Security Breach and Spilled Secrets Have Shaken the N.S.A.
nytimes.com
nytimes.com
Maybe my wording is not perfect "they are capable of leaking" well you could argue that NSA didn't leak, it was possibly hacked by an outside actor. I don't think the distinction matters much though in this case. The main point is that they can no longer say "trust us" with a straight face.
[1] https://cdn.securelist.com/files/2017/10/Guerrero-Saade-Raiu...
We (US, Soviet Union, etc) had this figured out in the 60s when we were primarily using human intel. [1] Except the danger that now, instead of walking out with rolls of film covering a few thousand pages, someone can take everything they have access to in < 24 hours.
My only explanation is all those long-won counter-intelligence lessons were thrown out when the Young Turks showed up with their "we can do it all and more via software" ways. Because they delivered (and you've probably seen this in your org) they were excluded from having all the pain-in-the-ass rules applied to them.
It seems our intelligence agencies now look exactly like our commercial software -- more featureful, more agile, less secure, less stable.
[1] https://en.m.wikipedia.org/wiki/T._A._Robertson https://www.cia.gov/library/center-for-the-study-of-intellig... https://www.salon.com/2015/09/26/how_to_explain_the_kgbs_ama...
But the gist of what you are saying is correct, a lot more interconnection, a lot more software, using standard (albeit locked down) desktop operating systems. I think there was a realisation that the ultra-compartmented sharing-via-paper approach was killing effectiveness.
What I haven't seen in any of the SB leaks is evidence of access to core NSA systems via implants or a very trusted source. All the powerpoints could all be individual data spills, collected over time. All the TAO tooling could be stuff that sat on the dev system behind some bastion host, ready to be pushed to staging servers. Personally, I would only let binaries get that far out, but operational exigencies occur, high side operators can be phished, etc.
Of course, given a defective Congress, what should the IC have done? Limit their use of computers? Stop sharing information? Encrypt everything on servers and decrypt client side via special hardware? Have someone watch the admins as if they are all wannabe traitors? Disperse honeypot systems and canary docs everywhere? Tripwire the heck out of every system? Fit explosive collars on systems administrators?
Well, all those things and more have now been contemplated. Everything except 'stop collecting'.
I doubt the SB are going to willfully release anything so sensitive in a dump.
Don't expose your methods and procedures, compartmentalize your assets and change your behaviour...
The Q Group will probably be more successful using old-school methodologies.
It's on purpose. After 9/11, the intelligence agencies were lambasted for not sharing information. They were told the next one (a) couldn't happen and (b) would be their fault if it did. Lots of other motivations for the expansion in power, too. One side effect of this was compartmentalization was weakened a lot across the board. Over time, the security strength of things such as cross-domain solutions and endpoints had been dropping. The rush to get everything in that could benefit the mission increased that further.
Yeah, they're probably more vulnerable now than they ever were with more information to take with less chance of detection. Government and private sector. Their people like Roger Schell and Brian Snow warned them for a long time. Private contractors warned them. Those such as Aesec, BAE, and Green Hills even built and paid for evaluations of the kind of tech they said they wanted. They just used it less and less with stuff easy to hack being used more and more. In Snowden's case, the level of security was worse than a lot of enterprises with far less money.
The full history of intelligence collection during the Cold War has not yet been fully declassified.
So there will be a need to upgrade wholesale bandwidth just because the internet keeps growing, people are already talking about next gen game consoles to be cloud based (ie the rendering to be made remotely) which will add more traffic. But not 5 orders of magnitude. The amount of data stored by the gmails and facebooks of this world are mind blowing.
Another point is defeating monitoring. I am sure the NSA (or Google/Facebook) could not notice 1GB of upload, but I like to think that uploading 1PB of data would make all sorts of red lights flash in they network security control room.
Most bandwidth is used sending many copies of the same content. Attackers aren't going to be interested in downloading the popular video 100 million times, they're just going to grab the logs which are nowhere near that size, and although large it's not implausible that even the best security teams wouldn't notice until it's too late.
There is no hard rule that the leaks need to come from the same central database either. That is unlikely considering the fact that large scale services are already, and necessarily, distributed. Imagine thousands of attacker hosts receiving from thousands of compromised hosts.
When storage and network bandwidth increase sufficiently, when we start measuring storage costs in terabytes rather than gigabytes, the sheer size of the data set is no longer going to be a preventative measure against ex filtrating it.
What are the chances that either corporations or 3 letter agencies are going to voluntarily delete their data on you before we reach that point?
Now maybe there are counter espionage methods developed... but the idea that our geopolitical competitors don't have a single other mole as a contractor with Snowden's level of access is no longer (and frankly never was) credible. You could probably make a similar argument about our advertising apparatus.
Never develop a tool/weapon you can't afford to be used against you, because in the long term it will.
If the politics of the last few decades has tried to teach us anything, it's that this is not true. No amount of shaming or obvious shortcomings will ever allow some people to bridge the reality/ideology-gaps in question. You don't see less lying as people are confronted with their lies, you're met with a hurricane of new lies, a Gish Gallop of misinformation, over and over. If all goes truly wrong, then people in power embrace the genuinely Orwellian and start talking about freedom in chains, or peace in war.
Nothing shakes them out of it, and nothing really changes how some people view it. Or at least, nothing so minor as what the future might hold; most people seem to struggle with what's actually happening today, under their noses.
Or it could be more prosaic than that: Money. The market value of NSA tooling is likely far far higher than the threat assessments of Joe Blow Smith in Hoboken, NJ.
They will just give the same bullshit answer as always. Sometimes throw in a new phrase ("24/7 guarded datacenter") to pretend they are not vulnerable to obvious risks.
NSA hacking tools can't necessarily be kept privately within their network, because they have to be used to attack targets across the Internet -- they have to be deployed.
By comparison, the data that the NSA collects can presumably be sucked into their airgapped network, where data has a way in but no way out.
The US Government as a whole has a massive talent retention problem. Only the mediocre will stay at NSA / CIA now and we'll probably see more of these leaks / hacks.
As far as money is concerned, NSA is way overfunded - it just spends money on the wrong things and wastes lots of resources due to inefficiency.
Or maybe it was created for both. Or neither. Shrug.
Just googled it.. Here's a quote from Larry:
[...] the NSA project Perl was (indirectly) written to support.
http://www.linuxjournal.com/article/3394Another one from his 2005 State of the Onion:
> You might say that Perl grew out of the Cold War. I've often told the story about how Perl was invented at a secret lab that was working on a secret NSA project, so I won't repeat that here, since it's no secret
https://en.wikipedia.org/wiki/Blacker_(security)
Here's the source on that:
http://cahighways.org/wordpress/?p=5460
Another notable aspect of that was it used an early secure kernel, GEMSOS, that is still marketed by Aesec but probably in legacy mode in bad way. It did resist penetration during NSA certification and time on market far as what data I have says.
The Feds want to contract out for anything they can. So you work for Lockheed or whatever and get most of the attributes of government employment.
Right, and the profits flow to a couple people who essentially own the contract. It’s essentially modern day aristocracy, except the contracts are more valuable to farm out to peasants than land is.
State and local government employees are paid well? Where? Which ones?
It all depends on what is valuable to you.
Not to my knowledge. Which ones for what jobs, do you happen to know?
https://www.nctq.org/districtPolicy/contractDatabase/distric...
In my indirect experience with Lockheed, their pay wasn’t that much better than being federal (they’re still a huge federal contractor and aren’t exactly boutique). It seems like a lot when you’re used to $80-90k as a senior engineer though for years to bump into $110k on a whim (this is without being particularly special or niche, the over-funded “cyber” contracts get anyone that can read and write shellcode $140k+ which is a ton of people at NSA).
The much bigger problem hitting defense as a whole is that smaller contractors that specialized in being nimble and elite are basically being driven out of business due to federal contracting trend shifts post-sequester. Myself and many others have permanently left the IC out of exasperation with contractors now getting oftentimes less than their federal counterparts and a severe drought of technologically interesting contracts that make business sense.
The CIA were never noted for being the sharpest of government agencies ...
However, the NSA generally had a very good reputation. The big problem with the NSA is who wants to work in a place where you can't actually talk about what you do?
The primary underlying problem is that sharing and security are fundamentally at odds. If the NSA can't even get it right, what chance does everybody else have?
From the front page of nsa.gov: "Defending our Nation. Securing the Future." The second point from their What we do page - "Defends vital networks". In the opening paragraph of Wikipedia: "The NSA is also tasked with the protection of U.S. communications networks and information systems". Etc.
For all the prestige of the TAO, who claims that the US networks are secure and well defended?
I read the news and see the nation's voting, power, media, and other critical infrastructure are all being hacked. Notably Equifax, a steward of all Americans most valuable information, was compromised in trivial fashion.
Our peers working at Google, Facebook, Twitter, etc are being attacked nonstop by foreign actors and they are rightfully being held to account by congress. But in my opinion the social networks are secondary compared to the primary infrastructure that honestly does not have access to the best talent should be aided by NSA.
Step two would be to consider some shared infrastructure, probably subcontracting with a cloud provider (AWS/Azure/GCP), hopefully multiple. Once we get to that step, then you can start considering things like Google's Titan (https://cloudplatform.googleblog.com/2017/08/Titan-in-depth-...). But there's a lot of low hanging fruit before we get there.
Do more work like SELinux.
There's lots they can do.
Their continued attack(yes,using malware and implants against someone is an attack) against their own people is in my opinion completely shameful and unpatriotic.
As someone who has no intention of breaking any law or of harming the united states,it is simply not ok for me to have to include my government as part of any threat model or as a potential attacker.
Its astonishing to me that in the US it requires a court order to tap someone's phone and yet the NSA collects and analyzes the online data of US citizens...
See the response to Kent State [1], in which all legal attempts to hold the guardsmen who opened fire responsible failed.
[1] https://en.wikipedia.org/wiki/Kent_State_shootings#Legal_act...
Maybe the U.S. is no better than those nations. Still doesn't make it right. If a soldier does not protect his people and their rights then he becomes nothing more than a henchman for politicians - worse than a traitor.
we need to stop thinking of maladaptive institutions as features of society gone askew, but rather as dark patterns that have emerged as a result of historical pressures.
what's the best way to stop a dark pattern at the large scale? trip it up at the small scale, where it can't react with its weight.
leak their information. jam their systems. turn off their water supply. make them show their hand for something that isn't quite worth it.
the shadow war with russia can be brough to peace later-- they know the boundary of the game we play.
for now, we must clean our own house.
Somebody created a fake Twitter account and were sending all sorts of tweets to the Shadow Brokers, someone who was either in the IC or formerly in the IC.
This is why the Shadow Brokers outed him in this post[0]
> TheShadowBrokers is having special invitation message for “doctor” person theshadowbrokers is meeting on Twitter. “Doctor” person is writing ugly tweets to theshadowbrokers not unusual but “doctor” person is living in Hawaii and is sounding knowledgeable about theequationgroup.
> Then “doctor” person is deleting ugly tweets, maybe too much drinking and tweeting? Is very strange, so theshadowbrokers is doing some digging. TheShadowBrokers is thinking “doctor” person is former EquationGroup developer who built many tools and hacked organization in China.
> TheShadowBrokers is thinking “doctor” person is co-founder of new security company and is having much venture capital.
It was easy for everyone on Twitter to figure out who he/she/they were referring to. I think this is important context - Shadow Brokers aren't just outing random operatives, they're flexing their access and abilities when being prompted to
I also wonder if this wasn't part of a plan to bring the Shadow Brokers out of their shell a little - coax them into revealing a little more about themselves than the usual document and software dumps - which would require the NSA to spend money to get a picture of what tools are available.
Jake says to the NYTimes that he isn't working with the NSA - but he'd also say this if he were working with the NSA to get a little more out of Shadow Brokers
I've never bought the theory that Shadow Brokers is Russia, or that it was Harold T Martin (or stolen from him). I think the Jake Williams incident lends further credibility to the theory that it is a former TAO or NSA employee.
The fake Russian style writing of the Shadow Brokers isn't ordinary bad English Russian (which has a number of characteristics that aren't reflected in how Shadow Brokers write). As the article mentions, there are also far too many cultural and infosec "inside baseball" references in the writing of Shadow Brokers for it to not be someone who is either familiar with the community or part of it.
I also don't recall Russian ops having OPSEC this good - to the point where they can't be identified or linked. The good OPSEC suggests the person/people behind the Shadow Brokers are familiar with what the NSA are capable of, and what they're not. Most Russian and Chinese ops are usually linked one way or another back to to them as they're less concerned about OPSEC as they have the operational advantage of not fearing arrest or extradition
Differences between SB and Fancy Bear or Russian ops: bad security practices (not locking down bitly) vs good, using clearnet domains[1] emails[3] vs steemit and onions, using VPNs rather than Tor, the use of Bitcoin vs Monero/Zcash, speaking only (broken) English vs either plain English or Russian[2], financial motive vs political motive, etc.
It feels like someone upset with the NSA, who knows the organization very well and is also motivated financially - but I wouldn't attribute greater than 50-60% certainty to any theory at the moment. If the Shadow Brokers go on to never be identified it would really be an incredible situation.
[0] https://steemit.com/shadowbrokers/@theshadowbrokers/theshado...
[1] https://www.secureworks.com/research/threat-group-4127-targe...
[2] https://www.fireeye.com/blog/threat-research/2014/10/apt28-a...
[3] https://www.threatconnect.com/blog/fancy-bear-anti-doping-ag...
Survival bias
Here's what the Shadow Brokers themselves actually say about their origins:
https://steemit.com/shadowbrokers/@theshadowbrokers/grammer-...
TheShadowBrokers shaking heads at arrogant pretentiousness of grammar critics.
Liberal Ivory Tower Logical Fallacies:
A) Deliver Method of Content (Spelling/Grammer/Profanity) = Content is invalid
B) Only Explanation of Spelling/Grammar/Profanity = Inadequate Education
The ShadowBrokers is writing TRADOC, Position Pieces, White Papers, Wiki pages, etc for USG. If theshadowbrokers be using own voices, theshadowbrokers be writing peoples from prison or dead. TheShadowBrokers is practicing obfuscation as part of operational security (OPSEC). Is being a spy thing. Is being the difference between a contractor tech support guy posing as a infosec expert but living in exile in Russia (yes @snowden) and subject matter experts in Cyber Intelligence like theshadowbrokers. TheShadowBrokers has being operating in country for many months now and USG is still not having fucking clue. Guessing so called global surveillance is not being as good as @snowden is claiming?
Edit: the whole Steemit is really worth a read. The rants here are truly epic. It's just implausible that this is the work of a government - why would government employees spend so much time writing such long political rants on Steemit where approx ~nobody will ever see them except Q Branch and occasional journalists? It serves no obvious political or espionage related purpose. Whoever is writing these things seems to be someone who has a lot of hatred and anger for the political system and wants to get it out. It sounds a lot like the rantings of a lot of the self-proclaimed libertarians you find in the Bitcoin community:
is funny thing about being rich, powerful, and in control, it comes with dirty deeds and many skeletons. Violence begets violence but leaks, dumps, hacks brings evil and corruption into the light. No more secrets. Secrets Equal Control. Secrets between peoples, spouses, partners, friends, ok two peoples might be having some problems. But secrets between government and governed, governed is getting fucked. Secrets between corporations and peoples, peoples is getting fucked. Why do corporation deserved privacy? FUCK SCOTUS!!! CORPORATION ARE NOT PEOPLE YOU FUCKING OVER EDUCATED OVER THINKING CORRUPT RETARDS.
No more classifying bullshit. No more black budgets and black ops. If we can't be surviving and prospering without dirty little secrets, operating in full daylight, then maybe we don't deserving to being surviving. This being time to standing up. Standing up against more wars. Standing up to globalist controllers. Eliminating career politicians. Eliminating money and lobbyist. Policing corporate and special interest. Investing in ourselves. Investing in all our children.
But why would you take lying criminals at their word?
TSB started out pretending to be criminals who wanted money, which nobody bought, and so they switched to pretending to be a Snowden/Assange caricature.
The one objective that TSB has actually delivered on is attacking the NSA. Everything else is obfuscation.
TSB started out pretending to be criminals who wanted money, which nobody bought
Their attempt to auction the exploits was one of the most fascinating aspects of the whole tale because it was verifiably a failure - we don't have to take their word for it. They published a Bitcoin address and nobody sent them enough money to reach their min threshold, if I recall correctly. At least, I'm sure they were using Bitcoin with a static wallet address to do the sale.
so they switched to pretending to be a Snowden/Assange caricature.
TSB's personality has been consistent throughout. They aren't pretending to be a Snowden/Assange cariacture. Their writing makes it quite clear they seem to have a serious grudge or dislike for Snowden specifically.
I don't think they are Russian. It makes no sense for a state actor like China or Russia to penetrate the NSA and then disclose it. When they disclose it they lose the ability to exploit it.
Even if the NSA had already closed all the holes, which we can guess they didn't because of Microsoft patching them after the leaks, a state level actor would still not show their hand because keeping your opponents in the dark is more disruptive to their operations, and showing your hand has the potential to reveal your own methods.
Whoever it is is specifically focused on attacking, disrupting and discrediting the NSA. They are not making money off it (even though the op has to be expensive) and they are not exploiting it for intelligence advantage.
I don't believe it is a Snowden type for the reasons I mentioned and because the op seems way too complex and long running for any individual or group to pull off for ideological reasons.
I would tend to believe that it is not a leaker or it was a one time leak to a third party who is now running the operation.
The NSA knows everyone who worked for them, and who had access to what, and I am sure they are watching every single one of those people so the only plausible way it could be a leaker is if the NSA can't connect the leaker to whatever individual(s) are running the online campaign.
The problem with a long running op like this is that all internet access can be traced back eventually. Every time you post online, even if you are going to really extraordinary measures, you are leaving a trail that will eventually converge on your location. That means you have to stay on the move. But travel is also observable and so moving all the time will eventually create a pattern that allows you to be identified.
It is some real Jason Bourne type shit.
It could just be some relatively crazy individual who is playing a high stakes game spy game for fun.
There are a couple of examples of criminals who engaged in robberies based on the movie Heat, which seems bizarre, but it happens.
http://en.wikipedia.org/wiki/North_Hollywood_shootout https://www.theguardian.com/world/2001/mar/24/gilestremlett
The European team that was obsessed with the movie and based their operations on it pulled off some of the biggest armed robberies in history.
Their willingness to overlook the constitution because it's inconvenient is a far bigger problem than leaks, IMO.
The NSA and CIA are institutions established to protect a nation that abides by the rule of law.
When the rule of law is brushed aside the people who are part of that system rebel.
how likely do you think it is that the russians or the chinese or anyone really has developed similar exploits?
These weapons are not designed to be patriotic; they can just as easily hurt anyone.
See: https://medium.com/@thegrugq/the-great-cyber-game-commentary...
All of their "illegal" programs are duly authorized by executive orders and DOJ legal opinions and signed off on by the intelligence committees.
You or me may view those operations as illegal but they are following orders given by democratically elected officials and signed off on by every level of the judiciary.
Ultimately I don't think it is productive to scapegoat the intelligence community for what is fundamentally a breakdown in the rule of law and democratic process. They are participants in that, but so is every voter, and every politician, not to mention all the corporations that happily do their work for them in exchange for money or favors and then lie about it.
The NSA doesn't spy on Americans.
If you look at the Snowden leaks, it talks of filters limiting access to collected data to foreign nationals and people contacting foreign nationals only, as per laws allowed under the US constitution.
Why would a TOP SECRET program have these filters if their operations were illegal?
Everything the NSA does is legal. It's now up to the public to accept that fact.
1. Leaks have happened in Russia, for example the KGB archives that Mitrokhin stole [0].
2. Somewhere above 845,000 people have TOP SECRET clearances in the US intelligence community[1]. I can't find size of the Russia and Chinese intelligence community but I would guess it is an order of magnitude smaller.
3. Privacy is not viewed with the same level of importance in Russia or China. The US and European intelligence communities are tasked with a mission which directly contradicts the core culture values of those societies. Additionally the US and EU countries have large non-state controlled media outlets allowing someone to blow the whistle.
4. Because of the Pentagon papers all leakers/whistleblowers have an example of intelligence leaks being beneficial and good for the country. Are there any similar role models in Russia or China that might motivate a whistleblower?
5. When the US captures intelligence from Russia or China the US generally does not leak it to make Russia or China look bad. Russia, and before that the Soviet Union, have been using espionage to make the US look bad for have 60 years.
[0]: https://www.dailydot.com/layer8/kgb-documents-now-public-mit...
[1]: http://freebeacon.com/national-security/chinas-spy-network-u...
And it isn't like these leaks are a frequent event here, the equation group is really the only one.
I think we just don't know what happens. I would be surprised if an article like this one would appear in the Chinese or Russian press. And if you were an American journalist, would you really want to touch the leaked FIS material? The First Amendment won't protect you.
Is it likely that a leak would impact the Russian election? Could a leak cause the Communist Party of China to be voted out of office? How likely is it that a leak would not simply be suppressed, but rather cause a change in the political direction?
Leaks in the US has a history of causing real change. That could be the biggest reason why we don't see much leaks from other superpowers' intelligence organizations.
I'm russian and Russia is more unstable than many believe. This alone[0] is likely the reason P. postponed his equivalent of the State of the Union speech, which was unheard of before.
[0]http://russia-insider.com/en/politics/us-senate-attempts-inc...
There is also the fact that P. has still not announced that he will run, and in this case silence is deafening. It means that there is a very severe conflict behind the scenes - the ruling elites have not agreed whether he should run or someone else should run as his successor that will guarantee his personal safety and not let him get the Milosevic treatment in Hague for the events in Ukraine.
That is probably the primary reason. Along with perhaps bringing dishonor to your family (in Asian culture i.e. China's case)
> “We have had a train wreck coming,” said Mike McConnell, the former N.S.A. director and national intelligence director. “We should have ratcheted up the defense parts significantly.”
Yes, I think many have said this for years. I'm glad someone high-up went on record.
I'm not against what the TAO does, but the NSA (and more broadly, the US government) has massively failed to develop defensive capabilities.
I hope the NSA will use this as a moment of introspection, and up their defensive work -- particularly opensource collaborations and research. (The IAD github page[0] is awesome in this regard; as are things like SELinux. On the research side, things like HoTT as a basis for verified software; which has some DoD funding, but would be so much more if NSA researchers collaborated.)
I get that attacking things is cool -- but we really need help defending the national infrastructure against constant assault. It's in rough shape. I hope the people at the NSA -- particularly those comissioned -- will reflect on why they're there, and take the stance that the safety of the nation is paramount. Then work towards that, as I know they're more than capable of.
“I felt like I’d been kicked in the gut."
This is to how a lot of people felt after the Snowden leaks.
“Every time it happens, you essentially have to start over.”
This goes both ways too. Every time something is compromised by the NSA, we have to start encrypting yet another part of our lives.
“It’s embarrassing that the people responsible for this have not been brought to justice.”
Again, both ways. Why has the NSA not been brought to justice? Closed courts and hiding behind the "national security" argument comes to mind.
At the risk of putting words in his mouth, but based on chats I've had with people who do this kind of work: Mr Williams probably sees what he does as righteous, legal, and noble while The Others he rails against are evil, immoral, and unlawful. It's not self-reflection because he thinks he was in the right and those other people are not.
Those are two very different things. Focusing on one of them doesn't automatically benefit your efforts on the other.
Uh, yeah. It isn't saying, "why did defense fail to automatically follow from offense?" It's literally just saying they failed to protect their own network, whether technically or organizationally.
If you have the best then you should test your systems against being exploited by the best. And then harden from there. If you have the knowledge - knowing you're a prome target- why not double its value?
As it is, their approach strikes me as one of arrogance, or (ironically) lack of intelligence about foreign threats, or worse...both.
Both is not what we're paying them for.
There are likely many conflicting departments and teams within NSA. Many are probably trying to fight for the public's security and have for years, with cryptographers earnestly trying to develop secure and efficient algorithms. They are probably at odds with the other forces in the organization that seek to play the espionage game, even if it puts the country at risk.
Directly at odds. I don’t believe you should encourage anyone to trust known espionage. If it’s good advice, someone else will say it too you can trust independently.
"We settled on the name ‘operator’ to designate an operational member of the unit (as opposed to a member of the support staff) due to some legal and political situations. We couldn’t use ‘operative’ because that name had certain espionage connotations from the CIA. The term ‘agent’ had some legal issues. An agent carries a legal commission to perform certain duties and a governmental authority empowered by a state or federal constitution issues that commission. In our case, we would perform our duties under the authority of the federal government as administered by the Department of Defense and the Department of the Army. But in the military, only officers carry legal commissions from the President and are confirmed by Congress. Sergeants, who are noncommissioned officers, are authorized to perform their duties by virtue of appointment by the Secretary of the Army. Sergeants therefore cannot be agents of the government. And since almost every operational member of Delta Force is a sergeant, we needed to choose a different name for ourselves. Hence, operator. If that sounds sort of convoluted, it’s because it is. But if you work for any governmental entity, it will make perfect sense to you."
Had the NSA acted with integrity and disclosed these vulnerabilities rather than hoarding them, that window would be even smaller.
Humble opinion: s/Antivirus/Automatic updates/
Perhaps antivirus were in fact an early experiment to test the feasbility of automatic software updates.
I recall many years ago, pre-smartphone, users being advised to leave their computers online 24/7 "so antivirus could download updates". Yikes.
They're setting themselves up for a hack so devastating that it will bring down their own country.
Either one of these agencies suffering such a major security breach would be extraordinary but both at the same time is unprecedented.
Plus you probably don't want your computers that you're using for offensive operations to look any different than a normal computer on the internet.. so my guess is that is that there was an exploit of an offensive computer somehow through that back to a secured network where those tools were developed and deployed... probably through the method of remote command and control.
I'm surprised they haven't found the method of infiltration yet. But my guess is they should seriously look into unknown vulnerabilities. But it's also true (if Wikipedia is to believe believed) that agencies work together in joint operations. In that case it would only take one rouge agent to get physical access to leaking materials that would effect both agencies if they were part of the joint operations.
Oh,good to see an organization entrusted with an unconstitutional amount of data on Americans is defending against those threats with rank pseudoscience. Maybe they should hire a psychic to find that mole of theirs.
What I managed to extract from the article (do point out any flaws, I am open to them and I am just trying to do some mini-analysis here without taking sides):
- The attackers understand that warning the wide public will net zero results, now and centuries in the future. Homo Sapiens hasn't evolved enough of a collective conscience to actually act on revelations such as Snowden's, that's the historically obvious fact. Even the words of the biggest security experts like Schneier fall on deaf ears either because the politicians are better at rhetoric or because the public is too busy posting their food pictures on Instagram, or (as I believe) a mix of both. So they opted for the nuclear approach: release the hacking tools and demonstrate practically to the world the dangers of these hidden-under-the-table hacking tools. And now many more business people and politicians pay more attention than before. This is a sound psychological attack technique. Demonstrate that your opponent's claims for doing the best for the populace are not holding to reality. Even though I find this immoral and potentially dangerous IMO none of us can deny the devastating results to NSA's reputation.
- Spread FUD and never share anything truly revealing. They use language fuzzing techniques, occasionally engage in political debates without clarify which side they ally with (saying they are on Trump's side means nothing), use both old and new hacking tools and other files, use vague speak to shift suspicion to former NSA employees or contractors (I imagine this is done so they exhaust the agency while it tries to plug yet another leak which might as well be imaginary -- but they can't risk it and the attackers know it) -- all of these tarnish the image of the NSA and forces them to work extra to try and find moles, fix bugs in their own defense systems, go on internal witch hunts, double down on efforts to find the remote hackers, compartmentalize their physical and virtual clearance levels, etc. As mentioned in the parentheses, the attackers seem to aim to exhaust the agency and IMO it's working -- although none of us keyboard warriors in HN can't know for sure of course.
- Have time work for you. The fact that Shadow Brokers are hunted by a lot of law-enforcement agencies for like what, 15 months now? -- is projecting a clear image to the world that these agencies aren't as ubiquitous as they would want us to think. This probably encourages other people to try and hit other (or same) agencies all over the world. Not sure if that is good or bad -- opponents of this approach might say it will lead to anarchy and chaos but in my opinion (partially founded by rudimentary knowledge of chaos theory and game theory) the living systems like ours have plenty of emergency levers to pull them back into a more balanced state. It's 50/50 though, I don't claim anything either way. In any case though, the agencies' inability to catch these people makes the wide public lose confidence in them.
----
Please note I am not taking sides here. I do believe NSA does a lot of unethical things and should be held much more accountable than it is right now, but I am uncertain if what Shadow Brokers is doing is the right way to achieve that result. It might as well make NSA and friends become even more paranoid and actually become much better and more subtle in its mass surveillance... which is a loss for everybody but them.
Oh well, time will tell. In any case, this is interesting news and development and I am slightly pleased that the intelligence agencies get some run for their money. And slightly terrified of the possible consequences.
> calling into question [..] its very value to national security
Its what now?What are elections for in a representative democracy if the people elected don't represent the majority?
What's the open source equivalent of DUAL_EC_DRBG or Kaspersky Anti-Virus?
lol "codes"
EX: Water simulation codes, cryptographic codes, FEM codes, etc.
I have heard similar usage from academics working in various US national labs, so it was not confined to a single coffee klatch. Some of the professors and postdocs using it back then are probably lab directors and program managers by now. I can easily imagine that this usage would be widespread among academic and federal lab computing environments. Like many kinds of jargon, it is both more precise in its meaning when used properly, but also what you might consider a "dog whistle" used for virtue signaling.