Live data from Hacker News

How the NSA Plans to Infect “Millions” of Computers with Malware

firstlook.org

151–160 of 182 posts

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#151

Earlier quoted context omitted.

If you combine this article with the dozens of others from the past ~year, the vacuum analogy is not at all hyperbolic.

Two NSA bulk collection programs have been outed: the NSA collects call log metadata to this day, and they used to collect email headers from unencrypted email deliveries entering or leaving the US until a few years ago. The remaining articles about NSA data collection have been about targeted programs. Though I disagree with some of their methods, they are not vacuuming up everything they can get their hands on by a…

> The remaining articles about NSA data collection have been about targeted programs.

Cut the crap.

* XKeyscore: NSA tool collects 'nearly everything a user does on the internet' [1]

* NSA collecting phone records of millions of Verizon customers daily [2]

* NSA taps Skype chats, newly published Snowden leaks confirm [3]

* NSA collects millions of text messages daily in 'untargeted' global sweep [4]

* Optic Nerve: millions of Yahoo webcam images intercepted by GCHQ [5]

I'll quote:

> Sweeps up emails, social media activity and browsing history

[1]: http://www.theguardian.com/world/2013/jul/31/nsa-top-secret-...

[2]: http://www.theguardian.com/world/2013/jun/06/nsa-phone-recor...

[3]: http://arstechnica.com/tech-policy/2013/07/nsa-taps-skype-ch...

[4]: http://www.theguardian.com/world/2014/jan/16/nsa-collects-mi...

[5]: http://www.theguardian.com/world/2014/feb/27/gchq-nsa-webcam...

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#152

Earlier quoted context omitted.

I feel guilty of upvoting a joke on HN. My only comfort is knowing that this one will be buried, and this will be my punishment.

That's a little dramatic, don't you think? :-)

Looks like the comment-parent isn't a native english speaker; a lot probably got lost in translation.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#153
post #35
post #13

Earlier quoted context omitted.

Yes it's called a revolution at which point we storm the bases and burn the data centres and monitoring stations to the ground. But, as Huxley was so keen to point out, that's not going to happen when people are staring at Honey Boo Boo and Hollyoaks.

Let's say we do that and then what? The NSA/GCHQ decides to build a fully decentralized spy network. Millions of nodes connected all over the place; a botnet of spying. Sound familiar?

Cut the cables. All of them. Leased, backbone, local loops.

Poison the routing tables.

Jam the wireless.

Take out root DNS.

I cringe slightly at quoting Firefly but it's similar in nature: "If your quarry goes to ground, leave no ground to go to."

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#154

Since they see everyone as a potential threat, taint their data so that everyone appears to be that threat. Millions of us could increase the signal-to-noise ratio in their collected data by using a bot to perform random human-like web searches and visits. If 100 people are searching for , the government has actionable surveillance data. If 100 thousand or 10 million are searching for it in ways that are indistinguis…

Has anyone looked into doing this? Meaning has anyone started building anything like this? I would be interested.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#155

Earlier quoted context omitted.

I grant that funding for the War on Terror has taken place. But I also don't think that a real, formal declaration of war has been approved. So, is the USA at war or not? I suspect (but I'm only 52% certain) that we're not at war. The follow-on questions (after "are we at war or not?"): In what state are we? What are the legal ramifications of this half-at-war-state? Why hasn't the US Congress declared war since WW2?…

There is no requirement, either under the Constitution or under laws of war, for any sort of formal declaration. And, there as an "authorization of military force" against al Qaeda and the Taliban. There certainly isn't some magic I DECLARE WAR requirement. > Why hasn't the US Congress declared war since WW2? Is there some consequence to declaring war or not declaring war that they're trying to avoid? Its an outdated…

Oh, so we are at war with a government that has been completely disbanded and a loose network of terrorists whose leaders are either dead or imprisoned. Next you'll be telling me that we are at war with Germany, Japan, and Italy.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#156

Earlier quoted context omitted.

I grant that funding for the War on Terror has taken place. But I also don't think that a real, formal declaration of war has been approved. So, is the USA at war or not? I suspect (but I'm only 52% certain) that we're not at war. The follow-on questions (after "are we at war or not?"): In what state are we? What are the legal ramifications of this half-at-war-state? Why hasn't the US Congress declared war since WW2?…

There is no requirement, either under the Constitution or under laws of war, for any sort of formal declaration. And, there as an "authorization of military force" against al Qaeda and the Taliban. There certainly isn't some magic I DECLARE WAR requirement. > Why hasn't the US Congress declared war since WW2? Is there some consequence to declaring war or not declaring war that they're trying to avoid? Its an outdated…

"There is no requirement, either under the Constitution or under laws of war, for any sort of formal declaration."

Given that the constitution explicitly gives congress "the power to declare war", I'm not sure this is entirely reasonable. That said, I don't think it's unreasonable to say the AUMF count, either.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#157
post #145
post #126

Earlier quoted context omitted.

One of the values of a constitutional democracy is supposed to be that it reduces the impact of the "tyranny of the majority" . That is to say, that it reduces the likelihood that a simple majority of people will trivially be able to oppress minority populations. This works by setting up a base set of rules that cannot be violated even if a majority of people in the democracy want to. In order to change or amend thes…

Since you seem to have thought about this quite a bit, do you happen to know something you think works better?

There are a few interesting proposals that I've heard over the years, but to answer your question truthfully, no. I've grown to accept that this isn't a situation I can resolve, only a situation I can hope to survive.

I view the current situation as not unlike being locked in a hotel room. In the main room is a hungry tiger. In the bathroom, is a pissed off cobra. You're locked in there so you have to pick your poison, but the last thing you want to do is mistake "the worst choice, but better than the alternative" with a satisfactory situation. I don't have a better suggestion than democracies, but that sure as hell doesn't mean that I trust democracies. I'll sleep with the cobra (with one eye open), but I sure as hell won't praise the merits of sleeping with a cobra just because that tiger looks hungry.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#158

Earlier quoted context omitted.

Two NSA bulk collection programs have been outed: the NSA collects call log metadata to this day, and they used to collect email headers from unencrypted email deliveries entering or leaving the US until a few years ago. The remaining articles about NSA data collection have been about targeted programs. Though I disagree with some of their methods, they are not vacuuming up everything they can get their hands on by a…

> The remaining articles about NSA data collection have been about targeted programs. Cut the crap. * XKeyscore: NSA tool collects 'nearly everything a user does on the internet' [1] * NSA collecting phone records of millions of Verizon customers daily [2] * NSA taps Skype chats, newly published Snowden leaks confirm [3] * NSA collects millions of text messages daily in 'untargeted' global sweep [4] * Optic Nerve: mi…

Reread the source documents.

XKeystore isn't a data collection program. It is a system for retrieving data and metadata already collected through data collection programs like PRISM.

I mentioned the Verizon program in my previous post. As I said, it is one of only two NSA domestic bulk collection programs that Snowden's documents have revealed, and it's the only one that is ongoing.

* The Skype chat collection is targeted, not bulk, according to Snowden's documents.

* The SMS program neither contains domestic data nor contains SMSes written by people. According to the document, it contains only automated SMSes. You're right about this one being bulk collection. I meant to write "bulk domestic data collection," and I didn't, so you are right that what I said was wrong. I didn't mean to mislead, only to correct the lunatics who continue to assert the government is doing things it is not, making the rest of us US privacy advocates look crazy by association.

* Optic Nerve is neither an NSA program nor does it contain domestic data. It contains data from Yahoo webcam traffic passing through the UK's borders according to the documents.

Re: How the NSA Plans to Infect “Millions” of Computers with Malware

#160
post #85

Earlier quoted context omitted.

Feel free to cite the document that shows Microsoft delaying fixes for NSA.

Do your own homework, you know how to use Google - so go use it .. a simple query "Microsoft collaborates with NSA" turns up enough reading material .. of course, unless you don't want it to be so easy to enlighten yourself on the issue, in which case no document is going to convince you of your position.

These guys are focusing narrowly on your choice of words ("delay fixes"). It was outed by the Guardian that Microsoft actively circumvents the security of some major products (Outlook, Skype) for the NSA. The Guadrian never released the Snowden doc for Microsoft collaboration [0]. Therefore, we don't the specifics of how. We just know that Microsoft backdoors its products for the federal government without telling its customers.

"Microsoft helped the NSA to circumvent its encryption to address concerns that the agency would be unable to intercept web chats on the new Outlook.com portal;" [1]

[0] https://twitter.com/ggreenwald/status/355391355939340288

[1] http://www.theguardian.com/world/2013/jul/11/microsoft-nsa-c...

Post reply on HN