NSA Exposes Tool Used by Russian Hackers
bloomberg.com
bloomberg.com
> By 1987, the Soviets began to sour on the campaign as Moscow’s scientific establishment rebuked it. Secretary of State George P. Shultz also accused Mikhail S. Gorbachev, who was then the leader of the Soviet Union, with hawking “bum dope about AIDS.” Mr. Gorbachev ordered the K.G.B. to stop spreading the conspiracy theory and after the collapse of the bloc, former Soviet intelligence officials owned up to it.
[1] https://www.nytimes.com/2017/12/12/us/politics/russian-disin...
Prior to SARS-CoV-2, researchers around the world had been warning that the next global pandemic would likely 1) be a coronavirus that 2) emerges from bat reservoirs 3) in China. There was a whole special issue of the journal Virus with multiple papers making that claim: https://www.mdpi.com/journal/viruses/special_issues/viruses_...
At least one of those papers was written by a Wuhan Institute researcher.[1] Is that supposed to constitute circumstantial evidence that implicates the institute? That's the sort of spurious logic at the core of all conspiracy theories. You can implicate anything with coincidence; it's a collection of related coincidences which constitute a hypothetical causal chain that make for evidence, and there are none with respect to the Wuhan Institute. And not only that, such a hypothesis has to overcome the a priori likelihood, not to mention substantive evidence (e.g. pangolin intermediary), of it emerging precisely as claimed by the consensus hypothesis.
Is it possible it leaked from the Wuhan Institute? Sure. Just as it was possible the U.S. manufactured AIDS as part of its extensive biowarfare program. They're both still nutty theories, it's just that one has the benefit of hindsight and distance filtering all the contemporaneous coincidences, while the other still seems intuitively plausible without the assistance of analytical thinking to clear the brain fog.
[1] "Thus, it is highly likely that future SARS- or MERS-like coronavirus outbreaks will originate from bats, and there is an increased probability that this will occur in China." Yi Fan, Kai Zhao, Zheng-Li Shi, Peng Zhou, Bat Coronaviruses in China, March 2, 2019. https://www.mdpi.com/1999-4915/11/3/210
Because that claim is nonsensical and defies common sense, whereas the idea that an accidental infection took place is entirely reasonable and requires no leaps of faith whatsoever.
>At least one of those papers was written by a Wuhan Institute researcher.[1] Is that supposed to constitute circumstantial evidence that implicates the institute?
What gave you the impression that this particular paper is the reason for the theory? This institute works extensively with bat coronaviruses, published over 40 papers on the subject, had teams doing field work in caves where they came in direct contact with bats, stored many samples on site, have had systemic deficiencies in their safety and training, and were in Wuhan, the ground zero which is hundreds of kilometres away from where the bat populations likely to carry the virus that SARS-CoV-2 mutated from actually live. All of this, while being insufficient to say anything definitive, together points to accidental release as a completely legitimate origin theory.
The US government of course may have a lot more information, leading it to believe that a lab accident is not just plausible, but likely. Or they could be lying and/or engaging in dirty politics. That too is a legitimate theory.
> not to mention substantive evidence (e.g. pangolin intermediary), of it emerging precisely as claimed by the consensus hypothesis.
Consensus hypothesis is very much subject to change. For example, the wet market origin was a significant part of it, and just a few days ago China officially said it now no longer considers that to be the source of the patient zero transmission, but merely a site of a super-spreader event. The pangolin theory was dismissed as recently as a month ago, and now there's some new evidence in its favour. Nothing we're talking about, including accidental release from a lab in Wuhan, remotely crosses into conspiracy theory territory.
>Is it possible it leaked from the Wuhan Institute? Sure. Just as it was possible the U.S. manufactured AIDS as part of its extensive biowarfare program.
What do these word games add to an adult discussion? 'Possible' means nothing. The difference between these, much like the difference between a one in ten and one in a billion chance, is how possible.
>They're both still nutty theories, it's just that one has the benefit of hindsight and distance filtering all the contemporaneous coincidences, while the other still seems intuitively plausible without the assistance of analytical thinking to clear the brain fog.
Again, analytical thinking, if you do choose to apply it, would lead you to see the clear difference between a conspiracy theory and a legitimate theory without sufficient proof. Here we have the latter, since accidental release would be logical, plausible, contradict no firmly established facts at all and would require no leaps of faith at all (unless you consider the idea that the Chinese dictatorship tried to obfuscate and cover up the truth about such a theoretical accident).
Only because of your political biases.
> unless you consider the idea that the Chinese dictatorship tried to obfuscate and cover up the truth about such a theoretical accident
This is how I know your views are driven by your political biases.
Or is it calling the Chinese dictatorship a dictatorship that's supposed to show my supposed "political biases"? I didn't realize pointing out directly observable facts has become so politically charged and controversial.
People outside of labs are exposed to bat coronaviruses all the time. The chances that one of a very small number of highly trained researchers working according to strict protocols was patient zero - as opposed to the millions of regular people who come into contact with bat coronaviruses with absolutely no protection or training - is minuscule.
Just like the Soviet misinformation in the 1980s, the theory can't be disproven right now, in exactly the same way that any other malicious accusation made with zero evidence can't be disproven. The Trump administration is acting extremely recklessly by spreading this unsupported conspiracy theory.
Explain the previous sars releases then.
After it spilled over naturally, it became the subject of intense study, sometimes in labs with poor procedures. Huge amounts of SARS-CoV were being cultured by people with little training.
That's an entirely different circumstance from now. The lab where they study coronaviruses in Wuhan operates at a much higher standard than poorly run Chinese labs in 2004. The lab in Wuhan wasn't even conceived back then.
It's essentially proven that SARS-CoV-2 was not under study before the outbreak, because the it's not in any of the standard databases where all known coronaviruses are published. But even disregarding that, the idea that huge quantities of a virus that nobody has ever heard of would be cultured is implausible.
No...it's an entirely plausible assertion that there's no evidence for. That's why it's gained traction so easily. Biohazard accidents have happened before. There's a lab doing work with dangerous microbes in Wuhan. That means plausible.
Conspiracy theories thrive on the tiny bit of truth buried in all the crap. If you dismiss the tiny bit of truth out of hand, it just becomes proof to the conspiracy that you're lying/deluded/part of the cabal.
highly trained researchers working according to strict protocols
To turn this back on your demand for evidence...how do you know? Is it plausible that someone was careless? Poorly trained? The protocols weren't as strictly adhered to as they should have been? Plausibility.
The Trump administration is acting extremely recklessly by spreading this unsupported conspiracy theory.
Well, duh. But you don't fight back with equally poorly considered knee-jerk retorts.
Not technically impossible is not the same as plausible. It's technically possible that Hitler survived WWII and lived it his days in Argentina. It's not plausible.
> To turn this back on your demand for evidence...how do you know?
Because it's a BSL-4 lab built in collaboration with a top French lab. The researchers are trained at top national labs in the US, France and Australia. Top international virologists insist that the lab in Wuhan has an excellent safety record.
There are a whole number of things that make the theory utterly implausible:
1. The lab did not have SARS-CoV-2. They sequence and publish a segment of the genome of every coronavirus they identify. SARS-CoV-2 is not among the several hundred viruses they've identified and published in this manner. In order to get around this, as a conspiracy theorist, you'd have to assert that the lab, for some reason, decided in advance not to publish SARS-CoV-2. That's implausible element #1.
2. Even if the lab had discovered SARS-CoV-2, and then not published it for whatever unknown reason, they wouldn't have found it interesting. It's 20% divergent from SARS-CoV. Before this pandemic, researchers weren't particularly interested in viruses that are so different from SARS-CoV. There are viruses that are only a few percent different from SARS-CoV. Those are the types of viruses that are intensively studied, where you can start spinning theories about lab accidents. This is implausible element #2.
3. People outside labs are exposed to SARS-related viruses all the time. There are estimates that literally millions of people are exposed every year. If you compare that against a few highly trained researchers working under strict protocols, you begin to see the absurdity of blaming the researchers. We're talking about odds that are literally a million to one here. That's implausible element #3.
> But you don't fight back with equally poorly considered knee-jerk retorts.
You should learn something about the subject before you comment that the theory is plausible.
You are undoubtedly a joy at parties.
Like distinguishing between "plausible" and "not technically impossible"? If "plausible" now refers to anything not ruled out by the laws of physics, with no reference to likelihood, then anyone can make wild, unfounded accusations and say they're "plausible."
> define your opinion ("they would not have found it interesting")
It's not my opinion. Look at the scientific literature on SARS-related coronaviruses from before 2020. What viruses did the Wuhan Institute of Virology publish on?
> ad homen attacks ("You should learn something about the subject...")
I'm annoyed by people who have no idea what they're talking about boosting this conspiracy theory. This is an important enough subject that before making these sorts of wild accusations, you should actually understand something about the field.
I'm annoyed by people who can't divorce their absolute, unshakable belief that their oh-so-exhaustively Googled faux-expertise from how actual humans are interpreting what is being said. Because, you spent so much time becoming an "expert", you can't possibly be wrong.
I'm annoyed and Google-experts who think anyone who says "maybe you're looking at this the wrong way" turn into Donald Trump and accuse them of not just being wrong, but of "wild accusations" and "boosting conspiracies" and the rest.
I understand this far better than you. You are the problem.
Isn't it the same with most conspiracy theories?(plain bullshit excluded) Just on History Channel you can see a lot of such cases about Hitler still being alive somewhere in Argentine, Ancient Aliens etc. Anyone can find compelling reasons to support anything but if you want to be objective you need to analyse the evidence. What evidence does Trump have that the virus was developed in a lab in China? Even with reasonable evidence I don't know who would believe him anyway.
These ones that you listed were plain bullshit though.
I think that you let your political affiliations get in the way and cloud your view.
My point is that without hard evidence anyone can provide "reasonable" arguments for almost anything. That's why we have protocols and run clinical trials instead to rely on what "makes sense"(i.e inject disinfectant to kill covid-19) in our more or less sharp minds.
Now if someone talks bullshit all day long it is very hard to figure out when he says the truth so without evidence it would be safe to assume that whatever he says it is very likely to be false or at least partially false.
I was replying to "Just on History Channel you can see a lot of such cases about Hitler still being alive somewhere in Argentine"
I hope you don't expect me to give all the inner details in a comment. Here[0] is a small summary though.
How is this more bullshit than "your" covid lab theory?
Odd turn of phrase.
https://thereader.mitpress.mit.edu/operation-denver-kgb-aids...
Maybe we can get them all to settle their differences with a dance-off on TikTok?
If it's done publically, it's usually not a message to a foreign entity but rather a message targeted for domestic consumption. The NSA got a bad reputation with the release of the Snowden files and I guess what we're seeing today is the result of that. Hiring talented people got more difficult for them. So they are releasing ghidra and doing PR stunts like this one to convince potential employees that the NSA isn't that bad.
I'm not making a judgement of what the NSA did or does is bad or what Snowden did was good or bad. Not even whether this PR move was warranted to show they are doing positive things. All I'm saying it's a PR move.
This is closer to calling out nations for spying - everyone knows nations spy on one another, but they call them out to humiliate or other goals. It's not really new.
So I guess this is an attempt to get exim users to update.
Edit: on a second thought, "more secure than sendmail" means nothing. It is probably impossible to be _less_ secure than sendmail.
The "Ex" in exim stood for experimental, and while it had some security goals, that was less up front. Unrelated, but interesting, the Exim author (Philip Hazel) also wrote the PCRE library.
(When I joined the university in 1997 it was fully deployed there; most people accessed their mail by telnet to a single large Sun server which ran PINE.)
No piece of software is 100% flawless.
So yeah, could be true but if you laugh at anyone claiming *Russians" with no evidence to back it that's probably the safest thing to do.
No evidence at all of Russian hacking Hilary's email if you were paying attention in the last week or so other than from evidence free DNC claims. Maybe they did, sure. And maybe Saddam had WMD - believing that lie, and i did, cost us rather a lot. It would be silly to fall for it again.
I wouldn't think that many people are using fetchmail + local MTA anymore, but maybe I'm wrong.
I used to do it for my family, but maintaining an MTA, spam filtering, IMAP/POP, webmail, CalDAV & CardDAV is rough. And supporting folks hooking up their devices that increasingly needed to go 8 menus deep to punch in the settings for something that wasn't gmail/hotmail/outlook was just too much.
And then you can't run it out of your house, unless you pay money for static IPs, or you pay for hosting and make sure you keep yourself off blocklists. Just the cost of doing it made it not worth it unless you hit economy of scale number of users.
That said, sendmail did improve my M4 skills FWIW.
(I think it was running by default, too, but I don't trust my memory. I uninstalled it pretty quickly.)
Someone should do the following:
1) Get all of the source code for Exim, and other codebases, codebases for which vulnerabilities have been discovered -- but before the vulnerability has been removed from source code.
2) Run machine learning on the code, with the understanding that different parts of code may have been written by different authors.
3) Use those ML models to see if other codebases, codebases which are as-of-yet unknown if they contain vulnerablilties, to see if those might have the same coding patterns in certain areas as the affected software above, indicating potential tampering.
In other words, via ML, software which has been tampered with -- might be able to be detected preemptively...
Disclaimer: I am not a ML expert, and this might be a somewhat futuristic idea, due to various constraints...
I personally use Exim. The developers of both have collaborated as required with each other in the past over certain issues and both projects are very mature. They are rather different beasts and there are loads of articles out there comparing them.
For the most part postfix/dovecot have become the default for full scale mail servers but back when the Debian defaults were decided there was still some uncertainty about what would replace sendmailNG as the lightweight default mta.
They are both mail-trasport daemons (basically mail relays).
dovecot is comparable to Cyrus, it's not a mail relay, it's POP/IMAP server used for accessing mail from storage.
You might have the two reversed?
I don't have hands-on experience with Exim, but every "getting started with email" document on the internet seems to recommend Postfix as easier for a beginner to install.
In fact, as an old hand (been dealing with exim configs since 2001), the very first thing I did and still do is delete the default debian hell and copy-paste a simple two-screen config which then needs only 3-4 lines tweaked.
Postfix has a high learning curve; the master.cf vs main.cf and the "chaining" of email filters (milters) is a lot more of a hurdle than exims comparatively simple configuration.
The issue is mostly that postfix is installed by default more places, so it's the default, much like sendmail was. And that setting up an MTA is quite difficult anyway.
It's basically an accident of history. But both are fine in their own right, neither is inferior to the other, just trade offs.
But I wouldn't call it complicated, not really. Expansions usually bite, but it had a REPL-like facility for getting them right since forever. The rest is pretty nice and clean DSL in my opinion.
Though not for RedHat or Ubuntu, both use postfix.
Please don’t down vote me for an obvious statement, but I do feel the maturity of Political discourse was brought to the school playground level with the election in 2016.
I'm still using exim, but not for any specific reason. It's just what I used in the beginning and I never had a reason to change.