Live data from Hacker News

Yahoo installed a backdoor for the NSA behind the back of the security team

diracdeltas.github.io

261–270 of 302 posts

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#261
post #194

Earlier quoted context omitted.

Engineers do speak up, frequently. For a famous example, see the Challenger disaster. Again, engineers aren't generally the problem. Still disagree?

The NSA don't seem to lack the technical talent to wantonly shit all over the Constitution. Plenty of HN posts laud people for working for the government, the entity which engages in war crimes, torture, and mass surveillance.

We know first hand what James Clapper thinks of the Constitution, today from the Intercept: https://theintercept.com/2016/12/15/james-clapper-has-a-clas...

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#262

Earlier quoted context omitted.

You mean American companies like Apple? Whether you trust them or not they've certainly brought it up. Though they might not label the spying indiscriminate; maybe still 'criminate. Or are Chinese companies doing some interesting walling-off?

Google encrypting traffic flowing between data centers seems to reflect significant awareness of the issue too.

When I worked at Square we required mutual TLS for almost all service-to-service communication within a datacenter, so sniffing traffic within the datacenter wouldn't be fruitful either (assuming no weakness in the cipher or TLS stack). Is that not common elsewhere?

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#264

Earlier quoted context omitted.

Google encrypting traffic flowing between data centers seems to reflect significant awareness of the issue too.

When I worked at Square we required mutual TLS for almost all service-to-service communication within a datacenter, so sniffing traffic within the datacenter wouldn't be fruitful either (assuming no weakness in the cipher or TLS stack). Is that not common elsewhere?

No.

I've had to explain to clients on numerous occasions why I enabled TLS between things in the same data center. Security requires layers and just because the data is on a network you own doesn't mean nobody can get in.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#265

Earlier quoted context omitted.

They are hurting for it, though. There are still lots of people willing to join the TAO and the like, but the NSA has been pretty open about struggling to recruit top talent. Not all of that is ethical stuff, they lose people for reasons from salary to drug and felony screens, but some of it is. Bear in mind that the NSA only needs good talent to compromise systems, not elite talent. They have some elite talent (Stux…

What's the TAO?

Tailored Access Operations. It's the "offense" branch of the NSA, responsible for gaining access to external computer systems: often technologically, sometimes legislatively when they're domestic. They did QUANTUM and FOXACID among other access tools.

It's a major part of the NSA, and generally considered to be where the bulk of the "serious hackers" work. The Equation Group is (probably) tied to TAO - they're the access group that was recently affected by the Shadow Brokers leak.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#266

Earlier quoted context omitted.

They are hurting for it, though. There are still lots of people willing to join the TAO and the like, but the NSA has been pretty open about struggling to recruit top talent. Not all of that is ethical stuff, they lose people for reasons from salary to drug and felony screens, but some of it is. Bear in mind that the NSA only needs good talent to compromise systems, not elite talent. They have some elite talent (Stux…

What's the TAO?

This appears to be what OP was referring to (a cyber espionage sub-unit of the NSA):

https://en.wikipedia.org/wiki/Tailored_Access_Operations

Bartweiss provided a better, short summary.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#267
post #156

Earlier quoted context omitted.

Yes. And dangerous in the long term because the US wont be the most powerfull country forever. High trees catch a lot of wind. People are more likely to hate the US. When the tides change and the power inbalance goes away the hate and mistrust will still be there. But maybe society is wiser this time around.

>> because the US wont be the most powerfull country forever I honestly find this hard to believe because: - When there is conflict in the world, countries always come to the US first for military intervention - When there is a serious disaster of some kind, countries always expect us to send billions in aid (both militarily and financially) to help them - When a country is trying to obtain nuclear weapons or weapons…

Aren't you assuming the implied change of power mentioned in the parent comment will come at the hands of a rational actor/state? That seems fraught with hindsight, no?

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#268

> [Update (12/14/16): Reuters has specified that the rootkit was implemented as a Linux kernel module. Wow.] Hm.. One more proof to avoid using non-free binary blobs in Linux kernel. Be safe. Use Debian GNU/Linux without non-free repo or any better[0] one. [0] https://www.gnu.org/distros/free-distros.html

I don't think this has anything to do with non-free blobs. They knew exactly what it did and they installed it anyway. It wouldn't have mattered if they had the source or the rootkit was open.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#269
post #249

Earlier quoted context omitted.

> But suppose we create a certification. To get certified all you have to do is promise not to work on a specific list of things: Mass surveillance, backdoors, etc. To lose certification forever all you have to do is work on one of those things. I fear you may be making a potentially dangerous assumption about how engineering works in a compartmentalized environment. Engineers do not always know the purpose of the sy…

You don't prohibit making or having knives, you prohibit stabbing people.

The problem with the certification model proposed is that it seeks to prohibit stabbings, but works on people who make knives.

Re: Yahoo installed a backdoor for the NSA behind the back of the security team

#270
post #266

Earlier quoted context omitted.

What's the TAO?

This appears to be what OP was referring to (a cyber espionage sub-unit of the NSA): https://en.wikipedia.org/wiki/Tailored_Access_Operations Bartweiss provided a better, short summary.

Thanks! In hindsight, I should have searched for 'tao nsa' rather than just 'tao'.
Post reply on HN