If so, can the people and companies that were affected file a class action?
Class action might be a solution for US citizens. The problem with malware though is that you end up infecting a whole lot of innocent civilians all over the place, which the people in Den Haag have slightly mixed feelings about. To be honest, I'm a bit disappointed that these cases never end up in international courts. The rules we have in place seem pretty clear to me.
Source Code Similarities Between NSA Malware and 'Regin' Trojan
101–110 of 200 posts
Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan
#102My current opinion on government hacking is, that I actually want democratic government to be the biggest meanest hackers of them all. The alternative, unfortunately, is that either organized crime or non-democratic governments (or a combination of both) would be the biggest meanest hackers. And hacking doesn't really scale. Mass surveillance just through attacking individuals with malware isn't possible, because of…
Not sure why people vote you down for sharing your opinion. Having said that, your logic is fundamentally flawed. Governments have to either focus on attacking or defending. Focusing on attacking means keeping a lid on vulnerabilities, which weakens the security of citizens and corporations inside their own country. Focusing on defending means disclosing those vulnerabilities in order to protect everybody, which also…
Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan
#103Assuming all of this is true, and the TPP leaks are indeed what they seem to be - wouldn't the TPP let every corporation outside $COUNTRY sue the government of $COUNTRY for malware? (e.g. for $COUNTRY in Five Eyes)? First upside to the TPP that I've seen, if true.
If you or I wrote it we'd go to jail for a very, very long time. When a government writes it, nothing happens.
After all, you could use this malware to spy on your child's use of your PC, which is legal, right?
Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan
#104Earlier quoted context omitted.
> You could quite happily rig elections, arrest opponents, suppress the population etc, while still claiming to be 'democratic'. There is nothing undemocratic about those thing as long as a majority of people agree to them - though with rigged elections, you might not be democratic for very much longer. "Democracy" is not synonymous with "respecting my values and human rights." If enough Americans were sufficiently u…
> "... as long as a majority of people agree to them ..." That requires that people are informed and able to comprehend the ramifications of their choices. Consider this: Is it still democratic if those who happen to be in charge are busy lying to and hoodwinking a poorly informed 'electorate'? As for the rest of your comment, it is not democracy simply because a majority agree it is. http://en.wikipedia.org/wiki/Dem…
Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan
#105Earlier quoted context omitted.
In my mind that's conspiracy-theory level claims. Got sources?
There's nothing conspiratorial about that one. Look up the echelon network and the UKUSA Agreement (both on Wikipedia). It has also been talked about in several books on the topic and discussed openly in the press. It is almost an "open secret" at this point. Heck you can almost read the above claims verbatim here: https://en.wikipedia.org/wiki/UKUSA_Agreement#Controversy > During the 2013 NSA leaks Internet spying s…
Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan
#106Seeing that this is a keylogger, how complex would it be to enable a sort of SSL protocol between the keyboard and a specific application? The computational overhead should be manageable, the connector (USB) wouldn't need to change and there should be a fallback for any applications which doesn't support it. But if crucial applications like mail and the browser programs could use it, it might deliver another blow to…
This is kind of what the kernel is for, though: if you can't modify the memory of other processes you can't handle IO for them. Hiding data in plaintext from the OS is basically impossible. Nearest you can get is heavy obfuscation (Skype) or communication to a secure hardware bastion (TPMs for DRM or otherwise, ARM TrustZone).
What might be more interesting and useful is secure communication between a remote website and a non-PC device. Kind of like PIN pads, but more user friendly.
Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan
#107If so, can the people and companies that were affected file a class action?
Class action might be a solution for US citizens. The problem with malware though is that you end up infecting a whole lot of innocent civilians all over the place, which the people in Den Haag have slightly mixed feelings about. To be honest, I'm a bit disappointed that these cases never end up in international courts. The rules we have in place seem pretty clear to me.
AFAIK there are no widely accepted international conventions that would forbid, say, USA goverment to install malware (intentionally or unintentionally) on a german user's computer; if you can name as specific one then that would make this discussion much more interesting. International law is not particularly restrictive to the rights of governments to attack each other or their citizens if they desire so; the citizens don't have much recourse in international courts if a foreign government accidentally killed them, much less damaged their computer.
Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan
#108Earlier quoted context omitted.
If you or I wrote it we'd go to jail for a very, very long time. When a government writes it, nothing happens.
Really? Apart from France, do most countries prosecute the author of computer/hacking tools? I was under the impression that the use of the tools is what mattered. Just like BitTorrent itself has been fine, but any hints of using it for copyright infringement get fire. After all, you could use this malware to spy on your child's use of your PC, which is legal, right?
Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan
#109Earlier quoted context omitted.
I am serious and I am aware of the issues you raised. Meanwhile Turkey has to remove pages from FB because they're "offensive", not to mention other issues that happens in the ME. I am certainly not saying the US has the better situation, and Europe looks good, unless you "offend" some groups of people... And if you think censorship by DMCA is bad in the US you should know the German GEMA. Please note that freedom fr…
"in any other country" reads a bit different than "turkey and some middle-east countries". This is rather about free speech than about copyright issues which GEMA and the DMCA deal with. Have a look at the Freedom of Press Index, where the USA are behind Botswana and El Salvador: https://en.wikipedia.org/wiki/Press_Freedom_Index
Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan
#110Earlier quoted context omitted.
Being a "journalist" is not, and shouldn't ever be, a magic get-out-of-jail-free card. In Brown's own court motions, he agreed that he had threatened the lives and families of FBI agents, and that he had hidden evidence during a warranted search. I ought to face jail for doing those things. So should Brown.
What would have happened had he been a politician?
I hope this isn't some weird "because some politicians might get away with obstructing search warrants and issuing death threats, then journalists should be able to get away with it, too." You don't fix a carve-out with more carve-outs.