Live data from Hacker News

The NSA Furby Documents

404media.co

71–80 of 129 posts

Re: The NSA Furby Documents

#73

Earlier quoted context omitted.

In any SCIF or SCIF-like office space, they're all prohibited. You leave your cell phone at the front door of the secured area. Internet access is via SIPRNet (for classified) or NIPRNet (non-classified, but secured). Phones are through dedicated secure switchboards. The above is common in the DC area (lots of DoD contractors).

How strictly are SCIF policies enforced? I'm just a civilian who's never had exposure to that world, but based on my experience with other parts of the government, I'd expect SCIF compliance to fall on a broad spectrum from "sloppy or non-existent" to "overly strict and paranoid." Is my intuition accurate? Who's accountable for the compliance of a given SCIF - can anyone with clearance "setup a SCIF" or does it need…

I don't work in this space, but many of my friends do, as did my father.

SCIF policies are usually strictly enforced. But, that's the most secure workplace available to civilians and they aren't all that common. They also tend to be located in facilities that are higher-than-normal security. Out here in Reston, all my friends who work in SCIFs are also in fenced/gated complexes with paramilitary guards.

There are secure (but not SCIF) facilities that probably vary more. My father's little 6 person contracting office had a secure room, with a Dod approved design and a safe inside, for contracts that required that level of security (State/DoD facilities in China and Russia required TS clearance, other projects varied).

The people that work in SCIFs also generally take it seriously. TS+poly is worth a big chunk of salary here in DC and not something to risk (and that's ignoring that flaunting those laws is a felony for anybody not named Trump). And most believe in the mission (whatever that happens to be). The work spans everything from military hardware to CIA or NSA operations. And a lot of stuff that probably doesn't really need to be TS, but that's a whole other discussion.

Re: The NSA Furby Documents

#74

Earlier quoted context omitted.

The hack is getting the unsecure system not to damage your encrypted signal, to carry even though it is expecting plain voice talking rather than a stream of binary digits.

We’ve been doing that for dialup internet for decades.

Dialup doesn't work over every phone line, especially over sat voice lines.

Re: The NSA Furby Documents

#76
post #27

Earlier quoted context omitted.

It's interesting to see how quickly the norms around cybersecurity changed. In 1999 the NSA was worried about avoiding ridicule for banning simple electronics in secure areas. In 2010 Stuxnet was introduced via simple electronics into a secure area and set back the Iranian nuclear program by several years. Some of the people receiving these furby emails were probably already conceiving of (or actively working on) Stu…

NSA is a military agency; their norm has always been to protect US assets and attack others.

It is no more a military agency than NASA or the USGS. Having military customers doesn't make an agency or company part of that military.

Re: The NSA Furby Documents

#77
post #29

The FOIA documents are up on archive.org now: https://archive.org/details/nsa-furby-memo/ I'm amused at page 8 of the listserve doc, in which someone points out that the ongoing discussion may at some point be released to the public under FOIA and to consider how it might look after showing up on the front page of a news site

They wanted to avoid FURBYGATE. They avoided FURBYGATE. Sounds reasonable to me!

[deleted]

Re: The NSA Furby Documents

#78

Earlier quoted context omitted.

Oh yeah, they take it seriously most of the time. But you do get seemingly odd outputs from those procedures. Case in point... Many years ago, I worked part-time for a small construction cost management contractor. They did some TS work for DoD/State (usually combo projects, where NSA/CIA/Army had a wing of a consulate that State managed). I did not have a TS (or any other clearance) at the time. One day, I'm tasked…

Thank you for publishing this info, comrade! Ve arr going to chek all old Munich hospitals.

It may or may not be in Munich.

Regardless, WikiLeaks already spilled the beans.

Re: The NSA Furby Documents

#79
post #21

Context: Furbys were the toy for a year or two, and were actively marketed as learning from speech, had an active mic, and did adjust their speech based on what they heard, "learning" to speak English from Furbish. [^1] It's not so different from the fundamental fear of Alexa/Assistant/microphones that's fairly well diffused now. Except the Furby actively claimed to learn how to speak based on your speech, and had a…

Of course some people really wanted to teach it to say new things, and figured out how to swap out the audio files (among other modifications): https://github.com/Jeija/bluefluff Fun fact: If you mess up and need to reset the furby, the procedure is to turn it upside down and hold down the tongue while pulling the tail for ten seconds.

> What I have achieved so far

> • Understand large parts of Furby's BLE communication protocol

> • Open a secret debug menu in Furby's LCD eyes

Then I looked at the project logo again and it spooked me out

Post reply on HN