Source Code Similarities Between NSA Malware and 'Regin' Trojan
spiegel.de
spiegel.de
Shouldn't we also assume that this malware, having been in the wild for "10 years", could have simply been modified and thrown into the NSA tool chest? When applying the same level of scepticism from the Sony hack, nothing in this article represents real proof to counter relevant arguments against US attribution.
Regardless, the Spiegel assumptions or slant is worthy if for nothing else than to teach everyone the issues with attribution, whether applied to greater or lesser evils.
"In the QWERTY code, there are numerous references to cricket, a sport that enjoys extreme popularity in the Commonwealth."
In the immortal words of John McEnroe, "YOU CANNOT BE SERIOUS!?"
Just playing devils advocate here.
The alternative is to do as the USG did and immediately jump to conclusions based on not that great evidence. If they don't give others the benefit of the doubt why should we give it to them?
If, on the other hand, your goal is to flame people who have done bad stuff when the opportunity arises, then yeah, go for it.
This is why I think cyberwarfare represents one of the most fascinating areas of exploration for political science students. In addition to the collective psychological affect from attribution complexity (further discussion if interested https://medium.com/@cyphunk/the-nature-of-conflict-is-changi...) there is also the breaking down of the 2 state/coalition actor assumption. The actor could be from a known state enemy, an unclear enemy just disturbed by your trade/sanctions policies, some activists with a cause or a bunch of people from b/chan doing it for the lulz. The absurdity of the US response and attempt to protect some lousy hollywood comedy only illustrates this change of environment all too clearly.
You are suggesting that a tool that has been around for 10 years was picked up and used by NSA/GHCQ. Even if we grant that, the sophistication level is a bit more than "simply modified". When is a fork no longer a fork because the code base has been modified/improved?
With your argument, one could go back as far as they wished - NSA takes an idea from academia and implements it, then we just say 'oh well, it was the univeristy who came up with it, not NSA as they only used it'
Also I think the remixed and implemented idea from academia applies less. It would be more like taking the paper from one journal, changing a few paragraphs and publishing it in another. And assuming these journals had a policy of publishing without names, how can we know who the author is in all prior journals when we eventually find a way to attribute one author to one journal?
We have something out in the wild (Regin) which contains a component (QWERTY) which was leaked in the Snowden documents, however it is quite possible that both descend from a common non-NSA source (Putative) such that:
P (non-NSA)
/ \
Q R (non-NSA)
(NSA)
Furthermore it is possible that in fact P = R, and that Q was derived from Regin rather than the other way around. Lots of possibilities are out there. We don't really have proof that P = Q and that therefore R also belongs to the NSA.The issue is that we can attribute malicious attacks to R, and the article seems to be suggesting that therefore we should attribute these to the NSA. The reply by cyphunk is saying that this is a dangerous logical leap.
Given the relative popularity of cricket in the US vs. the rest of the world, it's more likely that this was written outside the NSA.
"It's just not cricket"
This is clearly not source code.
Or journalists being journalists.
Or both.
Source code has the word "source" in it. Unless the original human wrote it directly in assembly without comments or macros (from his padded cell at the asylum, naturally), it is obviously not source code.
It may be usable in the same way as source code, but since it was produced as the output of a program that had an input closer to the source, it cannot be the source.
I imagine the compilation process like a stream. The source is the origin of the flow. All changes made there propagate downstream. Some streams are short, like those with M4-processed assembly. Others are longer, with MSIL or JVM intermediate code. Linked libraries are like tributaries; they have their own sources. The end product is a single river, which fans out into a delta for each supported processor architecture as it nears the sea of end users.
But let's hear your arguments, I'm curious.
that's assembler
I would love to see the actual source code of regin. What they've actually published is useless to me.
Not that I think nation-state malware is, you know, strictly cricket. (Quite the opposite, I've always said it was an irresponsible and reckless path, all the way back to the 1998 era.)
Leaves us back with the "How do we fix this?" problem. And "how do we find what replaced STRAITBIZARRE"?
Edit: More clearly written than my comment: http://lesswrong.com/lw/ih/absence_of_evidence_is_evidence_o...
But basically, people have already come to a conclusion. If the comments said "go <Virginia sports team>", that'd be considered evidence of made in the USA. And if the comments say " go English sports team " then that's evidence of have in the USA, because obviously comments are misleading.
Why not go recursive? They wrote about cricket because they wanted to frame the Americans, who always write misleading comments to frame the Brits.
The way I would implement it is that the keyboard has a switch to enable this SSL type communication. Then the keyboard can perform a Diffie–Hellman key exchange with the current process. As a result any other interaction with the OS would become impossible until that process is terminated - basically disabling all OS related shortcuts etc. This would allow true end to end encryption - even on compromised systems (as long as the kernel code isn't modified to allow accessing the memory of other processes).
The only similar thing I've heard of is the "Secure Attention Sequence" in Windows. That is, pressing CtrlAltDel before entering credentials lets you be sure an application is not mimicking the logon prompt. But of course if the OS is compromised (like by loading a driver that intercepts such keystrokes, like VMware Enhanced Keyboard) all bets are off.
Think about it, the OS is executing all the code for the app, and storing all the memory.
This is also why there is a push for trusted computing. Being able to have your processor, OS, etc be able to verify they are running a trusted configuration is a powerful thing. It makes the owner of the computer in control. (The downside is when the user is not the owner, but would like to be, then they get upset at restrictions.)
You MUST be a security professional! Only those have such a distorted view of reality!!!!
This is kind of what the kernel is for, though: if you can't modify the memory of other processes you can't handle IO for them. Hiding data in plaintext from the OS is basically impossible. Nearest you can get is heavy obfuscation (Skype) or communication to a secure hardware bastion (TPMs for DRM or otherwise, ARM TrustZone).
What might be more interesting and useful is secure communication between a remote website and a non-PC device. Kind of like PIN pads, but more user friendly.
It might be easier on a simple DOS like OS, where IO is m can be straightforward and handled by the hardware pretty much.
`Der Spiegel reported in November 2014.......`
`Fox IT found Regin on the computers of one of its customers, and according to their analysis parts of Regin are mentioned in the NSA ANT catalog under the names "Straitbizarre" and "Unitedrake".`
Pre-9/11 this is also how the US worked. The UK spied on the US and the US spied on the UK, thus both subverting national laws, they then shared intelligence with one another (which is legal) and thus the loophole was born.
This is actually the system the US is going back to, it is becoming politically unpopular for the NSA to spy on American Citizens, so GCHQ will likely take over the majority again, the reasons they couldn't after 9/11 was that the workload increase too much in too short a period, and the systems didn't yet exist.
Even now, it's well-documented and well-understood that all the first-world allied nations have varying degrees of intelligence-sharing relationships with their SIGINT programs. For example, with the NSA, you have the Five Eyes countries, and also Tier 2 countries like Germany.
I tihnk what also holds them back a little is also the fact it's amazingly hypocritical for them to complain too much, because every industrialized country is spying on every other industrialized country, allied or not. Of course, some are bigger targets than others. The US is obviously the biggest target, but there's smaller scale stuff going on too, as between France and Germany. According to Germany, France is the "evil empire" of industrial espionage perpetrated in part through their SIGINT programs.
The focus on the USA, and the NSA, is misleading. The NSA's role is probably comparable to the US government at large's role in world politics, (biggest, most influential) but all other nations are complicit. I don't intend to sound mean, but I feel like the attitude that so many people had in the wake of the Snowden revelations, that spying on allies was unheard of, unexpected, evil, is breathtakingly naive and historically and contextually unaware, and almost like some kind of twisted expression of the stereotypical American arrogance, that only Americans could commit so great an evil. This is an old, old, old game that has always evolved with technology.
I guess I rambled on a bit there. Sorry.
Also, IIRC this has been talked about for a long time... I'm pretty sure I read about this practice initially in the 80s/90s, probably in reference to Libyan sponsored terrorism in Europe.
Heck you can almost read the above claims verbatim here:
https://en.wikipedia.org/wiki/UKUSA_Agreement#Controversy
> During the 2013 NSA leaks Internet spying scandal, the surveillance agencies of the "Five Eyes" have been accused of intentionally spying on one another's citizens and willingly sharing the collected information with each other, allegedly circumventing laws preventing each agency from spying on its own citizens
I wouldn't go so far as to call it a "fact" but based on several leaks, books, and news sources it is likely more fact than fiction.
If you think about it from the lawyers' perspective, it goes something like this:
I(a)) A can gather data on BCITs.
I(b)) A cannot gather data or cause data to be gathered on ACITs.
II(a)) B can gather data on ACITs.
II(b)) B cannot gather data or cause data to be gathered on BCITs.
III) Data gathered via (I(a)) or (II(a)) is lawfully collected.
IV) Lawfully-collected data may be turned into intelligence.
V) A and B can share intelligence that is gathered by lawful means.
Therefore, A can receive intelligence on ACITs and B can receive intelligence on BCITs, so long as they do not derive that intelligence by gathering data or causing data to be gathered on their own citizens.
Now, this was pre-9/11; after that, who knows what gloves came off?
Another point is that enforcing closure of such stations is rather difficult. You can limit these activities by making noise in the public and declaring diplomats persona non grata, but such things come with a diplomatic price.
BTW, your question reminds me of the activities of Интернет исследовательское агентство. According to reports, they like to raise this kind of points, though sometimes more more aggressively (hence the name "troll army").
[0] http://www.spiegel.de/international/germany/cover-story-how-...
[1] http://www.spiegel.de/international/germany/german-helicopte...
[2] http://www.france24.com/en/20131024-nsa-france-spying-squarc...
[3] http://www.matthewaid.com/post/88066878726/bnd-admits-six-fa...
[4] http://articles.baltimoresun.com/1994-12-21/news/1994355023_... (1994!)
[5] http://www.spiegel.de/international/germany/the-german-bnd-a...
'Some reporters were surprised to learn that the University of Maryland had a "covert" NSA facility operating somewhere on or near the school grounds. [..] "Which facility and exactly where it was Snowden worked is unknown, but the NSA has connections to several university facilities, including the Laboratory for Physical Sciences, the Office of Technology Commercialization and the Lab for Telecommunication Science."'
http://www.motherjones.com/mojo/2013/06/university-maryland-...
Oh, and the University's college hacking team got 1st at the Major League Hacking Championship in 2013, winning over MIT, Carnegie Mellon and Rutgers. https://www.umdrightnow.umd.edu/news/umd-students-win-major-...
There are probably hundreds of other organizations which work 'in partnership' with the intelligence community to develop programs which are essentially used to better their espionage and analysis capabilities. Almost all the Virginia/DC/Maryland area's tech companies are employed in one way or another by the federal government, usually for the military or an intelligence agency.
First upside to the TPP that I've seen, if true.
When a government writes it, nothing happens.
After all, you could use this malware to spy on your child's use of your PC, which is legal, right?
When a government kills someone, nothing happens.
Nothing new.
When I was a youngster, being Canadian meant that Incould travel anywhere and be fine. Granted, there was a > 50% probability that the other Canadians I would meet were really Americans, but that was nothing. My country had a solid international reputation. Now???
Edit: Sorry, I didn't see it was paywalled (I'm not a subscriber of that site). I now see that it counts your visits and disable itself after a few times. "Private" browsing seems to solve the problem.
But from old memory: Hilux trucks are built amazingly and have awesome reliability. Real, authentic, Hilux trucks are thus valued by freedom fighters/terrorists in Afghanistan. Canada donated a bunch if real Hilux trucks to Afghanistan, and these vehicles had a Maple Leaf logo. People associated the Maple Leaf with the quality of Hilux, to the point of at least one person getting a Maple Leaf tattoo to signify his quality.
The alternative, unfortunately, is that either organized crime or non-democratic governments (or a combination of both) would be the biggest meanest hackers.
And hacking doesn't really scale. Mass surveillance just through attacking individuals with malware isn't possible, because of limited "talent" and a fear for exposing the tools, like just happened.
Building backdoors into systems or encryption schemes, on the other hand, isn't exactly hacking but does scale well to undiscriminate spying on millions of people.
The main issue is that intelligence and law enforcement agencies in the western world aren't bound to judicial control as tightly as they should. It also seems that a majority of voters either consent to these powers, or don't care. When politicians want to appear "acting decisively" after terrorist attacks, or foreign hacking incidents, it's not just because they like to do so. They know that, if they don't, voters will disapprove.
Also, surveillance of criminal and terrorist organizations without offensive capabilities is impossible.
Snowden has showed this to be absolutely false. "Oversight" has been the nominal preventative for spying on our allies for decades, and it has always failed because these are spy agencies we are talking about. Their nature (and job description) is to do things in secret. You cannot oversee what you cannot see. The NSA has a fundamental incentive to hide as much of its activities as possible, and American politicians have a fundamental incentive to look the other way lest they appear "soft on terrorism" or some such nonsense. What few laws constrain the behavior of the NSA, GCHQ, etc are routinely ignored or "interpreted" to their own favor.
You cannot let the technological genie out of the bottle and expect a close watch on the genie to keep it under control. Mass surveillance technology is a pandora's box that you can't control.
Hacking tools are not mass surveillance technology. Trojans just don't work for that.
And if you can't control how these agencies use their abilities, how do you propose to take these away from them? Adequate oversight is easier to achieve.
"Sorry, would like to tell you but doing so would be against the interest of the state ..."
How is that sentence anything other than a non sequitur?
We're talking about NSA overreach, and attributing Regin and/or Qwerty to the MSA or the 5 eyes. Why are you fudding up the Russians and the Chinese?
They should be using their capabilities to increase the security protections they have in place. For example, if they discover a vulnerability, they should work to get it fixed, instead of leaving it there so everyone is vulnerable, just so they can use it to attack others.
How would that fit in a democratic government?
If government agencies attack ordinary citizens or companies, without legitimate authorization, than it's not a problem of means or tools but rather a problem with democratic or judicial oversight on these organizations.
The thing is that without those "competitive advantages", I fail to see how they can have an advantage over the bad guys. Playing offense, when the need arises, won't cut it. You're gonna have to "lay the foundations" so to speak, for you to be a successful attacker.
So basically we reach the old, but not so tired, question of how much of your freedom you're willing to sacrifice, for your government to be the "meanest of them all"
The alternative to offensive hacking is to include backdoors in the encryption technology used by everyone. I think that this is causing more harm than good.
In order to attack(successfully), they employeed various techniques; from weakening security systems and protocols, to actively endorse weak crypto schemes. What about these? And for the sake of the argument, let's say that they have the best of intentions and they don't plan to use those against law abiding citizens.
Do you agree with these actions?
So maybe GP means he wants a well-designed democracy with a strong military, including infosec. Yeah, good idea.
What government provides is a practically viable method (kludge?) to reaching consensus on issues where other more reliable methods (like science) fail to do so.
Should "we" build up an army and enslave our neighbor nations or should we rather build up and industry and fabricate something all of them want to have (but can't produce themselves) and sell it to them for horrendous prices? Both alternatives have the same effect, but which one is "better"?
Science can't provide conclusive answers here .. so what do we do instead? In the past we'd ask some designated mastermind deriving his legitimacy from god or a certain bloodline and such. These days we tend to vote on who that mastermind should be or create institutions that allow for more direct control by the nations subjects.
But nothing of this has to do with picking a bigger bully. How big of a meanie you (as a nation) want to be is entirely orthogonal to being a government (or a democracy).
There are also good reasons to argue that the US is not democratic: http://www.bbc.com/news/blogs-echochambers-27074746
The NSA does have democratic oversight. It is controlled by the executive, legislative and judicative branches of the system. That this control is inadequate in our view, doesn't matter for the question whether or not the NSA is part of a democratic system.
It absolutely matters. Without those controls you have a democracy in name only. You could quite happily rig elections, arrest opponents, suppress the population etc, while still claiming to be 'democratic'.
There is nothing undemocratic about those thing as long as a majority of people agree to them - though with rigged elections, you might not be democratic for very much longer. "Democracy" is not synonymous with "respecting my values and human rights."
If enough Americans were sufficiently upset about the NSA, it would be gone. They aren't. It's not even a significant election issue.
That requires that people are informed and able to comprehend the ramifications of their choices. Consider this: Is it still democratic if those who happen to be in charge are busy lying to and hoodwinking a poorly informed 'electorate'?
As for the rest of your comment, it is not democracy simply because a majority agree it is. http://en.wikipedia.org/wiki/Democracy
In short, it really looks like some parts of the US government actively work to keep reporting very favorable or non-existent.
edit - This also makes sense from looking at the word. Democracy is rule by the 'demos', which means 'the people', which includes the minority. Rule by the majority is ochlocracy, from 'ochlos', meaning 'the mob'.
Are we sure of that? Wisconsin Senator Russ Feingold lost his re-election bid. He was the only Senator to vote against the PATRIOT Act in 2001.
Colorado Senator Mark Udall lost his 2012 re-election campaign after being a total gadfly in the Senate Intelligence Oversight Committee.
It strikes me that the NSA is a significant election issue, just not to the voters.
Also, you're kind of arguing about a technicality in the definition of "democratic". Our elected reps often act un-democratically. I hope this is to prevent tyranny of the majority, but I fear that it's just legislative capture.
You've just managed to explain quite succinctly why it isn't a significant election issue.
----
"Congressional oversight of the NSA is a joke. I should know, I'm in Congress" by Alan Grayson
http://www.theguardian.com/commentisfree/2013/oct/25/nsa-no-...
----
A minor quibble, but governments don't provide freedoms and liberties. They restrict them. Hence the word "govern" and its etymology.
Looking back at history, I vastly prefer the balance of liberty afforded by strong governments in the western world to the lack of such control.
Looking back at history, strong governments have been THE source of oppression and limitations of freedoms.
You may be able to defend yourself against your neighbor. What about women and children? What about against multiple aggressors, or ones with better weapons? Turns out, without an effective police force, liberties are distributed a lot less equally...
Steve Pinker explained in a TED talk that hunter/gatherer societies are a lot more violent than modern societies. For example these groups have to launch preemptive attacks against neighbors if only for fear of the other group striking first.
Pro tip: when disagreeing with someone on a philosophical point, it's good form to leave "you" statements out of the debate.
Good day, sir.
[citation needed]
http://rsf.org/index2014/en-index2014.php
https://www.freedomhouse.org/report-types/freedom-world
The U.S. is not exactly at the top in all such comparisons, but certainly "as good or better than most other countries."
Besides, freedom is only necessary for democracy, not sufficient. So his points all remain valid.
Yes, he would have. And in many, he would not need it.
Chomsky is a lot less controversial in a lot of countries outside the US than he is in the US.
I'm sure there are countries where he'd be unable to say what he wants, but there are also a lot of countries (e.g. in Europe) where his political views are reasonably close to mainstream, to the extent where he's no more controversial than the average left wing politician and his main problem would be that he'd be one of many voices saying similar things.
Th test of a country's liberty is better illustrated by the spectrum of allowed speech rather than whether or not an opinion corresponds with the mainstream. And in my opinion, the spectrum of allowed speech is narrower in the average European country than the US.
"Two men, an American and a Russian were arguing. One said, in my country I can go to the white house walk to the president's office and pound the desk and say "Mr president! I don't like how you're running things in this country!" The Russian said "I can do that too!"
"Really?"
"Yes! I can go to the Kremlin, walk into the general secretary's office and pound the desk and say, Mr. secretary, I don't like how Reagan is running his country!"
I wonder what Barrett Brown would say about this topic, if he wouldn't sit in prison right now: http://boingboing.net/2015/01/22/barrettbrown.html
Are you aware that (h)activists from around the world do not travel to the USA because they fear the consequences, having their equipment seized or being imprisoned? Do you know why Laura Poitras is living in Berlin right now?
Meanwhile Turkey has to remove pages from FB because they're "offensive", not to mention other issues that happens in the ME.
I am certainly not saying the US has the better situation, and Europe looks good, unless you "offend" some groups of people...
And if you think censorship by DMCA is bad in the US you should know the German GEMA.
Please note that freedom from critique of a country usually is much stronger while being outside of that country.
This is rather about free speech than about copyright issues which GEMA and the DMCA deal with.
Have a look at the Freedom of Press Index, where the USA are behind Botswana and El Salvador: https://en.wikipedia.org/wiki/Press_Freedom_Index
You mean, in position 46 of 180? Higher rated than Italy, Taiwan, South Korea, Chile and Japan?
Not the best position, surely, almost on the Top 4th
Nice attempt of data manipulation, btw, also implying that Botswana and El Salvador should not have good freedom of press "of course"
The answer being yes, according to reputable sources, Chomsky would have that liberty of critique in many other countries and in several countries it would appear that he would have more.
I ought to face jail for doing those things. So should Brown.
I hope this isn't some weird "because some politicians might get away with obstructing search warrants and issuing death threats, then journalists should be able to get away with it, too." You don't fix a carve-out with more carve-outs.
I'm sure he is, and I agree with him.
On the less serious side, it's like that old joke about American and Soviet journalists, who discuss freedoms and yelling "Down with the USA" at the Times Square and Red Square, respectively. You can do the same at both places without fear of consequences.
As far as your joke goes however, have you tried standing in Times Square yelling "Down with the USA"? I wouldn't think it would be that safe an enterprise.
http://en.wikipedia.org/wiki/Press_Freedom_Index
There are 45 countries that journalists rank as having better press freedom than the USA.
edit - For comparison, I just looked at the "Freedom of the Press" report by US NGO Freedom House. It has 21 countries with a better rating than the USA.
Attacking a computer means finding a bug and keeping it secret until you use it to attack said computer. Defending a computer means finding a bug and disclosing/fixing it so that nobody can use it to attack said computer. I hope it's obvious to you that these two ideas contradict each other.
Please let me know if you have questions. This is very important and not intuitive at all. I'd love to help you understand it better.
>If you have exploits available to you, you're making yourself attackable.
Do you?
I also didn't propose to uncompromisingly favor attack capabilities. I still don't think effective cyber defense is possible on a national level without leading the edge on offensive abilities as well.
---
I'm gonna explain it a third time. (Looks like you don't want to talk to me.)
Having offensive abilities means having one or more remote exploits ready to use. Having remote exploits ready to use means sitting on undisclosed vulnerabilities. Sitting on undisclosed vulnerabilities means weakening the security of the people you're supposed to protect.
It's quite simple, really. You can't remotely attack a computer without remote exploits. I only count remote attacks as "cyber warfare".
I think it is fair to say they all use the same tools!
Then the government says nothing, and bad people get prosecuted.
AFAIK there are no widely accepted international conventions that would forbid, say, USA goverment to install malware (intentionally or unintentionally) on a german user's computer; if you can name as specific one then that would make this discussion much more interesting. International law is not particularly restrictive to the rights of governments to attack each other or their citizens if they desire so; the citizens don't have much recourse in international courts if a foreign government accidentally killed them, much less damaged their computer.
There's very little doubt the NSA/GCHQ use the tool.
Here's some background reading:
https://news.ycombinator.com/item?id=8649402
https://news.ycombinator.com/item?id=8653454
https://firstlook.org/theintercept/2014/12/13/belgacom-hack-...
[1]: http://www.businessinsider.com/isis-captured-a-key-syrian-ai...
Who has that idea? I don't see anyone saying that.
also: http://www.nytimes.com/2012/06/21/world/middleeast/cia-said-...
People usually supply corrective upvotes if the downvote is unfair.
Or make it semi-private, and only the commenter can see the list. But that would just encourage useless activity as commenters selectively out their up and downvotes.
I'm not sure what new downvoting trend you're referring to, but I'm pretty sure there is no new anti-anti-Western-government trend on HN.
There's a strong cognitive bias toward seeing one's own views as being treated more unfairly. But as far as we can tell, there's nothing so systematic in voting behavior on the site.
I'm going to detach this subthread and mark it off topic now.
I don't know why HN doesn't do these types of crazy experiments in social/political science. I'd have a heigh day.
Regin details: http://en.wikipedia.org/wiki/Regin_(malware)
Sony hack details: http://en.wikipedia.org/wiki/Sony_Pictures_Entertainment_hac...
Not saying NSA wasn't involved as I don't really trust my government, but when I read the article and saw Kaspersky mentioned, that was the first thing that popped into my head.
In this specific case Fox-IT (Netherlands) said the same thing. They based the claim not on the "source code" but on the fact that Regin was part of programs/processes of the NSA department ANT and mentioned in some leaked presentation slide of them (Source: http://www.spiegel.de/netzwelt/netzpolitik/trojaner-regin-is... (German)).
Thinking about infosec companies that publish impactful findings from time to time there is F-Secure from Finland, Fox-IT from the Netherlands, Symantec from the US and Kaspersky from Russia. Does anyone know about important Chinese/Japanese information security companies?