NSA targeting domestic computer systems in secret test
news.cnet.com
news.cnet.com
It's like the government detected a structural problem in bridges and then decides not to fix it because that could make it harder to destroy other countries' bridges.
You should simply assume that the government has always, always, always been technically capable enough to break into hotel rooms undetected.
Two years before Cody's talk, an unknown entity (assumed by local police to be Mossad), used a third party device to reprogram VingCard hotel door locks in the field as part of the assassination of Mahmoud Al-Mabhouh in Dubai.
The NSA did make changes to the S-boxes used in DES at the last minute, and would not comment on the nature of the changes. Many people speculate this was the introduction of a backdoor. Last year at RSA a speaker from the NSA revealed that the (now 35 year old) changes served two purposes: 1. it actually fixed a weakness they had found, but did not want to disclose the details of. 2. scared the Russians into not trusting the now hardened algorithm and instead relying on older systems that they had attacks against.
What is the NSA being paid to do?!
Like most large organizations, the government has tons of different projects going on at the same time. When they take on a new project, sometimes they use actual federal employees, sometimes they use contractors with federal oversight. Sometimes they use a mix of both feds and contractors. It usually depends on what kind of funding they can get approved. They do not often hire more people than they need for a particular project, because right now it's pretty hard to get money for anything, and most politicians remain grossly uninformed about the significance of anything having to do with computers.
It's a fact that an enormous amount of taxpayers' money that gets wasted each year, but pen testing vital SCADA systems across the U.S. doesn't seem like a waste of time to me. I know that the article mentioned nessus, netcat, and nmap, but the tools that are used in the security world don't matter nearly as much as the people who are using them. Also, do you think that the NSA is really going to tell you every single piece of software that they are using for penetration testing? They were merely giving examples.
The program as described in the article is something I can get behind. This is the first time I've said that about a federal program in as long as I can remember. But $91 million? Really?
Two thoughts come to mind. First, even when they get it right, they get it wrong. Second, I wonder how many other, non-disclosed, activities are being funded with that money.
...I just imagined my mom coming across such a "funny" error page and freaking out. Way to go, cnet!
Or are they talking about the old "drop a usb stick in the parking lot and hope some idiot plugs it into their control panel computer" approach?
In which case I say crazy-glue the usb ports and devices like mouse/keyboard into the system.
I don't know what they're saying, but yes, I assure you, there is crazy stuff that is one or two pivot hosts away from an Internet attacker.
Edit: CNET are having site issues, its not just this one page. @redtuxx Thanks for the link