Live data from Hacker News

Source Code Similarities Between NSA Malware and 'Regin' Trojan

spiegel.de

111–120 of 200 posts

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#111
post #46

It is worthwhile to apply the same scepticism for placement of attribution as was applied with the Sony hack. In the latter many security analysts question NK attribution based on the similarity of code argument given by the US -- pointing out that the code base was in the wild for a long time, could be purchased on black market or reverse/reengineered after picking up the malware from a vulnerable machine. Shouldn't…

>> "It is worthwhile to apply the same scepticism for placement of attribution as was applied with the Sony hack."

Just playing devils advocate here.

The alternative is to do as the USG did and immediately jump to conclusions based on not that great evidence. If they don't give others the benefit of the doubt why should we give it to them?

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#112

Earlier quoted context omitted.

I am serious and I am aware of the issues you raised. Meanwhile Turkey has to remove pages from FB because they're "offensive", not to mention other issues that happens in the ME. I am certainly not saying the US has the better situation, and Europe looks good, unless you "offend" some groups of people... And if you think censorship by DMCA is bad in the US you should know the German GEMA. Please note that freedom fr…

"in any other country" reads a bit different than "turkey and some middle-east countries". This is rather about free speech than about copyright issues which GEMA and the DMCA deal with. Have a look at the Freedom of Press Index, where the USA are behind Botswana and El Salvador: https://en.wikipedia.org/wiki/Press_Freedom_Index

"where the USA are behind Botswana and El Salvador"

You mean, in position 46 of 180? Higher rated than Italy, Taiwan, South Korea, Chile and Japan?

Not the best position, surely, almost on the Top 4th

Nice attempt of data manipulation, btw, also implying that Botswana and El Salvador should not have good freedom of press "of course"

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#113
post #78

Seeing that this is a keylogger, how complex would it be to enable a sort of SSL protocol between the keyboard and a specific application? The computational overhead should be manageable, the connector (USB) wouldn't need to change and there should be a fallback for any applications which doesn't support it. But if crucial applications like mail and the browser programs could use it, it might deliver another blow to…

If the OS is compromised, then you can't work around that to secure a program inside the OS. You can run the program somewhere else, like on the keyboard itself. Some secure crypto devices have displays, so you can see what you're signing. The only similar thing I've heard of is the "Secure Attention Sequence" in Windows. That is, pressing CtrlAltDel before entering credentials lets you be sure an application is not…

"Trusted computing" puts the controller of the trusted infrastructure in control - the owner of the computer should expect that any NSA-approved malware will be considered properly trusted, and being in control of a secure OS doesn't help against attacks coming from the hardware (malware or backdoors on firmware) with direct memory access.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#114
post #6

Earlier quoted context omitted.

In the PDF (who's ever shipped binary as text in a pdf btw?) [1] they argue that it might be related to Australia; who knows... [1] http://www.spiegel.de/media/media-35668.pdf

Also "source code"... This is clearly not source code.

"This is clearly not source code."

that's assembler

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#115
post #102

Earlier quoted context omitted.

Not sure why people vote you down for sharing your opinion. Having said that, your logic is fundamentally flawed. Governments have to either focus on attacking or defending. Focusing on attacking means keeping a lid on vulnerabilities, which weakens the security of citizens and corporations inside their own country. Focusing on defending means disclosing those vulnerabilities in order to protect everybody, which also…

The best defense is a good offense.

I just explained to you why that's not true. Let me try again:

Attacking a computer means finding a bug and keeping it secret until you use it to attack said computer. Defending a computer means finding a bug and disclosing/fixing it so that nobody can use it to attack said computer. I hope it's obvious to you that these two ideas contradict each other.

Please let me know if you have questions. This is very important and not intuitive at all. I'd love to help you understand it better.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#116

Earlier quoted context omitted.

Also "source code"... This is clearly not source code.

I'd argue that it's source code at the lowest possible level...

And I'd argue that it is a disassembly of a binary compiled from source code.

Source code has the word "source" in it. Unless the original human wrote it directly in assembly without comments or macros (from his padded cell at the asylum, naturally), it is obviously not source code.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#117
post #46

It is worthwhile to apply the same scepticism for placement of attribution as was applied with the Sony hack. In the latter many security analysts question NK attribution based on the similarity of code argument given by the US -- pointing out that the code base was in the wild for a long time, could be purchased on black market or reverse/reengineered after picking up the malware from a vulnerable machine. Shouldn't…

>> "It is worthwhile to apply the same scepticism for placement of attribution as was applied with the Sony hack." Just playing devils advocate here. The alternative is to do as the USG did and immediately jump to conclusions based on not that great evidence. If they don't give others the benefit of the doubt why should we give it to them?

If your goal is to understand who is doing what, then you want to be smart about how you draw conclusions.

If, on the other hand, your goal is to flame people who have done bad stuff when the opportunity arises, then yeah, go for it.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#118
post #76

Earlier quoted context omitted.

The U.S. government, for all its weaknesses, is providing their citizens with freedom and liberties as good or better than most other countries. The NSA does have democratic oversight. It is controlled by the executive, legislative and judicative branches of the system. That this control is inadequate in our view, doesn't matter for the question whether or not the NSA is part of a democratic system.

The NSA has little to no oversight: ---- "Congressional oversight of the NSA is a joke. I should know, I'm in Congress" by Alan Grayson http://www.theguardian.com/commentisfree/2013/oct/25/nsa-no-... ---- A minor quibble, but governments don't provide freedoms and liberties. They restrict them. Hence the word "govern" and its etymology.

Try to enjoy your liberty, for example the right to property, when there is no government to stop your neighbor from just taking your stuff.

Looking back at history, I vastly prefer the balance of liberty afforded by strong governments in the western world to the lack of such control.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#119
post #80
post #71

Assuming all of this is true, and the TPP leaks are indeed what they seem to be - wouldn't the TPP let every corporation outside $COUNTRY sue the government of $COUNTRY for malware? (e.g. for $COUNTRY in Five Eyes)? First upside to the TPP that I've seen, if true.

If you or I wrote it we'd go to jail for a very, very long time. When a government writes it, nothing happens.

If you or I kill someone, we'd go to jail for a very, very long time.

When a government kills someone, nothing happens.

Nothing new.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#120
post #46

It is worthwhile to apply the same scepticism for placement of attribution as was applied with the Sony hack. In the latter many security analysts question NK attribution based on the similarity of code argument given by the US -- pointing out that the code base was in the wild for a long time, could be purchased on black market or reverse/reengineered after picking up the malware from a vulnerable machine. Shouldn't…

>> "It is worthwhile to apply the same scepticism for placement of attribution as was applied with the Sony hack." Just playing devils advocate here. The alternative is to do as the USG did and immediately jump to conclusions based on not that great evidence. If they don't give others the benefit of the doubt why should we give it to them?

Because 1) the USG isn't one single guy and 2) the truth might be more important to some than conclusion-jumping.
Post reply on HN