Hoax email blast abused poor coding in FBI website
krebsonsecurity.com
krebsonsecurity.com
Email from FBI Looks Odd - https://news.ycombinator.com/item?id=29208276 - Nov 2021 (150 comments)
All in good fun, I suppose.
Could've been the funniest thing the internet had seen in years, & will likely not happen at that scale again for quite some time.
Anybody gets their hands on the private key, ex employee, compromised via hack, etc then everything will sail through.
Letterhead and perfect graphics and absolutely perfect text and whatnot? You could send mail literally anywhere. Media. White House. Obscure government... stuff/facilities. International contacts...? FVEY? Infinite rabbithole much. SO MANY social engineering possibilities, like this is absolutely mad.
And then... and then you're on the run for the rest of your life - not only against someone who can have you added to all the nonexistent facial recognition databases, but against unimpressed individuals who will specially go out of their way to find you regardless of where you are.
Alternatively, you can pop the balloon in a way that's very obviously stupid, make absolutely no demonstrative points about social engineering in the process, and leverage everyone's collective panic attack to ensure there's a widespread search for the sending email address that would be much more far-reaching than a news article ever would.
Genius.
US government entities, like any other entity, aren’t superhuman. Taking basic steps to protect and anonymise yourself would be sufficient.
Somehow every single one of the US' enemies manages to get around it -- from OBL through to the entire ISIS network.
The reality is that the FBI can't beat maths and has no leverage over services from foreign companies. i.e, a Russian VPN on a clean VM is probably enough to skirt the whole of the FBI.
US digital intelligence is, for all intents and purposes, a paper tiger in 2021. The whole thing is a farce to give the appearance of sophistication to act as a deterrent.
Just because this would be easier for them to have official backdoors doesn't mean they can't ever do anything given enough interest and funding behind it.
>eventually blaming "Russia" for every attack based on trivial IP geolocation
There's plenty of political reasons to state that (even if they were to know otherwise) and if they actually do have more accurate information on a different entity it could avoid showing their hand if they just attribute it incorrectly.
>The reality is that the FBI can't beat maths and has no leverage over services from foreign companies. i.e, a Russian VPN on a clean VM is probably enough to skirt the whole of the FBI.
Probably can't beat math, but if the FBI is running the supposed "Russian VPN" that gives them lots of information. You only have to make one mistake and you could potentially out yourself. (Assuming you don't have further layers to fall back on)
>US digital intelligence is, for all intents and purposes, a paper tiger in 2021. The whole thing is a farce to give the appearance of sophistication to act as a deterrent.
Are you willing to bet your life that this is the case?
Considering there are random "mom and pop" scam agencies across South Asia and the Caribbean stealing billions of dollars from Americans annually while posing as the FBI and IRS and nothing whatsoever happens to them I'd wager that it's quite unlikely the FBI has the ability to do much of anything regardless of interest and funding.
> There's plenty of political reasons to state that (even if they were to know otherwise) and if they actually do have more accurate information on a different entity it could avoid showing their hand if they just attribute it incorrectly.
This is suggesting there is a 4D chess move at play, which is a straying a bit too far for me. The only other possibility here is if [Russia, China, NK, Iran] know the US is not able or willing to enforce a deterrence and they don't even bother hiding.
> but if the FBI is running the supposed "Russian VPN" that gives them lots of information
That's extremely unlikely to the point where if there was a complex covert operation like this they wouldn't burn exposing it on outing an independent malicious actor.
> Are you willing to bet your life that this is the case?
There are entire groups that have literally bet their lives on this and are still very much alive. If the US government was as sophisticated as you're suggesting, I don't think they'd still be driving patrols around the levantine desert trying to find ISIS members or have a giant fentanyl issue plaguing the country.
I really can't make sense of the idea that the US has all this power at their disposal but completely refuses to use it against actual organised groups targeting the US and Americans, but will somehow put all their cards on the table when Johnny from Idaho exploits a mail server.
That is shocking. What must the internal culture be like for such an idea to even be a possibility?
There were some genuinely good, smart people working there, but the culture was such that I’d be very surprised if they shipped a working product in 5 years time. If they did ship it, it would be an awful thing to behold.
I don’t know how to fix this issue. But from what I’ve seen and heard, the best minds (other than the rare altruist) stay in the private sector. It pays better, and there’s just so much less BS to deal with.
I worked on an application a number of years ago where it was trying to load all the comments and details about an internal bug tracker into memory. It must have worked fine at first, but after time it was a POS.
If the database fits onto client hard drive and the modifications are rare, preloading everything is almost always better.
If you have a dynamically changing system such as bug tracker, it is still possible to go fully local, but that would require considerable cooperation from server side. When the back-end does not have a fast, efficient API for sending diffs, you may get stuck waiting for it to be implemented. But that's a purely organizational problem.
Of course, all of above applies to actually saving data to permanent storage. Storing everything in memory is a sin by itself.
"Hard discount" stores like Aldi are supposed to have <1500 SKUs, for example.
Now the user will immediately get to see the full item and will be able to page through the results much more quickly.
I've definitely had cases where I had to process the data before sending it to the client, but I've also sent absurd amounts of data and rendered it client side. In fact, I think sending data embedded in HTML to the client is rarely a good idea, and once you've adopted that mindset, apps can look very different.
* Make it easier to fire incompetent people. A job that's in the service of the people should not be a cozy "I'm now set for life" type of gig.
* Pay semi-market rates.
* Stop going for the lowest bidder for contractors.
Yes, my point exactly. I think it's cheaper to pay people a reasonable salary and less job security. Otherwise it just ends up being a lot of dead weight throughout the organization. This dead weight leads to low productivity, which in turn e.g. leads the management to bring on expensive consultants to try and fix it.
I remember when healthcare.gov was launched and the clusterfuck it was, and then a much of FAANG level employees had to quickly go and clean it up as charity.
Same reasons judges are paid a lot
Private sector unions (making them impossible to fire)
Nepotism
Layers and layers of bureaucracy
You'd think an agency as important as the FBI would verify who is working on their systems, but probably no one did.
Why?
The upper echelons of these federal law enforcement and intelligence agencies are universally political animals with names suffixed by III and IV that instinctually perceive anything as even vaguely technical as far beneath them. The only time something like the security of a network becomes a priority for these people is when it causes them embarrassment. At all other times the operation of these systems is a budget item that gets farmed out according to the prevailing political prerogatives of the day; actual competence being well down on the list of priorities.
Or the second: https://www.newsweek.com/fbis-expensive-sentinel-computer-sy...
I have been trying to get US government contracts for years through my company, including offering $0, $1 and other guaranteed low price bids to try to get the work. We exceed every requirement in the RFPs. We are recognized as the best in the nation in our service area and have 200+ full time employees. Crickets.
In which case I could totally see how it's part of the culture, having worked in orgs like this:
- A person brings up this concern
- "Uh sweetie, I think IBM wouldn't make a mistake like that"
The security focused mindset we have today in web development just wasn't developed to that level whenever this thing was written. It's kinda a case in point for replacing websites entirely from time to time.
Brutal.
I appreciate that krebs give an explicit source to the claim - it shows journalistic integrity.
Also, on a side note.. this is our gov, this is how they operate. I worked for a short period on a project with the state government and it was miserable. The culture is truly suffocating. I've warned many, gov jobs is where your career goes to die; there is a stigma whenever you go anywhere else even if no one says it
Miserable as in nothing ever got done, even after requesting creds (once i got certified) they dragged their feet for 3 months. It was the worst gig.
The FBI's helpdesk # reportedly got swamped and this probably wasted hundreds if not thousands of man-hours of agents getting panicked calls from organizations they actually work with.
I'm guessing this wasted hundreds of thousands of man-hours of time at organizations around the globe as people tried to figure out WTF was going on. I'd bet a lot of people told their bosses it was obvious bullshit and were told to call a local FBI office to confirm anyway "just in case."
The person who exploited this could have done a proper vulnerability disclosure.
Or sent a genuinely funny/clever message along the lines of "We were lying about the aliens all along, press conference to be held at DoJ HQ this Sunday, 7:15AM" to a couple of news stations.
Whoever did this came across the vulnerability and decided to be an asshole about it.
If that proper vulnerability disclosure happens to land on the desk of some irrational apparatchik at the FBI that doesn't like your brand of facebook posts or doesn't want to be exposed as an incompetent they won't hesitate to open a file on you and dispatch a cadre of life ruining agents. And before you say "but if it's done properly..." I say hire a good Beltway lawyer before you say a mumbling word because you don't know what 'properly' is or if it even exists.
Anyone know what the beef is? Do they think he's incompetent?
If you want a closer approximation of the full source, outerHTML might also be better.
I've also seen "new XMLSerializer().serializeToString(document)" suggested. That seems to give the most complete source, but I've also read that it might have problems with things that need escaping. I have no experience with that approach because for what I needed the first thing I found when Googling, document.documentElement.innerHTML, gave me what I needed.
One more thing to consider. All of the above I'd expect give you source that would produce the currently displayed page including any modifications that were made after loading by JavaScript (which is probably what you'd want for cheating on a test so is fine). I'm not sure that is the same as what "view source" gives--does it give the current page or the page as it came over the wire?
She said she had the phone installed on the kitchen wall around the time her grandson was born. He was 27. I told her she could replace it for less than 20 bucks and she said no thank you she liked this phone very much.
She wasn't calling about the bill, she just wanted to get her e-mail working.
She spent upwards of $3,000 on that phone in rental fees alone. She might be still paying it today for all I know.
Not saying the method is violence per se, but rather that there are a lot of alternatives to finding vulnerabilities and backdoors.
Other engineers can reasonably design around known variability in the environment. You can engineer a 4x safety margin in a bridge. No such concreteness exists for programs.
When we make a product, we really have no idea what the landscape of computing will look like in the future. Even the projects that are less than five years old that I’ve worked on have had so much grafted onto them that I barely recognize what I had originally wrote for it. My hunch is that the email system is basically a “legacy app” that had more and more jammed into it as time went on. The prudent thing to do would have been to go with a new provider, but that is extremely expensive compared to jamming new features like that script into it.
In this scenario, how would a developer be held accountable? Would telling a judge “I really didn’t want to write this code but the client demanded these changes” be a viable defense?
I'd say it depends on why the actual problem is there.
Did a developer get strong armed into ignoring any potential problems by the management because it was necessary to ship software to meet some made up deadline? I don't think the blame lies with the developer, perhaps more so with the management.
Did a junior developer get tasked with getting something done with ancient technologies that just refuse to cooperate with them properly, without any processes being in place to catch these sorts of issues? I don't think the blame lies entirely with the developer, perhaps more so with the overall environment and the lack of testing, QA and other processes.
Did some developer just not care? Then the blame probably lies with the developer, but if that's the case, why are they even employed in the org, and why wasn't their work caught in one way or another before hitting prod?
Honestly, if we introduce full criminal responsibility for the code that individual contributors write, we'll end up with the same situation that happens in countries that choose to make their doctors have criminal responsibility for procedures gone wrong - they'll simply choose to work in other countries where they're not faced with such circumstances.
Also, the next zero day in Windows means Nadella should be tossed out of Redmond. It is very critical, no?
And, yes, it would be time for some senior folks to reflect on their continued helmsmanship.
EDIT: All right, “Dupe” might be the wrong word; “Related to the same newsworthy event” might be better.
Not dupes.