Canada's 'secret spy agency' is releasing a malware-fighting tool to the public
cbc.ca
cbc.ca
https://bitbucket.org/cse-assemblyline/assemblyline/src
Released under the MIT license with crown copyright. Looks like a plain ol' Flask application. I don't know what I was expecting from the government. Maybe more Microsoft and more Oracle, more "enterprise". And the git history goes back ten months with an initial commit of December 21, 2016.
I'm actually surprised to learn that CSE would be in charge of such a thing. I would have thought that this fell under the role of Canadian Security Intelligence Services. We definitely don't hear a lot about CSIS or CSE in the news to the point that I think most Canadians might have a hard time expanding those acronyms or know what they mean. It's good to see a little more transparency from them and to not have to wait for NSA leaks to figure out what their Canadian counterparts are up to.
They're good at their jobs.
edit: Spelling. They changed it from CSEC to CSE
> CSEC had been meeting with the heads of our country’s largest energy companies and debriefing them on all the secrets they’ve stolen from Brazil’s mining and energy ministries.
https://www.vice.com/en_ca/article/5gqkwq/the-canadian-gover...
I just doubt the hacking group is the same group that chose riak, solr, etc.
In preparation for the interview, they sent her the address, a map showing the building, and marked three separate entrances and how to get to their office from them: the main entrance, a side entrance, and one off the alley behind the building (which I assume is closer to parking? maybe?).
It was very weird. I think she decided just to go in through the lobby.
Security by obscurity works better in the physical world.
They can spy on Americans, the NSA can spy on Canadians, and the two governments can freely share information between eachother. (Because it's not information about their own citizens.) Canada is one of the five eyes, after all.
soon we'll learn this whole project a plant by NSA, complete with 10 months spent fabricating the commit history.
This sounds like it could sit nicely between Github and CI (Jenkins/Travis/Circle/etc), and be a pre-integration security scan. Can we name it Sherlock?
I'd be far more impressed and grateful if these state services released disclosures and actual patches for complex zero-day vulns, particularly in unmaintained, widely deployed closed-source products such as WinXP. 8-Ball says that is 'Unlikely' though.
Sure, they probably also release stuff not under their name and not open, but still.
That isn't necessarily a bad thing but seems important enough to be discussed.
So, why would anyone trust a spy agency's software? Only if it's all open source.
An interesting inclusion but it makes sense as it seems to work by hitting up all possible scanners (both remote and local). The consensus from security people seems to be use multiple AV products, if you insist on using them at all...
This tool will get extra scrutiny given it's coming from a spy agency and is OSS. That's not usually how spy agencies operate, too overt. Besides, they seem to have no problem quietly hacking your browser remotely with the click of a button with Quantum anyway.
I'm still not going to use it but I wouldn't personally be overly worried vs any other mainstream antivirus.
If they were to put a backdoor in it, whoever would find it would probably just take it for some error they made in coding.
https://www.google.ca/maps/@45.4325043,-75.6175154,97a,35y,1...
> … files go in, and a handful of small helper applications automatically comb through each one in search of malicious clues. On the way out, every file is given a score, which lets analysts sort old, familiar threats from the new and novel attacks that typically require a closer, more manual approach to analysis.
https://bitbucket.org/cse-assemblyline/assemblyline/commits/...
Couple interesting bits:
1. Bcrypt looks trusted. I guessed as much given that I've seen it used in other GC projects that were "Protected B" (think Revenue Canada / similar).
2. It doesn't look like they enabled HSTS by default until a couple months later in the repo:
https://bitbucket.org/cse-assemblyline/assemblyline/commits/...
Again, unsurprising since the CSE / CST main page doesn't have HSTS.
3. This part of the original version of the README is interesting:
<README SNIPPET>
#### License (or lack thereof) and Conditions of use
As is fairly evident, we haven't selected a license for this project as of yet. As discussed when members were first granted read access to the repository, dissemination is based on the premise of originator controlled. If you feel there are other partners that would benefit from an early view and would be able to contribute, please contact the project leads and we should be able to sort it out.
We will soon be splitting the platform and services into two separate repo's, so please treat the services as slightly more sensitive than the platform itself, ie: release it and perish!!! ... but seriously, we do not grant anyone the right to do anything other than deploy the platform and use it. No sharing, presenting, etc without our knowledge.
We hope to have a clear release plan soon.
</README SNIPPET>
So it looks like they passed it around a bit either internally in the CSE or to a wider audience that may have included other departments. Probably getting more eyes on it to stop something stupid from going out.
4. There are some fun little commits like this:
https://bitbucket.org/cse-assemblyline/assemblyline/commits/...
Or this (adding the French version is always one of the last steps before something goes public):
https://bitbucket.org/cse-assemblyline/assemblyline/commits/...
Or this (we've all been there):
https://bitbucket.org/cse-assemblyline/assemblyline/commits/...
// En français, s'il vous plaît
fonction commencer(état) {
si (état !== nonDéfini) {
laisser nouveauChaîne = `Bonjour, ${état}`;
faire {
console.journal(nouveauChaîne);
piraterTousLesSystèmes();
} tandisQue (systèmesSontDébloqués())
} autre {
merde(`partout`);
}
}
// Commencer!
commencer(`L'état du Brésil`);
// Bon.