Live data from Hacker News

Hacking Team hacked, attackers claim 400GB in dumped data

csoonline.com

221–230 of 240 posts

Re: Hacking Team hacked, attackers claim 400GB in dumped data

#221
post #77

Earlier quoted context omitted.

The massive PR hit they're taking means their company will most likely die. And "compromising" someone merely by letting one download stuff is at best a gamble, any decent infosec professional will examine this stuff with the same precautions as when analyzing malware.

This is exactly what I'm talking about: What I'm being downvoted for and what each comment is doing is rationalizing why this simply can't happen . Everyone is confident about what Hacking Team is or isn't doing/thinking. How can someone be so sure what an entity is thinking or doing? Yes, it's not likely. Yes, it's risky.. but what if they were really bold? The PR hit is a non issue if it is the case, since they can…

> Yes, it's risky.. but what if they were really bold?

Isn't the question really how careless the people downloading the file are?

Is it possible to infect hardware through a virtual machine? Let's just assume it is; what's to stop someone from using a throwaway, one-way laptop? Get fresh laptop, install the tools you need, copy the files over via USB or network, disconnect the laptop and never connect it to anything ever again. What am I missing?

To transfer a lot of data (e.g. analysis results) back from the potentially infected machine, play back the data encoded as audio, record that with another computer and convert it back to binary/plain text/whatever. (There might be better ways but hey)

Sure, most people probably won't bother with any such stuff, and just stick to "only" viewing text files and images etc., but then all HT would have shown is what has been proven with email spam already: that if you can get people to treat unknown files carelessly, not to mention run executables, you can infect them.

Re: Hacking Team hacked, attackers claim 400GB in dumped data

#222

Someone is uploading things to github: https://github.com/hackedteam/ Take a look at the GeoTrust repo... This is a very interesting file, too: https://github.com/hackedteam/rcs-common/blob/master/lib/rcs...

Looks like they are actively distributing child pornography. They should be charged.

It's probably a dummy value. I doubt there's a sinister scheme to plant "John Doe " in a victim's address book. [1]

[1] https://github.com/hackedteam/rcs-common/blob/master/lib/rcs...

Re: Hacking Team hacked, attackers claim 400GB in dumped data

#223
post #121

Earlier quoted context omitted.

I think that's a little bit of an excessively simple viewpoint. The US army does much more than Abu Ghraib, Guantanamo and drones (in fact, a lot of what you just described is probably managed by agents outside the army such as the CIA). To flip this around, should every employee of a Silicon Valley company be shamed for rising property values in the area that have left many homeless? Should every Google employee be…

>Should every Google employee be shamed for the illegal wifi capture done by Streetview vans? Oh FFS. I dislike Google. But doing tcpdump and forgetting to write -s 64 should hardly be a crime. Just because courts are technologically incompetent doesn't change the ethics of it.

Yeah, In retrospect I shouldn't have used that as an example - I was talking about something that I didn't know much about. My apologizes.

Re: Hacking Team hacked, attackers claim 400GB in dumped data

#225
post #121
post #108

Earlier quoted context omitted.

People who join the US army should be forced to watch videos of Abu Ghraib and Guantanamo torture, they should be forced to watch testimonies of people in drone-bombed municipalities. But I am afraid that for many the "we good, they bad" mentality would justify those atrocities. Like another commenter said, who is bad and who is good really depends on your viewpoint.

I think that's a little bit of an excessively simple viewpoint. The US army does much more than Abu Ghraib, Guantanamo and drones (in fact, a lot of what you just described is probably managed by agents outside the army such as the CIA). To flip this around, should every employee of a Silicon Valley company be shamed for rising property values in the area that have left many homeless? Should every Google employee be…

> To flip this around And that is to flip it a lot. The talk was about direct help to commit crimes against humanity. Your examples don't apply at all.

I think that helping dictatorial regimes to commit crimes should be itself a crime. "I just did it for money" is not an excuse legal nor moral.

Re: Hacking Team hacked, attackers claim 400GB in dumped data

#226
post #91

I do not want to sound shockingly naive, but I wonder how these people can sleep at night. You've just sold software to some of the most brutal governments in the world, who will use your technology to track down and brutally torture incredibly brave human rights activists. How can you do this, and still get up in the morning while looking at yourself in the mirror? I can understand petty crime if the alternative is…

Someone's gonna do it anyways? So the choice is whether you do something and profit off it (and possibly use the money to accomplish good things) or if you let someone else do it and make the money and perhaps do bad things. Pretty easy choice for me. In fact, I've written software to analyze VoIP networks (troubleshooting) at scale, and now I'm wondering if I can retarget that and sell to larger entities for much mo…

> Someone's gonna do it anyways?

You can apply this reasoning to justify for absolutely anything that you want to do. And it is false.

> On a separate note, we should be free to pursue scientific and engineering knowledge without having to deal with consequences of idiots that misuse such things.

Completely agree. But this people are the "idiots" that are taking the scientific research of others and putting it in bad hands. And what they are doing should be punishable by law.

Re: Hacking Team hacked, attackers claim 400GB in dumped data

#227
post #55

Earlier quoted context omitted.

I don't know how it is over there, but legally mandated record keeping requirements are a pretty good excuse for not using public key encryption on corporate mail servers. There are products that act as middlemen that transparently convert between keys that are public and self generated... but that kind of defeats the purpose of public key encryption.

Not at all. Just securely store a copy of all work keys on a non-networked, "cold storage" server and back it up for redundancy. Record keeping is preserved while you gain the full benefits of PGP.

You're right about the cold storage aspect, I was thinking about some of the transparent encryption gateway products that are out there. Email sent to folks without PGP would still be unencrypted when it goes through the corporate MTA, but a copy encrypted with the sender's public key would be stored long term.

Re: Hacking Team hacked, attackers claim 400GB in dumped data

#229

Earlier quoted context omitted.

A nation's strong defensive capabilities deter action. If Ukraine had NATO level arms that could counter Russia's weapons, there would be no war in Ukraine right now. Instead, their military is all Soviet relics that current-gen and even most last-gen Russian arms can easily overrun; thus the Russian led artillery, Russian led AA, Russian led forces, and Russian special ops making mincemeat of their military. Its inc…

> Its incredible how people pretend deterrence isn't real or a social benefit. It's incredible how people pretend deterrence is for social benefit. It brought us already once near a global atomic war. Remember? https://en.wikipedia.org/wiki/Cuban_Missile_Crisis We would live in a better world without nuclear arms, that I'm 100% sure of.

Why not post all the Wikipedia links too bloody mass-murderous wars pre-deterance?

Re: Hacking Team hacked, attackers claim 400GB in dumped data

#230

Earlier quoted context omitted.

It's software sold to law enforcement/intelligence agencies, and it is designed explicitly to plant false evidence. Even post-Snowden I think that qualifies as interesting.

Can you elaborate on "design explicitly to plant false evidence"? I don't know what the program does, but those path names are zero evidence, come on.

The file explicitly said "evidence" in the first line. It's deleted now.
Post reply on HN