Live data from Hacker News

If you only work on your malware on weekdays, you might be a CIA hacker

qz.com

11–20 of 25 posts

Re: If you only work on your malware on weekdays, you might be a CIA hacker

#11
post #7

The CIA's dos and donts specifically mention putting build timestamps into others time zones: https://www.schneier.com/blog/archives/2017/03/the_cias_deve...

Yes but domains are registered and C&C servers are activated, things that can be tracked on other ends like clients and public databases.

So what they really need to do is make a queue system for actions like that and have them execute randomly during weekends. Would require a lot more patience and long sightedness but I don't see any other way of masking it.

Re: If you only work on your malware on weekdays, you might be a CIA hacker

#12
post #10

If every government entity can fake/scrub/modify time zones, how are time zones are a "tell" at all? Let's say the US uses French time zones and France uses US eastern time zones. You've discovered malware that for whatever reason has time stamps for US Eastern. Is it really from the US or is it from France? How would you deduce such a fact? I posit it would be better to see who the malware is targeting: entities may…

> Let's say the US uses French time zones

I know you're only using France as an example, but it's even more ridiculous when you consider that (mainland) France has one time zone (CE(S)T), which it shares with more than a dozen of other countries (central Europe + most of the western Europe + majority of Scandinavia + former Yugoslavia).

Re: If you only work on your malware on weekdays, you might be a CIA hacker

#14
> “On one occasion a computer in the United States was compromised but, following infection, an uninstaller was launched within hours, which may indicate this victim was infected unintentionally,” the blog post said.

A surprisingly refreshing feature.

Re: If you only work on your malware on weekdays, you might be a CIA hacker

#15

Great example of a headline that captures something really interesting about the story without lying or misleading readers.

It does mislead the reader, because this pattern is the case for most malware, and has been for over a decade. If you only work on it on weekdays, you are probably not a CIA hacker.

Re: If you only work on your malware on weekdays, you might be a CIA hacker

#16

Great example of a headline that captures something really interesting about the story without lying or misleading readers.

It does mislead the reader, because this pattern is the case for most malware, and has been for over a decade. If you only work on it on weekdays, you are probably not a CIA hacker.

I disagree. The headline clearly states that if you only work on weekdays you "might" be a CIA hacker, implicitly admitting that there are also non CIA hackers working on weekdays. What I found funny and interesting about this is that if I were working on malware and making exciting progress I definitely would not be able to resist working on the weekend. The idea that there is a government employee who is paid to create malware but sees it just a 9-5 thing that he doesn't care about when he clocks out is pretty funny to me.

Re: If you only work on your malware on weekdays, you might be a CIA hacker

#17

Symantec had already concluded that Longhorn was a group based in North America. That was partly based on the American time zones they saw, but also on the finding that Longhorn primarily targeted devices in Europe, Asia, Africa, and the Middle East—and seemed particularly averse to American computers. Now the CIA is going to claim that for national security reasons, they're going to have to hack American computers t…

Humor aside, one wonders how much increased communication could facilitate common malware usage between the CIA, NSA, etc. If some common malware were developed and distributed agnostic to foreign or domestic targets, it could be a conduit for other, more targeted software to be deployed, and otherwise not appear, based on detection, to specifically target foreign or domestic machines.

Re: If you only work on your malware on weekdays, you might be a CIA hacker

#18

Earlier quoted context omitted.

It does mislead the reader, because this pattern is the case for most malware, and has been for over a decade. If you only work on it on weekdays, you are probably not a CIA hacker.

I disagree. The headline clearly states that if you only work on weekdays you "might" be a CIA hacker, implicitly admitting that there are also non CIA hackers working on weekdays. What I found funny and interesting about this is that if I were working on malware and making exciting progress I definitely would not be able to resist working on the weekend. The idea that there is a government employee who is paid to cr…

I don't know this for a fact, but I assume people working on top secret CIA malware probably can't work from home. They'd have to go into the office and access the code from a secure computer.

Re: If you only work on your malware on weekdays, you might be a CIA hacker

#19
post #4

I've put some thought into similar deductions in the distant past. And measures to avoid them. Still waiting for the day a leak is attributed to the French because of the length of lunch breaks inferred from timestamps.

How long is a typical French programmers lunch break?

Re: If you only work on your malware on weekdays, you might be a CIA hacker

#20

Symantec had already concluded that Longhorn was a group based in North America. That was partly based on the American time zones they saw, but also on the finding that Longhorn primarily targeted devices in Europe, Asia, Africa, and the Middle East—and seemed particularly averse to American computers. Now the CIA is going to claim that for national security reasons, they're going to have to hack American computers t…

Couple of hours and if you move south in Europe it could be even longer
Post reply on HN