Live data from Hacker News

Source Code Similarities Between NSA Malware and 'Regin' Trojan

spiegel.de

81–90 of 200 posts

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#81
post #78

Seeing that this is a keylogger, how complex would it be to enable a sort of SSL protocol between the keyboard and a specific application? The computational overhead should be manageable, the connector (USB) wouldn't need to change and there should be a fallback for any applications which doesn't support it. But if crucial applications like mail and the browser programs could use it, it might deliver another blow to…

If the operating system is compromised, your application stands no chance hiding its data (including keystrokes) from it. The keystrokes could simply be intercepted after decryption, or even before - if you keyboard controller is that capable, it probably has more than enough space for malware of its own.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#82

Earlier quoted context omitted.

I wonder if Chomsky would have that liberty of critique in any other country...

Are you serious? I wonder what Barrett Brown would say about this topic, if he wouldn't sit in prison right now: http://boingboing.net/2015/01/22/barrettbrown.html Are you aware that (h)activists from around the world do not travel to the USA because they fear the consequences, having their equipment seized or being imprisoned? Do you know why Laura Poitras is living in Berlin right now?

Being a "journalist" is not, and shouldn't ever be, a magic get-out-of-jail-free card. In Brown's own court motions, he agreed that he had threatened the lives and families of FBI agents, and that he had hidden evidence during a warranted search.

I ought to face jail for doing those things. So should Brown.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#83

Earlier quoted context omitted.

I wonder if Chomsky would have that liberty of critique in any other country...

Are you serious? I wonder what Barrett Brown would say about this topic, if he wouldn't sit in prison right now: http://boingboing.net/2015/01/22/barrettbrown.html Are you aware that (h)activists from around the world do not travel to the USA because they fear the consequences, having their equipment seized or being imprisoned? Do you know why Laura Poitras is living in Berlin right now?

[deleted]

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#84
post #46

It is worthwhile to apply the same scepticism for placement of attribution as was applied with the Sony hack. In the latter many security analysts question NK attribution based on the similarity of code argument given by the US -- pointing out that the code base was in the wild for a long time, could be purchased on black market or reverse/reengineered after picking up the malware from a vulnerable machine. Shouldn't…

I stopped reading the article when I got to this point:

"In the QWERTY code, there are numerous references to cricket, a sport that enjoys extreme popularity in the Commonwealth."

In the immortal words of John McEnroe, "YOU CANNOT BE SERIOUS!?"

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#85
post #29

Earlier quoted context omitted.

> "That this control is inadequate in our view, doesn't matter for ... a democratic system." It absolutely matters. Without those controls you have a democracy in name only. You could quite happily rig elections, arrest opponents, suppress the population etc, while still claiming to be 'democratic'.

> You could quite happily rig elections, arrest opponents, suppress the population etc, while still claiming to be 'democratic'. There is nothing undemocratic about those thing as long as a majority of people agree to them - though with rigged elections, you might not be democratic for very much longer. "Democracy" is not synonymous with "respecting my values and human rights." If enough Americans were sufficiently u…

> "... as long as a majority of people agree to them ..."

That requires that people are informed and able to comprehend the ramifications of their choices. Consider this: Is it still democratic if those who happen to be in charge are busy lying to and hoodwinking a poorly informed 'electorate'?

As for the rest of your comment, it is not democracy simply because a majority agree it is. http://en.wikipedia.org/wiki/Democracy

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#86
post #2

There are also additional clues pointing to Regin being a Five Eyes tool: In the QWERTY code, there are numerous references to cricket, a sport that enjoys extreme popularity in the Commonwealth. Given the relative popularity of cricket in the US vs. the rest of the world, it's more likely that this was written outside the NSA.

I don't think it's the sport. I think it's cricket = bug = spy tool.

It is the sport. The references they are referring to in the article include things like LEGSPIN.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#87
post #55

down voting on HN has become absurd. Also noticing this on other comments in this thread.

I think the problem is the consensus is the NSA/GCHQ use the tool. Your disagreement is whether the NSA/GCHQ originated it. Your comment reads as if you disagree with there being proof of any use, based on the evidence in the article. There's very little doubt the NSA/GCHQ use the tool. Here's some background reading: https://news.ycombinator.com/item?id=8649402 https://news.ycombinator.com/item?id=8653454 https://fi…

Whether they originated it, though, is the crux of the issue. Nobody doubts that government agencies undertake cyberwarfare. But the idea that they might have created something that is now being used by nongovernmental parties is the scary thing - it's like saying that the Army lost a cache of weapons now being used by ISIS. (Which itself is true [1], but that's another story.)

[1]: http://www.businessinsider.com/isis-captured-a-key-syrian-ai...

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#88
post #2

There are also additional clues pointing to Regin being a Five Eyes tool: In the QWERTY code, there are numerous references to cricket, a sport that enjoys extreme popularity in the Commonwealth. Given the relative popularity of cricket in the US vs. the rest of the world, it's more likely that this was written outside the NSA.

I don't think it's the sport. I think it's cricket = bug = spy tool.

Just as likely to be a tounge in cheek play on the stereotypically British line for something unfair:

"It's just not cricket"

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#89
post #29

Earlier quoted context omitted.

> "That this control is inadequate in our view, doesn't matter for ... a democratic system." It absolutely matters. Without those controls you have a democracy in name only. You could quite happily rig elections, arrest opponents, suppress the population etc, while still claiming to be 'democratic'.

> You could quite happily rig elections, arrest opponents, suppress the population etc, while still claiming to be 'democratic'. There is nothing undemocratic about those thing as long as a majority of people agree to them - though with rigged elections, you might not be democratic for very much longer. "Democracy" is not synonymous with "respecting my values and human rights." If enough Americans were sufficiently u…

Nearly all formulations of democracy are not just majority rule, they also explicitly include protections for the rights of minorities and consider it non-democratic for the majority to vote away the rights of the minority.

edit - This also makes sense from looking at the word. Democracy is rule by the 'demos', which means 'the people', which includes the minority. Rule by the majority is ochlocracy, from 'ochlos', meaning 'the mob'.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#90
Tinfoil hat: Hypothetically, if the Russian government were angry with the US government and wanted to give them a black eye, wouldn't having a Russian security firm announce to the world that the NSA was responsible for Reign be a good tactic?

Not saying NSA wasn't involved as I don't really trust my government, but when I read the article and saw Kaspersky mentioned, that was the first thing that popped into my head.

Post reply on HN