Live data from Hacker News

Source Code Similarities Between NSA Malware and 'Regin' Trojan

spiegel.de

181–190 of 200 posts

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#181
post #29

Earlier quoted context omitted.

> "That this control is inadequate in our view, doesn't matter for ... a democratic system." It absolutely matters. Without those controls you have a democracy in name only. You could quite happily rig elections, arrest opponents, suppress the population etc, while still claiming to be 'democratic'.

> You could quite happily rig elections, arrest opponents, suppress the population etc, while still claiming to be 'democratic'. There is nothing undemocratic about those thing as long as a majority of people agree to them - though with rigged elections, you might not be democratic for very much longer. "Democracy" is not synonymous with "respecting my values and human rights." If enough Americans were sufficiently u…

If enough Americans were sufficiently upset about the NSA, it would be gone. They aren't. It's not even a significant election issue.

Are we sure of that? Wisconsin Senator Russ Feingold lost his re-election bid. He was the only Senator to vote against the PATRIOT Act in 2001.

Colorado Senator Mark Udall lost his 2012 re-election campaign after being a total gadfly in the Senate Intelligence Oversight Committee.

It strikes me that the NSA is a significant election issue, just not to the voters.

Also, you're kind of arguing about a technicality in the definition of "democratic". Our elected reps often act un-democratically. I hope this is to prevent tyranny of the majority, but I fear that it's just legislative capture.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#182

Earlier quoted context omitted.

I don't think it's the sport. I think it's cricket = bug = spy tool.

A spy tool that chirps every few seconds to announce its presence? There are better insects to reference.

maybe because it jumps as malware usually does

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#183
post #104
post #85

Earlier quoted context omitted.

> "... as long as a majority of people agree to them ..." That requires that people are informed and able to comprehend the ramifications of their choices. Consider this: Is it still democratic if those who happen to be in charge are busy lying to and hoodwinking a poorly informed 'electorate'? As for the rest of your comment, it is not democracy simply because a majority agree it is. http://en.wikipedia.org/wiki/Dem…

There's no reason to believe the US government has to make any real effort to make sure voters are misinformed. They seem to manage it just fine on their own.

You're glossing over a huge amount of stuff relating to who does the reporting and how the reporting on the government is done. There's plenty to suggest that the government actively works to keep journalists in line. The Sterling prosecution and James Risen's legal problems spring to mind. The heavy weight of the Espionage Act also comes to mind, as does the very heavy use of "anonymous" or "unnamed sources" these days.

In short, it really looks like some parts of the US government actively work to keep reporting very favorable or non-existent.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#184

Earlier quoted context omitted.

Are you serious? I wonder what Barrett Brown would say about this topic, if he wouldn't sit in prison right now: http://boingboing.net/2015/01/22/barrettbrown.html Are you aware that (h)activists from around the world do not travel to the USA because they fear the consequences, having their equipment seized or being imprisoned? Do you know why Laura Poitras is living in Berlin right now?

> Are you serious? I'm sure he is, and I agree with him. On the less serious side, it's like that old joke about American and Soviet journalists, who discuss freedoms and yelling "Down with the USA" at the Times Square and Red Square, respectively. You can do the same at both places without fear of consequences.

What are you agreeing with though? Raverbashing didn't make a statement, he proposed a question. One which has been pretty well answered.

As far as your joke goes however, have you tried standing in Times Square yelling "Down with the USA"? I wouldn't think it would be that safe an enterprise.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#185
post #63

Earlier quoted context omitted.

> "Spying on European officials is a problem with oversight, not with capabilities." Snowden has showed this to be absolutely false. "Oversight" has been the nominal preventative for spying on our allies for decades, and it has always failed because these are spy agencies we are talking about. Their nature (and job description) is to do things in secret . You cannot oversee what you cannot see. The NSA has a fundamen…

Snowden and others have also shown that other countries' intelligence agencies will happily take over from the NSA and spy on you. For example the Chinese and Russians. Hacking tools are not mass surveillance technology. Trojans just don't work for that. And if you can't control how these agencies use their abilities, how do you propose to take these away from them? Adequate oversight is easier to achieve.

Snowden and others have also shown that other countries' intelligence agencies will happily take over from the NSA and spy on you.

How is that sentence anything other than a non sequitur?

We're talking about NSA overreach, and attributing Regin and/or Qwerty to the MSA or the 5 eyes. Why are you fudding up the Russians and the Chinese?

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#186
post #136

Earlier quoted context omitted.

And I'd argue that it is a disassembly of a binary compiled from source code. Source code has the word " source " in it. Unless the original human wrote it directly in assembly without comments or macros (from his padded cell at the asylum, naturally), it is obviously not source code.

"Source code" is generally code you can put into a compiler and get out object code. The term "source" refers to the fact that it is used as input. This is why, for example, the GPL specifies that you must release the original source code in the preferred format for editing — so that people wouldn't release source code generated by disassembly or a source-to-source transformer.

I suppose it all depends on how you define "source code". For me, source code implies that it was authored by a human or automatically generated to mimic human authorship. Any automated translation step that does not result in executable "object code" or "machine language" is "intermediate code".

It may be usable in the same way as source code, but since it was produced as the output of a program that had an input closer to the source, it cannot be the source.

I imagine the compilation process like a stream. The source is the origin of the flow. All changes made there propagate downstream. Some streams are short, like those with M4-processed assembly. Others are longer, with MSIL or JVM intermediate code. Linked libraries are like tributaries; they have their own sources. The end product is a single river, which fans out into a delta for each supported processor architecture as it nears the sea of end users.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#187
post #101

Earlier quoted context omitted.

Class action might be a solution for US citizens. The problem with malware though is that you end up infecting a whole lot of innocent civilians all over the place, which the people in Den Haag have slightly mixed feelings about. To be honest, I'm a bit disappointed that these cases never end up in international courts. The rules we have in place seem pretty clear to me.

For some malwares that may be true, but I doubt Regin was that sloppy.

Why not? Stuxnet got into the wild and I wouldn't consider it sloppy at all.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#188
post #104

Earlier quoted context omitted.

There's no reason to believe the US government has to make any real effort to make sure voters are misinformed. They seem to manage it just fine on their own.

You're glossing over a huge amount of stuff relating to who does the reporting and how the reporting on the government is done. There's plenty to suggest that the government actively works to keep journalists in line. The Sterling prosecution and James Risen's legal problems spring to mind. The heavy weight of the Espionage Act also comes to mind, as does the very heavy use of "anonymous" or "unnamed sources" these d…

Oh, sure, they might do it anyway, I'm just saying it's not needed.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#189
post #147
post #46

It is worthwhile to apply the same scepticism for placement of attribution as was applied with the Sony hack. In the latter many security analysts question NK attribution based on the similarity of code argument given by the US -- pointing out that the code base was in the wild for a long time, could be purchased on black market or reverse/reengineered after picking up the malware from a vulnerable machine. Shouldn't…

Spiegel might have done better to call it a GCHQ tool used by the NSA. You are suggesting that a tool that has been around for 10 years was picked up and used by NSA/GHCQ. Even if we grant that, the sophistication level is a bit more than "simply modified". When is a fork no longer a fork because the code base has been modified/improved? With your argument, one could go back as far as they wished - NSA takes an idea…

Basically what cyphunk is saying is: how do we know that this was used by the NSA? More precisely: how does Spiegel know to say "clear proof that Regin is in fact the cyber-attack platform belonging to the Five Eyes alliance"?

We have something out in the wild (Regin) which contains a component (QWERTY) which was leaked in the Snowden documents, however it is quite possible that both descend from a common non-NSA source (Putative) such that:

        P (non-NSA)
       / \
      Q   R (non-NSA)
    (NSA)
Furthermore it is possible that in fact P = R, and that Q was derived from Regin rather than the other way around. Lots of possibilities are out there. We don't really have proof that P = Q and that therefore R also belongs to the NSA.

The issue is that we can attribute malicious attacks to R, and the article seems to be suggesting that therefore we should attribute these to the NSA. The reply by cyphunk is saying that this is a dangerous logical leap.

Re: Source Code Similarities Between NSA Malware and 'Regin' Trojan

#190

Earlier quoted context omitted.

> You could quite happily rig elections, arrest opponents, suppress the population etc, while still claiming to be 'democratic'. There is nothing undemocratic about those thing as long as a majority of people agree to them - though with rigged elections, you might not be democratic for very much longer. "Democracy" is not synonymous with "respecting my values and human rights." If enough Americans were sufficiently u…

If enough Americans were sufficiently upset about the NSA, it would be gone. They aren't. It's not even a significant election issue. Are we sure of that? Wisconsin Senator Russ Feingold lost his re-election bid. He was the only Senator to vote against the PATRIOT Act in 2001. Colorado Senator Mark Udall lost his 2012 re-election campaign after being a total gadfly in the Senate Intelligence Oversight Committee. It s…

> It strikes me that the NSA is a significant election issue, just not to the voters.

You've just managed to explain quite succinctly why it isn't a significant election issue.

Post reply on HN