Copies of malware used by intelligence agencies to spy on journalists
wikileaks.org
wikileaks.org
Ignore for a moment whether it's a good or bad thing that police use tools like these. What I want to know is, what happens once they "get their guy", so to speak.
Does the malware stay on that computer forever, violating the privacy of family members, or other users of the computer should it be sold on and not wiped correctly? What happens if it's not the correct person?
Basically, why are the police spying? To me, that raises some ethical questions and makes me feel that the police will handle things like this in a very ham-fisted way, like they usually do with technology. Worrying.
[1] http://www.smh.com.au/it-pro/government-it/nsw-police-use-ha...
I personally have no qualms with the FBI planting malware as just another form of surveillance (if they have a warrant to search your home and tap your phone, why shouldn't they be able to get a warrant to monitor your computer?). The problem with Gamma Group, and what I suspect is one of the core reasons for this leak, is that they happily sell their product to extremely oppressive regimes and give them personal support, knowing full well that the tools are being used to spy on and find dissidents, protesters, and political opponents.
Is the US/Australia/Uk's treatment of Julian Assange (as an example) not count as "oppressive regimes" and "...dissidents, protesters, and political opponents."?
How is that different to <insert country you were thinking of when you wrote "oppressive regimes"> ? (I ask honestly, not rhetorically)
I'm not claiming that everything is perfect in those western countries, but compared to them there are some truly evil regimes around in countries where absolutely no checks and balances exists to rein abuse in.
While this may get me down-voted into oblivion, since the author may be easily one of the most hated people in the tech world, I recommend Evgeny Morozovs "The Net Delusion" which is a quite insightful take on the abuse of tech by oppressive regimes.
The US treats certain people very unethically, including Assange, but in these cases it's more a sense of vengeance for having our top secret dirty laundry aired, compared to simply disagreeing with or disliking the government. We still have a long way to go to, but the freedom to express yourself is simply a lot higher in most Western European and North American countries.
You're an idiot.
If you take a look at the actual licensing by countries, you will see my suspicions are indeed confirmed. The support tickets issued by Australian law enforcement, for example, mention that use is only permitted through warrants and even specifically states their reporting and documentation requirements.
>Our Warrants authorize the use of the the FF intrusion capability as well as the individual modules that are used. At the conclusion of a warrant there is a requirement that a report is made on every date / time each module captures information. For example, if a key logger captures data at 1pm 2/1/2013 we need to report this to our legal system. This time/date is important for reporting procedures as there is a requirement to record every instance a module is used. Is there some way of just extracting the time/date and module name to a report?
This does not constitute unethical use of this software. This is simply a way of placing a "wire tap" on a computing device.
Since law enforcement typically wants convictions, it could be a selling point to prompt for uninstall when a warrant expires.
If I were to set up a company which sold similar products at similar prices, I would expect the FBI to come knocking at my door very quickly.
Also good to see that, at least for a time, Gmail was able to detect infected files (see the Mongolian feedback numbers 10-12)
what people always seem to forget is that it's not the webcam but the microphone that presents the greatest privacy risk.
if you tape it off, it'll just lower the volume (and possibly dampen higher frequencies, but you just need 300-3800Hz for voice).
additionally (outside the coffee shop scenario you describe here), what's a webcam do? ok, it'll see your face. chances are they already know your identity. maybe it'll catch one second of your underwear, big deal. now compare to a microphone, much less data, but it picks up every conversation in the room, regardless if they're "in view". much worse.
Physical switches and/or duct tape FTW.
Consider also that some people have computers in line of sight of where they have sex, and an illicitly captured video recording of sex without sound is more often thought of as a privacy intrusion than an audio recording without video of the same ... as the noise from my neighbors might attest.
When people get their identities stolen, or lose all the money from their bank accounts, this might be regarded as "random" events, in the same way that most people won't get mugged and when it happens it's because of "randomly" being in the wrong place at the wrong time. But more people have experience dealing with the government, and though they believe that criminals aren't interested in them they know that the government might be, and thus the government is seen as a more tangible threat.
Is it possible that governmental surveillance is on average a good thing, since it raises people's awareness and makes them protect themselves more? Having enough money in your bank account to buy food is, after all, a more basic need in Maslow's hierarchy than not having copies of your e-mail conversations in a government database.
Hey guys, let's unzip this so the next guy can run it and spread the worlds most advanced malware on our home network.
I wonder if this has happened yet?
https://web.archive.org/web/20140703130707/www.vupen.com/blo...
Surprised to see Italy on there, though.
But when I do,
I do it on my production computer with 200 VM running.
======
and none of my firewalls pop a warning.
https://www.virustotal.com/en-gb/file/6ee40b8e7d49f4ea70b7ce...
https://www.virustotal.com/en-gb/file/688f1e15390faf8d977351...
[1] https://www.virustotal.com/en-gb/file/f827c92fbe832db3f09f47...
[2] https://www.virustotal.com/en-gb/file/0b465877a998a993a64a14...
Interestingly, both files were first uploaded to VT in 2010, meaning that AV vendors have had chances to analyze them.
Whatever you may think of the allegations, it has become extremely blurry as what the money donated to wikileaks' operation is actually used for, seeing as how Julian Assange wasn't supposed to be wikileaks.
Why do you?
Is what he wants you to believe.
http://www.theguardian.com/media/2010/dec/17/julian-assange-...
By Saturday morning, 21 August, journalists were asking Assange for a reaction. At 9.15am, he tweeted: "We were warned to expect 'dirty tricks'. Now we have the first one." The following day, he tweeted: "Reminder: US intelligence planned to destroy WikiLeaks as far back as 2008."
While everyone else is dissecting the information and trying to digest it and working on solutions to the surveillance problem; you're obsessed with the messenger.
Why?
I'm merely trying to explain it's worthwhile to consider Snowden isn't acting in our best interest. Imagine Snowden's supervisor comes to him and says: "You're going on an extended special mission abroad. Leak these documents to some journalists. Act like you're trying to shed light on what's going on by playing the victim card. The goal is...."?
Per the leaks, solutions to the surveillance problem are limited and likely won't become something proliferated through the masses due to cost, availability, usability, or some combination of the three. We're talking about eliminating hardware-level vulnerabilities, not patching software. And even when and if we do fix these vulnerabilities, what's to stop them from doing it again? All it takes is threatening the life of the company or individuals involved in the development process.
I disagree. Solutions can involve broadening technical security awareness and education, not only for experts, but for the great masses. Suddenly, people who wouldn't have done it otherwise, are installing PGP, guided by well-designed step-by-step-instructions which haven't existed before Snowden. This is per se a Good Thing.
Awareness leads to more people trying to exploit things previously thought to be at least very improbable to break. Discussions about Crypto-Quines, VM-breakouts, you name it, are suddenly on the rise, at least in my perception (which has since sharpened significantly, and I'm not even in the least involved in security)
Better tools are developed to prevent goto fail;s. Other people fork OpenSSL, sunset SHA1, visit security-related conferences or donate money, you name it. This is a slow process, but things are definitively moving forward.
But again, you're avoiding to answer the question: What a difference would it make if your scenario would be true? Would it negate that mass surveillance exists? Of course not. But that's what's important here, that's what's being worked on by people.
It's one thing to be a classical "we can't win anyway" naysayer, but is's a completely different thing to try to pull an ad hominem derailment, so the question arises: Who are you working for? What if your supervisor came to you telling you "Try to find something about Snowden we can use against him and his findings. A way to discredit him, maybe find someone who went to school with him who can make a fool out of him; maybe try to pull an assange-like sexual assault case on him, anything", what would you do?
Wouldn't we find you here?
This is the Internet. Isn't there enough room here for discussions about both the message and the messenger? Or is it that when the message gets strong or important enough, the messenger gets irrelevant in comparison?
What exactly would we gain from discussing the messenger? Would that move anything forward?
What if we found out Snowden was paid by some russian agency. What exactly would that change? Would the guys at Stellar say "Oh, the russians paid him? Everyone stop changing passwords and re-issuing certificates, guys, everything's fine; he got paid by the russians", and the slides with router passwords would suddenly disappear from the face of earth?
I hope it's the language barrier and I'm failing to understand your point.
The difference seems to be about whether we SHOULD discuss the messenger. Assange still has the power to decide what to publish, and maybe more importantly when to publish it. Everyone who has a message to convey will wait for the right time to do so. This is true for political statements, for press releases, for when you ask your girlfriend to marry you or for when you tell your parents that you failed an exam. It would be silly not to accept that Assange cares about timing.
A discussion about the messenger shouldn't be seen as a dicussion about the truthfulness of the message. For example: The Russian government accused the Ukrainian government of being fascists, and one of their excuses for entering Crimea was that they needed to protect the Crimean Tatars from these fascists. But the Tatars are pro-Ukrainian, and many of them fled when the Russians took control. Those who remained are being harassed, and there are Tatars who were even denied re-entry to Crimea after having traveled to Ukraine. Sure, there are far-right extremists in Ukraine. Of course there are. But the Russians didn't want to admit that the phenomenon is far more prevalent in Russia. Knowledge of the messenger helps us to put all of this into a context.
All I'm saying is that we should be generous enough not to censor discussions just because we're not interested in them. In this case, it means discussions about both the message and the messenger. When combined, the outcomes will provide us with even more information. Ad hominem arguments like "you're obsessed with the messenger" are designed to silence one of these discussions.
If it isn't seen as a discussion about the truthfulness of the message, it should be seen as completely worthless gossip. Why would I be discussing Snowden as a person if I don't know him personally and I don't dispute the truth of his disclosures? Can't we pick a prettier celebrity to discuss to no particular end?
The only purpose in gossiping about people who disclose information which nobody seriously disputes is to confuse the simple-minded.
That's the problem you should at least be questioning that truth just like you question the truth of what the government tells you.
Think of everyday life. Ever been told only half the story? Been around gossip? Ever played the game 'telephone'? In all of these, you are receiving information, but the motivations and morals of the messenger can affect the impact and reaction to a message.
No, but surely such a discovery should alter how we interpret the message, right? Suddenly, it's impossible to discern something that US government is doing to its citizens vs/ something than an enemy of the US wants you to believe.
I really don't understand why Assange and Snowden are getting such a pass. If anything, their motivations and the source of what they are releasing should be scrutinized ten times as much as any previous whistle blower or journalist.