1. The NSA has access to more info on both good crypto and broken crypto
2. Hacking Team's software & infrastructure were clearly vulnerable, otherwise they wouldn't have been hacked
3. Leaked docs show that NSA hacks everyone they possibly can, to get as much information as they possibly can.
It's really not a big leap to assume that NSA infiltrated Hacking Team's infrastructure, if anything I would think it's harder to believe they wouldn't have.
So if some Joe Schmoe broke into Hacking Team's system, I think it's pretty reasonable to assume that NSA did as well
But just so I can understand what you're saying, why do you think it's a big assumption?
Edit: Formating.
Here's another thought: what if the NSA hacked Hacking Team, and they were also the ones to release all the data publicly.
Re: #3 – do you have any links to that info? (I'm not challenging you to prove what you said, I'm just curious, if you don't have anything readily available, I'll Google search like a good Internet commenter :))
https://snowdenarchive.cjfe.org/greenstone/collect/snowden1/...
Quote:
For the past decade, NSA has lead an
aggressive, multi-pronged effort to break widely
used Internet encryption technologies
Their Motto: "We penetrate targets' defences."That would more likely be a GCHQ or MI5 or MI6 motto than an NSA motto.
A quick bit of Googling finds that the "PTD" in the slides refers to GCHQ's Penetration Targeting Defences unit. So it's their motto. Which explains the spelling.
I am reviewing some of the documents Snowden has
provided to the Guardian. Because of the delicate
nature of this, I cannot comment on what I have seen.
[1]http://www.technologyreview.com/news/519336/bruce-schneier-n...My take on this post on his blog is that it's probably a stretch for him to be analyzing the Hacking Team story in any depth.
So the same logic suggests that NSA has owned up every company of any real size in the world.
Could NSA do that? Absolutely yes. Did they? I doubt it. I do not see how NSA secures a single extra headcount by illicitly hacking every US and/or European company, and securing additional headcount is literally the core mission of NSA.
I can say that I used to work for one, and our departments' network was literally air gapped (not joking). Internal systems could not reach out, and no one could reach in. It was impossible for us to work remotely, because even a VPN wasn't set up. There was no physical connectivity.
But there's a difference between Hacking Team and every company on the Fortune 500: Hacking Team was in the Exploit business, they literally made money selling weaponized exploits to US enemies, and possibly allies.
If anything, I think that's literally the NSA's directive in collecting foreign intelligence.
Meaning, I believe if there was one foreign business that the NSA would spy on (and lets face it, I don't know that many), I think Hacking Team would absolutely be at the top of their list, purely for logical reasons.
But.....I also completely admit that my statement was an assumption, a "bet". I'm not guaranteeing anything, and I really don't care. I'm just over here, arm-chair quarterbacking this shit, haha.
Are you serious? Because there's no proof or mention of it anywhere. You're making an assumption based on literally nothing more than "well obviously, based on what I've read on the Internet, they could have done it so they must have". You're bending facts to fit a worldview, something I'm sure you yourself detest elsewhere in life.
This is like Russell's Teapot but for the NSA. You're shifting the burden of proof to someone who now has to prove a negative.
They did it, until they show me otherwise.
So, you want them to prove a negative? Just trying to be clear.
I bet a dime-to-a-dollar that should they be accused, they'd release a non-statement to the press:
"We cannot comment on...."
We know that the NSA spied on Google, Yahoo, and Microsoft, and those are our own (US) companies.
Hacking Team produced weaponized exploits/crypto/stuffs and sold it to US enemies and allies.
Having read through the documents, I assert that it's a small/likely/reasonable assumption.
It's literally the NSAs mission statement to defend the US against foreign intelligence.....how is Hacking Team not a perfect example of an appropriate target for them?
As for defense, they obviously didnt pass along what they found. If securing US networks was the reason for hacking, they completely failed to accomplish their goal.
This is the NSA's mission statement:
The National Security Agency/Central Security Service
(NSA/CSS) leads the U.S. Government in cryptology that
encompasses both Signals Intelligence (SIGINT) and
Information Assurance (IA) products and services,
and enables Computer Network Operations (CNO) in order
to gain a decision advantage for the Nation and our
allies under all circumstances.
And again, considering that HT sold weaponized crypto to non-allied countries, it's by definition "interesting" intelligence (in relation to the NSA).Also, I'm quite sure that the language in that statement indicates more of an offensive role than defensive, since that's usually what "advantage" signifies.
Even if their purpose was defense, the way our Government is set up, it's defense of the government, not the governed, so you can't say with any confidence that they didn't patch internal systems that mattered to them.
Then the software becomes a direct threat to their agents/allies overseas and it needed to be neutralized. That is the kind of competition you do not want as a state actor.
I also think Gamma International was the victim of a foreign intelligence agency. I don't believe the privacy-minded hacker Robin Hood stories anymore.