Live data from Hacker News

Security Breach and Spilled Secrets Have Shaken the N.S.A.

nytimes.com

121–130 of 193 posts

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#121
post #44

Living in Maryland, I've met several young people who put in a few years at the agency (including TAO) who then left for industry. Millenials don't care about a government pension, especially when you're in a windowless SCIF hacking Perl. The US Government as a whole has a massive talent retention problem. Only the mediocre will stay at NSA / CIA now and we'll probably see more of these leaks / hacks.

Wait, they use perl?

Wasn't Perl created for the NSA? At least that's a story I heard. The official JPL reason is a cover.

Or maybe it was created for both. Or neither. Shrug.

Just googled it.. Here's a quote from Larry:

    [...] the NSA project Perl was (indirectly) written to support.
http://www.linuxjournal.com/article/3394

Another one from his 2005 State of the Onion:

> You might say that Perl grew out of the Cold War. I've often told the story about how Perl was invented at a secret lab that was working on a secret NSA project, so I won't repeat that here, since it's no secret

https://www.perl.com/pub/2005/09/22/onion.html

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#122
This is a tricky industry. NSA hires a lot of folks from the underground world. The problem is most of these folks do not pledge any allegiances - not that it really matters, as we have seen many of the leaks from the past 6-7 years are leaked by U.S. citizens. But the fact NSA is hiring freelancers to do the work should be an alarm when it comes to "national security" as NSA claims its mission. I am sure NSA does have a vetting, but how much? How good is the vetting? Is there a post-work surveillance? We don't know.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#123
post #111
post #37

Earlier quoted context omitted.

Agree, though the only thing that gives me any comfort (and it is the same with google, gmail, facebook, etc) is that the amount of data they collect is nearly impossible to ex filtrate because of its sheer size.

Once upon a time movies were too big to download, and now look.

When was that, 1999? That's nearly 20 years ago.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#124
post #41
post #29

Earlier quoted context omitted.

This was covered in a recent kaspersky paper[1], which I found in [2], where it is termed "fourth-party collection". The pdf gives a more complete description on page 2 (I found the increasing level of separation between collector and reciever to be almost comical) [1] https://cdn.securelist.com/files/2017/10/Guerrero-Saade-Raiu... [2] https://news.ycombinator.com/item?id=15663985

It seems like those kinds of more removed scenarios point to a strategic void in compartmentalization. We (US, Soviet Union, etc) had this figured out in the 60s when we were primarily using human intel. [1] Except the danger that now, instead of walking out with rolls of film covering a few thousand pages, someone can take everything they have access to in My only explanation is all those long-won counter-intelligen…

"It seems like those kinds of more removed scenarios point to a strategic void in compartmentalization."

It's on purpose. After 9/11, the intelligence agencies were lambasted for not sharing information. They were told the next one (a) couldn't happen and (b) would be their fault if it did. Lots of other motivations for the expansion in power, too. One side effect of this was compartmentalization was weakened a lot across the board. Over time, the security strength of things such as cross-domain solutions and endpoints had been dropping. The rush to get everything in that could benefit the mission increased that further.

Yeah, they're probably more vulnerable now than they ever were with more information to take with less chance of detection. Government and private sector. Their people like Roger Schell and Brian Snow warned them for a long time. Private contractors warned them. Those such as Aesec, BAE, and Green Hills even built and paid for evaluations of the kind of tech they said they wanted. They just used it less and less with stuff easy to hack being used more and more. In Snowden's case, the level of security was worse than a lot of enterprises with far less money.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#125
post #17

One thing that is not talked about enough with NSA is that if they are capable of leaking some of their most sensitive and powerful tools, then they are also capable of leaking the most sensitive and private information they collect on people. Perhaps this has not yet happened, or perhaps it has (someone will no doubt point out any known incidents here if there are any) but the idea is unnerving. Maybe my wording is…

Maybe, maybe not.

NSA hacking tools can't necessarily be kept privately within their network, because they have to be used to attack targets across the Internet -- they have to be deployed.

By comparison, the data that the NSA collects can presumably be sucked into their airgapped network, where data has a way in but no way out.

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#127

Earlier quoted context omitted.

Wait, they use perl?

Wasn't Perl created for the NSA? At least that's a story I heard. The official JPL reason is a cover. Or maybe it was created for both. Or neither. Shrug. Just googled it.. Here's a quote from Larry: [...] the NSA project Perl was (indirectly) written to support. http://www.linuxjournal.com/article/3394 Another one from his 2005 State of the Onion: > You might say that Perl grew out of the Cold War. I've often told t…

It was for the high-assurance BLACKER VPN:

https://en.wikipedia.org/wiki/Blacker_(security)

Here's the source on that:

http://cahighways.org/wordpress/?p=5460

Another notable aspect of that was it used an early secure kernel, GEMSOS, that is still marketed by Aesec but probably in legacy mode in bad way. It did resist penetration during NSA certification and time on market far as what data I have says.

http://aesec.com/

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#128
post #113
post #56

Earlier quoted context omitted.

It does mean it's not universally held to be shameful.

I don't think that's the case either. Its more of a "ain't broken so why fixit" problem which hasn't affected people on a personal level just yet, so it isn't regulated as much. Its astonishing to me that in the US it requires a court order to tap someone's phone and yet the NSA collects and analyzes the online data of US citizens...

No, I mean it literally isn't universally shameful. In that in most countries obeying an order to fire on civilians, or doing so because you believe your life is in danger, will not result in penalties. Because "it's what you do" or "us against them" from some perspectives.

See the response to Kent State [1], in which all legal attempts to hold the guardsmen who opened fire responsible failed.

[1] https://en.wikipedia.org/wiki/Kent_State_shootings#Legal_act...

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#129
post #37
post #17

One thing that is not talked about enough with NSA is that if they are capable of leaking some of their most sensitive and powerful tools, then they are also capable of leaking the most sensitive and private information they collect on people. Perhaps this has not yet happened, or perhaps it has (someone will no doubt point out any known incidents here if there are any) but the idea is unnerving. Maybe my wording is…

Agree, though the only thing that gives me any comfort (and it is the same with google, gmail, facebook, etc) is that the amount of data they collect is nearly impossible to ex filtrate because of its sheer size.

For now!

When storage and network bandwidth increase sufficiently, when we start measuring storage costs in terabytes rather than gigabytes, the sheer size of the data set is no longer going to be a preventative measure against ex filtrating it.

What are the chances that either corporations or 3 letter agencies are going to voluntarily delete their data on you before we reach that point?

Re: Security Breach and Spilled Secrets Have Shaken the N.S.A.

#130
post #44

Living in Maryland, I've met several young people who put in a few years at the agency (including TAO) who then left for industry. Millenials don't care about a government pension, especially when you're in a windowless SCIF hacking Perl. The US Government as a whole has a massive talent retention problem. Only the mediocre will stay at NSA / CIA now and we'll probably see more of these leaks / hacks.

There’s a massive pay disparity between public and private, and those currently in power want to keep it that way and eat away even more at gov functions. That combined without a clear rallying call for public service (like the Cold War or collective pride) are a recipe for disaster.

I'm not even sure it's just pay. The govt is extremely inefficient and bureaucratic. If your thing is writing code, why go to a place like that? You'd spend half your day writing memos and wrangling red tape.
Post reply on HN