Live data from Hacker News

“Warning: Do Not use my mirrors/services until I have reviewed the situation”

article.gmane.org

81–90 of 167 posts

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#81
post #65

Earlier quoted context omitted.

it is pretty likely the USB device is this http://www.cru-inc.com/products/wiebetech/mouse_jiggler/ to prevent the computer going to sleep while this is utilized http://www.cru-inc.com/products/wiebetech/hotplug_field_kit/ These are pretty standard plays in seizing computers these days. One should note that the grsec linux patchset has functionality to not load drivers for any plugged usb devices, as well as log when…

The computer in question is a server. If the server were configured to sleep unless the mouse is jiggled, it would already be asleep. Thus, using a "mouse jiggler" or similar is pointless, and risks detection.

Wouldn't surprise me if there's some standard procedure for police raids that doesn't distinguish between the two. Keep in mind it's generally not the experts who go out to the various locations.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#82
post #12

Earlier quoted context omitted.

Does ISIS really have the resources to carry out criminal computer activities? From what I understand, they are a group with limited technological advantage, and there is no way they could carry out a major attack on the Internet.

(Note to ossreality, who also replied to this comment: you appear to be hellbanned.)

[deleted]

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#83
post #34

Earlier quoted context omitted.

Oh, the whole cyberwar situation is far from "hopeless". The truth is nobody to speak of has taken it seriously yet. Security is still mostly an afterthought, if that , almost everywhere you look. Even in nominally security-focused contexts. And much of the activity in places that really are security focused are built around an environment in which software must be assumed to basically be constructed out of styrofoam…

I agree about C and C++, but is there a language that exists today that you think would be better for writing security-conscious code? Should a language be invented that is specifically for writing security-conscious code?

Rust, for the former, Cryptol for the latter (just one caveat: written by the NSA/influenced people).

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#84

Interesting. It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. I've seen a 10x increase in various scripted attacks being attempted (patch early and often folks!) and a number of APT level compromises of systems either staging malware or deploying it (see the latest bulletin on the Afghan govern…

Did you even read the post? This has nothing to do with "cyberwar", "terrorism" and other scaremongering words you used.

His servers were taken over by law enforcement. You're free to call them cyberterrorists if you wish. These days it's hard to tell the difference in tactics between malicious rivals and your own government anyway.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#85

Earlier quoted context omitted.

If the USB device from the article is doing anything along the lines of BadUSB or EFI compromise, then re-imaging your server won't accomplish much. https://trmm.net/EFI

it is pretty likely the USB device is this http://www.cru-inc.com/products/wiebetech/mouse_jiggler/ to prevent the computer going to sleep while this is utilized http://www.cru-inc.com/products/wiebetech/hotplug_field_kit/ These are pretty standard plays in seizing computers these days. One should note that the grsec linux patchset has functionality to not load drivers for any plugged usb devices, as well as log when…

I had no idea the hotplug devices existed. Thank you for posting the link.

Has anyone used these in an IT support environment?

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#86
post #40

Earlier quoted context omitted.

The criminals were probably carrying a warrant.

Your comment is indicative of the crisis of legitimacy that has infected our governments, and most of the institutions of stability in our global society. It seems like a small thing; but once the perception that the forces of law and order are themselves lawless exceeds a certain critical threshold things begin to change rapidly. Indeed the United States itself came to be in the wake of the erosion of the legitimacy…

I'd love to see some historical basis for this supposition that there is a natural counter balance to "lawless" power. First of all, your premise presupposes that there is some standard of "lawfulness" against which the existing power structure can be judged. If the powers that be are faithful to their own interests and rules then by definition they are lawful, since they create and administer the law. Your appeal to a higher morality (I assume, since I don't know what other standard there could be) makes a good muse for an artisan, but I see no evidence in the long, bloody history of our species that it acts as some sort of automatic restorer of natural order. Quite the contrary, in fact. It is the current state of affairs in some Western countries, in which the citizens have leave to consider whether their governments are lawful and ways to act if they are not, that is the exception.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#87
post #34

Earlier quoted context omitted.

Oh, the whole cyberwar situation is far from "hopeless". The truth is nobody to speak of has taken it seriously yet. Security is still mostly an afterthought, if that , almost everywhere you look. Even in nominally security-focused contexts. And much of the activity in places that really are security focused are built around an environment in which software must be assumed to basically be constructed out of styrofoam…

> Security is still mostly an afterthought, if that, almost everywhere you look... yes, this will require immense effort. What I keep thinking, though, is, what would be the total dollar cost to make security a forethought, with information technology being pretty ubiquitous? I think it might actually have serious economic impact -- is it possible we literally can't afford security, as a society?

I think we could, because once we started down the path of taking security seriously, we would get better at it. What you see now is largely us not even trying. Well, just barely trying, maybe; not trying at all was the 70s. But there's still too many places where 'industry best practice' is insecure, and where even on places like HN you'll get serious fights over whether or not strong typing or even languages that prevent buffer overflows are worth it, to say nothing of what the industry at large thinks.

But there would have to be some pretty significant changes in our languages and how we program, and it probably would mean things like a certain slowing down of the rate of feature delivery.

In the long term, being unable to afford security is being unable to afford computerization at all, and the efficiency bonus is so great from computerization that it's hard to believe that we couldn't figure out how to make it work.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#88
post #34

Earlier quoted context omitted.

Oh, the whole cyberwar situation is far from "hopeless". The truth is nobody to speak of has taken it seriously yet. Security is still mostly an afterthought, if that , almost everywhere you look. Even in nominally security-focused contexts. And much of the activity in places that really are security focused are built around an environment in which software must be assumed to basically be constructed out of styrofoam…

> Security is still mostly an afterthought, if that, almost everywhere you look... yes, this will require immense effort. What I keep thinking, though, is, what would be the total dollar cost to make security a forethought, with information technology being pretty ubiquitous? I think it might actually have serious economic impact -- is it possible we literally can't afford security, as a society?

>what would be the total dollar cost to make security a forethought

There isn't one. There are too many people involved who categorically refuse to consider security, and there is no way to fix that in a reasonable time frame. We'd need to fix the education problem and then wait for a whole generation of new people to go through it.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#89
post #34

Earlier quoted context omitted.

Oh, the whole cyberwar situation is far from "hopeless". The truth is nobody to speak of has taken it seriously yet. Security is still mostly an afterthought, if that , almost everywhere you look. Even in nominally security-focused contexts. And much of the activity in places that really are security focused are built around an environment in which software must be assumed to basically be constructed out of styrofoam…

I agree about C and C++, but is there a language that exists today that you think would be better for writing security-conscious code? Should a language be invented that is specifically for writing security-conscious code?

C is a great replacement for C. No, I don't mean that as a joke. Using C as a low level language and proving it correct via a higher level language gives you the performance of C without the security problems: http://sel4.systems/

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#90
post #42
post #12

Earlier quoted context omitted.

Does ISIS really have the resources to carry out criminal computer activities? From what I understand, they are a group with limited technological advantage, and there is no way they could carry out a major attack on the Internet.

Must admit I'm slightly amused that this is even being considered as a plausible theory. They're busy executing elderly with AK47s...thats very far away from physically cracking open servers in a western data center and inserting USB devices with targeted attack software.

It is not merely the uneducated who can subscribe to extremist ideologies.

When the unskilled highschool grad gets off the plane and signs up, they are going to give him a rifle. When the engineer gets off the plane and announces himself as such, there is a chance that he will be put to better use.

Post reply on HN