Live data from Hacker News

Did this Tor developer become a victim of NSA's laptop interception program?

privacysos.org

121–130 of 169 posts

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#122
post #89

Earlier quoted context omitted.

The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviously high value target. A few comments: • This "low-level operative" was a system administrator who used social engineering to obtain other people's authentication credentials and gain access to material to which he wasn't aut…

> Internally, the keyboard and TrackPoint speak PS/2. While they could log keystrokes to an on-board chip and transmit keystrokes via radio, there aren't any especially interesting things the NSA can do to her laptop via a modified keyboard. They certainly won't be rooting it that way. This is a joke, right? A keyboard and a keylogger would give you everything you need to root a computer.

My point was that the modified keyboard alone couldn't do it. It's not a FireWire device that can read/write things from/to memory however it pleases, insta-pwning a computer as soon as it's connected (unless something like VT-d is being used to contain DMA transfers). It's not even a USB device that could abuse some poorly written driver to gain access.

If a hypothetical modified keyboard is logging keystrokes, someone has to eventually retrieve it to get the logged data. If it's transmitting keystrokes via radio, someone has to be nearby to capture them and then steal the laptop to get at its (presumably encrypted) data.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#123

Earlier quoted context omitted.

> No we did not. The disdain with which you discard my memories of that time is... interesting. Invent distrust? Of course not. However, I and my colleagues (as I recall), at the time just did not take the threat of government surveillance seriously. Did I trust the government? Yes. Yes I did. I'm Dutch. We have a childlike faith in our government. Being spied on by the government was something that happened on the o…

You weren't just naive. You were anomalously naive. It's funny you should mention PGP: the 1990s were the time of the crypto-wars, which were in part sparked by PGP. Remember "this t-shirt is a munition"? You couldn't even sell products with crypto in them without jumping through hoops.

> You were anomalously naive.

Now that type of thinking I find naive.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#124
post #97
post #90

Earlier quoted context omitted.

> Further, there isn't much in the way of intelligence presence in Alexandria. ARE YOU SERIOUS? Come. On.

Would you care to refute that instead of just shouting? Like, point out something that contradicts it? Because I can't think of any, and I lived in Alexandria for seven years.

NSA HQ, Ft Meade is 30 miles from Alexandria, Va.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#125
post #107

When I read the headline, and the comments here before reading the article, I was expecting to see tracking data that went from the seller to the buyer with a mysterious stop near the NSA. Then I read the article. The tacking data shows a delivery to a destination near the NSA. Does anyone here seriously think that the mechanism the NSA uses if they want to tamper with a laptop on the way to simply change the destina…

>Does anyone here seriously think that the mechanism the NSA uses if they want to tamper with a laptop on the way to simply change the destination address to be the NSA? And that no one has noticed this before?

No that doesn't pass the giggle test. If it has anything at all to do with the NSA, it's a blunder.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#126
I wonder what she's going to do with the keyboard when she gets it. Send it back and buy one locally? Examine it in detail for bugs/weirdness, and then use it normally? Connect it to a spare laptop, and use it to do searches for the weirdest porn you can think of?

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#127
post #9

HEY, KIDS! Do YOU know what time it is?! [wild audience applause] THAT'S RIGHT, it's time for WHICH IS MORE LIKELY? ! [intro music] Today on Which is More Likely? , we're looking at a replacement Lenovo Thinkpad keyboard that was shipped to Alexandria, Virginia, instead of Seattle, Washington. What a blunder! [slide whistle sound effect] Now put your thinking caps on and ponder, WHICH IS MORE LIKELY? ! • The largest…

Oh, I like this game. Let's play again: WHICH IS MORE LIKELY?! * The world's largest online retailer that does $54M in sales per day has a bug in its procurement system that randomly transposes tracking codes. ORRRRRRRR! * The intelligence agency whose massive scope and pervasive operational shortcomings were recently exposed by one low-level operative had a slip-up in applying a well-publicized tactic to an obviousl…

a couple weeks ago, my wife received an order from Banana Republic that was intended for a recipient in Newfoundland. the correct recipient's name was on the packlist inside the box but they showed it to the wrong person. likewise, my wife's actual offer took a few days longer to arrive, too. I suspect it was simple mistake inn the warehouse where an operator had two boxes, printed waybill stickers for both, and then slapped them on the wrong - already sealed - packages. I bet similar things happen regularly.

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#128
post #97

Earlier quoted context omitted.

Would you care to refute that instead of just shouting? Like, point out something that contradicts it? Because I can't think of any, and I lived in Alexandria for seven years.

NSA HQ, Ft Meade is 30 miles from Alexandria, Va.

And since Alexandria isn't 30 miles wide, we can conclude that NSA HQ is not "in Alexandria".

Re: Did this Tor developer become a victim of NSA's laptop interception program?

#129
post #85

Earlier quoted context omitted.

At this point aren't we all just guessing? Reading this thread I'm surprised how strongly many folks I respect (like you - viva FQ&A!) are insisting this could not be an NSA screw up. The truth is we don't know, so why rush to conclusions (even benign conclusions) instead of waiting to learn more? And imagine if you were Andrea and you develop software that dissidents around the world depend on with their life, while…

Yes, we are all just guessing. And I think you misunderstand. I am not arguing that it "could not be" the NSA. And I haven't see anyone say that. I am simply arguing that it is extremely unlikely. It's a guess, yes, but it's an informed guess. It's a matter of looking at probabilities and seeing what's more likely. Shippers screw up all the time. Packages make crazy detours because somebody tossed a box in the wrong…

Fair enough, and thanks for the thoughtful reply. I didn't mean to misrepresent your position -- I took "The obvious explanation here is that the USPS fucked up" to mean you belived it couldn't be otherwise, rather than when weighing the evidence the more obvious [simpler] explanation is that USPS screwed up.

Like you, I'm also a big proponent of Occam's razor. (Having been a med student, you don't know how many times I heard that "think horses not zebras" analogy from attendings.) I guess it just comes down to the degree of faith each of us has in the NSA and their corporate partners. Some of us are more willing to doubt their actions and/or believe it's possible they could screw up this way. But at this point we can only wait and see if we learn anything more in the coming days -- though probably not. One would hope the NSA is competent enough to cover this up, even if it was their screw up.

Added: BTW, there is another explanation that no one has mentioned. Leaving the Alexandria issue aside, the NSA interception program obviously relies on participation from one or more corporate partners. And just as we've seen at the telcos, it's reasonable to assume that there are staff at those partners who aren't particularly enthusiastic about the program. So it's possible someone decided to "accidentally" bypass/skip an important step that would have obscured this. It's not a huge leap to imagine a motivated techie realizing that this particular delivery would be an ideal opportunity to direct a lot of attention to the interception program -- if they felt compelled to take the risk. I'm definitely not saying this is the (or even a) likely possibility, but it's probably the only way we'll ever know if it was in fact the NSA.

Post reply on HN