Live data from Hacker News

Source Code Similarities Between NSA Malware and 'Regin' Trojan

spiegel.de

71–80 of 200 posts

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#71
Assuming all of this is true, and the TPP leaks are indeed what they seem to be - wouldn't the TPP let every corporation outside $COUNTRY sue the government of $COUNTRY for malware? (e.g. for $COUNTRY in Five Eyes)?

First upside to the TPP that I've seen, if true.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#72
post #33
post #2

There are also additional clues pointing to Regin being a Five Eyes tool: In the QWERTY code, there are numerous references to cricket, a sport that enjoys extreme popularity in the Commonwealth. Given the relative popularity of cricket in the US vs. the rest of the world, it's more likely that this was written outside the NSA.

Given that a NSA dev team was well aware that the spyware would be discovered and disassembled at some point in time, it was reasonable to intentionally leave behind evidence that points to countries other than the US. I'm not saying that's what happened, but I'd not take the cricket references too serious either.

Using that logic, what would constitute evidence? That's like the senator in favor of the Japanese interment camps saying that the fact that no Japanese Americans had committed a crime was just even more evidence they were planning something.

Edit: More clearly written than my comment: http://lesswrong.com/lw/ih/absence_of_evidence_is_evidence_o...

But basically, people have already come to a conclusion. If the comments said "go ", that'd be considered evidence of made in the USA. And if the comments say " go English sports team " then that's evidence of have in the USA, because obviously comments are misleading.

Why not go recursive? They wrote about cricket because they wanted to frame the Americans, who always write misleading comments to frame the Brits.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#73
post #6

Earlier quoted context omitted.

In the PDF (who's ever shipped binary as text in a pdf btw?) [1] they argue that it might be related to Australia; who knows... [1] http://www.spiegel.de/media/media-35668.pdf

Also "source code"... This is clearly not source code.

It's probably just reverse engineers being snobs.

Or journalists being journalists.

Or both.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#74
post #52

Earlier quoted context omitted.

I wonder if Chomsky would have that liberty of critique in any other country...

He certainly would in quite a lot of countries. Chomsky is a lot less controversial in a lot of countries outside the US than he is in the US. I'm sure there are countries where he'd be unable to say what he wants, but there are also a lot of countries (e.g. in Europe) where his political views are reasonably close to mainstream, to the extent where he's no more controversial than the average left wing politician and…

It seems strange to address raver's comment about liberty of critique by saying Chomsky is less controversial in Europe and his views are close to the mainstream.

Th test of a country's liberty is better illustrated by the spectrum of allowed speech rather than whether or not an opinion corresponds with the mainstream. And in my opinion, the spectrum of allowed speech is narrower in the average European country than the US.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#75
post #38
post #30

Earlier quoted context omitted.

Not related to this thread, but to your comment about the Maple Leaf: http://www.newsweek.com/why-rebel-groups-love-toyota-hilux-7... Edit: Sorry, I didn't see it was paywalled (I'm not a subscriber of that site). I now see that it counts your visits and disable itself after a few times. "Private" browsing seems to solve the problem.

that link is mostly paywalled. do you have another source?

Search the title.

But from old memory: Hilux trucks are built amazingly and have awesome reliability. Real, authentic, Hilux trucks are thus valued by freedom fighters/terrorists in Afghanistan. Canada donated a bunch if real Hilux trucks to Afghanistan, and these vehicles had a Maple Leaf logo. People associated the Maple Leaf with the quality of Hilux, to the point of at least one person getting a Maple Leaf tattoo to signify his quality.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#76
post #18

Earlier quoted context omitted.

I don't get it. The NSA is not a democratic government ... It's not elected by the people. The US people have no control over the NSA. There are also good reasons to argue that the US is not democratic: http://www.bbc.com/news/blogs-echochambers-27074746

The U.S. government, for all its weaknesses, is providing their citizens with freedom and liberties as good or better than most other countries. The NSA does have democratic oversight. It is controlled by the executive, legislative and judicative branches of the system. That this control is inadequate in our view, doesn't matter for the question whether or not the NSA is part of a democratic system.

The NSA has little to no oversight:

----

"Congressional oversight of the NSA is a joke. I should know, I'm in Congress" by Alan Grayson

http://www.theguardian.com/commentisfree/2013/oct/25/nsa-no-...

----

A minor quibble, but governments don't provide freedoms and liberties. They restrict them. Hence the word "govern" and its etymology.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#77

Earlier quoted context omitted.

Because the US shares intelligence with those governments. In some EU countries it is illegal for the government to spy on its citizens (also see the US pre-9/11), so the US spies on those countries and then relays the info back. Pre-9/11 this is also how the US worked. The UK spied on the US and the US spied on the UK, thus both subverting national laws, they then shared intelligence with one another (which is legal…

In my mind that's conspiracy-theory level claims. Got sources?

There's nothing conspiratorial about that one. Look up the echelon network and the UKUSA Agreement (both on Wikipedia). It has also been talked about in several books on the topic and discussed openly in the press. It is almost an "open secret" at this point.

Heck you can almost read the above claims verbatim here:

https://en.wikipedia.org/wiki/UKUSA_Agreement#Controversy

> During the 2013 NSA leaks Internet spying scandal, the surveillance agencies of the "Five Eyes" have been accused of intentionally spying on one another's citizens and willingly sharing the collected information with each other, allegedly circumventing laws preventing each agency from spying on its own citizens

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#78
Seeing that this is a keylogger, how complex would it be to enable a sort of SSL protocol between the keyboard and a specific application? The computational overhead should be manageable, the connector (USB) wouldn't need to change and there should be a fallback for any applications which doesn't support it. But if crucial applications like mail and the browser programs could use it, it might deliver another blow to security companies.

The way I would implement it is that the keyboard has a switch to enable this SSL type communication. Then the keyboard can perform a Diffie–Hellman key exchange with the current process. As a result any other interaction with the OS would become impossible until that process is terminated - basically disabling all OS related shortcuts etc. This would allow true end to end encryption - even on compromised systems (as long as the kernel code isn't modified to allow accessing the memory of other processes).

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#79
post #55

down voting on HN has become absurd. Also noticing this on other comments in this thread.

I think the problem is the consensus is the NSA/GCHQ use the tool. Your disagreement is whether the NSA/GCHQ originated it. Your comment reads as if you disagree with there being proof of any use, based on the evidence in the article.

There's very little doubt the NSA/GCHQ use the tool.

Here's some background reading:

https://news.ycombinator.com/item?id=8649402

https://news.ycombinator.com/item?id=8653454

https://firstlook.org/theintercept/2014/12/13/belgacom-hack-...

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#80
post #71

Assuming all of this is true, and the TPP leaks are indeed what they seem to be - wouldn't the TPP let every corporation outside $COUNTRY sue the government of $COUNTRY for malware? (e.g. for $COUNTRY in Five Eyes)? First upside to the TPP that I've seen, if true.

If you or I wrote it we'd go to jail for a very, very long time.

When a government writes it, nothing happens.

Post reply on HN