Earlier quoted context omitted.
I don't know, sometimes something in an article triggers another stream of thought or tangent, and its a comments section, and other people might want to discuss that. I don't necessarily agree with the comment (as I have next to no visibility of this) but certainly don't mind reading comments on it. Maybe I'm wrongly using the site!
FWIW, I come to Hacker News to read the tangents.
“Warning: Do Not use my mirrors/services until I have reviewed the situation”
151–160 of 167 posts
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#152Earlier quoted context omitted.
The computer in question is a server. If the server were configured to sleep unless the mouse is jiggled, it would already be asleep. Thus, using a "mouse jiggler" or similar is pointless, and risks detection.
Wouldn't surprise me if there's some standard procedure for police raids that doesn't distinguish between the two. Keep in mind it's generally not the experts who go out to the various locations.
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#153Earlier quoted context omitted.
Must admit I'm slightly amused that this is even being considered as a plausible theory. They're busy executing elderly with AK47s...thats very far away from physically cracking open servers in a western data center and inserting USB devices with targeted attack software.
It is not merely the uneducated who can subscribe to extremist ideologies. When the unskilled highschool grad gets off the plane and signs up, they are going to give him a rifle. When the engineer gets off the plane and announces himself as such, there is a chance that he will be put to better use.
Indeed. And I'll happily concede that point. I (and many other) are just surprised at the thought process...physical hardware attack in (presumably a western data center)...and the thing that comes to mind is the ISIS??? Really if you tell me Russia I would have bought it. Same for China, Korea, Turkey etc...but jumping straight to the cliched CNN "terror org" that is the flavor of the month...please...
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#154Earlier quoted context omitted.
Might be an interesting strategy to only allow one USB port to be used and if any other port is activated the machine self-wipes. Dell servers have an internal port along with the front and back externals.
Or use USB-ID white/blacklists.
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#155Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#156Latest update posted in the mailing list: https://lists.torproject.org/pipermail/tor-talk/2014-Decembe... No canary in this update.
Several nodes are going to go back online and are being requested to be un-blacklisted. "I have emailed some of the DirAuths to remove several nodes and IPs from the blacklist that we feel confident have not been breached or compromised in any way."
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#157Earlier quoted context omitted.
I'm surprised that this comment has been voted to the top. First, it has little to nothing to do with the comment posted, which concerns not a "cyberwar" but the possible police seizure of a Tor server. The assumption is it's either a false alarm or a police raid. No one thinks this was done by ISIS. Second, a post using the word "cyberwar" in a non-ironic manner at the top of HN?! O tempora o mores! So while your ob…
> I'm surprised that this comment has been voted to the top. Chuck's been around HN for a while, and has insightful comments frequently - that he posts this sort of "radical" comment implies that a non-nut is seriously considering it and quite possibly it's worth pondering as an idea.
I would agree, but it would be a monumentally stupid way of trying to send encoded information into a foreign government, given the notice that is linked to. So no, it's not.
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#158Earlier quoted context omitted.
IF we take the strict differences of the phrasing, we could say he's reasonably withholding information by request. Incorporated with the timeframe, this could be anyone — but given his response and the extra 250+ twitter followers today, he's probably been reminded the cost of drawing conjecture in public.
I am thinking this guy is very exact and precise in his phrasing, especially with regards to a canary. He's a crypto-geek, anarchist and running an exit node and this crowd knows Alice is not Bob. He knows what he says will be scrutinized by thousands. Why wouldn't he be very careful in what he says? Based on his first canary vs the last, he could, as you say, "reasonably" be withholding information on request. Perha…
> 3. The DC has confirmed via Twitter that the servers were not "accessed". Having been raided in the past I know indeed they can be forced under Dutch law not to inform clients of raids, but I don't feel this may be the case. With that being said, a chassis intrusion indicator still must be addressed and I cannot find it in the logs anymore. The DC company are not the people who I directly interact with however so I am still awaiting a direct response form those we host the server with.
Either way, it's not a direct raid or seizure, if anything a backdoor installed by someone at the DC, but honestly at this point you have to accept the possibility and either accept/balance/mitigate the risk or get new hardware.
[1]: https://lists.torproject.org/pipermail/tor-talk/2014-Decembe...
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#159Earlier quoted context omitted.
I'm surprised that this comment has been voted to the top. First, it has little to nothing to do with the comment posted, which concerns not a "cyberwar" but the possible police seizure of a Tor server. The assumption is it's either a false alarm or a police raid. No one thinks this was done by ISIS. Second, a post using the word "cyberwar" in a non-ironic manner at the top of HN?! O tempora o mores! So while your ob…
I don't know, sometimes something in an article triggers another stream of thought or tangent, and its a comments section, and other people might want to discuss that. I don't necessarily agree with the comment (as I have next to no visibility of this) but certainly don't mind reading comments on it. Maybe I'm wrongly using the site!
Re: “Warning: Do Not use my mirrors/services until I have reviewed the situation”
#160Earlier quoted context omitted.
Why do you think those USB devices are "pretty likely"? In this case, I would bet on a firmware compromise, similar to DIETYBOUNCE: https://www.eff.org/files/2014/01/06/20131230-appelbaum-nsa_... As a countermeasure, I would not fully trust TXT in this particular case. It's likely a state actor who could spoof measurements over the the LPC bus.
TXT doesn't rely on the LPC bus on modern motherboards because the TPM is integrated into the Northbridge. If any government agency can break TXT it'll be the NSA and I don't know if they are in the business of handing out their best exploits to random police teams at the moment.
Regardless, this whole thing turned out to be a false alarm due to a KVM device being attached.