“Warning: Do Not use my mirrors/services until I have reviewed the situation”
article.gmane.org
article.gmane.org
It is entirely possible it is survivor bias on my part but I get the suspicion that a global sort of 'cyberwar' that has been rumbling along for years is heating up rapidly. I've seen a 10x increase in various scripted attacks being attempted (patch early and often folks!) and a number of APT level compromises of systems either staging malware or deploying it (see the latest bulletin on the Afghan government compromise). And of course the whole Free Syrian Army / ISIS / terrorist nom de jure attacks.
I can't shake the analogy to pictures from WW II where shop keepers were huddled in the back while soldiers fought from the front of the store. I see innocent servers being 'occupied' by enemy malware so that it can launch attacks on other servers further into a protected network.
Fortunately in this modern version of war you can "kick the soldiers out" of your server by bringing it down and re-imaging it. And they won't turn around and shoot you, but that is not all that comforting somehow.
It might have been a freudian slip or some kind of intuition, but when I was describing my life plans to my family, I said something along the lines of "I don't want to manage people, I want to stay on the front lines with the code." Except I don't want it to be scary, because I can't take anymore of that in my life. So what I really mean is "deploy knowledge bases" and that I choose to work in education. So I continue to stand on a soapbox of 'ethical coding' and I continue to request the ability to separate the responsibility of the developer from the technological applications to warfare. I just want to code difficult stuff, with intense mathematics and abstractions, and solve hard problems. I don't want people using that to hurt other people, and people who don't code don't seem to get that.
People wonder why I get depressed, and to a lot of people it probably looks super dumb and selfish, and I've lost a lot of friends over the years over things I couldn't really explain. People say I over-analyze things and that I think too much. Maybe I do, maybe I don't think enough. It's pretty easy for me to have these opinions when my life is stable.
The logical conclusion though, is you can either own that problem and spend your efforts on developing and making available countermeasures to code that can kill, or you can let go of the problem. In a similar way when you have kids you want the best for them, but at some point you have to let them be the individuals they will be, for good or ill.
Letting go of that which you don't have influence over is, for me, the hardest part of being an adult.
> A novice asked the Master: "I perceive that one computer company is much larger than all others. It towers above its competition like a giant among dwarfs. Any one of its divisions could comprise an entire business. Why is this so?"
> The Master replied, "Why do you ask such foolish questions? That company is large because it is large. If it only made hardware, nobody would buy it. If it only made software, nobody would use it. If it only maintained systems, people would treat it like a servant. But because it combines all of these things, people think it one of the gods! By not seeking to strive, it conquers without effort."
His goal was actually to provoke Congress to explicitly pass a law against tele-operating lethal robots.
I guess that didn't work out so well...
I wonder where the code that is running inside the drones today comes from. Some one who never meant to be involved in those things must have written either the compiler, specs or actual code that these things use to do their killing, I can't imagine any company (no matter how secure they might want to be) designing a completely new processor architecture and tools and compilers and all that from scratch.
I still love math, and I still love computer science. I just don't want to use it the way the a lot of the world uses it, and I don't know how much thinking I have to do before I can create code that I am satisfied over being both intelligent and humane. It's absolutely ridiculous, sometimes. Sometimes I can just stare at a cursor blinking on an IDE and feel like I'm falling into a void of 'what ifs'. Other times it is like there is no difference between myself and the machine. And then I wonder whether I'm thinking enough, again, or am I letting calculation and logic get the best of me. Have I abstracted this problem too much, too far away from reality? Does anything I think matter at all? My life continues to improve, but suffering still exists, and I feel like it is almost taboo to talk about in this way. But what is the point of existing if you can't actually make real improvements?
I'll say. You could throw it in and go work as a coal-miner, but then you'd have to worry about the coal you mined being used to smelt steel that goes on to be manufactured as bomb casings. And so on. Certainly you shouldn't work on anything that offends you conscience, but the mere fact that something can be repurposed for warfare doesn't create moral responsibility.
This isn't to say that worrying about war or your personal purpose is misplaced GH Hardy opined that ballistics was 'repulsive' both because of the moral purpose and the triviality of the mathematics involved, and there are more musings on the ethics of that sub-branch of math here: http://www.augustana.ualberta.ca/~hackw/mp480/exhibit/ballis...
But as long as you're knowingly working on some sort of combat system, it's folly to beat yourself up over the limitations of foreseeability and the vague possibility that something you craft might turn out to have military utility which you din't intend at the time you conceived it. Instead, look for ways to provide utility in other areas.
But you are right. I look to provide utility in areas where the net effect seems most likely to be positive. When I can't evaluate that entirely I just assume neutral or no effect, it sort of just dissipates over time, like a wave collapse function, assuming entropy, or some manner of mental equality among peers.
Or because you didn't work on guidance systems, you could wonder if that was the reason the near miss which causes a lot of civilian deaths happened.
Or you could note that the use of military power is not really constrained by technical limitations and never has been, but the effect most certainly is, and start voting and advocating politically which would be more effective at stopping wars in every way.
But then you would have some much more direct responsibility for how the various conflicts turned out.
I don't have the energy for that. These situations are so complicated and they never seem to get resolved. As soon as peace comes someone sees that as opportunity to manipulate (or is the perception of that what causes it to happen?)
I'd rather just stare at math and code, seriously, even if it doesn't talk back like a person. At least it's not crazy.
I don't think that it's fair to condemn oneself because his/her ideas could potentially end-up sparking an idea about killer drones in someone-elses mind. In the end we're all very much alike, and it doesn't take much to transfer a few missing links if you know and they don't.
In the end the same laws of nature rule in all our heads, and while it seems like each and every one of us are our own compartmentalized observers, it's not until you think a good long while about the principle of locality(and most of the other fundamental laws) that you understand that it's the other way around.
Thinking this way for me is peaceful. I can't believe in god or another entity but to follow this chain of thought always leads me to consider that I'm part of something greater and more important than one single life can ever hope to be. I guess these days I see humanity more as some sort of super organism . Just as I emerge from individual cells so does humanity emerge from all the humans inside of it. I just try to do my part inside the greater of humanity, and I leave it at that.
I interviewed a candidate for a job once who wrote code for military drones. He didn't think it was bad that they were used to kill innocent people. In fact, he thought it was awesome. There are a lot of coders who have a low moral bar and will code anything for money. These are the people who write this kind of software.
Dr. Rawlins: No it's THEIR runway, Jim! Try not to think so much! Try not to THINK so much!
One of my favorite quotes of all time when I dealt with similar issues myself, from Empire of the Sun.
His servers were taken over by law enforcement. You're free to call them cyberterrorists if you wish. These days it's hard to tell the difference in tactics between malicious rivals and your own government anyway.
First, it has little to nothing to do with the comment posted, which concerns not a "cyberwar" but the possible police seizure of a Tor server. The assumption is it's either a false alarm or a police raid. No one thinks this was done by ISIS.
Second, a post using the word "cyberwar" in a non-ironic manner at the top of HN?! O tempora o mores!
So while your observation about an increased number of scripting attacks is interesting (assuming you did in fact establish a reliable baseline) it's in a strange place.
Did you mean to post elsewhere?
> Did you mean to post elsewhere?
No, I meant to post it here.The author, Thomas White, writes of losing control of his Tor exit node servers, not to this audience but to the folks who read the tor.user newsgroup. Robert, aka chummm, posted it here as being of interest to the community. His was one of a series of articles/notes being posted here that have described potentially state-actor level activity. And there has of course been quite a bit about the Sony hack in the news. I also happen to run a fairly large internet visible infrastructure which acts a weird sort of observation instrument for the network as well.
I presume that Robert submitted it here because he felt it was interesting, and a number of people concurred with him. And after reading the article of yet another person finding themselves on the receiving end of external forces trying to compromise their systems, it crossed some vaguely defined threshold for me between crystallized a thought that has been tugging at my subconscious for probably a month or more. That being that the the number of and frequency of penetration attacks is noticeably higher now than it was before. Yet I don't keep some sort of threat index or anything, I just get to see the number of things my automated defenses have fended off, or the clusters in the datacenter. And I allow that it is entirely possible for the combination of lots of computer intrusion in the news cycle has combined with perhaps a lot of bored teenagers on winter break or something to create something illusory. But as this story brought that observation to the forefront of my consciousness, I thought I would share what I was observing here, in the comments people are making about this story.
Your comment/observation is also very interesting, but had little to do with the Tor issues. So I was confused.
But I get sometimes things trigger tangentially related things, which is as you've said what happened here.
And thanks for addressing my comment is such a polite manner, especially after my snarky critique of your use of the word "cyberwar". Apologies for coming across in a negative manner, if you took it that way (except for the 'cyberwar' bit, I wasn't actually trying to be negative, I was mostly just confused about the comment's context).
Chuck's been around HN for a while, and has insightful comments frequently - that he posts this sort of "radical" comment implies that a non-nut is seriously considering it and quite possibly it's worth pondering as an idea.
Yes, my comment was that I didn't get why ChuckMcM posted it in this particular context, not who he was. I've also been around HN for a while, not always under this username.
http://www.cru-inc.com/products/wiebetech/mouse_jiggler/
to prevent the computer going to sleep while this is utilized
http://www.cru-inc.com/products/wiebetech/hotplug_field_kit/
These are pretty standard plays in seizing computers these days.
One should note that the grsec linux patchset has functionality to not load drivers for any plugged usb devices, as well as log when it happens, possibly resulting in action being taken.
If the server were configured to sleep unless the mouse is jiggled, it would already be asleep. Thus, using a "mouse jiggler" or similar is pointless, and risks detection.
In this case, I would bet on a firmware compromise, similar to DIETYBOUNCE: https://www.eff.org/files/2014/01/06/20131230-appelbaum-nsa_...
As a countermeasure, I would not fully trust TXT in this particular case. It's likely a state actor who could spoof measurements over the the LPC bus.
If any government agency can break TXT it'll be the NSA and I don't know if they are in the business of handing out their best exploits to random police teams at the moment.
Regardless, this whole thing turned out to be a false alarm due to a KVM device being attached.
That said, very good point wrt grsec.
http://cgit.freedesktop.org/systemd/systemd/commit/?id=7212a...
It runs "loginctl lock-sessions" whenever a USB input device with a name of "Wiebetech LLC Wiebetech" is plugged in.
Has anyone used these in an IT support environment?
http://www.gamespot.com/articles/gdc-panel-tackling-the-emil...
>Will Wright, the creative mastermind behind SimCity and The Sims, spoke last, charming the crowd with a fluid mix of academic design insight and brash humor. "I'm convinced that if she was alive today, she'd be an Internet addict," Wright began. Citing television show Futurama as a key influence, Wright presented his idea for an Emily Dickinson desktop agent. Wright explained that, like a mix between Tamagotchi, the Microsoft Paper Clip, and Seaman, the Dickinson agent would be moody, portable, dependent, somewhat annoying, and observant of all your computer-based actions.
>Wright envisioned that the agent could be sold on USB memory sticks, in order to cleverly "backdoor" the program to unsuspecting customers. "USB Emily," as Wright dubbed the agent, would then interact with the user via IM, e-mail, and pop-up messages. USB Emily might snoop into the user's programs and documents in order to find keywords to comment upon or send poems about. Over time, the user would "slowly bootstrap a relationship with her."
>Referencing some of the emotional problems from which Dickinson suffered, Wright explained, "I want to put the player in the role of her psychotherapist." In one scenario, the player might help USB Emily through her problems and eventually befriend her. But in the two "degenerate cases," USB Emily might either become romantically obsessed with the user (a reference to her often erotic poetry) or fall into a suicidal depression (in which case the program might delete itself).
http://games-beta.slashdot.org/story/05/03/10/1723254/emily-...
>Will Wright's was the final design up for consideration, and was a truly inspired idea. It included such charts as the one to the left, showing the overlap between Emily Dickinson readers and GTA players.
>Then he put forth his goals. He wanted to have the mood dependency and portability of a Tamagotchi, the helpful/annoyance of Clippy, and the relationship and creepy aspects of seaman.
>What he came up with was USB Emily Dickinson. The game would be a small program bundled with a USB memory drive, which is now a large business and an almost impulse buy. The "Emily" program would sit on the drive, and would occasionally interact with you in order to begin to derive an emotional relationship with you. * These interactions would include Instant Messaging, email, and interruptions while writing. Over time, the program would develop a model of behavior depending on how you'd interacted with it. Will's thought was that, while you could eventually get her to a stable state it was more likely that she'd become romantically obsessed with you, or suicidally depressive. In the latter case, he said, she would have the option of deleting herself off the USB drive.
>To respect the license idea, again, Wright opined that the program could be adapted for any famous figure, and to have many different USB individuals operating on the same computer. If you had enough ports you could even have them interact with each other through natural language generation. Thus, you could slot drives to view a conversation between Marx, Twain, and Homer Simpson. While all of the ideas were stellar, Wright took home the first prize for the second year in a row.
When the unskilled highschool grad gets off the plane and signs up, they are going to give him a rifle. When the engineer gets off the plane and announces himself as such, there is a chance that he will be put to better use.
Indeed. And I'll happily concede that point. I (and many other) are just surprised at the thought process...physical hardware attack in (presumably a western data center)...and the thing that comes to mind is the ISIS??? Really if you tell me Russia I would have bought it. Same for China, Korea, Turkey etc...but jumping straight to the cliched CNN "terror org" that is the flavor of the month...please...
[Ace is having difficulty with throwing knives] Ace Levy: Sir, I don't understand. Who needs a knife in a nuke fight anyway? All you gotta do is push a button, sir. Career Sergeant Zim: Cease fire. Put your hand on that wall trooper. PUT YOUR HAND ON THAT WALL! [Zim throws a knife and hits Ace's hand pinning it to the wall] Career Sergeant Zim: The enemy can not push a button... if you disable his hand. Medic!
That being said, they do not look to me like a group that would be using, and generally be interested in, such tactics.
I'm fairly convinced that if we all really tried we could secure things much better than they are today. The personal tripwire I've been watching for is when it finally becomes simply general knowledge that C is completely unsuitable to write security software in and C++ is pretty damned dangerous. (Many people know this, but a large contingent will still push back on that. Once we get serious about security, one of the things that will have to happen is C is going to have be evicted from its current privileged position.)
Lest I sound utopian, yes, this will require immense effort. My point is precisely that we've never really tried that level of effort yet, not that the effort will be low. There's no real reason that the Internet actually has to be made out of swiss cheese, but it will take a significant change of viewpoint before it will be resolved.
What I keep thinking, though, is, what would be the total dollar cost to make security a forethought, with information technology being pretty ubiquitous? I think it might actually have serious economic impact -- is it possible we literally can't afford security, as a society?
But there would have to be some pretty significant changes in our languages and how we program, and it probably would mean things like a certain slowing down of the rate of feature delivery.
In the long term, being unable to afford security is being unable to afford computerization at all, and the efficiency bonus is so great from computerization that it's hard to believe that we couldn't figure out how to make it work.
We'd definitely still be using mechanical computers. But I could easily see lots of eye candy being stripped out to conserve cycles (after all, having a 3D desktop on a Pi isn't all that useful :)
Big blip, though. But at the current rate we're headed for that anyhow, regardless.
There isn't one. There are too many people involved who categorically refuse to consider security, and there is no way to fix that in a reasonable time frame. We'd need to fix the education problem and then wait for a whole generation of new people to go through it.
Now if you go with a weakly typed language like Javascript there are a whole other class of bugs that can bite you:
https://medium.com/@octskyward/type-safety-and-rngs-40e3ec71...
... so don't use those.
Your guess is as good as mine...
Fortunately in this modern version of war you can "kick the soldiers out" of your server by bringing it down and re-imaging it. And they won't turn around and shoot you, but that is not all that comforting somehow.
Until "DeathRay3000" becomes a standard peripheral it is slightly comforting...Overall, I worry more about the hacks I haven't detected than those I have. Re-imaging is a pain, but not as much as not knowing your server is secure.
The ISP told Tweakers that the account of Thomas White was blocked due to a security policy of the company. The customer let a deadline for verification accidentally expire and logged in through KVM. "Some KVM's generate a USB event when you use it to set up a connection to the server, this is what the customer just notified." - according to the ISP Snel. Meanwhile, the man's account is released.
[1] https://tweakers.net/nieuws/100388/beheerder-verliest-contro...
https://lists.torproject.org/pipermail/tor-talk/2014-Decembe...
Few quick points (that I found most interesting, click link to read everything):
"The likelihood of this being the work of law enforcement seems to be lower than originally anticipated. This is good in many ways but asks more questions than it solves right now."
"Support staff at the ISP have confirmed to me there has been unauthorised access to my account. This could be down to the fact I access the control panel often via Tor (yes, using TLS before anybody asks), however it does raise the prospect of a non-LE person(s) being behind this but does not explain why a chassis intrusion was detected for example or anything else to do with on-board sensors."
"Again, at this moment in time I am under no gagging orders or unreasonably withholding information under orders."
Node fingerprints are as follows, please blacklist ASAP. Some servers are
accessible via their KVM again but not networked.
D78AB0013D95AFA60757333645BAA03A169DF722
6F545A39D4849C9FE5B08A6D68C8B3478E4B608B
5E87B10B430BA4D9ADF1E1F01E69D3A137FB63C9
0824CE7D452B892D12E081D36E7415F85EA9988F
35961469646A623F9EE03B7B45296527A624AAFD
1EA968C956FBC00617655A35DA872D319E87C597
E5A21C42B0FDB88E1A744D9A0388EFB2A7A598CF
5D1CB4B3025F4D2810CF12AB7A8DDDD6FC10F139
722B4DF4848EC8C15302C7CF75B52C65BAE3843A
93CD9231C260558D77331162A5DC5A4C692F5344
A3C3D2664F5E92171359F71931AA2C0C74E2E65C
575B40EF095A0F2B13C83F8485AFC56453817ABF
27780F5112DEB64EA65F987079999B9DC055F7C0
54AA16946DB0CF7A8FA45F3B48A7D686FD1A1CEF
1EB8BDA15D27B3F9D4A2EDDA58357EA656150075
17A522BC05A0D115FC939B0271B8626AAFB1DDFF
1324EC51FBFA5FD1A11B94563E8D2A7999CD8F57
[1] http://thread.gmane.org/gmane.network.tor.user/34619Not much further info at this point. Trying to do secure log dumps but most systems seem unavailable again. Bracing for possible local raid
Apologies no further info atm, I don't know what I am dealing with yet, ISP has made no comment Re: if warrant executed at servers
Interesting that the servers were briefly up and running, but down again.
Update on tor-talk: https://lists.torproject.org/pipermail/tor-talk/2014-Decembe...
In the first original email, he writes "At this moment in time I am under no gagging orders or influence from external parties/agencies. If no update is provided within 48 hours you may draw your own conclusions."
Please may I call your attention that this canary paragraph is missing from the latest tor-talk update. Draw your own conclusions.
The one you linked to says:
> 7. Again, at this moment in time I am under no gagging orders or unreasonably withholding information under orders.
He knows what he says will be scrutinized by thousands. Why wouldn't he be very careful in what he says?
Based on his first canary vs the last, he could, as you say, "reasonably" be withholding information on request. Perhaps terrorists, kitty pr0n or the threat of jail is reason to him. Good resons, who knows.
He could also be under the control of someone that asks him to add new, lie or modify information. Worse reasons, perhaps.
Either way his first canary reminded us that whatever he says now needs to be treated as possible disinformation.
> 3. The DC has confirmed via Twitter that the servers were not "accessed". Having been raided in the past I know indeed they can be forced under Dutch law not to inform clients of raids, but I don't feel this may be the case. With that being said, a chassis intrusion indicator still must be addressed and I cannot find it in the logs anymore. The DC company are not the people who I directly interact with however so I am still awaiting a direct response form those we host the server with.
Either way, it's not a direct raid or seizure, if anything a backdoor installed by someone at the DC, but honestly at this point you have to accept the possibility and either accept/balance/mitigate the risk or get new hardware.
[1]: https://lists.torproject.org/pipermail/tor-talk/2014-Decembe...
Because he's under time pressure?
If his paranoia was true (after all, paranoia doesn't mean they aren't after you), he could have had little time to get his message out before he would have lost his network access. At that moment, timeliness would have been more important than precision; what mattered was that the directory authority operators and mirror users knew that his servers were potentially compromised.
There won't be an announcement; but once that threshold is crossed events begin to move rapidly and forcefully and do not stop until a new arrangement of powers is found that society can scaffold itself upon. Who knows what will be the stable state of a world seeded with the idea of networks and knowledgable in their subversion and subornation.
Map political science onto the sandpile model [1] to get a first order approximation of the framework of analysis I'm using from a macro perspective. On the micro level of individual perception; what matters isn't merely the perceived lawlessness of the elites and of the guardian castes, but the growing sense that "If you play by the rules; you're a sucker." And depending on your level of investment in the current order that sense can be a powerful motivator to working around limits that were introduced to promote institutional stability.
And if most peoples reality is that the ruleset they're working off of is largely economically workable only because it's technically illegal... that's inherently unstable.
So you're right to point out that there is no "threshold" as stated by the OP, however the frenzy with which the US government is undermining its own legitimacy as well as that of many other Western governments, does not bode well for our civilization (Western or otherwise).
Which comes to an interesting situation: if this was acted upon by NSL, here there's proof something happened, so how does that get explained without breaking the gag order?
Modifying anything before you have a complete forensic dump is a big no-no because you need to preserve evidence.
A Linux server (I'm guessing for no particular reason it's a Linux server) would have no reason to automount a USB stick, and its console would be at a login screen (so a HID device would gain nothing).
So my guess for the intrusion scenario would be a "cold boot" attack: plug a specially prepared USB stick, open the server case, short the reset pins in the motherboard (AFAIK, modern motherboards still have the pins for the reset button, even though modern cases don't have a reset button anymore), and tell the BIOS to boot from the USB stick. The USB stick then dumps the memory, which still has data from the previously running system (since it was an unclean shutdown), with some luck including cryptographic keys.
That scenario would also explain why he briefly saw the server back on the KVM: they might have been using the KVM to interact with the BIOS.
The defense against such a scenario would be to aggressively shut down all processes and kexec to a memory-wiping kernel as soon as any unexpected device (not only USB, but also PCI and others) is seen, or if the case is opened. Also make it send an alert message through the network with the details whenever it's triggered, to be able to diagnose why the server shut down without warning.
But there's another possible scenario: the "bureaucratic confusion" scenario. It's possible that the systems at his hosting location got confused, and thought he was no longer a client. The apparent intrusion would be a techie repurposing the servers for another client.
Interestingly enough, look who makes it.
> The Raytheon Company is a major American defense contractor and industrial corporation with core manufacturing concentrations in weapons and military and commercial electronics.
Law enforcement also has additional undisclosed methods to avoid detection by systems.
Or maybe just..
input: USB HID v1.11 Mouse [Logitech Logitech USB Optical Mouse] on usb-0000:00:1d.1-1.3 the chassis of the servers was opened and an unknown USB device was plugged in only 30-60 seconds before the connection was broken.
In which country did this happen?As an European I expected the US/EU governments would keep their hands of Tor because dissidents use it in countries where US/EU want regime change.
$ whois 77.95.229.11
No canary in this update.
Several nodes are going to go back online and are being requested to be un-blacklisted. "I have emailed some of the DirAuths to remove several nodes and IPs from the blacklist that we feel confident have not been breached or compromised in any way."
Also, warning people not to use those mirror sites is a responsible reaction to possible compromise.
Other than that, I agree, I don't see what the point of this would be. Especially when there was some early warning. It is possible that the warning from a few days ago is entirely unrelated to this incident, though.
Maybe this is related to the Sony hacks, the authorities could know about a forthcoming data leak or threat. Taking away a major source of anonymity could prevent the information getting out.
Also, IMO it's unlikely that these events are unrelated.
1. Tor says they might get compromised.
2. Guy's exit node gets compromised. an attempt to incapacitate our network in the next few days through the seizure of specialized servers in the network called directory authorities.
- https://blog.torproject.org/blog/possible-upcoming-attempts-...Given that they're often run in datacentres (either colocated or within a VM) - wouldn't a USB device capable of scraping RAM and dumping a list hosted .onions be quite practical for law enforcement purposes?
They're obviously finite amount of datacenters in each country/jurisdiction that accept bitcoin or sell VPSs.
Any thoughts? Comments?