I Hunt Sys Admins
firstlook.org
firstlook.org
Our target is using a network. We need access to that network. The sysadmin has the keys to the kingdom. The sysadmin uses Facebook. Through QUANTUM INSERT, we own anybody who uses Facebook. So we just need to figure out the IP address of the sysadmin.
If they use unencrypted telnet we just hack the account and grab the telnet server's IP address whitelist. With our resources and capabilities, this is so easy that someone should write a script to automate it and do it in bulk.
If they use SSH, we do it be listening to the connection. Even though we can't decrypt communications, we can figure out which IP addresses sysadmins are logging in from.
But it's not just us who are hacking routers. We can also hack the hackers ... and the rest is redacted. Shame. That would have been REALLY interesting.
https://en.wikipedia.org/wiki/Tailored_Access_Operations#QUA...
I went full RMS in 2007. Uncomfortable at first, but it's really the only way to stay unmonitored. Consider avoiding the gross anti-social bits of his personality, but don't throw the baby out with the bathwater.
[1] http://www.ibtimes.com/nsa-quantum-program-leaked-edward-sno...
A previous article, "How the NSA Plans to Infect ‘Millions’ of Computers with Malware" [0], linked to "a classified list" [1][2] of the various "QUANTUM*" programs entitled "There is More Than One Way to QUANTUM".
If I'm understanding your question correctly, the table in [1] and [2] should illustrate the (similarities and) differences.
[0]: https://firstlook.org/theintercept/article/2014/03/12/nsa-pl...
[1]: (TS/SI) https://s3.amazonaws.com/s3.documentcloud.org/documents/1076... (PDF)
[2]: (TS/SI) http://i.imgur.com/ZxVAnju.png (a screenshot of the slide in [1], for those who may prefer to avoid PDFs)
I am so sickened, angry, and ashamed.
It may be distasteful to you but it is the traditional work of spies in service to their country.
So it's worse in one way because of scale.
In general spies break laws, that's what's make them special. It's why it's "ok" to torture spies, or kill them, or hold them in a hole -- they're not considered soldiers, when (if) they're caught, they are treated as scum (or as we say these days, as terrorists).
I don't think anyone's saying: "Oh, we're mighty miffed you've stolen all our data. We'd be ok with you just coming over on foot, seducing a few, killing a few, and stealing our military and industrial secrets."
No-one's ok with that either. As for the American People, they are (rightfully) miffed because their so-called foreign intelligence services, that are supposed to break laws only abroad, are violating privacy on a scale that makes the Stasi look like child's play.
If a US agent seduced me and installed a back door on my computer to access the networks I have access to -- and I found out -- I'd be mighty upset about that, too. And I'd try to help counter intelligence get hold of the perpetrator. But that's not bloody likely to happen, is it?
Now, we pretty much know that any value target (network, and by extension admin) is reachable in a few keystrokes. The effort needed is minimal, to quote Sarah Connor: "No one is ever safe."
To my knowledge, it was only publically proven that the Russians use these tactics, but the US?
And now you are telling me that the NSA compromising the informational integrity of thousands of sysadmins is not surprising since they already used unethical TV-drama bullshit in the past?
This raises so many questions. Do you have examples of the NSA blackmailing a clerk?
I've always found it more likely that if any country has been proven to be using these tactics, then Occam's razor states that they all are (if they can afford to).
Intelligence agencies may be answerable to governments in theory, but human nature (as well as game theory) show that lack of independent oversight leads to manipulation of the rules. Doesn't matter what country you come from, if you can get away with something with little risk of detection, let alone retribution, you do.
This is why laws exist, and why it's inexcusable that any sector of any government should be immune to them.
This is a very strange belief. I mean I prefer living under US rule to living under Russian rule but the idea that the US has clean hands is laughable. I'm curious -- did you grow up inside the US? I've found that perceptions from inside the US reality-distortion bubble are very different from perceptions even a few hundred kilometres away.
I DO REALIZE NOW that this was of course a distorted picture of reality, which I think dawned on me around the time the illegal rendition/secret torture prison affair of the CIA came to light.
However, compared to the Americans, the Russians were never _too_ discrete about the rough practices of their intelligence agencies. This is what I was refering to: To the current state of my knowledge (which, admittedly I did not update with even a Google search) there are publically known instances of the Russians crushing private individuals by inserting HUMINT into their lives, whereas I don't know of any example involving an American service.
Maybe this is also why the Belgacom hack was so shocking to me. I had not previously thought that they (NSA GCHQ) would take apart some poor schmuck who happens to work at the wrong company just to gain access.
On a more general note, to me it just seems that bringing down the power of a governmental intelligence agency on an innocent bystander for the sake of a "shortcut" is unethical.
The problem with the Gentleman's guide is that (on purpose) it is hard to distinguish someone who disagrees with you, someone who is trolling (a little bit), and someone actively using it.
So common for wrongdoers to resort to such rationalization to justify their wrongdoings.
To help in snapping out of the cultic mindset, replace "country" with "organization". For instance, Scientologists had the same mindset with their Snow White Operation.
Clearly I work on the wrong systems. :(
And, immediately after having written the above, I suddenly recalled a few portions of the SF86[0] and, based upon their existence, I'm inclined to believe it happens much more than what I would initially have expected.
[0]: https://www.opm.gov/forms/pdf_fill/sf86.pdf (PDF)
Since majority of traffic logging capabilities of no such agency is coming from US itself and few close allies we collaborate on intelligence with* you can estimate that Sys Admin SSH technique is most useful in US itself and aforementioned close allies. Thus I would expect this to disproportionally affect Google as opposed to let's say Baidu.
* I am making an assumption here, please let me know if it is unwarranted.
Incidentally, those are areas where China has a strong economic development interest so you have another well funded government as a adversary that's known to target routers and such.
So far as admin SSH, once you reach a certain size you generally stop letting admins ssh in from random places and require VPNs (often with crypto tokens), if only because it gives you a easy chokepoint to disable access when you fire people. From what I've seen those most likely to use direct SSH or telnet are small companies (including regional/emerging telcos) that have a handful of people actually running things.
This is a organization that has nuclear submarines (see also SSN-23) outfitted to tap cables and runs intercept stations (Pine Gap, Menwith Hill, etc) around the world positioned for satcom coverage. If you can get most of what you want from a handful of colo rooms in allied countries then why bother with submarines, satcom stations, and satellites that spy on other satellites?
Clearly they feel that the value and scope of information gathered from intercepting communications that take place outside of (and not crossing) allied countries justifies the expense.
And, as we know, the NSA is actively collecting IPSec handshakes and has (at least in some cases, I'd love to see more info on this) the capability to crack session keys: https://firstlook.org/theintercept/document/2014/03/12/vpn-v...
I am completely torn between really wanting to work for the NSA because they have the ability to do really awesome analysis like that with huge amounts of data, and being deathly terrified. Nothing in that article should be a surprise to me, or anyone else who can half-guess the NSA's capabilities, but it is still shocking to read. For some reason, knowing that the NSA has information on literally everyone stored in some database isn't that frightening to me, but seeing specific details that they could have (and probably do have) is very scary.
How about wanting to help your country? I thought that's the main motivation behind for most people who join the NSA.
-Nietzsche
I believe there is a notable and recent case of how this actually plays out. What was it? Towden? Mowden?
See also Schindler's List for an example of how a contractor of the enemy can undermine it.
Schindler saved a thousand people through some pretty ballsy actions. But for scale, the battles of Stalingrad, Leningrad, and Moscow each had total casualty rates for both sides of 1-2 million people apiece.
Also, there is some indication that Schindler sabotaged the bomb parts he made so he saved more people than is immediately obvious.
I have not seen Schindler's List, but he also acted against and outside of the organization, rather than "move the needle," yes?
Sensible in that place means catching terrorists.
It's easier to justify injustices if you can rationalise it by saying you are saving lives.
Have we seriously entertained using "OSS" licenses that would prevent NSA & co. from using them?
I know Douglas Crockford has his "don't be evil" JSON license that got everybody's knickers in a twist. And I know OSI has a nice page on why field of use restrictions are bad.
However... I wonder if these pre-Snowden viewpoints credibly consider an organization that uses the software community's tools to conduct targeted attacks on that community. I mean, these documents suggest a much scarier attack on software developers than, say, putting the Linux kernel in a TiVo or whatever they changed in the GPLv3.
On the other hand, maybe FOU restrictions are still bad on principle. What do you all think?
It has happened as far as I can tell.
Now, assume you found out, via a leak of some of these classified documents, that they were using it -- in violation of your license -- and you decided to sue.
Having seen some of the excuses they've come up with before (and assuming that you have as well, which seems like a reasonable assumption), why wouldn't they simply argue that the software applications they use internally are classified, that disclosure of such would be detrimental to national security, and, because of that, your case should be thrown out (like they have argued so many other times)?
current mood: juche-licious
The only juche I know of is the north korean one[1], guessing this is just a random joke, just wanted to ask in case there's an alternate meaning I'm missing?
It sounds like international security is being run by 10 year old wannabe anonymous members.
Do the NSA employees really watch presentations such as this?
Yep. Replace "wannabe anonymous members" with "wannabe hardass" or "war hawk" and you have the essence of the US approach to international relations.
So while childish language for childish actions bothers me, so does the act of trying to class-up childish behavior with the well worn flavor of political rhetoric that acts like whatever bullshit getting peddled is reasonable and responsible.
I can't decide which I like less.
Probably, but that sounds like a bad idea to me.
I have seen the enemy and he is a 14 year old boy who's found his father's (admittedly very large and scary) gun.
"I have seen Ronald Reagan and he is a demented old man with no brain."
----
These "jokes" appear to belittle the people with real power, in the public's mind. It makes the people feel better. They make them appear harmless. It is a complete mistake to do this. It helps the powerful to spread these jokes, it does not help the people.
"oh he won't harm us, he's stupid. He wouldn't be evil, he has no brain. He wouldn't spy on the world, he's just a kid"
Include the team of shameless government managers, many who swore an oath to uphold and defend the constitution, turning this operation and all these databases over to a third party and these kids.
A form of institutionalized secrecy concealed and locked away behind a highly-trained, tightly-regimented, hierarchical, ideological organization of indoctrinated, unquestioning personnel (recruited directly from high school, with the incentive of financing an over-priced education that would otherwise be out of reach, which would serve as a catalyst for a career of employment in jobs that will not hire anyone without practical experience), all bristling with automatic weapons, mechanized artillery, naval artillery, supersonic airplanes, 500 lb laser-guided bombs, self-guiding nuclear weapons and a vast logistics infrastructure to keep it all running. An organization that doesn't obey laws. Indeed, an organization designed with the express purpose of overriding the laws of every other country on earth. But yes, let's act within the boundaries of civilian law to ask for permission to make this complex ask for permission before not asking for permission.
Oh wait, this thing without a name is funded by a civilian political system filled with politicians that lie to me and don't listen to me, who are bribed by large, faceless, private, for-profit corporations that don't pay taxes, and make all their money providing logistics and equipment to the personnel that guard the institutionalized secrecy which disinforms me of its own existence, and it's all paid for by my taxes, which I get thrown in jail for refusing to pay.
...BUT I SURRRE ASKED FOR IT!!! I GET WHAT I DESERRRVE! WHEEEEEEEEEEEEEE!!!
* disabling telnet on your router
* creating 4096-bit ssh keys
* enabling ssh key-based authentication only.
* setting ssh to non-standard ports
* enabling port knocking
* using _only_ tor to check webmail
* deleting your facebook account
Only to find out at the end, it's all been real and the people with the tin foil hats aren't really that far off base.
Basically, is there any way to know that you are being targeted?
edit: This might be of interest:
http://ask.wireshark.org/questions/8490/tcp-retransmission-i...
edit2: Perhaps a logging dns resolver (to track "strange" ip changes) coupled with an iptables rule that uses contrack and logs INVALID packets is a start?
It's interesting how this is boils down to existing malware strategies but with a how to. They're probably not going to type this stuff up in a wiki anymore going forward, shift to in-person training and word-of-mouth.
I like the NSA, because they show the world how stupid most computer users and especially the "geeks"are that do not see how ridicolous it is to show of a big apple logo on a speaker desk.
I-diots are always the problem.
So how long have you been an exclusive Lemote Yeelong user?
This is too many words for inherently trivial ideas that are all based on the magic assumed already to be in place and readily available. But mostly it's the tone and triviality of what's being discussed. It's all a script-kiddie level.
These are the questions that this brings up, which I find interesting.
What makes us think that techies in government departments are different from techies in other places?
What makes us think that pictures of kittens and internet memes are only acceptable for open source freedom hackers, and not people working for the government and private companies?
What makes us think that the internal messaging systems of secret organisations should not be trivial, human and sharing humour?
What makes us think that if someone thinks they are helping and protecting their country in their mind that they are morally wrong and have a criminal personality (James Bond Villain) because they are systematically abusing the law?
These guys make the "professional" hacker gangs look like a bunch of clueless amateurs.
The "simple" techniques are enabled by some very sophisticated backend stuff that is just taken for granted in these slides.