Live data from Hacker News

Source Code Similarities Between NSA Malware and 'Regin' Trojan

spiegel.de

141–150 of 200 posts

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#141

Earlier quoted context omitted.

Using that logic, what would constitute evidence? That's like the senator in favor of the Japanese interment camps saying that the fact that no Japanese Americans had committed a crime was just even more evidence they were planning something. Edit: More clearly written than my comment: http://lesswrong.com/lw/ih/absence_of_evidence_is_evidence_o... But basically, people have already come to a conclusion. If the comme…

So I can clearly not choose the drink that is in front of you!

They both did it yo

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#142

Earlier quoted context omitted.

Class action might be a solution for US citizens. The problem with malware though is that you end up infecting a whole lot of innocent civilians all over the place, which the people in Den Haag have slightly mixed feelings about. To be honest, I'm a bit disappointed that these cases never end up in international courts. The rules we have in place seem pretty clear to me.

Unlikely, you can't sue the Federal Government without its permission. In any case the NSA would simply say "national security" and boom you are done.

Then sue Alexander and Clapper for their roles, and lay the case that their actions were not in the scope of the office they held.

Then the government says nothing, and bad people get prosecuted.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#143
post #95
post #55

down voting on HN has become absurd. Also noticing this on other comments in this thread.

Ignore initial downvotes. People usually supply corrective upvotes if the downvote is unfair.

fare enough. but wondering what the value down voting brings at all, or if current model of blessing according to activity gives better results than blessing random users or randomly blessing users with N down votes per time or other quantifier. One of the later two would certainly be less cast based. Whereby the cast system of HN is according to "activity" not expertise.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#144
post #63

Earlier quoted context omitted.

> "Spying on European officials is a problem with oversight, not with capabilities." Snowden has showed this to be absolutely false. "Oversight" has been the nominal preventative for spying on our allies for decades, and it has always failed because these are spy agencies we are talking about. Their nature (and job description) is to do things in secret . You cannot oversee what you cannot see. The NSA has a fundamen…

Snowden and others have also shown that other countries' intelligence agencies will happily take over from the NSA and spy on you. For example the Chinese and Russians. Hacking tools are not mass surveillance technology. Trojans just don't work for that. And if you can't control how these agencies use their abilities, how do you propose to take these away from them? Adequate oversight is easier to achieve.

How do gain oversight over something that's by definition secret?

"Sorry, would like to tell you but doing so would be against the interest of the state ..."

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#145
post #55

down voting on HN has become absurd. Also noticing this on other comments in this thread.

I've been tracking the new downvoting trend for the last week or so. Seems there's a lot of accounts downvoting everything that doesn't coincide with Western Government sensibilities. The recent North Korea and LSD threads (not just my replies, but you can get to the threads from my comment history) are really interesting examples to trudge through and see how many valid replies are sitting at -1 or worse.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#146

Tinfoil hat: Hypothetically, if the Russian government were angry with the US government and wanted to give them a black eye, wouldn't having a Russian security firm announce to the world that the NSA was responsible for Reign be a good tactic? Not saying NSA wasn't involved as I don't really trust my government, but when I read the article and saw Kaspersky mentioned, that was the first thing that popped into my hea…

I see your point.

In this specific case Fox-IT (Netherlands) said the same thing. They based the claim not on the "source code" but on the fact that Regin was part of programs/processes of the NSA department ANT and mentioned in some leaked presentation slide of them (Source: http://www.spiegel.de/netzwelt/netzpolitik/trojaner-regin-is... (German)).

Thinking about infosec companies that publish impactful findings from time to time there is F-Secure from Finland, Fox-IT from the Netherlands, Symantec from the US and Kaspersky from Russia. Does anyone know about important Chinese/Japanese information security companies?

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#147
post #46

It is worthwhile to apply the same scepticism for placement of attribution as was applied with the Sony hack. In the latter many security analysts question NK attribution based on the similarity of code argument given by the US -- pointing out that the code base was in the wild for a long time, could be purchased on black market or reverse/reengineered after picking up the malware from a vulnerable machine. Shouldn't…

Spiegel might have done better to call it a GCHQ tool used by the NSA.

You are suggesting that a tool that has been around for 10 years was picked up and used by NSA/GHCQ. Even if we grant that, the sophistication level is a bit more than "simply modified". When is a fork no longer a fork because the code base has been modified/improved?

With your argument, one could go back as far as they wished - NSA takes an idea from academia and implements it, then we just say 'oh well, it was the univeristy who came up with it, not NSA as they only used it'

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#148
post #46

It is worthwhile to apply the same scepticism for placement of attribution as was applied with the Sony hack. In the latter many security analysts question NK attribution based on the similarity of code argument given by the US -- pointing out that the code base was in the wild for a long time, could be purchased on black market or reverse/reengineered after picking up the malware from a vulnerable machine. Shouldn't…

>> "It is worthwhile to apply the same scepticism for placement of attribution as was applied with the Sony hack." Just playing devils advocate here. The alternative is to do as the USG did and immediately jump to conclusions based on not that great evidence. If they don't give others the benefit of the doubt why should we give it to them?

I agree and this is what I was hinting at with the last point. I think in the end there is no way to update our understanding to a world filled with acts of conflict that are difficult to attribute. We've lived in an attribution luxury until now. So this Hippocratic of attribution will probably continue. I do think in the end the public will just learn to take attribution with a grain of salt.

This is why I think cyberwarfare represents one of the most fascinating areas of exploration for political science students. In addition to the collective psychological affect from attribution complexity (further discussion if interested https://medium.com/@cyphunk/the-nature-of-conflict-is-changi...) there is also the breaking down of the 2 state/coalition actor assumption. The actor could be from a known state enemy, an unclear enemy just disturbed by your trade/sanctions policies, some activists with a cause or a bunch of people from b/chan doing it for the lulz. The absurdity of the US response and attempt to protect some lousy hollywood comedy only illustrates this change of environment all too clearly.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#149
post #55

down voting on HN has become absurd. Also noticing this on other comments in this thread.

I've been tracking the new downvoting trend for the last week or so. Seems there's a lot of accounts downvoting everything that doesn't coincide with Western Government sensibilities. The recent North Korea and LSD threads (not just my replies, but you can get to the threads from my comment history) are really interesting examples to trudge through and see how many valid replies are sitting at -1 or worse.

Would you care to post/link to how you're tracking the voting trends? I didn't realize that data was available.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#150
OK, if you believe that there is actually such a thing as "Cyberwar" then this means that the USA has attacked Belgium. Does this give Belgium the right to physically blow up some important American infrastructure? ... or is Cyberwar a type of cold war which would limit the response to some sort of hacking of important American infrastructure?
Post reply on HN