>But the CIA’s interim system contained a technical error: It connected back architecturally to the CIA’s main covert communications platform. When the compromise was suspected, the FBI and NSA both ran “penetration tests” to determine the security of the interim system. They found that cyber experts with access to the interim system could also access the broader covert communications system the agency was using to i…
Between the lines: it was Tor. Deploys on computers. Web-based. Detectable through decryption or pattern analysis. Firewalls. It was a pair of Tor hidden services. The mistake was probably that they ran both on the same machine with only a firewall separating them, rather than physically different servers.
Botched CIA Communications System Helped Blow Cover of Chinese Agents
141–150 of 206 posts
Re: Botched CIA Communications System Helped Blow Cover of Chinese Agents
#142>But the CIA’s interim system contained a technical error: It connected back architecturally to the CIA’s main covert communications platform. When the compromise was suspected, the FBI and NSA both ran “penetration tests” to determine the security of the interim system. They found that cyber experts with access to the interim system could also access the broader covert communications system the agency was using to i…
Re: Botched CIA Communications System Helped Blow Cover of Chinese Agents
#143>But the CIA’s interim system contained a technical error: It connected back architecturally to the CIA’s main covert communications platform. When the compromise was suspected, the FBI and NSA both ran “penetration tests” to determine the security of the interim system. They found that cyber experts with access to the interim system could also access the broader covert communications system the agency was using to i…
To me, preventing this seems like exactly the sort of thing the NSA ought to be for.
Re: Botched CIA Communications System Helped Blow Cover of Chinese Agents
#144Re: Botched CIA Communications System Helped Blow Cover of Chinese Agents
#145Earlier quoted context omitted.
I wonder if this is due to the ever increasing scale of the US intelligence services. From my working life perspective smaller teams of talented people are often more impactful than significantly larger teams. E.g. Large teams create bureaucracy. And 'weak links' become harder to spot and typically allowed to remain. I know nothing about this area so take my comment as curiosity only, but I wonder what USA gets/achie…
From my brief view into a federal agency: Employee breakdown is as follows: 1/6 extremely capable and dedicated high performers 1/6 extremely capable and dedicated but go home at 5pm 1/3 average (not going to screw things up massively, but also never going to make a large contribution) 1/3 shocking (as in where do you even find people this useless and disagreeable - if you’re lucky their managers put them in an offic…
Re: Botched CIA Communications System Helped Blow Cover of Chinese Agents
#146Earlier quoted context omitted.
To me, preventing this seems like exactly the sort of thing the NSA ought to be for.
There was a time when the NSA was in the white hat business; securing networks, identifying vulnerabilities and contributing to net sec projects. SELinux has been their most famous contribution. This all changed with the war on terrorism. Finding and exploiting vulnerabilities was the mission.
No, they've always had both roles. For instance, their experience and knowledge of advanced code-breaking techniques allowed them to strengthen the DES cipher's S-boxes in ways that weren't publicly understood until decades later.
https://en.wikipedia.org/wiki/Data_Encryption_Standard#NSA%2...
Re: Botched CIA Communications System Helped Blow Cover of Chinese Agents
#147"This didn't make it into the piece, but here's how the Chinese treated people working with the CIA: According to one source, one asset working at a state tech institutes, and his pregnant wife, were executed live on closed circuit TV in front of the staff." https://twitter.com/zachsdorfman/status/1029861843521523712
Obviously a revelation on Twitter about a secretive organisation's workings should always be taken with a grain of salt. However these sorts of reports aren't too uncommon, and it surprises me how there's a lot of pro-china commentators in communities such as HN who seem to glaze over these sorts of things and still aggressively promote the "Chinese way of doing things" is superior to whatever western value or opinio…
Re: Botched CIA Communications System Helped Blow Cover of Chinese Agents
#148Earlier quoted context omitted.
To me, preventing this seems like exactly the sort of thing the NSA ought to be for.
There was a time when the NSA was in the white hat business; securing networks, identifying vulnerabilities and contributing to net sec projects. SELinux has been their most famous contribution. This all changed with the war on terrorism. Finding and exploiting vulnerabilities was the mission.
Re: Botched CIA Communications System Helped Blow Cover of Chinese Agents
#149Earlier quoted context omitted.
I wonder if this is due to the ever increasing scale of the US intelligence services. From my working life perspective smaller teams of talented people are often more impactful than significantly larger teams. E.g. Large teams create bureaucracy. And 'weak links' become harder to spot and typically allowed to remain. I know nothing about this area so take my comment as curiosity only, but I wonder what USA gets/achie…
I don't think that's it. I personally think the best window into this world is William Binney and his thinthread project. He developed thinthread to protect Americans privacy, and it only was going to cost a handful of millions. His functioning program was scrapped for a billion dollar program that didn't protect Americans privacy and that didn't work because all it did was make the haystack so big finding the needle…
Re: Botched CIA Communications System Helped Blow Cover of Chinese Agents
#150Earlier quoted context omitted.
Here I was always assuming they employed the types of people who read HN to build systems like this. I'd expect e2e crypto, perfect forward secrecy, perhaps something akin to tor, and maybe even the ability to use steganography to disguise the fact any comms were really happening at all. Oh look at this cute kitten picture, let me save it and then get the encrypted code out of it. That's great, let me upload this equ…
it wouldn’t surprise me if it was a tor service via bridge. the snowden docs showed that gchq uses tor to communicate with assets. a big part of the value of tor is that even if youre detected connecting to it, that doesnt prove youre doing anything in particular on it, only that you’re using the network.