NSA Owns Everything (2015)
blog.thinkst.com
blog.thinkst.com
> "Why did we never see it coming?"
Many people saw it coming. I was warning about the possibility of dragnet surveillance, the existence of ECHELON, the use of the American security apparatus to steal trade secrets, the surveillance of non-American politicians, et al... For many, many years before Snowden. And I'm just some rando on the internet who follows the mainstream news!
We were called _Conspiracy Theorists_; but when the action is _probably_ fact[0][1][2][3], why is it still ridiculed to say it might be happening?
0: https://www.theguardian.com/us-news/2015/jul/08/nsa-tapped-g...
1: https://en.wikipedia.org/wiki/ECHELON
2: https://fas.org/irp/program/process/991101-echelon-mj.htm
What snowden did was provide independently verifiable content and details of their activities. His leaks were outdates by half a decade by the time they were public too. Everyone sort of accepted the IC will do shady stuff to stop terrorists after 9/11 because "american lives" so it was a solid conspiracy theory backed (not proven) by facts at the time. We sort of hoped they didn't care enough to snoop into our boring lives.
When you can surveil and blackmail the entire world, including your political taskmasters, what sort of person will that role attract?
I use a stronger (more specific) form of that heuristic that seems to hold up well in practice:
If something evil is within technological possibility, and there is economic gain to be had from doing it, someone will end up doing it.
(Note, by "within technological possibility" I don't mean "there are COTS tools available for doing that", but closer to "physics doesn't prohibit it, and we have a good grasp on how it could be done in theory".)
I actually first figured out this phrasing of my intuition during Snowden revelations, to explain to myself why my initial reaction was a complete lack of surprise.
Like life, technology always finds a way. Much of the talk back in the day was not based on reality because it was not based on what tech could practically do. The compute and storage weren’t there.
But it was pretty obvious by the late aughts that all the pieces for panopticon were coming together nicely. Tech finds a way.
When a few key entities are central points of information distribution it is very simple to monitor everything. End-to-end encryption is helpful, but it isn't enough, becaues no effort is required to know where to find everything. If you really want to lower the probability of state monitoring you need end-to-end encryption and point-to-point communication without a central service provider.
Major information providers and social media have no motivation to solve that problem. Removing them from the communication channel between you and your grandma instantly renders them irrelevant.
This article is asking how the NSA managed a hacking empire leaving practically no evidence. Many people correctly assumed it was happening, they just couldn't prove much.
"Why did we never see it coming?" Is a poor way of phrasing their premise, but it's not false.
> If the NSA was owning everything in sight (and by all accounts they have) then how is it that nobody ever spotted them?
It’s sad that people routinely find the first disagreeable thing in any submission then derail the whole discussion based on an out-of-context misrepresentation of that.
>The purpose of this post isn’t to discuss the legality of the NSA's actions or the morality of the leaks, what we are trying to answer is: "Why did we never see it coming?"
They clearly made it the central theme. With enough context what they are saying makes sense, but that phrase is so often used to describe how people predicted something without evidence. I'm sure I've read several articles talking about how some health organization "saw the cornavirus pandemic coming in 200x"
The article then goes on to explain why, even with hundreds of thousands of ppl doing incident response investigations, nobody caught / correctly attributed these attacks.
All of the talk of how some people on HN totally for real knew the NSA was hacking people is irrelevant and a total distraction from the far more interesting question of why we needed a leaker to confirm it.
I think this should rather say "nobody ever came forward". I'm sure there always were enough pieces of evidence even if scattered and nobody had the whole picture. But the ones who were close enough to put together some of it and get an idea had no incentive to open their mouths.
Coming forward with enough evidence was likely close to impossible until a decade or two ago. The ones who have such comprehensive evidence also have some "incentive" to keep quiet. Up to the proverbial "terminated with extreme prejudice" option, which I'm sure must have been employed given the sensitivity of the topic. Or perhaps risking being labelled a terrorist which would likely lead to even worse outcomes. When the efforts were escalated after 9/11 so were the security measures and the "incentives".
And coming forward with just shreds of evidence of something like this will only get you labelled a nut, enemy of the state, shill, etc.
Snowden and a few others did it at great personal cost and I'm sure they now serve as an example for others to not do it. Look around even today, people see the world in black and white and if you're not with them, you're against them, and they will treat you as such.
It reminds me of that "CIA manual" that floats around about how to derail conversations and sew doubt when infuriating an organization (can't find link). About doing things like bringing up irrelevant information, highlighting less meaningful things, revisiting already solved problems, etc. I mean what did the GGP do besides say "_I_ knew about this, but you all called me a conspiracy theorist! Who's laughing now?" What good does such a statement do? Clearly they are following the CIA handbook and derailing the conversation! (I'm joking)
But I think it comes down to not wanting to read the entire article _AND_ process the information contained within. I think a lot of people read things for the words written and not for the meaning, and I find this odd.
Most of what's listed as "disinfo agent" tactics there are the general fallacious and bad faith tactics that go on in almost any forum under heated discourse.
But yeah, I fully agree that this is essentially about bad faith tactics. My new strategy to dealing with this is to call these people out on their bad faith rather than engaging in the misdirection that they are creating. At least in my experience it seems to push these conversations down from the top spot (but that may be a selection bias).
The better questions then would be "why didn't people listen? and "why didn't the general public see it coming?" It would be useful to understand these well to prevent future occurrences and even possibly to escape the current situation and future unfolding.
It was a theory that there was a conspiracy. The issue is that people dismiss conspiracy theories out of hand - even when the theory is backed by means, motive and incentives.
"This power is being used to influence the political process in the US" is still a conspiracy theory and will likely turn out to be true as well one day - because again the people involved have means, motive and incentives. But incentives based predictions are a bit subjective and most people don't seem to believe that incentives overrule character.
There must be a Luntzian phrase for believing in proven conspiracies.
The whole dialogue is skewed in the favor of those who call others "conspiracy theorists". Once labeled, no more dialogue. This is one of the dialogical moves, and conflicts with the cooperation principle to resolve disputes.
>> "Why did we never see it coming?"
You were never taught it in a rote fashion.
Fact is all intelligence services are heavily into their science and control. Its not just computer hacking they are into, they use psychology, medicine and finance to control the population. They have evolved the techniques first used and developed by successive religions since at least as far back as the ancient Sumerians.
Solomon Asch and his conformity experiments https://www.youtube.com/watch?v=TYIh4MkcfJA which continue to evolve to this day, is a useful tool for keeping people out of trouble, otherwise to quote an ancient religious expression "The devil makes work for idle hands to do" and who wants to go backwards in the Maslow's Hierarchy of needs?
So just like some people do not want to believe that God doesnt exist, some people do not want to believe their country's security services are spying on them 24/7 since the day they were born, hence why the hierarchical structure of society, currently called democracy, but included Royal governance and religious governance in the past, is still the leading way to operate in plain sight after more than 10,000 years of society. Maybe I should be called Mustapha Mond ;-)
This thread is full of opportunities for me to contribute, but this is the comment that is the most important.
I've spent a long time sifting through conspiracy theories, and I came to a conclusion at one point that the most important thing in the world the oligarchs and TPTB have at their disposal is control and influence of various degrees on the mass media in all it's forms. Therefor, the most important task is to inform people. Problem one is that the propaganda mass conciousness influence has been almost perfected, and it's very numbers based. So for example, lets say I showed you some of the more crazy conspiracies that have been at play in the US. If you are someone who wants an ugly truth over a beautiful lie, you might see the merit to my arguments. I can take the time to do that, but my numbers will never reach the MSM numbers... and so they keep doing what they are doing, because we are far away from the critical mass needed to actually push back against that power with power. The few movements that do start with that intention are quickly infiltrated and taken over, etc. Essentially, as long as the media can fool X percentage of people, it doesn't matter how many people want to fight the system, the fooled masses in their herd mentality will quash any dissent, and the perpetual cycle of abuse continues.
Second, is that I have discovered that most people simple don't want to know the truth, and in particular the ugly truth over the beautiful lie. I've "woken" (sorry it's cliche but appropos) people up who at a later point said "I don't want to know, that's too dark..." etc, but a lot of people really would rather hang on to any lie that makes them feel better than to hear about how borked the US is (and the world).
Combined, these two principles work in tandem to make sure even those who might still have a spark of dissent in their bones tend to be extra dismissive of any "conspiracy theory", either for self-preservation whether concious or not, because of herd mentality, and/or because they've been propagandized too heavily.
Also, there was a definite leap in sockpuppetry tech about ~2010, and I think there are a lot more "digital dissociative disorder people" on the web than anyone is willing to admit. (largely working to create the illusion of that herd mentality which then becomes reality)
The problem I'm running into now isn't yesterdays NSA conspiracy, it's trying to tell people about what TPTB are doing now! So maybe some people were forced to eat their words about NSA (not that many admitted that), but if you bring up the scandal of today or of tomorrow, you go right back to being considered a "wackjob crazy conspiracy nut" or some such nonsense. I don't know how you could possibly break through the control of mass conciousness to change this...
These reasons are also why the oligarchs are after control of the internet. As a withering but still standing bastion of anarchistic freedom of speech, it is their primary threat right now.
Anyway, the bottom line is that the truth, the real world, is chock full of actual conspiracies that are so much stranger than fiction.
You'll notice I kept it meta to avoid digressing into a debate about a particular conspiracy, but the number one issue is that people seem to have completely forgotten what inductive logic is, and how powerful it can be. Of course evidence (deductive logic) is preferred wherever possible, but in the arena of intelligence agencies and billionares who spend a lot of time covering up their tracks (especially by degrees of seperations), you aren't going to get that evidence except in the most rare cases. Even in the cases where the evidence does show up, it is often covered up, destroyed, lost, inadmissable, gag ordered, blackbagged, etc.
Any specifics you are most curious about?
How dire? Where to look? Timeline?
I wish there was a wiki build on a trust network where I could control the weights.
Where to look: I suggest starting with one term, though often overly applied to just terrorsts, and that is "threat finance".
Timeline: Minimum is ~120 years or so.
"As the Americans learned so painfully in Earth's final century, free flow of information is the only safeguard against tyranny. The once-chained people whose leaders at last lose their grip on information flow will soon burst with freedom and vitality, but the free nation gradually constricting its grip on public discourse has begun its rapid slide into despotism. Beware of he who would deny you access to information, for in his heart he dreams himself your master."
- Commissioner Pravin Lal, Peacekeeping Forces (Alpha Centauri, 1999)
Just a point about this part. That sentence is a nearly universal symptom of helplessness.
Those people are not denying the problem, will not fight you, but are tired of hearing about problems they can't do anything about. That is bad if the helplessness is false (propaganda does make people believe they can't do anything while they can), and you'll get a much better response by fighting the helplessness itself than in trying to push your original message.
Although I will shamefully admit that I was one of the naysayers. I might have even called someone a Conspiracy Nut in a prior conversation, with my perception of the person being obsessed with potential NSA spying / collection.
Oh, how wrong I was.
Side note: I find it interesting that a period of time developed where any type of deep curiosity into government activity was enough to get oneself stamped as a Conspiracy Nut. If I were the person pumping these narratives and troupes out, I'd be very happy with my result, in retrospect.
> We were called _Conspiracy Theorists_
Depends who "we" is. If "we" is people on HN, who are tuned in and more closely associated with this stuff, then yeah. _You are not_ just some rando on the internet who follows the mainstream news, you are tech literate and actively participating in a niche technology forum.
But if "we" is more a general term then the premise isn't false and I'd argue is still relatively true today. The general public is only starting to turn away from ideas like "I don't care if Google reads my emails, what are they going to do?" And that's only because ad suggestions have gotten too good, enough that they believe that Facebook is turning on their microphones. Obviously didn't learn from Target[0]. You're clearly aware of this because of your last sentence!
You can sit with your pride telling everyone that you were right all along and not crazy, or you can further the reach to the more generalized "we." The two options are not really inclusive.
[0] https://www.nytimes.com/2012/02/19/magazine/shopping-habits....
> Yet another circumstance must be mentioned which proves favorable for the Nazis and their immensely powerful apparatus of oppression: the development of modern technology gives the rulers, as has long been insufficiently understood, an advantage over the ruled. The more effective the weapons become and the less you can protect yourself against them, the more the armed is superior to the unarmed. The Bastille could not be successfully stormed in the age of airplanes and tear gas. Rifles equipped with rifles have no chance against motorized police forces; it makes no sense to build barricades against a government that has tanks. And in the event of a revolution, it is not only weapons development that favors those in power, the state over the individual: modern technical development and the associated sophisticated organization work in the same direction. Traffic has led to the countries becoming small and easy to monitor. How many hiding places there were in a country a hundred years ago! At that time, every power hit natural barriers! Today there is no loophole and no hideout for the rebel anymore. Even the thoughts that are able to penetrate the walls have become "controllable" because they are tied to the mass distribution of news, to radio, film and the press. How long will it take before every house has its own microphone and every private word, like every telephone call today, can be heard? The ant state is at hand. It may not be a coincidence that states like Germany and Russia have elevated technology to the status of a religion. Conversely, this development of modern technology makes the preservation of freedom a human task that is more urgent than ever.
-- Sebastian Haffner "Germany: Jekyll & Hyde (1939 - Deutschland von innen betrachtet)"
The above is my crappy translation because I don't have the English original (!). Apologies to Haffner as author and anyone who enjoys reading good English, but I think the content speaks for itself.
It's not just so-called conspiracy theorists who warned us, but also people in the midst of our society, near the zenith of human achievement. Our best and brightest. And we paid a LOT of lip service to respecting a LOT of people who warned us, while trampling what they held up as most important underfoot. We just wanted their gimmicks, their clever oneliners, the stuff we could kill time with.
> Now the police dreams that one look at the gigantic map on the office wall should suffice at any given moment to establish who is related to whom and in what degree of intimacy; and, theoretically, this dream is not unrealizable although its technical execution is bound to be somewhat difficult. If this map really did exist, not even memory would stand in the way of the totalitarian claim to domination; such a map might make it possible to obliterate people without any traces, as if they had never existed at all.
-- Hannah Arendt, "The Origins of Totalitarianism"
She wasn't the type to get excited and pushy, about anything. And maybe she wasn't aware of how she hit bulls eye when she wrote that. But here we are, and we know she did.
> If both the past and the external world exist only in the mind, and if the mind itself is controllable – what then?
-- George Orwell
What if society became completely digital? What if people completely loose the ability to remember things, and look up their own lifes and history in the data stores? I've seen dozens, countless comments on HN that seem to be longing for something like that, of course while completely ignoring the implications, the destruction of humans and human society that would entail.
> Meanwhile, in the course of this "Terrorist Generation" campaign, for Obama to claim, "you know, I'm really worried about terrorists, so I have to to read -- well, they claim they don't read it -- I have to get information about your email, where you are, who you're talking to, what you have on Facebook; I've gotta put that on my big database"... actually, we're moving into a world which was described, pretty accurately I think, by one of the founders of Google... I don't know if you followed the stories about Google Glass? Well, Google has some new, ridiculous thing, they're marketing glasses which have a small computer on them. So you can be on the internet 24 hours a day, just what you want. It's a way of destroying people, but quite apart from that, this little device has a camera, and presumably, if it doesn't already it will soon have a recorder, which means that everything that's going on around you, goes up on the internet. Some reporter asked Erich Schmidt, didn't he think this was an invasion of privacy, and his answer was exactly right, comes right out of the Obama administration, he said: "If you're doing anything that you don't want to be on the internet, you shouldn't be doing it." This is a dream that Orwell couldn't have concocted. We're moving into it, and it's not the only case. if you read the technical journals, there's more stuff coming along. So, for example, right now there are corporations that are concerned about using computers with components made in China, because it's technically possible to build into the hardware devices which will record what the computer is doing and send it to those bad guys. well, the articles don't point out that if the Chinese can do it, we can do it better, and probably are, so it may end up in Obama's database the next time you hit the computer.
-- Noam Chomsky
That was located at http://grittv.org/?video=noam-chomsky-on-secret-trade-deals-... but that site is dead and directs somewhere else. Don't click. I transcribed it 7 years ago, I can't prove that, but if seriously challenged I would go try looking for another source.
My point is, that's not some old man who doesn't understand technology. He understands it better than the people who are used to make it. And did you catch what he called Google Glass? "a way of destroying people" That's not exaggeration, that's cutting right to the heart of the matter.
Maybe they mean that most security providers didn't see it coming. Some people would think that the NSA are part of the set of security providers and hence, in a way, it's not that you don't see something coming, it's simply that you don't see them as the aggressor.
If you change from the topic of "computer security" to "nuclear weapons" then perhaps you can see how intelligence gathering, obfuscation and subterfuge is perhaps not an inherently offensive thing. For nuclear weapons, I think the only objective is to prevent nuclear explosions. Some people think the US's role is to stop nuclear war; some people think the US is part of the problem.
My personal take on the topic is that Snowden's main role was to challenge the idea that the NSA is keeping the peace.
My parents' friend who had lived in New Zealand for a decade at that point came to the country to bury his father and was over at our house for dinner. He's an electrical engineer and used to work for a telco in New Zealand. He had heard about this ECHELON thing from multiple colleagues and found it plausible enough to talk about. He was told that all internet and phone traffic was being recorded realtime. Mind you, this was pre-9/11, so no 'terrorist threats'. The world ran on shitty computers and expensive storage and voice in any form (even compressed telephony) was considered bulky at the time. And this is 15 years prior to the machine learning boom, voice transcription was really bad, I still doubt it was used at that point, even though he mentioned it.
But he had witnessed an expansion of fiber and datacenter capacity sometime in 1997-99 and it seemed plausible to him (a real serious and professional guy).
Imagine my surprise when it turned out to be true. I mean, the story slowly became less and less far fetched over the following decade, but was still a total surprise when Snowden blew the whistle.
There were many people who were going out on a limb with the assertion that the NSA was probably vacuuming it all up, they had means, motive and opportunity handed to them on a golden platter, on top of that it corresponded with what we would expect to do ourselves when in that position (not that there was any such temptation). The hacker community was well capable of seeing this as a theory, rather than as a conspiracy simply for absence of proof. That didn't stop others from labeling the hacker community as a bunch of conspiracy theorists simply because they could not imagine it to be the truth, but a lack of imagination is not the same as proof and the output of such a process is better described as wishful thinking than rational thought.
Snowden changed all that. All it took was one person willing to burn their career to provide the proof. But beyond that nothing much has changed.
This is wrong. It took a LOT more than that. It took one man forgoing his life and liberty, and a group of people endangering theirs to assist him. Snowdon is not going to get his life nor his liberty back, ever.
It took multiple institutions dedicated to publishing the truth to actually bring the news to a wide audience, and it didn't end without a degree of betrayal.
Snowden is currently in political exile and probably closely monitored, likely for the rest of his life. US congressmen have openly called for his assassination. If he were to return to this country it's highly likely he would spend the rest of his life in a federal prison, at best.
Please explain how 'all it took was for someone to burn their career' isn't utterly misconstruing the cost being addressed?
This should have been the case as in normal whistleblower cases. Seems it was not. I also suspect that Russia will eventually try and call the favor to coerce him to do something for them
EDIT: had no idea this would be so negatively viewed. If you're going to down vote please indicate what you're against...
And as for why your post was down voted, you stated that a whistleblower should lose their career for their uncovering the truth.
https://en.wikipedia.org/wiki/Conspiracy_theory#Etymology_an...
Examples such as the Climate Change hoax, Moon Landing hoax, COVID-19 hoax, New World Order and so on abound and I probably should not even give them the courtesy of repeating them here because they are like little bits of actively infectious DNA that will sooner or later encounter a fertile medium for reproduction.
If fringe theories would be susceptible to reason then the bulk of them wouldn't exist and the remainder would not be classified as a belief system but just another theory waiting for confirmation or rebuttal.
> I would have ignored it out of hand
Those two next to each other is kind of amusing.
The issue is that by not acknowledging that there are two separate uses, people end up lumping any theory about a conspiracy into "conspiracy theory".
For example, I remember reading a comment on HN around 2010 from someone who worked at an internet backbone. They said that there was some secret fiber cables, nobody knew what they were for, but they were not allowed to touch them. However they were the same size/caliber as the other cables that went to the next backbone, so the reasonable conclusion was that basically all traffic that went out of one pipe went out the other one too. And it was some kind of US government thing.
That, plus other things I've seen over the years, convinced me that the US had a massive domestic spying operation, like the NSA. There were news articles about the NSA building massive new facilities post 9/11 -- what would the point be of them? Turns out I was right, thanks to the Snoweden revelations, and honestly I didn't understand why they were such a big deal. OK, it was hard evidence, but it blew my mind that people were sooo surprised that it existed. Sometimes, occam's razor suggests a conspiracy.
This is a far-cry from the theory that the world is ruled by lizard people.
This list:
https://en.wikipedia.org/wiki/List_of_conspiracy_theories
Does not include anything even remotely like 'The NSA is listening in on all of us'. At present it is not even a theory, it is established fact but at no point in the past would I have put that on the same level of the items on that list.
The paranoid irrational beliefs one is the one that I think best covers the payload. The second one is only interesting from a pedantic/academic point of view.
Or, for example, https://en.wikipedia.org/wiki/List_of_conspiracy_theories#MK... which we actually know as having been real (though not necessarily all of the related theories are true, as I don't know what they are. But I am pretty sure that if you said "the goverment is kidnapping Americans and doing chemical mind control experiments on them" before all the facts abotu MKUltra came out, people would have labeled you a conspiracy theory nut.
As for the MKUltra stuff: the whole crux of a good conspiracy theory is that it is rooted in some real world event and then puts a crazy spin on it. People probably don't even realize when they step off the cliff of reason into the world of the nut cases.
Snowden's leak is a good example of something that proved a lot of conspiracy theories to be true
At that stage it was 'just a theory', with little support.
That some people then went a step further and mislabeled it is mostly their problem, they should have realized that the standard of proof required to shift it one way or the other wasn't available. Snowden gave us that proof.
Your average conspiracy theory is trying to make claims that go against available evidence to try to come up with some kind of alternate history of what must be true. Typically these involve privileged knowledge, powerful people and internally inconsistent claims.
The NSA could be listening in on a lot more than they are letting on theory never had any of those problems.
The NSA engaged in a conspiracy, which was to "hoover up everything in sight". There was a theory (which was largely dismissed) that the NSA was in fact doing this.
It was therefore a conspiracy theory that the NSA was doing what it was doing. That is the point: please use the phrase correctly.
You've taken the phrase and made up a new definition for it. I'm saying that the phrase already has a definite meaning. Feel free to make up your own phrase though...so long as it's unique.
This is likely why people just combined theory, conspiracy theory all together, because the moment you look at the grey area, it becomes nuanced.
The idea that "conspiracy theory"===false comes right out of COINTELPRO. You know, the big secret (at the time) conspiracy to subvert domestic US movements. In fact, much of the 20th C was defined by secret conspiracies - the Bolshevik revolution, the rise of the Nazis, every post-colonial coup, etc. Project Echelon was well understood in the 80s. What is the USS Jimmy Carter even for?
No, it's not. It's a theory that a conspiracy has taken place.
They didn't have the legal right.
> All it took was one person willing to burn their career to provide the proof.
Snowden proved that the NSA does not vacuum everything up in the US and only vacuums everything in a few countries. You seem to be reading different documents from the ones that Snowden released.
And yet I believe crime exists regardless of its legality.
> Snowden released a trove of internal documents not vetted by the secret keepers
Why on earth should the secret keepers be the ones to vet documents about themselves when they are being whistleblown on?
> And yet I believe crime exists regardless of its legality.
Well over 99% of the time, the government does not go out of their way to break laws. I didn't claim that the fact that it is illegal proves they didn't do it. I simply said that the fact that it is illegal makes it more likely that they didn't do it. Do you disagree?
> Why on earth should the secret keepers be the ones to vet documents about themselves when they are being whistleblown on?
Who said they should? My point was that despite the fact that they weren't combed through by the secret keepers, the documents did not say that the NSA did the illegal things that GGP claimed. Instead, these documents supported the opposite conclusion — that the NSA didn't do those things — by repeatedly citing the laws that they follow that don't allow them to do those things.
One of the strategies can be to completely poison information, as you said "label". In that way it would be hard to distinguish between "true" and "untrue", and in that way basically force researchers to even approaching subject. In that way only person from inside could uncover truth... I guess ...
And this is same problem like with corrupt government, if they hold all the keys it is very hard to overthrow dictator, as it is very hard for truth to surface out.
As an admin at BAH he was using his colleagues' passwords for discovery. He was willing to burn their careers to hack access to more leaks.
So much leaks that he could not vet these all. This was no Ellsberg tasked with copying some confidential papers and reading lies in them. It was wholesale collection of all Snowden could get his hands on.
Then, instead of making his point with his own whistleblower findings, he went to journalists and handed them over all the documents, instantly making them available to intelligence agencies all over the world, burning all NSA/CIA analysts with records in the dump (for instance, everyone who contributed to Intellipedia, which had zero reason to be in a dump meant for whistleblower purposes).
Then instead of facing justice (and there are whistleblower protections for doing the right thing), he cooperated with Wikileaks and fled to China and Russia, causing a permanent PR disaster for US intelligence with his new public speakings, book deals, and social media influencing career.
The reason Snowden's leaks got a lot of attention is that they "proved" (we never got confirmation that they were real) that data on Americans is being collected. We already knew, by law, that the Americans are allowed to fully spy on European civilians. That's how they are able to warn on impending terrorist attacks and improve their buy-in with European countries leadership (or how they are able to perfectly copy Germany-invented motors or Belgium-invented speech-to-text technology before these countries are even building it, because a strong US economy is a matter of national security).
I think it was pretty well understood at the time that the Obama administration could not be dependant on upholding whistle blower protections.
This is literally part of what whistleblowers do.
> instead of facing justice (and there are whistleblower protections for doing the right thing)
Whistleblower protections that didn’t really exist?
> causing a permanent PR disaster for US intelligence
One which they got for callously breaking the law?
> The reason Snowden's leaks got a lot of attention is that they "proved" (we never got confirmation that they were real)
What kind of confirmation do you want? You can’t just put things in quotes and hope to weaken them.
No, this is outsourcing your whistleblowing activities to journalists. It is leaking unvetted data in the hope that there is something of public note/damaging to your employer in there (of course there is, top secret and noforn classifications are there for a reason)
> Whistleblower protections that didn’t really exist?
They existed. Just because Snowden did not like his chances with American justice does not mean whistleblower protections do not exist. Obama even pardoned Chelsea Manning (I believe that leak was part of a suicidal life style).
> One which they got for callously breaking the law?
I am not saying the PR disaster is not warranted. I am noting the extend of the PR disaster. I am also adding the soft-ball questions from journalists, and Snowden's meticilously prepared talking points.
> What kind of confirmation do you want? You can’t just put things in quotes and hope to weaken them.
The NSA coming out and saying these documents are real. Thread OP was talking about proof, but proof requires a better standard. Of course, it is highly likely these were real documents, and the Chinese or Russians did not add false documents to muddy it, like they do with their own leaks. I actually added the quotes, not to be pedantic, but to ward against pedantic replies.
Not particularly nitpicking.
However, Snowden risked his whole life. He was pretty sure that he will be sentenced as traitor, and putting him life on the line.
The question is, with all of these companies performing IR, why didn't they see mass exfiltration and C2?
I think the article lays out largely correct claims.
I personally would imagine (2) and (5) to be the most significant.
Regarding (2), it is so hard during an incident to know exactly what is attacker behavior and what isn't, to know that it's all the same attacker, etc. It isn't so uncommon to go digging into an incident only to find some unrelated malware - and in fact many companies find out they're owned from their pentesters.
With regards to (5), defenders have frankly been to slow to evolve. The people investigating these attacks likely only have a rudimentary understanding of TCP/IP, have virtually no ability to read or write code, and mostly are trained to build and enforce policy. The idea that they can catch even basic attackers in realtime is a joke, that they are to also be tasked with catching the NSA is just a depressing, hard to swallow reality.
Attackers are out here building up toolchains from scratch - anyone who isn't doing that is called a script kiddy. And yet defenders who can't build a single thing, who can only throw tools at a problem, are the standard. Attackers are flat out better than defenders - they work smarter, they have better capabilities, and defenders don't even seen to care en masse.
As Alex Stamos said (paraphrasing), most companies aren't even "playing the game", and it's a select few that even know what game to play - not even that they're playing well, but at least they showed up to the right ballpark (I'm butchering his statement). The vast majority of companies employee outdated models of security and incident response is probably the least mature, with devops pushing more and more infrastructure and product security engineers over IT admins.
No doubt that NSA's scale allowing novel forms of exfil like passive collection also played a major part.
What a sad state.
Having taken VC money to try to improve the situation I do always laugh when thinkst talks about that :) but much respect!
1. Good tradecraft means that, except for skilled IR folk, they wouldn't see mass exfil/C2.
2. American IR companies know what side of their bread is buttered on. From both employees' personal allegiances to their former employers and the company's active government contracts, there's not a lot of incentive to report on their own government's actions.
More likely, as the author mentions, the NSA disguises its attacks as less sophisticated than they really are.
I just go with a bit of ridicule. Something like: It is not that sophisticated, educated, wealthy and influential people in power could get together and have some kind of plan. If they did it couldn't possibly escape your attention but if it did it wouldn't be interesting enough for you to talk about.
Or maybe it isn't that. Maybe the quality of government depends entirely on the citizens? If you think drag net spying is a good idea is a yes/no question. If you don't care means yes which in turn means they should be doing it. Same goes for enriching themselves at your expense. I mean if you approve of it?? Or is not caring and approving not the same thing?
However, the way the event was covered by the media - told a different story. The media focussed on the man rather than the info he provided, so the conversation was 'where was he?', 'where was his girlfriend?', etc - that told me everything. They hardly touched on what was provided and what that meant (that we were being spied on 24/7). And what was provided took years to come out...... So, the media are complicit - just another arm of the governance structure we find. The intercept, the MSM, all are just playing a role in mis-informing the people.
Since then, I have even come to change my views on the Snowden event itself. I think this was an intentional release of data, an orchestrated event. Snowden is probably a character created by some agency. He may not be a real person - things like bits of his glasses disappearing indicate that he could be CGI. Perhaps this sounds crazy - but if you are in the business of governance, you want to manage everything, even the opposition. (Think 1984 and the way that the opposition is created and controlled in that book).
Why would "they" create Snowden and the release of apparently top secret files?
Well, if you know what is coming you do not respond with shock, you do not reject it out of hand. You acclimatise to the new reality. There was little we could do with the Snowden event, except watch it play out. We were put on notice and informed of what was/is coming. And what's coming is a technocratic system with very fine grained control in the hands of the technocrats.
As to how you can end up 'there'. Well it mostly depends on what news feeds you let into your life, and do not go into them with a health dose of deep skepticism. Youtube can get a bit stuck on particular things as its alg feeds on engagement. Watch 1 video from someone and you have kind of exhausted your other threads of thought in their system and it will go hog wild and show you a different class of stuff if it is not on their 'do not show this to people list'. Remember ML/AI is basically very fancy cubic spline fitting across many nodes with some calculus thrown in and N stages. But if you end up between two points you can get strange results. But a computer does not know a garbage result from a good one. So it gives it to you with a 90% confidence.
If something jumps categories some people like that idea. They like the idea they can say 'Ive know about that for years'. I think it also gives comfort to them if they can not make sense of an idea. But my jedi mind skills are weak so I can not read minds :)
Here's a link to a video on Snowden's disappearing glasses: https://www.youtube.com/watch?v=5QqxLalvh-4
Cutting to the chase, if it is as I suggest it is - that most media is there as part of the governance structure to beam a particular type of messaging to us - you then have a few options.
You can refuse what I say, and accept the media as is presented. This is surely the path of least resistance.
If you care about the truth, you can look more deeply and research all ideas before accepting them as true. Just because you see something on TV does not make it true. My thesis is that news media is just production of a show, like a film or cartoon. You don't trust films or cartoons - so don't trust the news. Here's a fun example: https://www.youtube.com/watch?v=5cDYKXMkSRs - check the folder change colour live on the news! Is it fair enough to manipulate what we see on account of a "green" budget?
My bottom line nowadays, philosophically speaking, is that I am only prepared to accept as true that which I can confirm for myself via my own experience. This may sound a weak position, and it is perhaps. But I stand on solid ground as I am personally able to verify whatever I claim.
With regards to events that are presented in the media, I take an aggressive deconstructive position, and ask questions such as: have I been provided evidence, am I being emotionally manipulated, is the story coherent, etc. I find my questioning frequently provides evidence that the story is not coherent, and can be dismissed. That again may sound weak, but the thing with truth is that it is resilient and not incoherent - when you are presented with an incoherent story then you can dismiss and ignore _all_ of it.
So, my default position with media stories is to autohoax them and to lend far greater weight to personal experience.
Maybe maybe not, but it can also be that you are a "opinion magnet" ;) See that's the fun in politics, agencies, diplomats and game of thrones, you can play mind/war-games. But often Secret services work much leaner and cleaner than you probably think, first you don't need complicated stuff to find a 'secret' and second, the more complicated the more errors can happen.
So you're essentially saying the revelations were a false flag operation? I considered that possibility, but Snowden's background is well researched and the first thing media outlets look at before publishing their findings. The Guardian probably thoroughly doxed him before publishing anything. And in interviews he comes across as sincere and genuinely politically passionate. There's no way someone could fake all that. Snowden is the real deal.
If the NSA wanted to showcase their 'box of tricks' then they would have other ways of doing that like fake leaks that have a bunch of decoy material to confuse their enemies; not the real/actual tooling that is used to surveil (as that would be stupid). They would release plausible-looking material that advertises their capability, but be scant on the details and mechanics of the tooling itself.
If it was an affair beneficial to NSA, please elaborate why non-US state actors didn't have their own Snowdens?
If you knew, what would you really do? There are insiders and outsiders, and if you talk about this stuff, you are an outsider. Life strategy-wise, which one are you going to be? It sounds jaded, but really, having been one of those experts playing in this invisible sandbox, I used the tools I had and worked with integrity. That I didn't defeat a multi-trillion dollar conspiracy of hundreds of thousands of people doesn't bother me much, and where I scored a few points on them, I feel pretty good about it.
-- Sophie Scholl
But otherwise, if you read the interrogation transcripts, I don't think she regretted anything. She knew what she was doing and why she did it, and she knew she did well. IMO her life ended so much better than that of people who just give in to pressure against their conscience. It's not like those are immortal, and then they have to spend the rest of their time with who they became, too. Some find a way back, most don't. As Shakespeare wrote, the coward dies a thousand deaths -- Sophie Scholl died but one, and it was rather majestic, if you squint just right.
I still wish she would never had a chance to prove her greatness in this particular manner and had survived instead, so don't take this as me negating your point.
This can be very hard.
but what i found out is most people conducting interviews don't want to know and they don't want to hire nor work with anyone who does want to know the big T Truth. I have been able to tell the interview conversation tone just shut down after I mention Snowden or the Shadowbrokers. All of the interviewers were ex-DoD and/or ex-Intelligence. I could tell they would not be proceeding to hire me because they got very quiet and quickly transitioned to the "let's wrap this up" phase of the conversation.
it greatly puzzled me for a long time why would the class of civillian infosec workers be affraid of the knowledge of how NSA had ran circles around them in the dark and why would these workers on the front lines of security want to NOT know how to defend themselves and their customers?
maybe ex-DoD folks are scared of Snowden, because they were always forbidden from reading Snowden leaks, since they would be violating their classification authority by learning about top secrets for which they were not cleared to know. i find that funny and scary in an Emperor's New Clothes sense, that us unwashed civillians on the streets can know more about cyberwar than DoD's own cyberwarriors, because we can study public information, while DoD indoctrinated workers have to pretend the Snowden leaks and Shadowbrokers never happened. there is probably also a factor of shame and face saving that makes DoD infosec types choose to be willingly ignorant. Snowden and the Shadowbrokers were the biggest embarassments to NSA.
imagine you are NSA. you are untouchable, you have as good as an infinite black budget and you are above all laws. you have pulled off the biggest victory in intelligence history--for 12 years after the Patriot Act, you have been hacking everyone and spying on everyone and nobody has figured it out and nobody can prove a thing. then along comes Snowden and the Shadowbrokers and your whole cover is blown. that's gotta make anyone who drink the Pentagon's kool-aid pretty personally mad. so anyone else who comes along and is blabbing about things they read in Snowden leaks will be treated like an outcast and shunned for adding insult to injury.
https://www.google.com/search?channel=fs&q=james+bamford+nsa
The exfiltration protocol described in the "misdirection" section has "Dated: 24 Feb 98" in the bottom right corner.
That it's being regarded as reasonably novel is a good measure of just how broken the collective security discussion is.
Just as broken as the PGP situation, thinking about it; in which case everything is operating as intended... moving on...
Context? I remember that Snowden regarded PGP as a usable defence against his former bosses.
what this 1998 date means is that NSA TURMOIL--passive sensor ingest, had to exist PRIOR TO 2001.
this even screws Bill Binney's narrative that the system he designed--THINTHREAD, which he says would spy on all traffic without violating our privacy laws, was built in 1999-2000. THINTHREAD was ultimately canceled and Hayden chose STELLARWIND instead.
but this screencap show FASHIONCLEFT already existed in 1998. therefore NSA has been spying on the whole Internet for waaaay longer than the official narrative says.
i was one of those conspiracy theorists ranting on USENET about ECHELON back in 1998. turns out, we were RIGHT.
you're assuming this is intended for american infrastructure. they were probably violating the civil rights of americans before 9/11, but this is an inconclusive piece of evidence.
Although there was large political influence, it really doesn't shine a good light on them and their capabilities or more probable what they make of them.
That said, I think restricting their abilities is the way forward, otherwise you just get a new form of a cold war, which in hindsight was just stupid. Their current capabilities cannot be justified with security concerns and if so, they should at least be able to fix the IT of prominent political actors.
They scared the right people to get privileges to data that is formally protected in most western countries. So not only do they do a bad job, they are also criminals.
Attribution in the cyberspace is still pretty shaky, even though there have been some high profile accusations flying around lately. Sometimes you see links being drawn to GRU on the basis of things like some executable having a compile time matching to a Russian time zone or a file being last modified by a user called "Dmitry."
Seeing as the IC cyber business is already murky as hell, who knows which party is actually doing what. I think only the PLA plays with slightly more open cards, mostly because they just don't give a damn about being caught.
This kind of reputation makes them the an easy target for every other actor to take advantage of.
This tactic was invented by the KGB. It's not that they don't care, it's that if it looks like you did it, and there was no apparent attempt to conceal that it was you, then it actually seems more like you were framed by someone else and you didn't do it. In other words, the truth acts like its own disinformation campaign because people often assume the real criminal would try to conceal themselves.
I doubt much of anything off the shelf for companies even if they open their wallets a lot can be realistically expected to defeat against advanced well funded nation state intrusions.
I would not add North Korea or Iran to that list. I think they are far behind. Maybe North Korea gets some scarps from China
The US has without a doubt the most powerful position. All major operating systems are made here. GitHub is for the most part here. A lot of equipment comes from there or at least in warehouses or just pass through. Given ample opportunities for modification. We have the FAANG. Twitter and lots of other worldwide platforms that have millions of users. All slurped Up by the NSA (at least if they want to).
The US has a very coveted position.
Presumably China possibly is next. So much manufacturing happens there on whole equipment or parts for it. Should give them rich opportunity to modify products they are interested inn.
This allows immense corruption and profiteering. However, its not all just "ma' capitalism" - there are very strong indicators that a socialist superstate is being constructed within this society, which is parasitically feeding on the corpse of America today. Many consider the US military industrial complex the largest socialist organization that ever existed - it certainly crosses a lot of the boxes.
Socialism is destroying America!! Can't you see??!
And yes, it is the American government doing this.
Mind you, a lot of these projects are post-9/11 so I'm confident a lot of it has been a result of it and the massive financial injections that the US government put into counter-terrorism since then.
Finally, I like to think that the NSA and co don't want to advertise how much attempts they thwart; if they, for example, stop an attack every day, the people will become afraid of terrorists because incidents happen so often. But I'm not sure if they are being kept silent.
Coleen Rowley was the whistle-blower on this event, and testified to congress. Everything on the laptop had the evidence of the 9/11 attacks, but was blocked by the FISA court.
https://en.wikipedia.org/wiki/Coleen_Rowley
Ironically great investigators with 2001 tech could have prevented the 9/11 attacks. Appallingly then the FISA court approved the whole sale surveillance of any Verizon customer. The wholesale Verizon order was the 1st and one of the biggest important information leaks from the Snowden documents.
A court that was set up to protect the civil liberties of Americans during the abuses of the 1960's-1970's failed in the protection of the largest terrorist attack in US history, but was then used to circumvent the civil liberties and privacy rights of a massive numbers of American citizens.
Then the government used the pretext of 9/11 to create these technologies by for the NSA to surveil the large majority of its own citizens, when all that was needed was 1 FISA warrant approval.
https://en.wikipedia.org/wiki/Thomas_A._Drake
https://en.wikipedia.org/wiki/William_Binney_(intelligence_o...
It's appalling, with the loss of our rights and the digital world now being used to further deteriorate these rights when it can be used in such better and positive ways.
Also a 20+ year war, Trillions of dollars, and millions of deaths could have prevented from not blocking this warrant. While right now, with COVID, we could use Trillions of dollars to help keep US citizens safe and use it for small business support during these tough times.
They even failed to keep it from literally putting a carrier out of commission.
Their mission has become “collect it all”, but I think they (and a lot of commentators and even everyday people) can’t really imagine what a large percentage of intelligence is useless noise, deliberately wrong (such as counterintelligence but they don’t realise), just plain wrong (like most intel gathered from torture - people will say literally anything they think you want to hear), correct but misinterpreted, etc.. And it’s extremely hard to meaningfully sort through that much information. I expect they do expend a lot of effort trying to combat this, but historically I don’t believe they’re very good at it, and I’m sceptical machine learning and things like that is really going to help that much.
And then just watching the wrong people. Take the Boston bombing, for instance. There are reports that the key focus of groups like the DHS at the time in that area were the Occupy Boston protests, so the bombing happened even though the FBI had been tipped off about one of the bombers from Russian intelligence services. Then things like the NZ mosque attack, where this far-right wing white supremacist came from Australia and murdered a bunch of people. At the time, the media where I am in Australia was reporting FUD campaigns from Australian security agencies about ISIS and Islamic terrorism, radicalisation etc., so I imagine that’s where the focus was and he slipped through.
This goes way back throughout history. Just think of the massive amount of wasted resources surveilling suspected “communists and homosexuals” back in the day. Here they had agents actually infiltrating university communist groups. The groups got up to extremely dangerous things like going to protests - great use of millions of dollars of surveillance...
I wonder ... it seems like there might be a certain personality profile that is inclined to a security career -- might be correlated.
1) If the NSA interacts with you, you are a victim. It's possible there are no meaningful exceptions to that.
2) The NSA interacts with Americans (not suspected of a crime) as if we were a hostile foreign actor.
3) It is both sound and safe to presume that the IC community has lost it's way. This is true during every administration. It may be somewhat less true, for a time, after a bit of IC wrongdoing is outed.
4) IC chiefs lie to the public to the point where it's unclear if they ever tell a meaningful truth.
5) The National Security portion of NSA's title implies that the interests served by the agency are US Gov's but not the public's.
6) The NSA does not even pretend to defend the Constitution of the United States against all enemies [to the Constitution], foreign and domestic; or to bear true faith and allegiance to the same [Constitution].
I particularly liked the bit in the article about hiding data in packets intended for other hosts and harvesting them through passive relays. Is there a way to detect this sort of thing?
Is everything really compromised?
Given the documents and budgets which have leaked so far - it seems more sensible to assume that all hardware & software is compromised until proven otherwise. From the limited information provided so far we can see that if you use any Intel CPU, any Seagate/Hitachi/Fujitsu/Samsung hard drive, any version of windows, most commercially available routers, notepad++, or VLC - the NSA has access. Their scope is ridiculous.
https://notepad-plus-plus.org/news/v733-fix-cia-hacking-npp-...
My bad, that one was the CIA.
Rather, the NSA has the capability to subvert these things. Sometimes before they reach you, sometimes remotely. But you’d be “lucky” to come across one where they’ve actually done it.
but NSA has access to the emails, internal bug trackers and source code repos of the entire dev teams at all of those vendors. think how easy it would be to hack all firmware on an indistrial scale when you can cheat and read the blueprints?
NSA is the biggest cheater. i no longer consider them as being gods of cyberwar. rather, they merely tricked us all to believe NSA was not mass surveilling everyone, then we were blinded to the scale of what was really possible behind the curtain.
if we had the source code to the firmware of every hard drive, we could do exactly the same thing NSA did.
also, yes, do not ever trust a computer. remember the photo of David Miranda's macbook motherboard after his laptop was siezed when he was connecting to a flight in London and acting as the courier between Laura Poitras in Berlin and Greenwald in Brazil? the photo showed GCHQ melted like a dozen chip on his motherboards. when that photo came out, it was puzzling, because the Snowden leaks about NSA hacking firmwares had not yet leaked. in hindsight, now we know. NSA and FVEYs physically destroyed every chip that they could implant, out of fear that someone else could BADBIOS attack David's macbook and steal the Snowden cache.
Could well be a threat there but I want actual evidence when the threat bogeyman is invoked in the name of more power. I believed the WMD lie. I hope I have learned from that.
If we believe the NSA then your question is exactly the right one to ask and has some obvious implications.
https://en.wikipedia.org/wiki/Nayirah_testimony
So pretty much all of US's wars in Iraq has been based on lies.
https://en.m.wikipedia.org/wiki/Multi-National_Force_%E2%80%...
Can you proof that or is that maybe something the CIA or the Pentagon would say?
https://www.reuters.com/article/us-supermicro-chips/super-mi...
And:
Apple, Amazon and U.S. and U.K. officials have all said they have no knowledge of any hardware attacks via Super Micro
Why is China accused of supporting them?
Prosecutors said the men at times acted in their own self-interest - including one occasion when they demanded a ransom from a company in exchange for not releasing its private information - but at other times "were stealing information of obvious interest" to the Chinese government.
According to the indictment, the hackers "worked with, were assisted by, and operated with the acquiescence of" the MSS.
This isn't a red vs blue issue here. It's about whether or not we're going to allow the powerful to pick and choose election winners.
It's also hardly an old tactic.
All I will say is that when I was forced by personal experience to inexorably learn the scope of what can be covered up is at least two orders of magnitude beyond what I'd thought possible... it gave me and still gives me waking nightmares and sleep deprivation.
Imagine if we all were still using insecure protocols like plain HTTP today.
Encryption is against lower level non-state actors.
State-level surveillance can be eliminated through physical data diodes but it is would be very capital intensive.
Does this mean running in a public cloud might actually be more secure? Or do we just have to assume that the NSA has their hardware in place in any cloud provider and that there actually is no security possible in the cloud?
If that public Cloud is from an American company: obviously no. And whether you prefer some Chinese intelligence service having access to your data probably depends on what you want to do.
Yes with two conditions: 1. your public cloud is run by an Amazon, Google, Microsoft-type company (FANMAG) 2. You trust the company to lean on rule of law.
1. Very few providers have the capability and desire to put the work into supply chain security, things like OpenTitan, etc.
2. They might hand over your data in response to warrant, but their systems are designed to prevent covert extraction of data. The company should have a track-record of pushing back against overly broad warrants.
But you actually can run software on compromised hardware that can provide end to end encryption irrelevant on how thoroughly the system spies on you if you can control its network traffic and construct crypt generation from basic arithmetic functions of the system in question.
Example of shared hosting providers not patching postfix fast enough or having a support person that chmodded the wrong thing on shared hosting server, customer with old wordpress install that was exploited to drop a webshell, etc.
> But you actually can run software on compromised hardware that can provide end to end encryption irrelevant on how thoroughly the system spies on you
Do you have any references? I'd like to read more.
If this were generally true, attempts to make trusted enclaves like Intel SGX (though flawed) would not need to exist.
No, because cloud providers are one subpeona, court order or warrant away from surveillance and exfiltration of your data without your knowledge.
If the DHS deems you a threat, then all proceedings can happen through secret courts and you'll be none the wiser to it happening, and you'll get a gag order on top of it.
Within my hacking community it was well know. We used to do that thing were you send out massive amounts of email with trigger words to cause problems. I think it created 0 problems.
It was an open secret. Well I guess at the time a conspiracy theory. One that has been proven true and it was much worse than we thought
>We are also always open for ideas but our focus is on firmware, BIOS, BUS or driver level attacks.
Anyone on WiFi AC or up are backdoored right now by NSA. All of them are compromised, no doubt in my mind. All the LTE. All the x86 hardware on the market. All of it.
If you aren't running fully free software, you're affected. And if you are a rare case running fully free software, you're an easy target for interdictions, since there's so few of you.
But, well, you can stop at your CPU's manufacturer website, where you will find ME/PSP, well documented as a backdoor. It will save you the trouble of verifying the hardware and firmware.
You might be thinking of me_cleaner[1], which removes most but not all of the ME blobs. This is unrelated to Libreboot though, it works on newer systems and is not needed when using Libreboot because the latter gets rid of the (very early versions of) the ME completely.
https://stikonas.eu/wordpress/2019/09/15/blobless-boot-with-...
SoCs will also have "pre-boot" code that runs before that:
> However, even one of their most ardent open-source advocates pushed back quite hard when I suggested they should share their pre-boot code. By pre-boot code, I’m not talking about the little ROM blob that gets run after reset to set up your peripherals so you can pull your bootloader from SD card or SSD. That part was a no-brainer to share. I’m talking about the code that gets run before the architecturally guaranteed “reset vector”. A number of software developers (and alarmingly, some security experts) believe that the life of a CPU begins at the reset vector. In fact, there’s often a significant body of code that gets executed on a CPU to set things up to meet the architectural guarantees of a hard reset – bringing all the registers to their reset state, tuning clock generators, gating peripherals, and so forth. Critically, chip makers heavily rely upon this pre-boot code to also patch all kinds of embarrassing silicon bugs, and to enforce binning rules.
It's a ROM. Read only.
https://www.fsf.org/news/freebios.html
"The BIOS was impossible to replace because it was stored in ROM: the only way to to put in a different BIOS was by replacing part of the hardware. In effect, the BIOS was itself hardware--and therefore didn't really count as software. It was like the program that (we can suppose) exists in the computer that (we can suppose) runs your watch or your microwave oven: since you can't install software on it, it may as well be circuits, not a computer at all."
Edit: >ROMs can still be backdoored, which is the point of this discussion.
You said it wasn't free, and when proven wrong, you moved the goalpost. Since I'm a wrongthinker who can only post once every hour or two on this site, I'm done discussing this with you. If you want to try to convince people that a 32K ROM is the same as IntelME, then you're not worth my time anyway.
Since we're editing: Free has many definitions. The FSF's on that one page doesn't take into account backdoored software; they would absolutely agree that backdoored ROMs aren't free. It removes user ownership over their computation. It's not "moving the goalposts" to point this out, especially when the entire point of the discussion is around backdoored software.
Remember when the NSA tools were dumped with their secret Windows exploits? WannaCry? North Korea picked that up and launched ransomware attacks. That's the sort of thing that's going to happen again with the newly published Intel backdoors. Just wait and see. Tim Cook is 100% vindicated this week about not adding intentional iPhone backdoors.
The Wifi Alliance has made some heinously bad choices that if you attributed to incompetence simply make no sense, they treat anyone who questions them with disdain and shoots down attempts to fix the mess they make. WPA3 was hilariously broken a month after getting rolled out.
> That's the sort of thing that's going to happen again with the newly published Intel backdoors.
This is not even remotely true. You have to read more than just the headlines.
> Anyone on WiFi AC or up are backdoored right now by NSA. All of them are compromised, no doubt in my mind. All the LTE. All the x86 hardware on the market. All of it.
Extraordinary claims require extraordinary evidence. Please provide some.
there is proof that NSA has been mass hacking WiFi since at least 2005. that batch of Snowden leaks came out one week after the Shadowbroker's first leak.
NSA programs SECONDDATE and BADDECISION were used to mass hack into WiFi routers in Iraq in 2005-2007. note the slides say NSA breached the WiFi routers of EVERY INTERNET CAFE IN IRAQ. that is the Collect-It-All scale we expect from NSA.
also note, NSA did this FROM THE SKY! SECONDDATE is a sensor installed in Cessna and low flying planes. NSA flew over every WiFi hotspot of every Internet cafe in Iraq and deployed the BADDECISION exploit to install implants on the WiFi routers to then mass surveil everyone.
no futher leaks about BADDECISION have come out. we dont know if it is a protocol attack or crypto exploit. we dont know if WiFi is still vulnerable to BADDECISION.
how much do you want to bet that NSA only used SECONDDATE and BADDECISION in Iraq and NOT back here at home in America?
how much would you bet that NSA is NOT bulk hacking WiFi routers of ENTIRE US CITIES FROM THE AIR?
consider how much cheaper and easier that would be now in 2020 compared to 2005?
> how much would you bet that NSA is NOT bulk hacking WiFi routers of ENTIRE US CITIES FROM THE AIR?
I would bet very good money that they are not doing this. If SECONDDATE has been around since 2005, and they are bulk installing it on millions of routers in the US, where are the people coming out saying "I found some NSA shit on my router"? Is there a _single_ example to support this?
https://m.startribune.com/mystery-surveillance-plane-that-ci...
https://minnesota.cbslocal.com/2015/06/02/secret-aerial-fbi-...
since at least 2014, the FBI has a secret air force of over 100 planes that fly constant circles over the biggest US cities.
what do you think FBI is doing? joy riding?
https://www.eff.org/deeplinks/2016/03/new-foia-documents-con...
those FBI planes are equipped with DRTBOX's--cell site simulators and wifi interception sensors.
in the TAO ANT Catalogue leaked by Snowden, it shows NSA SECONDDATE is manufactured by Harris.
Harris also makes DRTBOX, and Stingray.
wanna bet FBI is using DRTBOX in exactly the same way NSA used it in Iraq? wanna bet NSA is actually helping FBI run this little domestic program?
why would NSA and FBI surveill all US cities from the sky? because you dont need a warrant or even a subpoena. "reading the air" is free--it's public space with no expectation of privacy. and radio signals you emit through your phone or wifi router are also public space.
but what is FBI and NSA's endgame to run a real-time monitoring program over US cities?
back in 2004-2008 in Iraq, the Pentagon deployed something called GORGON STARE. it stiched together the video feeds from all drones and jets and satellites into a composite video watching entire cities.
https://longreads.com/2019/06/21/nothing-kept-me-up-at-night...
Gorgon Stare has come home to roost.
> Anyone on WiFi AC or up are backdoored right now by NSA. All of them are compromised, no doubt in my mind. All the LTE. All the x86 hardware on the market. All of it.
Still _zero_ evidence of any of this. Why not post some?
You also ignore questions like..
> If SECONDDATE has been around since 2005, and they are bulk installing it on millions of routers in the US, where are the people coming out saying "I found some NSA shit on my router"? Is there a _single_ example to support this?
> Just this week a 20GB dump of private Intel source was dumped with backdoors included. > That's the sort of thing that's going to happen again with the newly published Intel backdoors. >> This is not even remotely true. You have to read more than just the headlines.
> If SECONDDATE has been around since 2005, and they are bulk installing it on millions of routers in the US, where are the people coming out saying "I found some NSA shit on my router"? Is there a _single_ example to support this?
there are 2 sites which archive the complete Snowden leaks:
https://search.edwardsnowden.com/search?utf8=%E2%9C%93&q=spi...
https://snowdenarchive.cjfe.org/greenstone/cgi-bin/library.c...
It's not just corona crisis that's hurting western economies.
edit: why down vote? We can pretend negative SEO networks don't exist on a massive scale, but that wouldn't be truth.