GCHQ Used Fake LinkedIn Pages to Target Engineers (2013)
spiegel.de
spiegel.de
They would never use it to give their own industry insider information.
</sarcasm>
I thought that language or cultural barriers prevented those companies from succeeding or that those countries suppressed US companies because they are evil and want to control their population.
Today I think I'm more realistic about that. All sides want to control their population (US included), and no one wants foreign countries to access data of their citizens.
That's why there's so much redundancy. China would never allow Facebook to succeed in their market and the US wouldn't allow Sina Weibo, Renren or Vkontakte to succeed on their market.
The US wouldn't ban those companies outright (like China did), but there would be a media campaign against them and the COMMUNIST THREAT that those companies pose to the minds of our innocent children in the west, which basically would have the same effect.
Put your mobile phone permanently in flight mode and go back to relying on landlines/email.
The alternative choice to this is accepting the fact that "GCHQ now wants to turn the mobile web into an all-seeing surveillance machine."
The alternative is most definitely not landlines/email. We can and must demand free verifiably-secure hardware and software, including for our mobile phones. There is ABSOLUTELY NO REASON why the mobile web must be a surveillance machine.
I agree 100%. Open source software + hardware + FIRMWARE must be part of any long-term solution. "Long-term" because short-term, governments won't let that happen (they will always work with/help corporations to keep circulating products with backdoors in proprietary/closed-source firmware).
I know much of the reaction to that is going to be cynicism about what is possible there, but I'm pretty sure that cynicism is one of the bigger stumbling blocks.
If you want secure communications, the transport layer (3G, internet, land lines, postal, talking to people) should always be untrusted and cryptography should be used.
However you can only trust one method for the long term which is a pre-shared manual one time pad. Other methods are proven to be somewhat variable in their implementation and ability to remain secure.
https://stallman.org/stallman-computing.html
Search for wget.
That is if the routers inside your own network can be trusted. Paranoid turtles, all the way down.
Maybe run separate VMs for casual browsing, work, entertainment, etc? Like Qubes does http://qubes-os.org/trac
Also, even if you solve the political problem in one country, you still need to worry about external and criminal threats that operate with the same tradecraft.
If I understand things correctly, it's not claimed that GHCQ made fake profiles or exploited their platform. It's possible that whoever made the statement didn't really understand MITM, but this kind of reads like another one of the usual carefully worded non-denials.
Full paragraph in the article:
When contacted, LinkedIn stated that the company takes the privacy and security of its members "very seriously" and "does not sanction the creation or use of fake LinkedIn profiles or the exploitation of its platform for the purposes alleged in this report." "To be clear," the company continued, "LinkedIn would not authorize such activity for any purpose." The company stated it "was not notified of the alleged activity."
EDIT: Because the ability to MITM SSL sessions is a lot more scary to me than the willingness to MITM non-SSL sessions.
If I disable it again, those pages work again...
Governments can MITM without any problems.
Also, one thing I'm pretty confident about, is that if GCHQ is behind any of these certs they wouldn't go labeling it as "UK Government - GCHQ". So presumably I'm just trusting Microsoft that when these certs get pushed out as part of Windows they are who they say they are...
http://googleonlinesecurity.blogspot.com.au/2013/01/enhancin... https://blog.torproject.org/blog/detecting-certificate-autho... http://www.chromium.org/Home/chromium-security/root-ca-polic...
How many of them are not amenable to some government somewhere? 0.
And how many would GCHQ have to compromise to get deniable MITM? 1.
The Apple SSL bug seemed overblown (from a government perspective) for that reason, and unlikely to be a government effort. Exploiting a CA seems significantly easier than embedding bugs in specific platforms. I suppose they might do both, but I doubt their abilities were reduced after it was patched.
I'm still waiting for the blackmail revelations. Though I doubt NSA & friends would be that stupid to make slides about that little objective.
There you go! Track all the phone users, and anyone who doesn't have one, and is therefore untracked, is probably a terrorist!
Actually that's not far-fetched. I do recall, vaguely, some old indymedia article about a European political activist being arrested, with the fact they left their phone at home before turning up at a meeting being part of the grounds for suspicion. Indymedia stories tend to be rather ephemeral and hard to search so providing actual details is somewhat troublesome...
This is how I would scare people if I were paid by the NSA.
So is HN. And it's ancient. Any ideas of possible vectors to attack HN-loving engineers?
[1] https://src.chromium.org/viewvc/chrome/trunk/src/net/http/tr...
[2] https://github.com/mozilla/gecko-dev/blob/master/security/ma...
Trusting the SSL certs is another thing though.
It's Totalitarianism, nothing more or less.
Obviously september 11th 2001 happened and to see your colleagues actually see that as job security and a way to sell more weapons and celebrate that turned it for me. I started to question the ethics of what I was doing and decided it was best that I left. I bailed one afternoon, gave no notice and spent three months selling Sun kit on ebay before taking a job at a web agency selling whiskey and houses instead.
Most people didn't get that "moment" and are still prisoners of the inane propaganda. The same is true of those at GCHQ.
My children are doing GCHQ sponsored mathematics work (cryptography challenges) at the age of 10 probably in the vain hope that they will eventually see this as normal and be recruited before they have a chance to question the ethics of it all.
What? Care to elaborate? (I'm American if that explains why I have no idea what you are referring to)
There was a lot of publicity and propaganda and hype around Alan Turing and cyber-security over the last few years in the UK media. This drove a whole codebreaking fascination thing with mathematics.
So not wishing to miss out on all the action, a project was started called The Enigma Project which features basic codebreaking challenges (basic substitution ciphers, OTP etc) aimed at primary school children. This was started by Simon Singh / Cambridge University after good old Si released a book called The Code Book after which he wanted to drum up publicity rapidly. No other reason.
So after a year or so of neglect these sheets work their way into "photocopy circulation" amongst schools in the UK as part of the typical "teachers don't give a shit and just want to hand out worksheets" culture that appeared.
Obviously any other material that could be assembled cheaply was chucked on the back. Turns out there's a couple of sheets plainly marked from GCHQ in there as well as "additional exercises". Rather interesting as they are above what you'd consider appropriate for that age (prime factorisation and rapid factorisation techniques etc). Very odd!
Now this in itself is pretty null and void but it leads into the culture which I experienced where we were asked in secondary school mathematics to enter various "challenges" to play off against other schools. I was pretty good at mathematics (at GCSE and A-level) and did well on these challenges but was approached after this by people recruiting for SIGINT rather than go to university. Other people who did well were similarly propositioned. I impolitely declined and relaxed into a life of electrical engineering, pizza and beer which I thoroughly don't regret.
I'm worried my children will be similarly filtered out and recruited to be honest.