We may have witnessed a NSA "Shotgiant" TAO-like action
blog.erratasec.com
blog.erratasec.com
A government is far more likely to oppress you, deny you rights, blackmail you for political reasons, etc. because it has the resources to do so.
I don't know... you're asserting as a fact here that one is more likely to be oppressed or blackmailed by the USG than by a criminal. But for blackmail alone there are thousands of criminal cases per year in the US, and an incalculable amount of "oppression" caused by criminals generally. What are the numbers for USG cases of blackmail each year? I guess they wouldn't be tallied... But I'd have to estimate that they're somewhat lower.
Asking for facts elides the far more nuanced question of whether it is good for the American Government Marketing Team to continue to operate a known blacksite when the American public is auditing security practices.
"as the NSA grows in both size and power..."
Do you consider this to be a foregone conclusion? Is this not something to be resisted or reversed?It's really, really easy to say this living in a place where the rule of law is reasonably robust. There are many parts of the world where this isn't the case.
The point of rule of law is supposed to be that the government is bound by the laws. Calling this "robust" with regard to the NSA is the equivalent of putting ones head in the sand....
There are even more parts of the world where the "rule of law" is what opresses people rather than criminals. Dictatorships, third world monarchies, banana republics etc. And sometimes, criminals and an opressive government go hand in hand, as in some latin american countries...
I will admit though that as an American it seems weird to have a Sultan of a small district in a larger parliamentary democracy. It would be like having a King of New Hampshire....
The first is "wow, did I just see them in action?".
The second is that journalists are consulting the wrong "experts" in situations like this. They think "cryptographers" are the experts in these Snowden leaks, but the real experts for most stories are incident responders, pentesters, reverse engineers, and even simple IT engineers.
As for being wrong, I'm sure if I could reveal more details, people might be able to debunk me. Sadly, I can't.
As HN's possibly-most strident torchbearer for the measurement of organizational dynamics, can you quantify this statement? How are your ranking?
Rob is saying that Huawei retains the commercial ability to log directly into their customer's equipment. That's the lede, not NSA!
Indeed, there's a recent legal case of a company selling stuff to Iran. The company said they weren't responsible, because it was resold by intermediaries. Yet, their support engineers were connecting in to manage the box.
The lede was really "here's what we saw", at least to the extent that we can reveal anything being bound by customer confidentiality agreements (which, frankly, isn't much, which kinda sucks for the reasder).
Can you people cut the fucking bullshit? Everyone here is speaking either "quantitatively" or in "probabilistic" terms, but I have yet to see research or actual discourse backing it up.
You're saying Huawei is more power hungry than the NSA?
EDIT:I'm sorry for being so abrasive.
Huawei accounts alone are already at risk of being abused by Huawei. We don't know if NSA has access to the accounts. But even if they did, it would still be more probable that Huawei's access would be abused than the NSA using Huawei's access.
(edited a few times for clarity)
http://www.spiegel.de/international/world/nsa-spied-on-chine...
1)We can assume NSA has access. 2)Is it not the NSA that wants to actively penetrate every single device in existence? https://firstlook.org/theintercept/document/2014/03/20/hunt-... 3)Is there any evidence that Huawei abuses their customers? Like, evidence, not CNN talking points.
Now. Is it more likely that the NSA will abuse them? That's a completely different question. Probability describes the function of an outcome based on a set of fixed parameters; in other words, you can estimate how often a coin flipped will land heads 10 times. The likelihood, however, is based on watching it come up heads 10 times, and would describe whether the coin was rigged or not.
Based on outcomes, is it likely the NSA is spying on customers using Huawei's tech support accounts? The only outcomes we can see is one report from a guy who says he saw a Huawei tech support account exfiltrating data that an American intelligence agency would like to have. It's really not enough data to make many conclusions. The only likelihood we can determine is that Huawei accounts are used to exfiltrate data from companies that American intelligence agencies would like.
Like someone else commented (could have been the OP?) another possible actor could be a CIA mole or some bribed/corrupt employee. Could be a rival company, or someone who wants to sell the information. We don't really know. We could assume the NSA is the only organization with an interest in hacking Huawei because this is the only report we've heard about such a thing, but that's speculating about unknowns.
There's really nothing about this action that screams NSA specifically; it's just being correlated with the story because the data appears to be useful for American intelligence. To say that there is no data that could be useful to both American intelligence and other parties would probably be a stretch. The only thing we do know for sure is that Huawei's accounts were used to exfiltrate data; who wants the data, and what for, is a mystery. But what is certain is that you should be afraid of your Huawei support accounts.
However, I urge you to read this. http://www.spiegel.de/international/world/nsa-spied-on-chine...
"We currently have good access and so much data that we don't know what to do with it," states one internal document. As justification for targeting the company, an NSA document claims that "many of our targets communicate over Huawei produced products, we want to make sure that we know how to exploit these products."
Attackers are not earthquakes.
If we assume that both NSA and Huawei are intelligent actors (spare us the jokes please) and that both NSA and Huawei have the option of abusing a certain power, then
P(I get pwned) = P(NSA wants to pwn me) + P(Huawei wants to pwn me) + P(other)
Either NSA or Huawei can pwn you with this power, or both. Even if they both elect not to it's still possible someone else can and will.P(A) >= P(A n B)
Always holds whether or not A and B are independent. A contains (A n B) therefore is always bigger.
The assumption being made is that the NSA can't abuse the Huawei access without Huawei being complicit. I.e. if NSA pwn me, Huawei gave them access, so actually it's the NSA and Huawei pwning me together.
P(NSA pwn me) = P(NSA pwn me because Huawei pwned me and gave them access) <= P(Huawei pwn me)
Yeah.
> The assumption being made is that the NSA can't abuse the Huawei access without Huawei being complicit.
I didn't understand that. That seems like a ridiculous assumption.
P(NSA abuses H's access) > P(someone abuses H's access),
which would be an example of the fallacy you cite, but
P(NSA abuses H's access) > P(H abuses H's access).
What we do have evidence for is NSA abusing Huawei - http://www.spiegel.de/international/world/nsa-spied-on-chine...
Conjunction fallacy only applies if A=A. Here, your first A is different than your second A, no? If A is "X will abuse account access, given the opportunity" then it matters who is X.
I have no information on what sort of access Huawei employees have but I assume at the very least they are not recruited specifically to spy on me and find 'individuals of interest'. People who are recruited to spy on individuals will have a completely different mindset to your average network engineer.
But either way it's a less than ideal situation, and too much power is at the fingertips of these employees.
Just a few years ago, Chinese hackers were caught hacking into the US for no reason. The fact of the matter is that Huawei, with its close connections to the Chinese Government, could be straight up responsible for this.
Remember, half of the western world have banned Huawei devices from their country.
http://www.bbc.com/news/technology-25417332
http://www.theregister.co.uk/2013/11/01/australian_confirms_...
http://online.wsj.com/news/articles/SB1000087239639044398290...
------------------
Keep up with the modern cyberwar people! The Chinese National Security Committee has already deployed "The Great Firewall of China" and banned the use of VPNs on their shores. HTTPS connections fail randomly in China and encryption is illegal.
Between the US and China, there is one country where people disappear for saying the wrong things on the internet.
I only see a difference between an opaque, unaccountable organization in the USA and an opaque, unaccountable organization in China when I look through a nationalistic lens.
They're less accountable than I would like, but they are accountable for their actions.
The US is just as much a direct threat to my countries economic interests as China. A pity my countries politicians are in Washington's pockets and are silent now when only two years ago they were yammering about the threat from Chinese government hackers and Huawei.
I smell propaganda in the air.
Not true. France does have an Intelligence Committee ("Délégation parlementaire au renseignement"). And there is a control organism like the FISA Courts ("Commission nationale de contrôle des interceptions de sécurité"); while legally their decisions are only consultative, in practice the government almost always respects them. And it denies between 1% and 2% of requests, whereas the FISA only denies 0.03%.
However I'm no expert, so I can't say how much power or independance they actually have.
You can read their annual reports (in French):
http://www.ladocumentationfrancaise.fr/rapports-publics/1440... http://www.assemblee-nationale.fr/connaissance/delegation_re...
EDIT: No offense, peterwwillis, but I tend to take arguments such as those from Americans with a grain of salt. Americans like to think that they are better than those nasty commies, but history says otherwise, what with the CIA transporting cocaine and overthrowing foreign governments, and the nsa actively carrying out MITM attacks.
Neither citizenry has any meaningful control over "their" spy agencies. They're not your favourite sports team that you need to defend. If you harbour any illusions of democratic control: the elected class is a lot smaller and a few degrees more stable than the candidate pool. Before they get access to power, candidates tend to renounce any action against the NSA.
http://www.politifact.com/truth-o-meter/article/2008/jul/14/...
But qualitative statements are of literally no value. It's all gut instinct. Of course you'd like to think that the US can take moral high ground over the Chinese.
What we're discussing is the subjective perception of both agencies. NSA has most of their programs exposed, as opposed to the PLA, and yet the public still gives NSA the benefit of the doubt. Now that's what I call freedom.
Going around like thieves in the night and breaking into places and steal stuff like common criminals is not exactly the conduct of someone accountable for their actions. I would actually say its the opposite behavior.
For example. You can become a Juniper Networks Certified Internet Expert but that doesn't mean you can get a job. People still need to trust you.
And a good spy is someone people trust.
Everybody is hacking these. You should not feel comfortable.
PLA Unit 61398: http://en.wikipedia.org/wiki/PLA_Unit_61398
Hacking the Dali Lama: http://www.telegraph.co.uk/news/worldnews/asia/china/7559103... and http://www.reuters.com/article/2013/08/12/net-us-tibet-cyber...
But embedding themselves inside the support infrastructure would give the NSA nearly unlimited access to much of the world. Huawei claims that a third of the Internet is running their devices. Almost all of it is under support contract. These means a Huawei support engineer, or a spy, can at any time reach out through cyberspace and take control of a third of the Internet hardware, located in data centers behind firewalls.
So the companies that use Huawei's products put the control ports behind their firewalls, but somehow are allowing unrestricted access through that firewall to/for Huawei's support mechanism?
Is that common?
It's the norm today that companies have firewall/VPN holes allowing support engineers from other companies to have access to their networks, to manage things as simple as the HVAC system, or things as complex as their entire routing infrastructure.
Throughout the world, most Huawei routers come with such support contracts.
Hello, Target breach. =)
1. Huawei has support contracts
2. Huawei needs to be able to interact with their hardware to execute those support contracts
3. Companies don't want to expose routers
4. Huawei routers "phone home" (i.e. query Huawei) and in this fashion allow Huawei support to establish a connection
The "phone home" model is one of the safer ones to my knowledge, if only because it allows a blanket "-A INPUT -j drop" rule. Outbound connections should be filtered, yes, but inbound is even more important.
I'm a little skeptical.
I wonder what they mean by "watched," because I doubt that they guessed the tty for reading or that the hacker joined a screen session. What is the likelihood that one would just "happen" to be staring at that server during an "incident."
The SQL query took 15 minutes to run. We saw it using 'ps'.
We then kept dumping their '.bash_history'.
As an alternative to dumping history, if your system has perl and strace and you want to watch a live ssh or bash session, I wrote a script that will do that. https://github.com/psypete/public-bin/blob/public-bin/src/sy...
export HISTSIZE=0?
And how do you know these were unmodified versions of netstat, who and ps that you ran?Do they have mtree in this OS?
I'm no security expert but this little story just sounds very unsophisticated given the seriousness you are attributing to it.
You can remotely connect to machines and analyze memory, commands, etc. It doesn't matter what TTY it was when you have full system access.
http://digital-forensics.sans.org/blog/2011/07/21/live-mem-f...
My interpretation was that after IDS had identified a particular host, they had tailed syslog (or the equivalent) on that host. The observation that they would have missed it if they hadn't been watching seems to imply that normally their logs wouldn't have retained the level of detail needed to see either the event or the deletion of the logs of the event.
I am somewhat skeptical as well.
Edit: finally found it, with some Googling. There are a lot of things with TAO as their TLA leading to a lot of false leads. TAO in this story means "Total Access Operations".
Edit 2: "tailored", not "total".
The capabilities the NSA and GCHQ have developed are scary enough in and of themselves but the sheer breadth and depth of what they have achieved is far more horrifying, If I was the CTO for a large multi-national or a foreign government I'm not even sure where I'd start protecting against them.
Has anyone else come up with a better reason?
The US government was publicly accusing the Chinese government of inserting backdoors in Huawei products, while at the same time seeking and exploiting vulnerabilities in Huawei products themselves.
Perhaps this was an attempt to cover tracks by pre-emptively blaming the Chinese government for backdoors installed by the US government, should these backdoors ever be discovered.
Personally I'm inclined to call Hanlon's razor on the hypocrisy of it all.
The US intelligence agencies can simultaneously act to protect the information security of American businesses by warning people of the vulnerability AND act to exploit the vulnerability for their own intelligence-gathering goals.
First, if its fear they're trying to spread, it's working. No way I'd ever use a Huawei device, ever.
Secondly, do you think a nuclear arms race in the middle east would be a good thing??
It seems like something that powerful would be of interest to any intelligence service (or group of any sort), anywhere.
Chinese intelligence might be interested in something simply because they (correctly or not) deduce that American intelligence will be interested in it.
However, it had both a subject and a timeframe that were peculiar. Googling the subject revealed news stories about it -- making it clear this was something the U.S. was interested in, but which would be no particular interest to anybody else.
The OP probably has a contractual duty to protect their client's identity & therefore can't take the risk that revealing more details would result in their client being identified.
That doesn't make sense.
The results of the query are probably private customer information, but the query itself has nothing to do with them (hopefully) and was simply the net the TLA was casting.
You've broken the seal by reporting that it was done at all and reporting the exact query doesn't change that.
OTOH, not reporting on what the actual query was makes me very skeptical about the whole thing.
By all means, obfuscate table names or whatever if there was a wildcard involve that matched customer defined elements (or whatever).
Here are rules I am suggesting.
1. The on-premise appliance should not be directly accessed from the network unless folks at the local environment enable contact.
2. Everything else, regarding services, should be loosely coupled and designed not to give significant access to either party over the other.
This sort of thing strikes me as an area where the industry is going to have to evolve. The danger of "we can connect to your systems" is becoming clearer to a larger section of the market.