Live data from Hacker News

New Snowden Docs Indicate Scope of NSA Preparations for Cyber Battle

spiegel.de

191–200 of 295 posts

Re: New Snowden Docs Indicate Scope of NSA Preparations for Cyber Battle

#191

Here's a story for you. I'm not a party to any of this. I've done nothing wrong, I've never been suspected of doing anything wrong, and I don't know anyone who has done anything wrong. I don't even mean that in the sense of "I pissed off the wrong people but technically haven't been charged." I mean that I am a vanilla, average, 9-5 working man of no interest to anybody. My geographical location is an accident of my…

Agree completely..

When the docs first leaked, I wrote this: https://medium.com/@haroonmeer/why-discussions-on-cyber-snoo...

Re: New Snowden Docs Indicate Scope of NSA Preparations for Cyber Battle

#192

Earlier quoted context omitted.

But by stockpiling vulnerabilities they are making civilians less safe. Offensive digital capabilities should never come at the expense of fixing software.

I ended up rescuing & then adopting a German Shepherd 18 months ago, without having planned such a thing. These days I don't even bother to read the the scarevertising from burglar alarm suppliers that turns up in the mailbox every month or two. I don't want to barricade myself into my own home or have some corporation constantly surveilling it for me. While it's far from an exact analogy, I actually feel quite a bit…

What is the "active deterrent" analogy in computer security that makes it worth leaving vast numbers of civilian computer systems vulnerable to stockpiled 0-days, engineered backdoors, and weaknesses surreptitiously introduced into standards?

Re: New Snowden Docs Indicate Scope of NSA Preparations for Cyber Battle

#193

Here's a story for you. I'm not a party to any of this. I've done nothing wrong, I've never been suspected of doing anything wrong, and I don't know anyone who has done anything wrong. I don't even mean that in the sense of "I pissed off the wrong people but technically haven't been charged." I mean that I am a vanilla, average, 9-5 working man of no interest to anybody. My geographical location is an accident of my…

This agency gathered information on you, attempted to friend you on linkedin and infected your family's computer. I don't think any of those actions warrant accusations of inhumanity. I can understand that it's disturbing to feel that you're being stalked, or even just monitored. But it doesn't sound like anyone took action to intervene in your private affairs or intentionally lead you to feel threatened. It's legal…

Much like trying to comprehend what it is like to be a parent when you are not a parent. You will not grasp how clueless you were about it until you become one.

Re: New Snowden Docs Indicate Scope of NSA Preparations for Cyber Battle

#194
post #25

Everything at the lowest levels needs to be tightened up now. Buffer overflows in trusted code have to go. This means getting rid of the languages with buffer overflow problems. Mostly C and C++. Fortunately we have Go and Rust, plus all the semi-interpreted languages, now, and can do it. We need something that runs Docker-like containers and, all the way down the bare metal, has no unsafe code. We need dumber server…

One problem with most "interpreted languages" you cite as preferable is that they rely on C/C++ run-times for now. This means these languages are only as safe as the underlying C/C++ run-times and the core libraries they rely upon (glibc and the like.) We need to start to think of replacing underlying runtimes and core libraries with Rust and Go-based alternatives (or similar) to make them safer. Ultra-large goal and…

It may not be that big a task. How much code do you really need to run a container instance? If you could get an airtight Xen-like system, you might not need much of an OS inside each container. Xen already does memory allocation, CPU dispatching, I/O handling, timer handling, and message passing, which is all an OS really needs.

Rust programs running on "libnative" do not, I think, use "libc" any more.

Re: New Snowden Docs Indicate Scope of NSA Preparations for Cyber Battle

#195
post #30

Looking at the comments in support of the NSA here makes me suspect an astroturfing campaign is happening. Edit: I should add that my suspicion came from noticing that the vast majority of the comments when this was first posted seemed aligned in favor of the NSA's mission. It wasn't the presence of pro-NSA comments that was interesting but rather that these opinions were the overwhelming majority. This is, of course…

wait so if somebody disagrees with you, even on principle, it's evidence of astroturfing?

Re: New Snowden Docs Indicate Scope of NSA Preparations for Cyber Battle

#196

Earlier quoted context omitted.

>we foreign people are just fair game for targeting That's not exactly true in that not every non-U.S. citizen is an interest to the U.S. Government. To your broader point though, the idea that a state's Security, Defense or Military arms are singularly focused on foreign "threats" or potential threats is a fundamental assumption of nearly every international relations theory. Why would you think it would be otherwis…

What the US is doing is extraordinary, mainly because it is the only country with the resources to run the operation that it's running, but also because everybody seems to be infected with fear. If we were talking about Georgia, or Israel, or Ukraine, or Japan, I would understand the fear. But the USA has no enemies, there are no threats. It's a tragic case of paranoia.

> there are no threats. It's a tragic case of paranoia.

Unless, of course, you have a non-US company competing with a US company, then you are targeted.

http://en.wikipedia.org/wiki/ECHELON#Concerns

"In the early 1990s, the U.S. National Security Agency intercepted the communications between the European aerospace company Airbus and the Saudi Arabian national airline. In 1994, Airbus lost a $6 billion contract with Saudi Arabia after the NSA, acting as a whistleblower, reported that Airbus officials had been bribing Saudi officials to secure the contract.[58] As a result, the American aerospace company McDonnell Douglas (now part of Boeing) won the multi-billion dollar contract instead of Airbus."

"The American defense contractor Raytheon won a US$1.3 billion contract with the Government of Brazil to monitor the Amazon rainforest after the U.S. Central Intelligence Agency (CIA), acting as a whistleblower, reported that Raytheon's French competitor Thomson-Alcatel had been paying bribes to get the contract."

"In order to boost America's position in trade negotiations with the then Japanese Trade Minister Ryutaro Hashimoto, in 1995 the CIA eavesdropped on the conversations between Japanese bureaucrats and executives of car manufacturers Toyota and Nissan."

And these are only the public cases of course. If you can eavesdrop on the conversations between your competitor and prospect, I don't have to tell you the huge advantage.

You guys are pissing off friendly nations (I'm European).

Re: New Snowden Docs Indicate Scope of NSA Preparations for Cyber Battle

#197

Earlier quoted context omitted.

But the USA has no enemies, there are no threats. I am interested in how you came to this conclusion.

I'd be interested to know who you think is a threat! The US has two borders. One with Canada, one with Mexico. Neither of these countries are likely to invade. The US has the largest naval force in the world. I believe the Coastguard is also the 13th largest. Again, nothing to fear. Of the countries that are "enemies", most would quite like to improve relations, for instance Cuba and Iran. Iran in particular has exte…

It might be more accurate to say that there are no existential threats to the US.

The US certainly has competitors for geopolitcal influence (~enemies), as does any other nation.

Re: New Snowden Docs Indicate Scope of NSA Preparations for Cyber Battle

#198

Earlier quoted context omitted.

I ended up rescuing & then adopting a German Shepherd 18 months ago, without having planned such a thing. These days I don't even bother to read the the scarevertising from burglar alarm suppliers that turns up in the mailbox every month or two. I don't want to barricade myself into my own home or have some corporation constantly surveilling it for me. While it's far from an exact analogy, I actually feel quite a bit…

What is the "active deterrent" analogy in computer security that makes it worth leaving vast numbers of civilian computer systems vulnerable to stockpiled 0-days, engineered backdoors, and weaknesses surreptitiously introduced into standards?

Bombs under your neighbor's porches, according to this sister comment - more seriously, the offensive capabilities outlined in the original article. I think both of you are taking an over-literal reading of my comment.

Re: New Snowden Docs Indicate Scope of NSA Preparations for Cyber Battle

#199

Earlier quoted context omitted.

I ended up rescuing & then adopting a German Shepherd 18 months ago, without having planned such a thing. These days I don't even bother to read the the scarevertising from burglar alarm suppliers that turns up in the mailbox every month or two. I don't want to barricade myself into my own home or have some corporation constantly surveilling it for me. While it's far from an exact analogy, I actually feel quite a bit…

What is the "active deterrent" analogy in computer security that makes it worth leaving vast numbers of civilian computer systems vulnerable to stockpiled 0-days, engineered backdoors, and weaknesses surreptitiously introduced into standards?

Bombs under your neighbor's porches, according to this sister comment - more seriously, the offensive capabilities outlined in the original article. I think both of you are taking an over-literal reading of my comment despite the qualification therein.

Re: New Snowden Docs Indicate Scope of NSA Preparations for Cyber Battle

#200
post #103

Earlier quoted context omitted.

It's a good thing for allies to spy on each other to understand intentions, as this article in Foreign Affairs argues. http://www.foreignaffairs.com/articles/140247/jennifer-sims/...

Point taken. But let's keep the CSC vs de-mail discussion for another time. I see a huge difference between spying to get to know the others' intentions, and preparing sabotage, destruction and infrastructural doom for maximum threat potential.

And industrial espionage to steal contracts form Non-US "allied" countries for economic gain.
Post reply on HN