the access they need to sniff traffic? Their support of dissidents in other countries doesn't require private nodes to exist.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#73
post #66

Earlier quoted context omitted.

it is pretty likely the USB device is this http://www.cru-inc.com/products/wiebetech/mouse_jiggler/ to prevent the computer going to sleep while this is utilized http://www.cru-inc.com/products/wiebetech/hotplug_field_kit/ These are pretty standard plays in seizing computers these days. One should note that the grsec linux patchset has functionality to not load drivers for any plugged usb devices, as well as log when…

About the jiggler: would the hid driver even be loaded on a server?

Yes, for the KVM, since not all KVMs use the older PS/2 protocol.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#74

Earlier quoted context omitted.

If the USB device from the article is doing anything along the lines of BadUSB or EFI compromise, then re-imaging your server won't accomplish much. https://trmm.net/EFI

it is pretty likely the USB device is this http://www.cru-inc.com/products/wiebetech/mouse_jiggler/ to prevent the computer going to sleep while this is utilized http://www.cru-inc.com/products/wiebetech/hotplug_field_kit/ These are pretty standard plays in seizing computers these days. One should note that the grsec linux patchset has functionality to not load drivers for any plugged usb devices, as well as log when…

Why do you think those USB devices are "pretty likely"?

In this case, I would bet on a firmware compromise, similar to DIETYBOUNCE: https://www.eff.org/files/2014/01/06/20131230-appelbaum-nsa_...

As a countermeasure, I would not fully trust TXT in this particular case. It's likely a state actor who could spoof measurements over the the LPC bus.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#75

Interesting. It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. I've seen a 10x increase in various scripted attacks being attempted (patch early and often folks!) and a number of APT level compromises of systems either staging malware or deploying it (see the latest bulletin on the Afghan govern…

    Fortunately in this modern version of war you can "kick the soldiers out" of your server by bringing it down and re-imaging it. And they won't turn around and shoot you, but that is not all that comforting somehow.
Until "DeathRay3000" becomes a standard peripheral it is slightly comforting...

Overall, I worry more about the hacks I haven't detected than those I have. Re-imaging is a pain, but not as much as not knowing your server is secure.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#76

the chassis of the servers was opened and an unknown USB device was plugged in only 30-60 seconds before the connection was broken. In which country did this happen? As an European I expected the US/EU governments would keep their hands of Tor because dissidents use it in countries where US/EU want regime change.

The USG is not a monolithic entity. The State Department loves TOR, for the reasons you list, while Justice hates it. The Justice Department does not need State approval to get warrants and take down servers, nor do they need State approval to work with their foreign partners to do the same.

One of my favorite examples of this: http://articles.latimes.com/1989-06-07/news/mn-1711_1_rocky-...

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#77

Earlier quoted context omitted.

If the USB device from the article is doing anything along the lines of BadUSB or EFI compromise, then re-imaging your server won't accomplish much. https://trmm.net/EFI

it is pretty likely the USB device is this http://www.cru-inc.com/products/wiebetech/mouse_jiggler/ to prevent the computer going to sleep while this is utilized http://www.cru-inc.com/products/wiebetech/hotplug_field_kit/ These are pretty standard plays in seizing computers these days. One should note that the grsec linux patchset has functionality to not load drivers for any plugged usb devices, as well as log when…

That doesn't seem pretty likely at all. It's much more likely that the machine in question is a rack-mount server that never goes to sleep.

That said, very good point wrt grsec.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#78
post #34

Earlier quoted context omitted.

When it hits hedge funds and private equity firms people will start caring.

Oh, the whole cyberwar situation is far from "hopeless". The truth is nobody to speak of has taken it seriously yet. Security is still mostly an afterthought, if that , almost everywhere you look. Even in nominally security-focused contexts. And much of the activity in places that really are security focused are built around an environment in which software must be assumed to basically be constructed out of styrofoam…

I agree about C and C++, but is there a language that exists today that you think would be better for writing security-conscious code? Should a language be invented that is specifically for writing security-conscious code?

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#79

Earlier quoted context omitted.

I've had job offers for programming drones. I was involved with computer security for a while, and I still have a strong interest in every computational and mathematical aspect of it. I have friends that work on those things. I like those friends. I write code. I write math. We all think. We all share abstract models, different ways of thinking. It's not just code that gets turned into code. It's thought, and everyth…

Have I abstracted this problem too much, too far away from reality? I'll say. You could throw it in and go work as a coal-miner, but then you'd have to worry about the coal you mined being used to smelt steel that goes on to be manufactured as bomb casings. And so on. Certainly you shouldn't work on anything that offends you conscience, but the mere fact that something can be repurposed for warfare doesn't create mor…

I know. I might as well blame myself for breathing out air that is used by a tree that is used to build a house that houses the person who pushes the red button of destruction. It's like tunnel vision, following one path of articulation that follows the model of a logically sound abstraction. Things may be connected, but, causality with regards to the relations between mind to mind is very difficult to understand.

But you are right. I look to provide utility in areas where the net effect seems most likely to be positive. When I can't evaluate that entirely I just assume neutral or no effect, it sort of just dissipates over time, like a wave collapse function, assuming entropy, or some manner of mental equality among peers.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#80
post #12

Earlier quoted context omitted.

Does ISIS really have the resources to carry out criminal computer activities? From what I understand, they are a group with limited technological advantage, and there is no way they could carry out a major attack on the Internet.

(Note to ossreality, who also replied to this comment: you appear to be hellbanned.)

Re: his edit, thank you for your compliment, but I just think there are more constructive ways to approach most conversations than accusing people of talking out of their ass, or calling them losers. :( If you truly were banned for arguing with someone important, that's unfortunate, but I saw two good reasons to ban you in your most recent three comments. Maybe I just caught you on a bad day.
Post reply on HN