Live data from Hacker News

Knock Knock Who's There? – An NSA VM

reverse.put.as

21–30 of 46 posts

Re: Knock Knock Who's There? – An NSA VM

#21
post #2

It seems most vulnerabilities published by shadow brokers are on Windows. What percentage of vulnerabilities are focused on Linux or macOS? What can ordinary users do to protect themselves other than patching?

From the article: “.. a port knocking backdoor with multiple targets such as Solaris, Linux, FreeBSD, HP-UX, JunOS, OS X” So this was far more reaching than Windows. To answer what ordinary users can do: Against a well funded adversary hell bent on getting access to your systems/data - probably not a lot! In the case of NSO group even a fully patched iPhone wasn’t going to help you. However, on reading this article m…

The NSO could get root on anyone’s device knowing only the phone number.

If NSO does it, so could the intelligence agencies of dozens of countries. Looks like a hopeless situation, where a small percentage of population have access to anyone’s data (but not conversely).

This is posing a threat to the democratic society.

There ought to be a way to make a secure device.

Re: Knock Knock Who's There? – An NSA VM

#22

> I made local presentations at 0xOpoSec and BSidesLisbon but those slides were never published for obvious reasons (aka live implants all over the Internet). I don't understand. Or does this mean because the malware was being used you refused to publish documentation about it? Because you think people targeted by nation states are evil? Intelligence services are the worst terrorist organizations, and most people tar…

You don’t understand why somebody wouldn’t want to publicly kick the beehive that is the NSA. I’d imagine He didn’t want to get thrown in the back of a van and disappeared. Even more mundane punishment could be quite severe.

Re: Knock Knock Who's There? – An NSA VM

#23
post #2

It seems most vulnerabilities published by shadow brokers are on Windows. What percentage of vulnerabilities are focused on Linux or macOS? What can ordinary users do to protect themselves other than patching?

From the article: “.. a port knocking backdoor with multiple targets such as Solaris, Linux, FreeBSD, HP-UX, JunOS, OS X” So this was far more reaching than Windows. To answer what ordinary users can do: Against a well funded adversary hell bent on getting access to your systems/data - probably not a lot! In the case of NSO group even a fully patched iPhone wasn’t going to help you. However, on reading this article m…

> To answer what ordinary users can do: Against a well funded adversary hell bent on getting access to your systems/data - probably not a lot! In the case of NSO group even a fully patched iPhone wasn’t going to help you.

Well, you can - you just need to live a mostly offline live with few, highly hardened devices and enter you passwords under a blanket. Edward Snowden does manage, after all. But you'll have to skip on a lot of enjoyment - new software, games, even Netflix - forget it.

The real question is, is it worth to you to live such a live. Probably not.

Re: Knock Knock Who's There? – An NSA VM

#24
Slightly off topic, but at the end of the article he says he is looking for Linux devs and says something like "Send me an email to bla bla at put.as". The domain sounded wrong in Spanish (like bitch.es), and when I visited the website it had a NSFW logo. I found it strange.

Re: Knock Knock Who's There? – An NSA VM

#25
post #10

Earlier quoted context omitted.

Live implants, means if they published you or I can access the implants and therefore the victims' systems.

If you've got root RCE can't you use it to "close" the implant and make sure noone gets hurt like some have been doing to counteract IoT botnets? How is leaving a gaping hole better? EDIT: To those saying it would be a legal liability risk, isn't it a criminal offense in your jurisdiction if you know about a danger to someone else, not to do something about it if only warn them? (non-assistance à personne en danger,…

> isn't it a criminal offense in your jurisdiction if you know about a danger to someone else, not to do something about it if only warn them?

In America where the NSA is located? I’ve never written “lol” on this site, but this time called for it.

Since you’re in France I’ll now explain nicely. Not even our cops have any legal requirement to intervene: both when there’s an active crime or even if they see another cop committing a crime in the line of duty (e.g. excessive force).

And civilians (in the American press both military and “deputized” police are called non-civilian) will frequently ignore all manner of crimes, from shootouts to a person overdosing on drugs.

Re: Knock Knock Who's There? – An NSA VM

#26
post #21

Earlier quoted context omitted.

From the article: “.. a port knocking backdoor with multiple targets such as Solaris, Linux, FreeBSD, HP-UX, JunOS, OS X” So this was far more reaching than Windows. To answer what ordinary users can do: Against a well funded adversary hell bent on getting access to your systems/data - probably not a lot! In the case of NSO group even a fully patched iPhone wasn’t going to help you. However, on reading this article m…

The NSO could get root on anyone’s device knowing only the phone number. If NSO does it, so could the intelligence agencies of dozens of countries. Looks like a hopeless situation, where a small percentage of population have access to anyone’s data (but not conversely). This is posing a threat to the democratic society. There ought to be a way to make a secure device.

This is correct, and why many lawyers do not maintain online presences, and do not conduct business online, in any capacity.

Re: Knock Knock Who's There? – An NSA VM

#27

Earlier quoted context omitted.

If you've got root RCE can't you use it to "close" the implant and make sure noone gets hurt like some have been doing to counteract IoT botnets? How is leaving a gaping hole better? EDIT: To those saying it would be a legal liability risk, isn't it a criminal offense in your jurisdiction if you know about a danger to someone else, not to do something about it if only warn them? (non-assistance à personne en danger,…

> isn't it a criminal offense in your jurisdiction if you know about a danger to someone else, not to do something about it if only warn them? In America where the NSA is located? I’ve never written “lol” on this site, but this time called for it. Since you’re in France I’ll now explain nicely. Not even our cops have any legal requirement to intervene: both when there’s an active crime or even if they see another cop…

US LEO here. This is not exactly correct. At least this bit: "both when there’s an active crime or even if they see another cop committing a crime in the line of duty (e.g. excessive force)."

Cops generally have no duty to protect anybody. That's not their job, no matter what the decals on the squad say. But if you're on duty, and you witness a crime being committed right in front of you, especially if it's something as serious as a violent felony, and literally ignore it, and anybody finds out, you'll at least probably be fired. Depending on the jurisdiction and totality of circumstances, it may also be a crime.

Re: Knock Knock Who's There? – An NSA VM

#28

Earlier quoted context omitted.

> isn't it a criminal offense in your jurisdiction if you know about a danger to someone else, not to do something about it if only warn them? In America where the NSA is located? I’ve never written “lol” on this site, but this time called for it. Since you’re in France I’ll now explain nicely. Not even our cops have any legal requirement to intervene: both when there’s an active crime or even if they see another cop…

US LEO here. This is not exactly correct. At least this bit: "both when there’s an active crime or even if they see another cop committing a crime in the line of duty (e.g. excessive force)." Cops generally have no duty to protect anybody. That's not their job, no matter what the decals on the squad say. But if you're on duty, and you witness a crime being committed right in front of you, especially if it's something…

Doesn't work like that in Seattle. Police actively ignore drug use in the (clean) parks, even with complaining witness. Police point and laugh at homeless fighting each other. Source: my eyes.

Re: Knock Knock Who's There? – An NSA VM

#29
post #24

Slightly off topic, but at the end of the article he says he is looking for Linux devs and says something like "Send me an email to bla bla at put.as". The domain sounded wrong in Spanish (like bitch.es), and when I visited the website it had a NSFW logo. I found it strange.

Definitely is the right website though... The first link on it says "Reverse" and that article is the one at the top of the list. But I agree with your sentiment, I saw the domain name on HN before even getting to the article and it did raise my brow for that same reason.

Re: Knock Knock Who's There? – An NSA VM

#30

Earlier quoted context omitted.

> isn't it a criminal offense in your jurisdiction if you know about a danger to someone else, not to do something about it if only warn them? In America where the NSA is located? I’ve never written “lol” on this site, but this time called for it. Since you’re in France I’ll now explain nicely. Not even our cops have any legal requirement to intervene: both when there’s an active crime or even if they see another cop…

US LEO here. This is not exactly correct. At least this bit: "both when there’s an active crime or even if they see another cop committing a crime in the line of duty (e.g. excessive force)." Cops generally have no duty to protect anybody. That's not their job, no matter what the decals on the squad say. But if you're on duty, and you witness a crime being committed right in front of you, especially if it's something…

"Protect and serve" (the incumbent power structures, not arbitrary citizens)
Post reply on HN