Live data from Hacker News

“Warning: Do Not use my mirrors/services until I have reviewed the situation”

article.gmane.org

121–130 of 167 posts

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#121
post #104

Earlier quoted context omitted.

it is pretty likely the USB device is this http://www.cru-inc.com/products/wiebetech/mouse_jiggler/ to prevent the computer going to sleep while this is utilized http://www.cru-inc.com/products/wiebetech/hotplug_field_kit/ These are pretty standard plays in seizing computers these days. One should note that the grsec linux patchset has functionality to not load drivers for any plugged usb devices, as well as log when…

Pretty sure Jake Appelbaum stated at 30c3 that the Mouse Jiggler will cause the system to lock immediately if plugged into Systemd [0]. [0]: https://www.youtube.com/watch?v=vILAlhwUgIU

It's the udev rule added by this commit:

http://cgit.freedesktop.org/systemd/systemd/commit/?id=7212a...

It runs "loginctl lock-sessions" whenever a USB input device with a name of "Wiebetech LLC Wiebetech" is plugged in.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#122
post #74

Earlier quoted context omitted.

it is pretty likely the USB device is this http://www.cru-inc.com/products/wiebetech/mouse_jiggler/ to prevent the computer going to sleep while this is utilized http://www.cru-inc.com/products/wiebetech/hotplug_field_kit/ These are pretty standard plays in seizing computers these days. One should note that the grsec linux patchset has functionality to not load drivers for any plugged usb devices, as well as log when…

Why do you think those USB devices are "pretty likely"? In this case, I would bet on a firmware compromise, similar to DIETYBOUNCE: https://www.eff.org/files/2014/01/06/20131230-appelbaum-nsa_... As a countermeasure, I would not fully trust TXT in this particular case. It's likely a state actor who could spoof measurements over the the LPC bus.

TXT doesn't rely on the LPC bus on modern motherboards because the TPM is integrated into the Northbridge.

If any government agency can break TXT it'll be the NSA and I don't know if they are in the business of handing out their best exploits to random police teams at the moment.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#123
post #34

Earlier quoted context omitted.

Oh, the whole cyberwar situation is far from "hopeless". The truth is nobody to speak of has taken it seriously yet. Security is still mostly an afterthought, if that , almost everywhere you look. Even in nominally security-focused contexts. And much of the activity in places that really are security focused are built around an environment in which software must be assumed to basically be constructed out of styrofoam…

I agree about C and C++, but is there a language that exists today that you think would be better for writing security-conscious code? Should a language be invented that is specifically for writing security-conscious code?

Basically all modern languages with strict type systems do better than C or C++ when it comes to security. Anything JVM based can't be buffer overflowed or double-free/use-after-free exploited, for instance.

Now if you go with a weakly typed language like Javascript there are a whole other class of bugs that can bite you:

https://medium.com/@octskyward/type-safety-and-rngs-40e3ec71...

... so don't use those.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#124
A Dutch tech news site [1] published the news on their site and got in contact with the ISP Snel:

The ISP told Tweakers that the account of Thomas White was blocked due to a security policy of the company. The customer let a deadline for verification accidentally expire and logged in through KVM. "Some KVM's generate a USB event when you use it to set up a connection to the server, this is what the customer just notified." - according to the ISP Snel. Meanwhile, the man's account is released.

[1] https://tweakers.net/nieuws/100388/beheerder-verliest-contro...

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#125
post #42
post #12

Earlier quoted context omitted.

Does ISIS really have the resources to carry out criminal computer activities? From what I understand, they are a group with limited technological advantage, and there is no way they could carry out a major attack on the Internet.

Must admit I'm slightly amused that this is even being considered as a plausible theory. They're busy executing elderly with AK47s...thats very far away from physically cracking open servers in a western data center and inserting USB devices with targeted attack software.

If you put an AK47 into a USB port and pull the trigger, the server is very likely to go offline. Not even reimaging will help.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#126
post #34

Earlier quoted context omitted.

When it hits hedge funds and private equity firms people will start caring.

Oh, the whole cyberwar situation is far from "hopeless". The truth is nobody to speak of has taken it seriously yet. Security is still mostly an afterthought, if that , almost everywhere you look. Even in nominally security-focused contexts. And much of the activity in places that really are security focused are built around an environment in which software must be assumed to basically be constructed out of styrofoam…

I'm actually amazed that there's someone else out there who recognizes that C and C++ have to go if we want real infosec.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#127
post #30
post #28

Earlier quoted context omitted.

Can you explain more? How do go about dumping memory?

This is a good intro to the subject http://www.forensicswiki.org/wiki/Memory_Imaging Law enforcement also has additional undisclosed methods to avoid detection by systems.

Undisclosed even to courts? How do courts know such forensic methods are done according to the law if they're undisclosed?

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#128

A Dutch tech news site [1] published the news on their site and got in contact with the ISP Snel: The ISP told Tweakers that the account of Thomas White was blocked due to a security policy of the company. The customer let a deadline for verification accidentally expire and logged in through KVM. "Some KVM's generate a USB event when you use it to set up a connection to the server, this is what the customer just noti…

So much about ISP customer confidentiality then!?

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#129

A Dutch tech news site [1] published the news on their site and got in contact with the ISP Snel: The ISP told Tweakers that the account of Thomas White was blocked due to a security policy of the company. The customer let a deadline for verification accidentally expire and logged in through KVM. "Some KVM's generate a USB event when you use it to set up a connection to the server, this is what the customer just noti…

I don't really buy it. This doesn't explain why a chassis intrusion alarm was triggered, nor why a large chunk of logs are now missing.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#130

Interesting. It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. I've seen a 10x increase in various scripted attacks being attempted (patch early and often folks!) and a number of APT level compromises of systems either staging malware or deploying it (see the latest bulletin on the Afghan govern…

I'm surprised that this comment has been voted to the top. First, it has little to nothing to do with the comment posted, which concerns not a "cyberwar" but the possible police seizure of a Tor server. The assumption is it's either a false alarm or a police raid. No one thinks this was done by ISIS. Second, a post using the word "cyberwar" in a non-ironic manner at the top of HN?! O tempora o mores! So while your ob…

I don't know, sometimes something in an article triggers another stream of thought or tangent, and its a comments section, and other people might want to discuss that. I don't necessarily agree with the comment (as I have next to no visibility of this) but certainly don't mind reading comments on it. Maybe I'm wrongly using the site!
Post reply on HN