Sysadmins see evidence that they have been hacked by GCHQ [video]
spiegel.de
spiegel.de
I think here on HN and other tech and privacy forums we understand what is happening. Unless there is a reporting like this, it will be a bit harder to engage a wide audience. Telling the proverbial grandma about "PRISM" or "they are listening to everyone" is not going to quite work. What works is to do this -- showing one particular grandma with a name, address, life story and showing how maybe her recipe for baking cookies is now logged in Utah's NSA's headquarters in room 5B, on storage node 18Z and so on.
I'm only in support of this video because so much other evidence has been delivered on this topic before this vid came along.
[1] http://www.nytimes.com/2012/08/23/opinion/the-national-secur...
[2] https://en.wikipedia.org/wiki/Laura_Poitras#Government_surve...
That they tend to be run by technically incompetent people, using expensive black box hardware they don't understand, and with multiple levels of indirection between end user and the Internet (transponders, ground stations, facilities, virtual network operators, ...) makes it all much more vulnerable.
Combine that with price sensitivity (so subsidized government stuff can be cheaper, and legal expenses unacceptable), and a highly regulated environment (ITAR + various spectrum licensing and launch regimes), and it's a perfect storm.
The only more interesting target would be "satellite comms network dedicated to high value international payments".
(Disclaimer: I started/ran a satellite communications and wireless provider, and worked for or with a bunch of others.)
Which means you are under active and targeted surveillance. Great to see you put encryption contact info in your profile.
You might notice some discussion there of what counts as a country.
Came to say that as well. I don't know the satellite internet business market, but it's obvious that if it's used by individuals in the middle east, it will be an obvious target.
Having a mobile internet connexion in africa can easily draw attention...
Documents: http://spiegel.de/media/media-34756.pdf http://spiegel.de/media/media-34757.pdf http://spiegel.de/media/media-34758.pdf
Sadly Der Spiegel is not providing https, even if we now know that this means putting your readers security at stake.
This is The Intercept article on this (https, yay!): https://firstlook.org/theintercept/2014/09/14/nsa-stellar/
I also don't care if Germans are our "allies." 9 months ago Russia and Ukraine were best friends, now Russian soldiers are blowing away Ukranian civilians with total impunity. Shit changes. Shit gets real quick. Being at a information disadvantage can lead to serious consquences.
I think we live in a time too used to peace and as we can see from recent events, that time is now over. The far left's obsession with pacifism and the far right's obsession with isolationism are just impractical. This just causes conflicts that need to happen to be put away and ignored which leads to larger conflicts later. For example, the US and Iraq should have worked together when ISIS took Fallujah MONTHS AGO. The US should not have caved into pressure from the EU and Russia to not take out Assad. Instead, we chose the path of politics and sticking our head in the sand and an entire region just became destabilized. On top of it, petty dictators like Putin see our weakness and use it against us by invading his neighbors, knowing he'll only receive a slap on the wrist.
Downvote away, but we need SIGINT, now more than ever.
Well, that's what I'd do anyway.
It goes like this - Stellar gets offered a big hosting contract that they aren't going to turn away. They don't do any due diligence on this new customer, and if they did, they probably hit a couple of USG Cayman Islands dead-ends anyway. They install this company's servers inside their own network.
Boom... headshot.
A prime example of how this thinking can be applied is the TrueCrypt fiasco. Ask yourself: If you were the group leader at the NSA tasked with TrueCrypt, would you have your undelings doxx the authors? Would you then try to lean on the authors?
If I was a group leader at the NSA, I certainly would.
Indeed, but I would add that these people are more than just savvy. Many of these people have been picked out because they are smarter than the average bear. They've also be brain-washed into the mold to believe that if you aren't inside, then you are the enemy, or the friend of my enemy, or a potential "task".
Many of these guys (and girls) are converts - young hackers who have been caught hacking and have been given the option to serve jail time or join the cause. Its an easy sell to young impressionable minds who want to be a hacking James Bond.
More importantly, these guys are hacking targets across the world with a remit; a licence to hack if you will. If you or I go out hacking random companies for fun and profit, we'll get a 5am dawnraid knock-knock visit and spend a couple of years 'rooming with Bubba'.
These guys can do what they want without the fear or stress of that 'Sword of Damocles' hanging over their heads. They have a free reign, and they are smart. They also have the feeling that what they are doing is right. That makes them way more dangerous than you or me.
Thanks the hat tip nevertheless. I grew up in a government security type environment. These things rub off on the kids. Somehow you learn to evaluate risk, locations and people very quickly in this kind of environment. I guess it is useful in some ways. It also makes you a constant analyst, which tires the brain somewhat, but you see things that others don't.
I could be wrong but I thought Ali had an extremely guilty reaction. As if he was waiting for the reporter to accuse him of being an NSA asset. Which he very well may be.
Let's keep personal attacks down and talk about the issue at hand rather than go for character assassination.
I actually thought the same. I kept thinking the whole point of the clip would be that they would see their own names and how they had been recruited. I, too, thought 'tasked' meant bribed/coerced.
... that's not character assassination, that's just like my opinion, man.
In intelligence communities of different countries they use jargon to mean specific things (just like lawyer like to use Latin words). Except in this case it is usually English words that have specified (overloaded) meaning that might or might not retain a relation to the colloquial meaning.
But if we accept the translation and explanation from the video. Then "tasking" meaning to target specifically (focus on on detail so to speak). That is what I got from it.
Although you'd probably start by developing a list of targets, then learning (open source, government records, etc.) as much as possible, then maybe task someone with observing or recruiting.
And using TAO?
This isn't crazy movie stuff, this is exactly how people are recruited.
Because our government may not have that same level of access/power over whatever the Chinese version of Android is.
I hope that now sysadmins from all over the world know that they are subject to NSA surveillance. If you are a sysadmin, please read:
https://firstlook.org/theintercept/2014/03/20/inside-nsa-sec...
You could easily be a target for TAO:
http://www.spiegel.de/international/world/catalog-reveals-ns... https://news.ycombinator.com/item?id=6979457
If you are a sysadmin, they are after YOU.
Probably the best way to describe this, is to compare security and pro sports teams. From what I have read, the NSA is a top tear team winning championships across the globe, with billions in research and development, and thousands of highly trained athletes, living and breathing this day in and day out. Yet, they are matched up against a local beer league who likes to play casually Thursday nights. Who do you think is going to win?
Go read the "A Look at Targeted Attacks Through the Lense of an NGO" [3] paper, then put yourself in their shoes. Think about the IT resources a small NGO with 30-50 employees has. Maybe they have a sysadmin and a helpdesk guy. They are dead meat. The threats are so vast, spear phishing, target malware via MITM attacks, etc. It almost seems hopeless. But it is not just the NSA at the top of the heap, you have lots of foreign governments, which have direct access to your playing field via the internet.
Think about the resources that Google, Facebook, and Apple throw at security, then you see something like Operation Aurora [4, 5]. What chance does an ISP or small business have? None. Personally, it just seems like the entire model is broken. Yet, nothing seems to change, in that we are all just waiting for the next zero day to drop, and the cycle continues. All it takes is one targeted zero day addressed to a normal employee, the attackers gain access to the network, then move laterally [6, 7]. The odds are further stacked, in that you have a top tear team against a targeted employee, who doesn't even know the game.
ps. sorry for the tone of this
[1] https://firstlook.org/theintercept/2014/03/20/inside-nsa-sec...
[2] http://www.theguardian.com/world/2014/aug/13/snowden-nsa-syr...
[3] http://www.mpi-sws.org/~stevens/pubs/sec14.pdf
[4] http://www.wired.com/2010/01/google-hack-attack/
[5] http://en.wikipedia.org/wiki/Operation_Aurora
[6] http://g0s.org/wp-content/uploads/2013/downloads/Inside_Repo...
[7] http://intelreport.mandiant.com/Mandiant_APT1_Report.pdf
Look at Google, Apple or Facebook. There is just sooooo much different attack space. Thousand of servers, thousand of employees that could be bribed, hundreds of third-party people they rely on (Content Delivery, ISPs, Colocations/Datacenters, Hardware suppliers....). A single NSA-controlled computer in your network is a starting point to take over the rest of the network.
/edit: Even if they straight up tell them they have a "bug" in their network, how the hell would they ever find it? I could be a switch, it could be a VoIP phone, it might have been a software-package that was injected with malicious code _while_ downloading, it could be a RaspberryPi camouflaged as some other device, it could be a employees computer, it could be a network-printer, it could be a hijaked VPN account. It could be anything. I just don't see how there is any way to protect yourself against this, even with a dedicated security team and a big budget.
A great point but I would argue that there might be enough "n" at a company with only, say, 500 employees.
On a different note, I'm not sure the best angle of attack is to bribe anyone. After all someone bribed is also someone who can disclose info. Or could even get hacked themselves whereby someone else would discover that they are cooperating and release or expose that fact. For many reasons. Could be a roommate, an angry spouse or girlfriend etc. And after all a bribe is also money so there is a money trail if large enough and/or not paid in cash. And some people just like to talk and brag.
Secrecy wise, the less people that they were to involve the less chance of a leak. At least one reason that top secret programs have limited people that even know they are going on, right?
The NSA/FBI/DEA can and have used tactics like extortion (e.g. for planted drugs, money laundering charges etc.) to make people cooperate. It's like a bribe just without the risk of exposing.
Would you cite sources for that?
If any of the three-letter agencies (or, for that matter, any big govt agency) uses these kinds of tactic, then there is no reason at all to believe other branches of govt refrain from doing the same shit.
Once, a long time ago, that last sentence would make me a tinfoil-hat-wearer... sad that this is not the case anymore.
They can easily plant their own agents inside the company as employees.
("undercover agent" getting a job at the company like a regular person)
I'd be very very surprised if they already haven't done it.
1., They are willing to sell you intel for money.
2., You can now blackmail them as they accepted a bribe.
Point 2 is the reason you should never accept bribes when doing business, especially abroad and everyone tells you "it's normal". they're just waiting for a foreigner to get exposed, take your passport and have fun with you. see Russia, etc.
No need to be Macchiavelli.
> is to find something they are really really embarrassed about
I don't think NSA needs to employ high school level tactics.
If they want to pin something, they will. True or not.
That's not a bribe.
Learn the difference between strong-arm tactics such as blackmail and bribes. Two completely different approaches.
Patronising dickhead.
Link me to a case where NSA/CIA/FBI blackmailed AND worked with / gave money to an individual at the same time.
The CIA typically recruit through a combination of carrot and stick - i.e. bribery and blackmail.
"Hey dude, let me tell you about this sweet slightly dodgy thing I can get you in on."
... ...
"Oh by the way, I hope you like all that money you made. I work for the CIA. Work with us or go to jail, your call."
More commonly than not it's not about self-preservation, rather protection of loved ones - read up on Operation Mockingbird, which was driven pretty much entirely on this basis - luring journalists in with a subtle bribe hook, then using it to blackmail them.
Did you read anything I posted? In what instance was somebody bribed AND blackmailed at the same time during the Mockingbird?
Please go back to Wikipedia and try again.
Some might dispute that, but I think you're exactly right in a "big picture" view.
E.g. lets pick on Microsoft because it's such an easy target. Bill Gates announced his company wide security effort in 2002. Yes, twelve years ago. And while security at Microsoft has gotten better, I think Microsoft still has plenty to be ashamed of.
It's the same everywhere else. There's a forest fire raging and people are walking around with super soakers trying to put out spot fires.
Our approach is therefore totally flawed. We need some big picture rethinking of how we are implementing security.
It's just a whole different world.
EDIT: thanks Mr krapp.
The real threat is pranksters, disgruntled employees and most importantly criminal enterprises who need to weigh their targets. The relative security of our credit cards in a digital world speaks to the measured success of small time security.
I agree with you, though, that the real threat is not the NSA for most of us. But many of us do have users, and do actually value the privacy of our users (and for those of us in EU countries, we have a legal obligation to safeguard the personally identifiable data we store) and so it is still of interest to learn about what we can do.
For many of us it is also a matter of principle and/or political viewpoints that this surveillance needs to be countered and stopped. If the public is prepared to remain complicit by not voting out the people who continue to deny the existence of these programs and/or continue to refuse to stop them, then we need to seek other alternatives. (Note that I explicitly avoided singling out the US in this part, because I live in the UK: GCHQ is as large and a problem as the NSA, yet the British public appears to not care at all)
Being in a different country didn't help Kimdotcom.
GCHQ is a different problem to the NSA - they appear to try to obey the law but have weak oversight and scrutiny. There are at least some politicians who don't want to give GCHQ more power and who think they need better regulation.
Most of us are not in lines of business that are so easy to cook up excuses for raids about, nor have a past that makes it so easy to try to make us come out looking like Bond villains.
I'm not saying there are not plenty of cases where "just taking the servers" is a viable option. But that does not mean there aren't a lot of us for whom protecting against NSA to the extent feasible is an option that is not ever likely to result in someone raiding our servers.
> GCHQ is a different problem to the NSA - they appear to try to obey the law but have weak oversight and scrutiny
Arguably the NSA tries to come down on the right side of the law too. It's just that they do so by creatively exploiting every available loophole and making use of every possible discretion of their lawyers and lax oversight as well.
I'm not so sure GCHQ wouldn't do the same if their oversight wasn't such a joke that they were found to boast about how weak it is in one of the NSA documents.
Unless they want to use your hardware to attack someone else or building a wide dragnet or want to steal corporate secrets or ...
This is infeasible for a lot of organizations, unfortunately. And it also becomes much more difficult if your adversary has full control of your DNS servers or can perform a man-in-the-middle due to their backbone Internet access. Something like an Evilgrade (https://github.com/infobyte/evilgrade) attack conducted via an ISP MitM is very hard to detect and prevent, and I suspect NSA uses Evilgrade-like tactics frequently. And if you live in the US it's game over by default, since they can legally send people onsite to compromise you.
If ^^that^^ is true, then I'd argue your first sentence is not. There is simply no way to truly protect yourself if the gear manufacturers are complicit.
Edit: oh, you'd have to import the Chinese one yourself into the US to make sure it doesn't get its firmware "updated" somewhere in the suppliers chain.
Remember the pictures of Cisco gear allegedly intercepted by the NSA on its way out to customers? Unless you carry that router with you on a flight, you have little guarantee other than hoping you're too insignificant for them to pay attention.
The big problem with this is that even though nobody knows your private key, they don't know your public key either, they have to rely on knowing the CA's public key and accept whatever public key they get when they connect so long as the CA says that the key is kosher. So let's say the NSA wants to track what you're doing on yourdomain.com, they just send a secret court order to VeriSign saying that they must turn over their private key that they use to sign certificates because computer security is a terrorist threat. Now they just use their own public key and send you a cert signed by VeriSign saying that the NSA key is the correct key to use. Because the NSA has more or less priviledged network access they can intercept traffic going to the IP address for yourdomain.com and just do a standard MITM but replacing the good SSL cert with their bad one.
What complicates things further is that there are tons and tons of CAs out there that are trusted by default and there's no isolation (AFAIK) such as "only these 10 CAs can sign certs for .com" so when the Iranian government wants to dish out some Orwellian justice on it's citizens they now have that huge mountain of targets to choose from because getting into one CA in the world (like DigiNotar) means that they can essentially break vanilla SSL until that CA's public key is blacklisted and all of the clients are aware of the revocation.
Just as a disclaimer, this was rather simplified but I feel like that's close enough to get the point across.
That is why the CA-system is a joke, you only need to compromise any of the CA's that are trusted by default to fool all certificate users.
Frankly, you don't have a chance if you're in a business that is valuable to a three letter agency. Even if you do the right things, you have to assume your colleagues are compromised. Look at those Sysadmins in that video -- chances are one or more of them is not only under surveillance, but actively collaborating with NSA or some NSA front.
It's NOT the system administrator's work to secure the network. The ISP/minor IT company should have a security engineer to overview the network, although some sys-admins are extremely skilled when it comes to security.
There are so many security layers that can be implemented on a Linux/BSD server that makes the machine virtually un-hackable and IF anyone enters, all bells and whistles could start cheering.
Examples: GRsecurity[1], IPTables[2], Snort[3], chroots (or jails), VPNs, malware scanners (clamav, spamassassin), encryption and what-not.
To me securing linux desktops, especially simple ones (e.g. window manager + basic programs... almost like thin clients) is easy. Securing Windows XP/7/8/etc is extremely tricky BUT can be done.
Once you do all that, I'm 100% that you're going to be one hell of a target for anyone. And you really don't trust your team you can always hire people to test your network's security and improve it.
The most important thing though is having a strict general user policy: What users can and can not do must be crystal clear with no exception. When a 'tiger team' finds a secure network, they usually target the people not the infrastructure.
[1] GRsecurity: https://grsecurity.net/
I know easier said than done. Writing firewall rules/ confug reporting tools for every computer in the internal part of a network is hard too, that's why almost no one does it.
I was talking on a keyboard-only level, but even that can be largely mitigate with proper policies IMHO.
That said, an insider is an achilles heel for every security scheme out there (e.g. Snowden).
>security layers that protect Infrastructure from all but the most sophisticated attackers (aka state/country funded).
I think the OP was specifically talking about defending against highly targeted government sponsored / APT attacks.
If you try to make your network absolutely NSA proof, you'll become broke trying. But maybe you can make reasonably sure that they will have to sneak in the custom router firmware, or have to bribe two or more engineers, instead of learning the secret passwords through an injected-Facebook-drive-by-download they can pit into their systems for free.
What do you mean precisely when you say that "sysadmins have tons of stuff going on"?
Just found this https://firstlook.org/theintercept/2014/09/14/nsa-stellar/ which includes more narrative and GCHQ's involvement.
Please advocate for change, actively, with the people you interact. GPG, OTR, TextSecure, Redphone, Signal, decentralized services… If they are complicated, set them up yourself. And please, urge your representatives to act!
And at least a few... are collaborators.
As PHK cautioned, the NSA/GCHQ/etc can submit patches or comment in development discussions just like everybody else, and at least some of the suggestions against using proper crypto are intended to keep the internet in plaintext.
As far as I can tell, the actual documents were just publicly released today. I suppose the point of the video, as noted by other comments here, is to show real human beings finding their name and email address in a top-secret document directing they be found and "tasked". Most of the filming may have been done back in March, and it seems they were made aware back then, and have hopefully taken steps to re-secure things since then.
I'd be interested in evidence that they should have specifically known about this earlier, though.
[0] http://www.spiegel.de/international/germany/gchq-and-nsa-tar...
if you're a sysadmin at a telco or infrastructure provider your definitely a target for the NSA, GCHQ.
let that sink in.
infrastructure these days also means AWS, facebook, youtube, twitter. every piece, site, offer that might be used by ISIS, for example.
The other things seemed to be network topology, IP addresses, and engineer lists, which are fairly public.
I have no idea but I'm able to believe easily.
I basically agree NSA could pwn anybody they want, but there are probably other considerations such as how obvious they want to be, whether the target is valuable enough to reveal zero-days nobody else has seen yet, etc. Maybe it's wishful thinking, but I'd like to believe if you don't do things like open unsolicited email attachments, you're still pretty safe.
But, perhaps as the lead engineer of an ISP "interesting" people use, nothing is off the table and he has been pwned repeatedly.
I forget the name of that method, but according to the documents it was used to target sysadmins. Though if you use a password manage with unique passwords for every service that should help protect you.
For more details: https://firstlook.org/theintercept/document/2014/03/20/hunt-...
Most people hold a similar view as you. i.e. "Why is X wrong when people do it, but not when government/government employee does it". However, we anarcho-capitalists, who examine the basis of government in terms universal moral principles, apply this critique to everything a government does.
Your singular question is one of many. And I urge you to explore such questions further, as far as you're comfortable questioning. You'll find that much of what government does is logically inconsistent, even with its own set of defined "morals".
Outside the US, NSA operates with the diplomatic and military support of the US. It's not a matter of an individual hacker, but "an international incident" should something arise. There's some risk that an agent or operative (non-agency employee acting on behalf of the NSA) could be caught, but that would vary by field of operations and relations between that country and the US.
Nothing is happening because the NSA and most representatives are PARTNERS in this crime. You must contact your representative and let him know that you are ready to do anything in order for him not to be reelected if he won't actively ask for justice.
Worked fine for me in FF on linux. Might be worth a try in Chrome.
As of today, there are two kinds of people in the world: those who believe we're still stuck in post-9/11, and those who realised we are now in post-Snowden.
There is a third kind who have Facebook accounts, but those are just the nature's way of saying that Darwin got it right.
That's a non sequitur.
Having a facebook account or not is an almost negligible factor in the grand scheme of things.
The kind of information commonly exposed on facebook can be more conclusively inferred from other information sources.
Do you use a smartphone? Skype? Any search engine?
Does your home internet come out of a plastic router? Do you click on the little lock icon every time you go to a SSL site, to verify the certificate hasn't changed? Do you know the fingerprint of the legitimate facebook SSL certificate?
Think about what any one of the above devices "knows" about you in comparison to what facebook knows about you.
The only difference is that somehow Google still maintains a straight face telling people they are not guinea pigs in their next study. Zuck never had that option in the first place, their only strategy is to maintain grip on the population at all costs, and no means are too sleazy.
What you want to try is to shut down your Facebook account and check some e-mails they will be sending you for months to come... Prepare for the drama. They will be showing you the cutest photos of your family and closest friends, saying they're all devastated because you've gone antisocial.
Zuck broke our hearts.
Wow, you just trash talked over 1 billion people in one sentence.
> There is a third kind who have Facebook accounts, but those are just the nature's way of saying that Darwin got it right.
really amusing. But it is really wrong and bad to talk like this. We need those people to understand the issues of surveillance. We won't go nowhere without them, and even if you get ultra-secure, they will always be potential attack vectors. Don't trash them like that, but teach them, instead, how to behave, how to communicate in the post-Snowden era.
But really, language breaks down trying to describe the epic scale of a tragedy we are watching from the front row for many years now, one called Facebook.
There is no practical way to tell one billion people that "Facebook" and "surveillance" are synonyms. This is simply too much to bear and process without relevant background and experience. There's no right kind of advice to be given. On top of everything, there will be an immense PR department trying to label your ideas dangerous and sociopathic.
There is no better way to illustrate this effect than Stallman's formidable Facebook crusade:
I just don't understand the outrage about collecting data on what happens in the church basement after mass (that's essentially Facebook; who likes who/what, etc) when much more important things have been shared for a lot longer and no one cares.
How would you like a credit card company which is selling information about things you really wanted to buy, but never actually did? Books you thought you should read, but never found time for? Who is the girl you fell in love with, but never dared to approach, or got turned down by? How often you're browsing Internet very tired, or drunk? What are you browsing for when you're drunk? What was the sentence you've started typing last night, but never finished?
Who could benefit from buying such information about you, and how? How much of this church basement stuff can be used to influence you in 5 years from now? To affect your career in 15 years from now?
Think how much your shopping mall history from 10 years ago is worth compared to a good educated guess about what is happening inside your head right now.
These are the questions Facebook's resident data miners are routinely answering. This is what Facebook is after, and this is what makes them disgusting.
http://arstechnica.com/business/2013/12/facebook-collects-co...
If you're on Facebook, get out. If you're working for them, quit.
Facebook can profile as well, but the analogy I like is the magazines I choose to read from the pile in a doctors office waiting room. It's a sliver of a sliver of a sliver of one version of me, that's only relevant in a very narrow sense.
I may "like" something for a whole host of unknown reasons, and likes are not scarce. When I put my money where my mouth is, it carries a lot more weight.
But personalities aside, lets talk mass markets.
Think of a random teenage girl who shopped for Alphabits 4 hours ago, twitted of #mileycirus 40 minutes ago, then started typing a private Facebook message to that bully from school, then took a monthly dose of her brother's ADHD prescription and went postal 2 hours later with the largest shotgun from her dad's attic.
Or maybe she didn't?
As of two hours ago, she still had a chance to become the next Rosa Parks. You don't know that. I don't know that. Mark Zuckerberg knows. Three years later, he wants to sell her profile to her first five potential employers for ten US cents apiece, and probably ruin her life forever.
(I might be exaggerating just a bit for the sake of argument, but God knows how many Stanford graduates on Facebook payroll are looking for much more subtle patterns in her data as I write this)
Good news is that Facebook is doomed. Ephemeral is the new king, guaranteed crypto ephemeral is the next one. No one wants to talk to Zuck when one wants to talk to his girlfriend.
Zuck is simply out of fashion. Somehow, teenagers know better than we do.
You're right that ephemeral is the future, it's also the past and present. Any insight one may surmise from mining Social Data is just as ephemeral.
But you will agree Snowden did a lot to help general population understand where we are today. Definitely not Kansas, and no other New Deal in sight.