Live data from Hacker News

Canada's 'secret spy agency' is releasing a malware-fighting tool to the public

cbc.ca

21–30 of 83 posts

Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public

#21
post #15

Billangual README!

Its a Canadian government rule that even URLs have to be bilingual. eg You can't have http://host.ca/news (with bilingual text on the page) it has to be http://host.ca/news_nouvelles This is only for fed government sites.

Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public

#22
post #3

The main repo seems to be here: https://bitbucket.org/cse-assemblyline/assemblyline/src Released under the MIT license with crown copyright. Looks like a plain ol' Flask application. I don't know what I was expecting from the government. Maybe more Microsoft and more Oracle, more "enterprise". And the git history goes back ten months with an initial commit of December 21, 2016. I'm actually surprised to learn that CS…

If you read through the Snowden leaks you'll see just how normal the CSE is. If you're a reasonably good hacker think how you'd do it. They probably do it kinda like that.

Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public

#25
post #5
post #3

The main repo seems to be here: https://bitbucket.org/cse-assemblyline/assemblyline/src Released under the MIT license with crown copyright. Looks like a plain ol' Flask application. I don't know what I was expecting from the government. Maybe more Microsoft and more Oracle, more "enterprise". And the git history goes back ten months with an initial commit of December 21, 2016. I'm actually surprised to learn that CS…

CSE is comparable to America's NSA in general function and scope. While CSIS does intelligence work with computers and hires a lot of programmers and analysts, CSE is traditionally the more technologically-focused of the two. You also hear significantly less about it than even CSIS. They're good at their jobs. edit: Spelling. They changed it from CSEC to CSE

Citation needed.

Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public

#26
post #3

The main repo seems to be here: https://bitbucket.org/cse-assemblyline/assemblyline/src Released under the MIT license with crown copyright. Looks like a plain ol' Flask application. I don't know what I was expecting from the government. Maybe more Microsoft and more Oracle, more "enterprise". And the git history goes back ten months with an initial commit of December 21, 2016. I'm actually surprised to learn that CS…

If you read through the Snowden leaks you'll see just how normal the CSE is. If you're a reasonably good hacker think how you'd do it. They probably do it kinda like that.

They've been given additional powers lately to expand surveillance on regular citizens, so I wonder how much that "sweet innocence" of theirs will last and how long until they also become more like the NSA, especially under a conservative government in the (near) future.

Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public

#28
post #17
post #12

Interesting, Kaspersky is constantly maligned for simply being USED by Russian spy agencies, or "having associations with" them. Russia and China now demand audits of security software from the USA. Countries build their own national Linuxes now that Windows phones home all your passwords, for the CIA and NSA to easily backdoor or get via an order. So, why would anyone trust a spy agency's software? Only if it's all…

It's MIT license, and the repo seems to have full history.

Should we be reminded that bugs such as Apple's GoTo Fail can exist? Or like Heartbleed, which actually was in open source software?

If they were to put a backdoor in it, whoever would find it would probably just take it for some error they made in coding.

Re: Canada's 'secret spy agency' is releasing a malware-fighting tool to the public

#30
post #17
post #12

Interesting, Kaspersky is constantly maligned for simply being USED by Russian spy agencies, or "having associations with" them. Russia and China now demand audits of security software from the USA. Countries build their own national Linuxes now that Windows phones home all your passwords, for the CIA and NSA to easily backdoor or get via an order. So, why would anyone trust a spy agency's software? Only if it's all…

It's MIT license, and the repo seems to have full history.

That doesn’t mean that the binaries match the repo content.
Post reply on HN