Live data from Hacker News

“Warning: Do Not use my mirrors/services until I have reviewed the situation”

article.gmane.org

111–120 of 167 posts

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#111
Off Topic: But out of curiosity what does a Tor hidden service keep in memory? Would there be any information that would uniquely identify the services it's running?

Given that they're often run in datacentres (either colocated or within a VM) - wouldn't a USB device capable of scraping RAM and dumping a list hosted .onions be quite practical for law enforcement purposes?

They're obviously finite amount of datacenters in each country/jurisdiction that accept bitcoin or sell VPSs.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#112
post #72

the chassis of the servers was opened and an unknown USB device was plugged in only 30-60 seconds before the connection was broken. In which country did this happen? As an European I expected the US/EU governments would keep their hands of Tor because dissidents use it in countries where US/EU want regime change.

The US/EU governments run their own nodes. Why WOULDN'T they take down third parties that aren't willing to give them the access they need to sniff traffic? Their support of dissidents in other countries doesn't require private nodes to exist.

Which nodes are gov run?

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#113

As the Tor community knew of a possible compromise in advance, what what is the purpose of this? Sounds like fear mongering by the TLAs with the aim to discredit anonymity within the network rather than actual malice.

I thought the advanced warning was related to directory servers, not exit nodes.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#114

As the Tor community knew of a possible compromise in advance, what what is the purpose of this? Sounds like fear mongering by the TLAs with the aim to discredit anonymity within the network rather than actual malice.

I thought the advanced warning was related to directory servers, not exit nodes.

It is.

  an attempt to incapacitate our network in the next few days through the seizure of specialized servers in the network called directory authorities.
- https://blog.torproject.org/blog/possible-upcoming-attempts-...

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#115
post #12

Interesting. It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. I've seen a 10x increase in various scripted attacks being attempted (patch early and often folks!) and a number of APT level compromises of systems either staging malware or deploying it (see the latest bulletin on the Afghan govern…

Does ISIS really have the resources to carry out criminal computer activities? From what I understand, they are a group with limited technological advantage, and there is no way they could carry out a major attack on the Internet.

ISIS has foreign supporters, and I promise you there's at least one sysadmin or netsec professional out there backing the outfit.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#116

Earlier quoted context omitted.

If the USB device from the article is doing anything along the lines of BadUSB or EFI compromise, then re-imaging your server won't accomplish much. https://trmm.net/EFI

it is pretty likely the USB device is this http://www.cru-inc.com/products/wiebetech/mouse_jiggler/ to prevent the computer going to sleep while this is utilized http://www.cru-inc.com/products/wiebetech/hotplug_field_kit/ These are pretty standard plays in seizing computers these days. One should note that the grsec linux patchset has functionality to not load drivers for any plugged usb devices, as well as log when…

How about disabling GPM?

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#117
post #28

Earlier quoted context omitted.

Can you explain more? How do go about dumping memory?

The specific tool they were mentioning is: https://secondlookforensics.com/ Interestingly enough, look who makes it.

I understand that as I googled it before asking the question. It's advertised as a tool to analyze memory dump, not to take them, but I have no doubts they sell tools for that as well. If you know how they work, please tell.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#118
post #12

Earlier quoted context omitted.

Does ISIS really have the resources to carry out criminal computer activities? From what I understand, they are a group with limited technological advantage, and there is no way they could carry out a major attack on the Internet.

ISIS has foreign supporters, and I promise you there's at least one sysadmin or netsec professional out there backing the outfit.

I considered partnering with a data center owner in the US until I learned that his organisation was monitored by NSA for doing bad stuff in Syria. As you say, of course ISIS and similar organizations has supporters among "ordinary people" in EU and US.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#119

Interesting. It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. I've seen a 10x increase in various scripted attacks being attempted (patch early and often folks!) and a number of APT level compromises of systems either staging malware or deploying it (see the latest bulletin on the Afghan govern…

I'm surprised that this comment has been voted to the top.

First, it has little to nothing to do with the comment posted, which concerns not a "cyberwar" but the possible police seizure of a Tor server. The assumption is it's either a false alarm or a police raid. No one thinks this was done by ISIS.

Second, a post using the word "cyberwar" in a non-ironic manner at the top of HN?! O tempora o mores!

So while your observation about an increased number of scripting attacks is interesting (assuming you did in fact establish a reliable baseline) it's in a strange place.

Did you mean to post elsewhere?

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#120
post #109
post #90

Earlier quoted context omitted.

It is not merely the uneducated who can subscribe to extremist ideologies. When the unskilled highschool grad gets off the plane and signs up, they are going to give him a rifle. When the engineer gets off the plane and announces himself as such, there is a chance that he will be put to better use.

Sadly, the fastest route to martyrdom is quite literally by biting a bullet, so no, AK-47's all round. Keyboards don't have quite the same sacrificial qualities.

I can imagine that those AKs are just the front. There might be someone or some organizations that sponsor the extremists. Money or otherwise. People who might benefit from instability, hatred towards the US etc.
Post reply on HN