Live data from Hacker News

Source Code Similarities Between NSA Malware and 'Regin' Trojan

spiegel.de

151–160 of 200 posts

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#151
post #55

down voting on HN has become absurd. Also noticing this on other comments in this thread.

I've been tracking the new downvoting trend for the last week or so. Seems there's a lot of accounts downvoting everything that doesn't coincide with Western Government sensibilities. The recent North Korea and LSD threads (not just my replies, but you can get to the threads from my comment history) are really interesting examples to trudge through and see how many valid replies are sitting at -1 or worse.

I've experienced a couple of really bad downvotes as well lately, and they had definitely no intention of editorial feedback, but it was quite obviously mindless prejudice, almost on the level of /r/politics or /r/worldnews. I wished HN would replace downvotes with a system for short and private annotations, so that people could receive concrete feedback, not something that is vaguely implied by a number. That would also remove the problem that people mindlessly jump on the downvote bandwagon.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#152
post #147
post #46

It is worthwhile to apply the same scepticism for placement of attribution as was applied with the Sony hack. In the latter many security analysts question NK attribution based on the similarity of code argument given by the US -- pointing out that the code base was in the wild for a long time, could be purchased on black market or reverse/reengineered after picking up the malware from a vulnerable machine. Shouldn't…

Spiegel might have done better to call it a GCHQ tool used by the NSA. You are suggesting that a tool that has been around for 10 years was picked up and used by NSA/GHCQ. Even if we grant that, the sophistication level is a bit more than "simply modified". When is a fork no longer a fork because the code base has been modified/improved? With your argument, one could go back as far as they wished - NSA takes an idea…

My question was concerning attribution. Though debatable lets assume still the original was not theirs and they remixed it. Even if they made massive changes turning into their own beast allowing us to call the Snowden version significant we are still left with the question of: Are all the attacks over the past 10 years attributed to this general varietal, their attacks? Without full knowledge attribution is like a blind taste testing of different vintages of wine.

Also I think the remixed and implemented idea from academia applies less. It would be more like taking the paper from one journal, changing a few paragraphs and publishing it in another. And assuming these journals had a policy of publishing without names, how can we know who the author is in all prior journals when we eventually find a way to attribute one author to one journal?

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#153

Earlier quoted context omitted.

Or, you know, they could concentrate on defense rather than offense

How can they provide adequate defenses without having the best offensive hackers? At the very least, penetration testing is an indispensable tool in cyber security. Also, surveillance of criminal and terrorist organizations without offensive capabilities is impossible.

Having offensive hackers, and using them for penetration purposes - that is "white hats", is fine by me. Using them for "black hat" purposes is not. That makes them the bad guys.

They should be using their capabilities to increase the security protections they have in place. For example, if they discover a vulnerability, they should work to get it fixed, instead of leaving it there so everyone is vulnerable, just so they can use it to attack others.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#154
post #129

Earlier quoted context omitted.

Try to enjoy your liberty, for example the right to property, when there is no government to stop your neighbor from just taking your stuff. Looking back at history, I vastly prefer the balance of liberty afforded by strong governments in the western world to the lack of such control.

The right to property implies the right to also defend that property. I'm what stops my neighbor from taking my stuff, not the government. Looking back at history, strong governments have been THE source of oppression and limitations of freedoms.

And if your neighbor is bigger and stronger than you? If 100 of your neighbors get together to take your stuff? If 100 of your neighbors independently want your stuff?

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#155
post #2

There are also additional clues pointing to Regin being a Five Eyes tool: In the QWERTY code, there are numerous references to cricket, a sport that enjoys extreme popularity in the Commonwealth. Given the relative popularity of cricket in the US vs. the rest of the world, it's more likely that this was written outside the NSA.

I know GCHQ contractors (BAE Detica, funded as a part of the "Mastering The Internet" tender) had a hand in at least some of it; it's not unreasonable to guess it might've been that module, as that does link it? (Although of course, that's just a guess, and doesn't really tell us anything particularly new or useful.) Not that I think nation-state malware is, you know, strictly cricket . (Quite the opposite, I've alwa…

Update: It seems Australia's DSD was likely a better guess in this particular instance - more to come from the authors soon. (Which leaves that Detica module currently unaccounted for. I don't know what that could be yet.) Of course, they're all Five Eyes, and at least US and UK have both used it, so I wouldn't be too surprised to see CAN/AUS/NZ too.

Leaves us back with the "How do we fix this?" problem. And "how do we find what replaced STRAITBIZARRE"?

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#156

OK, if you believe that there is actually such a thing as "Cyberwar" then this means that the USA has attacked Belgium. Does this give Belgium the right to physically blow up some important American infrastructure? ... or is Cyberwar a type of cold war which would limit the response to some sort of hacking of important American infrastructure?

I don't know. We'll find out when the attacker will be Belgium and the victim the US.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#157
post #78

Seeing that this is a keylogger, how complex would it be to enable a sort of SSL protocol between the keyboard and a specific application? The computational overhead should be manageable, the connector (USB) wouldn't need to change and there should be a fallback for any applications which doesn't support it. But if crucial applications like mail and the browser programs could use it, it might deliver another blow to…

If the OS is compromised, then you can't work around that to secure a program inside the OS. You can run the program somewhere else, like on the keyboard itself. Some secure crypto devices have displays, so you can see what you're signing. The only similar thing I've heard of is the "Secure Attention Sequence" in Windows. That is, pressing CtrlAltDel before entering credentials lets you be sure an application is not…

I LOVE how you come with trusted computing on a topic about a malware allegedly created/modified by the NSA.

You MUST be a security professional! Only those have such a distorted view of reality!!!!

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#158
post #151

Earlier quoted context omitted.

I've been tracking the new downvoting trend for the last week or so. Seems there's a lot of accounts downvoting everything that doesn't coincide with Western Government sensibilities. The recent North Korea and LSD threads (not just my replies, but you can get to the threads from my comment history) are really interesting examples to trudge through and see how many valid replies are sitting at -1 or worse.

I've experienced a couple of really bad downvotes as well lately, and they had definitely no intention of editorial feedback, but it was quite obviously mindless prejudice, almost on the level of /r/politics or /r/worldnews. I wished HN would replace downvotes with a system for short and private annotations, so that people could receive concrete feedback, not something that is vaguely implied by a number. That would…

And/or, make up and downvotes public. A link from a comment to the list of uppers and downers.

Or make it semi-private, and only the commenter can see the list. But that would just encourage useless activity as commenters selectively out their up and downvotes.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#159
post #129

Earlier quoted context omitted.

The right to property implies the right to also defend that property. I'm what stops my neighbor from taking my stuff, not the government. Looking back at history, strong governments have been THE source of oppression and limitations of freedoms.

And if your neighbor is bigger and stronger than you? If 100 of your neighbors get together to take your stuff? If 100 of your neighbors independently want your stuff?

What if the government wants your stuff or 20-50% of it?

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#160
post #159

Earlier quoted context omitted.

And if your neighbor is bigger and stronger than you? If 100 of your neighbors get together to take your stuff? If 100 of your neighbors independently want your stuff?

What if the government wants your stuff or 20-50% of it?

At the absolute barest minimum, even disregarding any context, it's better to have to one known entity demanding a share than an unlimited number of unknown ones doing the same.
Post reply on HN