Live data from Hacker News

“Warning: Do Not use my mirrors/services until I have reviewed the situation”

article.gmane.org

151–160 of 167 posts

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#151

Earlier quoted context omitted.

I don't know, sometimes something in an article triggers another stream of thought or tangent, and its a comments section, and other people might want to discuss that. I don't necessarily agree with the comment (as I have next to no visibility of this) but certainly don't mind reading comments on it. Maybe I'm wrongly using the site!

FWIW, I come to Hacker News to read the tangents.

Perhaps you should use www.reddit.com

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#152
post #81
post #65

Earlier quoted context omitted.

The computer in question is a server. If the server were configured to sleep unless the mouse is jiggled, it would already be asleep. Thus, using a "mouse jiggler" or similar is pointless, and risks detection.

Wouldn't surprise me if there's some standard procedure for police raids that doesn't distinguish between the two. Keep in mind it's generally not the experts who go out to the various locations.

The experts usually brief their soldiers about the tactical plan...

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#153
post #90
post #42

Earlier quoted context omitted.

Must admit I'm slightly amused that this is even being considered as a plausible theory. They're busy executing elderly with AK47s...thats very far away from physically cracking open servers in a western data center and inserting USB devices with targeted attack software.

It is not merely the uneducated who can subscribe to extremist ideologies. When the unskilled highschool grad gets off the plane and signs up, they are going to give him a rifle. When the engineer gets off the plane and announces himself as such, there is a chance that he will be put to better use.

>It is not merely the uneducated who can subscribe to extremist ideologies.

Indeed. And I'll happily concede that point. I (and many other) are just surprised at the thought process...physical hardware attack in (presumably a western data center)...and the thing that comes to mind is the ISIS??? Really if you tell me Russia I would have bought it. Same for China, Korea, Turkey etc...but jumping straight to the cliched CNN "terror org" that is the flavor of the month...please...

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#154
post #67

Earlier quoted context omitted.

Might be an interesting strategy to only allow one USB port to be used and if any other port is activated the machine self-wipes. Dell servers have an internal port along with the front and back externals.

Or use USB-ID white/blacklists.

Because USB VIDs and PIDs can't be spoofed.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#156
post #150

Latest update posted in the mailing list: https://lists.torproject.org/pipermail/tor-talk/2014-Decembe... No canary in this update.

One more update: https://lists.torproject.org/pipermail/tor-talk/2014-Decembe...

Several nodes are going to go back online and are being requested to be un-blacklisted. "I have emailed some of the DirAuths to remove several nodes and IPs from the blacklist that we feel confident have not been breached or compromised in any way."

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#157

Earlier quoted context omitted.

I'm surprised that this comment has been voted to the top. First, it has little to nothing to do with the comment posted, which concerns not a "cyberwar" but the possible police seizure of a Tor server. The assumption is it's either a false alarm or a police raid. No one thinks this was done by ISIS. Second, a post using the word "cyberwar" in a non-ironic manner at the top of HN?! O tempora o mores! So while your ob…

> I'm surprised that this comment has been voted to the top. Chuck's been around HN for a while, and has insightful comments frequently - that he posts this sort of "radical" comment implies that a non-nut is seriously considering it and quite possibly it's worth pondering as an idea.

> that a non-nut is seriously considering it and quite possibly it's worth pondering as an idea.

I would agree, but it would be a monumentally stupid way of trying to send encoded information into a foreign government, given the notice that is linked to. So no, it's not.

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#158
post #134

Earlier quoted context omitted.

IF we take the strict differences of the phrasing, we could say he's reasonably withholding information by request. Incorporated with the timeframe, this could be anyone — but given his response and the extra 250+ twitter followers today, he's probably been reminded the cost of drawing conjecture in public.

I am thinking this guy is very exact and precise in his phrasing, especially with regards to a canary. He's a crypto-geek, anarchist and running an exit node and this crowd knows Alice is not Bob. He knows what he says will be scrutinized by thousands. Why wouldn't he be very careful in what he says? Based on his first canary vs the last, he could, as you say, "reasonably" be withholding information on request. Perha…

Further, his subsequent posts to the mailing list[1] are missing the canary entirely, but everything has been addressed except for:

> 3. The DC has confirmed via Twitter that the servers were not "accessed". Having been raided in the past I know indeed they can be forced under Dutch law not to inform clients of raids, but I don't feel this may be the case. With that being said, a chassis intrusion indicator still must be addressed and I cannot find it in the logs anymore. The DC company are not the people who I directly interact with however so I am still awaiting a direct response form those we host the server with.

Either way, it's not a direct raid or seizure, if anything a backdoor installed by someone at the DC, but honestly at this point you have to accept the possibility and either accept/balance/mitigate the risk or get new hardware.

[1]: https://lists.torproject.org/pipermail/tor-talk/2014-Decembe...

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#159

Earlier quoted context omitted.

I'm surprised that this comment has been voted to the top. First, it has little to nothing to do with the comment posted, which concerns not a "cyberwar" but the possible police seizure of a Tor server. The assumption is it's either a false alarm or a police raid. No one thinks this was done by ISIS. Second, a post using the word "cyberwar" in a non-ironic manner at the top of HN?! O tempora o mores! So while your ob…

I don't know, sometimes something in an article triggers another stream of thought or tangent, and its a comments section, and other people might want to discuss that. I don't necessarily agree with the comment (as I have next to no visibility of this) but certainly don't mind reading comments on it. Maybe I'm wrongly using the site!

Is this comment itself not a tangent on a tangent?

Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”

#160
post #74

Earlier quoted context omitted.

Why do you think those USB devices are "pretty likely"? In this case, I would bet on a firmware compromise, similar to DIETYBOUNCE: https://www.eff.org/files/2014/01/06/20131230-appelbaum-nsa_... As a countermeasure, I would not fully trust TXT in this particular case. It's likely a state actor who could spoof measurements over the the LPC bus.

TXT doesn't rely on the LPC bus on modern motherboards because the TPM is integrated into the Northbridge. If any government agency can break TXT it'll be the NSA and I don't know if they are in the business of handing out their best exploits to random police teams at the moment.

How "modern" is modern? I understand there are some TPM implementations out there that are on-package, but there are still new servers being sold with TPM headers that I would expect to be easy to interpose.

Regardless, this whole thing turned out to be a false alarm due to a KVM device being attached.

Post reply on HN