Researcher Grabs VPN Password with Tool from NSA Dump
motherboard.vice.com
motherboard.vice.com
the NSA has collected all of our bait, and put it in one insecure location.
If they had built fort knox of network security maybe there would be less concern about data getting out, but regardless of how secure it is, it never needed to be collected, certainly not collected then stored insecurely.
That's why we don't want NSA backdoors (among other reasons).
A more accurate analogy would be that the NSA has copies of all the keys in your neighborhood hanging in a cabinet on the street with a slightly better lock (a 7-pin tumbler!).
No thanks.
A far fetched tin-foil hat idea - Shadow Brokers made a few exploits themselves and are looking to bring maximum profit from a smaller amount of work.
The second tin-foil idea is that the NSA themselves are pretending to leak their old tricks in order to find out who the big players are.
https://theintercept.com/2016/08/19/the-nsa-was-hacked-snowd...
There's a string ("ace02468bdf13579") that is mentioned in a previously-unreleased document from the Snowden cache and also found in some of the binaries contained in the dump.
1. Snowden leaves NSA with documents. Some of these (but, crucially, not all) are published.
2. Shadow Brokers release something claiming to be NSA hacking tools containing ace02468bdf13579 string.
3. The Intercept looks in the unreleased parts of the Snowden documents and finds the same string.
Thus, the fact that the leaked tools contain non-public NSA-specific information is what makes it clear the tools originate from NSA. The only other possibility is that the Shadow Brokers also had access to the full set of Snowden documents and decided to use them to fake the dump, which is much, much less likely.
You could start dropping ace02468bdf13579 into binaries willy nilly now, but it wouldn't do much, because that's now public information.
Or am I missing something?
(0x01234567uLL + 0x55555555 & 0x77777777) * 0x200000002 + 0x111111112015:
http://www.ijirst.org/articles/IJIRSTV1I9059.pdf
and 2013:
https://www.halowaypoint.com/en-us/forums/d76f090378914a9bb8...
Still, the string (instead of the binary values) is somewhat less probable than this to be an accidental match.
But, apparently not: https://www.google.com/search?q=ace02468bdf13579&client=fire...
> Both Al-Bassam and Maksym Zaitsev, another researcher who has been looking into BENIGNCERTAIN, believe that the attack is likely capable of extracting private encryption keys from VPNs as well, which is another, more robust way of authenticating access.
Seems similar to the famous "Heartbleed" OpenSSL bug, possibly even easier to achieve.
That is not a conspiracy theory, btw.
A few weeks back, H.D. Moore of Rapid7/Metasploit fame was on the Risky Business podcast. The topic of the week was bug bounty programs, and in particular the larger programs that aggregate individual vendors under a common umbrella - and notably a common set of guidelines.
Moore mentioned that a recurring theme is that when researchers discover a new trick, they will the proceed to apply that trick to every possible vendor on the bounty program, netting 2-3k from each one they pop. In the same vein, I would find it odd if this extraction technique was not applied to every possible encryption target the NSA could think of.
like many movie trailers
If the NSA really wanted to keep us safe, they would focus their efforts on patches instead of exploits.
If it was only needed for comparison, the plaintext password shouldn't even be in a database.
> On Friday, he tweeted a message of the output from his test, which revealed his test password of “password123” among a list of two other possibilities.
A password and a pre-shared key can mean the same thing depending on context. Regardless of what it is, the value in memory should not be able to be used externally to log into the system. The article references "password123"---that should not be recoverable from memory.
Can't say I approve of these tools being leaked, but you have to admire their style.
Well, if you're familiar with that fictional universe, the name they chose for themselves definitely makes sense.
They are not marked as classified. That is something different than not being classified. Any US person with any sort of national security-related job, or any hopes of ever getting one, should think twice.
It's like having a stealth fighter crash in your back yard (this has happened). The pieces are not marked as being classified, but selling them on ebay isn't going to win you friends.
But overall I don't think this would affect you having a security clearance in the future, this isn't the first time leaks happened and I somehow doubt that it would affect security screening.
You are asked a question along the lines of "have you been ever exposed to classified information without having an explicit permission" if you say yes it was on cover of the goddamn washington post they can't do much.
Saying that it was leaked all of the internet, reported by 100's of news sources, fully analysed and you've looked at it yourself to see if you can learn anything from it isn't going to hurt you either.
But overall this isn't like a stealth fighter crashed in your backyard, it's like a stealth fighter crashed in China, they reverse engineered it, mass produced it, it was reviewed by everyone on the planet and you got one to try it out.
>reported by 100's of news sources
That really doesn't matter for many people. Anyone with any links whatsoever to the US military (a large chunk of the US population, including retirees) is bound by orders not to read classified material despite it being all over the newspapers/CNN. This was and still is a big deal re the Snowden material.
So I don't even see how they can be considered "classified" if the US doesn't officially admit they produced them. As far as I understand, there's nothing that carries their signs or any other such marks (like "top secret US government property").
For the reference, the production of Stuxnet by the US was never officially admitted. So you still don't have to answer you've seen something declared as secret by the US if you've seen a report about Stuxnet. And I honestly don't expect the US will soon admit the production of it officially. Unofficially, sure, there's that NYT article reporting what some "American officials" said.
[1] https://en.wikipedia.org/wiki/Pentagon_Papers#The_Supreme_Co...