Further ties of NSA to Equation Group hackers
arstechnica.com
arstechnica.com
As the NSA et al get more [unchecked] power it will become more corrupt, isn't this like, the law of nature?
People say "This is exactly what I want the NSA to do -- foreign espionage, just like always" -- Sure, there's past precedent for this being a good idea.
How far are you willing to take this? How much power should one [or small group] employee at the NSA have?
Right now, Right this very minute, I bet if [Employee X] wanted you silenced, it would happen, and no one would bat an eye. Is that the world you want to live in? What road are we taking?
No, we shouldn't stop all foreign espionage [anytime soon].
No, I don't want Employee X doing queries on oil activists for the purposes of muffling them.
My solution? Take them to court, and establish clear oversights. This is what keeps getting said.
EDIT: CIA changed to FBI/Hoover
We already know the NSA's power has been extensively abused with "SEXINT" (stealing people's private photos for personal enjoyment and likely blackmail), JTRIG (discrediting people not accused or suspected of any crime), PRISM (monitoring every communication via to/from data and other private data), not to mention others.
None of these things relate to foreign espionage or generalized signals intelligence. Snowden said it himself: the NSA is only about SIGINT in their press releases. Really, their purpose is social control and consolidation of power. Their spying does not stop at members of the public or foreign publics; whistleblower Russ Tice said long before Snowden that the NSA had a tap on Barack Obama as early as 2004.
I would just like to remind everyone that surveillance is about control, not security. Some may claim it's security through control, but that's not the social contract I was taught to understand my country worked under.
So if someone, say Europe, became more powerful than the US they would be extremely corrupt. Where does that tautology leave us?
Source: https://youtu.be/d6m1XbWOfVk?t=2m45s
They went after General Patreus, Justice Alito and Senator Barack Obama [3:25].
http://www.nytimes.com/2014/11/16/magazine/what-an-uncensore...
I agree, but there's no proof that the Equations Group/TAO were conducting operations without oversight, so I fail to see why this is a big deal. The fact that the oversight that DOES exist consists of rubber-stamping is the fault of either ineffective overseers or unscrupulous intelligence officers. It has no bearing on the people writing the exploits.
Those are absolutely real issues, but they don't apply to this case in any apparent way. I'm all for Intelligence reform but railing against the evils of the NSA when discussing a highly effective portion of its legitimate purpose just muddies the waters of the debate.
I'm not saying contractors are hives of abuse or anything, just that if there is abuse, it seems far more likely to happen there.
I'd also say the more senior the position, government or not, the more likely they are to be able to get away with it.
Most worrisome are the well-connected people who sit at the intersection of state and corporate power. For example, former intelligence officials who frequent the revolving door and take high-level executive positions at major contractors. These are people you wouldn't want to cross.
Another thing I've gleaned is that Mallory spends incredible amounts of money to undermine the stability and security of our internet & hardware. We cannot compete with them on that level; we don't have the means to stabilize as quickly as they destabilize.
I actually want to know if anyone has any ideas about what to do in this reality. What do you do when constructive and legal means both fail? Seems like Mallory can get away with anything.
"saying only that the operation had to have been sponsored by a nation-state with nearly unlimited resources to dedicate to the project."
Hmmmmmm, you mean like Russia or China?
"malware developers endeavor to scrub usernames, computer IDs, and other text clues from the code they produce. While the presence of the "BACKSNARF" artifact isn't conclusive proof it was part of the NSA project by that name, the chances that there were two unrelated projects with nation-state funding seems infinitesimally small."
Ironic considering this is almost the same scenario people were using in the Sony hack. Saying the code was similar in other attacks used by North Korea while most of the Info Sec community was saying it didn't believe their findings since malware can be reused, shared and distributed - but apparently all that goes out the window in this case?
I'm starting to have NSA fatigue for this stuff.
Kaspersky seems to be the only player actively trying to tie EVERYTHING they find to the NSA. While most of the stuff (flame, stuxnet) have been confirmed by other companies, I'm starting to wonder if Kaspersky has an axe to grind here as well - his ties to the FSB and the Russian government are well documented.
I'm not dismissing this out of hand, but I'm starting to take a lot of their claims with a few grains of salt.
http://eugene.kaspersky.com/2012/07/25/what-wired-is-not-tel...
Except that part about Kaspersky. Or do you not believe the Wired article from 2012?
http://www.wired.com/2012/07/ff_kaspersky/all/
"Kaspersky’s rise is particularly notable—and to some, downright troubling—given his KGB-sponsored training, his tenure as a Soviet intelligence officer, his alliance with Vladimir Putin’s regime, and his deep and ongoing relationship with Russia’s Federal Security Service, or FSB. Of course, none of this history is ever mentioned in Cancun."
I'm also glad you actually read my entire post before gang banging your keyboard with your response. I said I don't dismiss this outright, but I've become somewhat skeptical of Kaspersky. He's done a good job exposing NSA activities while seemingly turning a blind eye to Russian state hacking activities. I think its fair to ask why he's catching all these NSA sponsored groups, but was totally silent about a Russian group of hackers who have had access to our critical infrastructure since 2011:
http://www.washingtontimes.com/news/2014/nov/6/russian-hacke...
Or maybe the JPMorgan Chase hack?
http://www.usatoday.com/story/money/business/2014/10/04/jpmo...
Again, like I said in my post (which you clearly didn't read) I'm getting NSA fatigue. If other Info Sec companies came out and said they had found these, in my eyes, they would have more credibility than Kaspersky. It just seems like the only stuff he finds are NSA tools and I have to consider his background before I jump up and say this is a smoking gun. Similarities? Yes. Like I said in my post, this is the same thing other Info Sec people dismissed about the Sony Hack, why can't I use the same argument here?
You want a smoking gun? Get the president to admit it like he did with Stuxnet:
http://www.businessinsider.com/obama-cyberattacks-us-israeli...
"Administration officials revealed to Sanger that the Stuxnet virus was developed by the National Security Agency (NSA) and Israel's Unit 8200 (i.e. Israel's secretive cyber arm) to "become the attacker from within" Iran's nuclear facilities."
While I fully support limiting the mass surveillance, stopping the NSL practice, and indiscriminate data collection being performed (along with other Star Chamber-esque behaviors), it is pure folly to expect targeted spying to be limited technically or not take place. It's simply too valuable to be able to monitor $espionage_target's computations.
They were doing exactly what NSA was supposed to do. We moved from NSA should not spy on everyone to NSA should be toothless ...
Of course you can't prevent efforts to break into systems. But you can spend enough resources on making it difficult and fruitless that it is reasonably certain that our data can't be accessed by spooks of any nation.
We get what we pay for. Right now we spend vastly more on surveillance than on privacy and security. Guess which one we have more of?
Also, are we really thinking "Grok" is some sort of identifying name/tag?
The leaks from Snowden that I've read thus far they do not mention anything about what TAO does. They are hinted at as the "big guns" you go talk to when you have actionable intelligence.
As a foreign citizen of the US (or UK) where this type of activity seems king, I'm threatened and consider these activities hostile and reason enough to not do any sort of business with US based companies or US residents.
There are no legitimate spying efforts, these agencies from day one have used and abused their positions to misdirect the public, start wars, spy on those they had no business spying, hack infrastructure on foreign land (which should be considered an act of war pure and simple), and the list goes on, including torture and murder.
I have no respect for these agencies and the work they do and they have no business existing.
This could have various consequences, but one obvious one is how it affects a jury. It would probably be a lot easier to conclude there is a reasonable doubt the accused did not commit some type of computer or network crime when the NSA is attacking so much infrastructure. If the NSA was known to be targeting legitimate targets with limited, targeted activities that did not affect everybody else, the doubt that any random computer crime could have been the NSA's responsibility would not be reasonable.
> or that evidence of NSA activities would be admitted in trial.
What repercussion should the US have received if the Iranian uranium enrichment had exploded and thrown fine radioactive dust into the environment? Would NSA take responsibility for the deaths and environment damage for their spying, or would they hide and put the blame on a third-party?
The answer to your question is that the potential for damage that malware has, and the responsibility we expect from those who make it is extremely disproportional. It is a big deal, and the risk/cost to human lives is why we should be very careful allowing organizations to spread malware.
That's usually the point of this sort of work, yes. Espionage isn't just about acquiring information, it's about spreading false information, and dragging your enemies through the mud.
I don't approve of this shit, but "the them" have been up to it since forever, and the answers to your queries are a straightforward: "None", "No", "Yes" - unless someone else's intelligence agency outwits them, and has a media mouthpiece that can't be drowned out by chaff.
Edit: Your post got me thinking about Chernobyl and Reagan. The CIA had a programme to export defective technology to the USSR - which (apparently) culminated in http://en.wikipedia.org/wiki/Siberian_pipeline_sabotage
One has to wonder. Yes, I'm aware that the questions as to how Chernobyl are well answered, and all the rest, case closed, etc. - but one still has to wonder. Nothing should be trusted 100%.
People should probably not kid themselves about geopolitics and military competition vanishing if we somehow manage to regulate "electronic warfare".
I know that you didn't mean for your comment to be taken literally but there is literally zero chance of enemy airplanes invading US skies and dropping munitions from great heights onto buildings with people in them. It is a silly thing to say and it does nothing to justify the current situation vis a vis the NSA et al. Try not to hyperventilate.
It's an ugly situation, since Iran's geopolitical strategy involves gaining concessions through a game of chicken with the US counter-proliferation regime. At some point, unless it's resolved in a way that ends the Iranian nuclear arms program, it is going to end in explosions, and scores of lost lives.
This is a descriptive observation, not a normative one.
It is also true that if Iran somehow arranged for explosions at US nuclear facilities, the USG's response would be world- historically horrific. Any reasonable observer knows this to be a fact, so we can acknowledge it without getting into philosophy and move on.
The chances of a full-blown Iranian nuclear weapons program not eventually bearing an attack by explosive munitions are pretty close to zero; see Osirak. If malware that only really impacts centrifuges forestalls that for a couple years, I see it as a good thing.
[1] https://www.schneier.com/blog/archives/2013/12/more_about_th...
I'd actually like to see the outcome of that. By all means, please go ahead and do this -- in Brussels.
As a citizen I'd be pretty alarmed by NSA-level activities of my local agencies because quite frankly it's way too excessive and privacy is a lot more important to me than the supposed security massive and not very transparent surveillance activities alledgedly brings. Most importantly it just shows a worldview that doesn't care about privacy at all and just wants to absorb all data. Which is very alarming.
In the past, you had "privacy" speaking with someone in your own home. Even though the vibrations could theoretically be felt through the walls, we didn't have sufficiently sensitive instruments to recover that into speech. Now we do, and that technology is never going to be uninvented - it's only going to get better.
If you can't adapt to changing times, no hard feelings. The same thing happens every generation. The world can move on after you grow old and die.
It's fairly unclear what the NSA is supposed to be doing. They appear to be attempting to destabilize the internet in a way that is advantageous to them and them only.
In conventional espionage sabotage does not have the same footprint as intelligence collection. They are easier to tell apart. For this reason merely copying the rules and norms of HUMINT and SIGINT into computer network operations is very dangerous.
If you want your data secure and private, use and develop systems to allow that (pgp for start)
If a regular person created tools such as what the NSA made they would get in a heap of trouble, even if they did nothing with them.
If the NSA does it; it's ok? This is the kind of logic that leads to abuses of power. Government are just people, and they are just as likely if not more likely than the average person to abuse their power.
What does the government need to protect users and corporations from that sort of hacking ? Is the government's role only to attack or in what levels can it help safeguard our online activities ?
Once the NSA global spying was revealed I was hoping to see more reports of governments finding and shutting down the monitoring probes that surely need to be installed.
Anticipating a comment that comes up in threads like this most of the time on Hacker News, I will mention why I am not overly afraid of NSA controlling the whole country by blackmailing politicians. I don't believe NSA blackmail can or will happen in general, for reasons I have mentioned before here on HN. One of the most common kinds of comments here on Hacker News about issues like this is a comment that ASSUMES that if government leaders are under pervasive surveillance they are all afraid of blackmail. But I don't believe that, because some government leaders and some political candidates are essentially shameless. Even after they are caught (by old-fashioned journalism, or by a jilted lover or some unrelated criminal investigation) doing something unsavory, they are still willing to run for office, and SOME ARE REELECTED. United States Senator David Vitter was reelected in 2010 even after a scandal involving behavior that I would consider shameful,[1] and the antics of former DC mayor Marion Barry[2] are probably still notorious enough that they don't need further discussion here. In short, I call baloney on the idea that NSA can keep politicians on its leash simply by knowing their secrets. Some politicians have PUBLIC lives full of dirt, and still get elected and influence policy anyway.
The other reason I don't believe this HN hivemind theory of politics is that I by no means assume that everyone in politics lacks personal integrity. Some politicians, I am quite sure, could have all their secrets revealed only to have voters think "Why is that person such a straight-arrow? Why not have some fun once in a while?" The simple fact is that there is value system diversity in the United States electorate, and there is personal conduct probity variance among United States politicians, and there isn't any universal way to unduly influence politicians merely through even the most diligent efforts to discover personal secrets. If politicians think that NSA is going too far (as evidently several politicians from more than one party do think), then they will receive plenty of support from the general public to rein in the surveillance. (Obligatory disclaimer: Yes, I am a lawyer, who as a judicial clerk for my state's Supreme Court used to review case files on attorney misconduct, and, yes, some of my law school classmates are elected officials, including one member of Congress. I am absolutely certain that there are enough politicians ready to mobilize to roll back NSA surveillance programs if they really think the programs are excessive in their scope.)
[1] https://en.wikipedia.org/wiki/David_Vitter#D.C._Madam_scanda...
[2] https://en.wikipedia.org/wiki/Marion_Barry#1990_arrest_and_d...
This seems a very paternalistic view of politics that assumes politicians inherently know better than the public and that the people here are overblowing the dangers of NSA surveillance. I can imagine an alternate universe where there was no one like Snowden to make public the breadth of surveillance and the system was allowed to run unchecked. Isn't it a worrying sign that the system of checks and balances required a whistleblower? Before that, the government was writing laws that were eroding privacy without the knowledge and input of the public. That's not how things are meant to work in a democracy.
What if some politicians manage to get an insider peek at the data NSA has ? NSA does not necessarily need to seek power on its own, but it can become a tool of control, usable by people who might want to make use of it.
Information is indeed power. The problem with that surveillance program is that it's a secret warchest of data, it's secret because it's purposed for criminal investigations. Anyone who can manage to bribe or have enough influence towards NSA employees could theoretically make unimaginable use of this data. It's having a monopoly on information. It also create distrust in computers in general, which is not necessarily a good thing.
The problem is not privacy, the problem is the possibility of small groups having privileged access to mandatory, potential sensitive data about anyone. That data is supposed to be secret because it's for investigative purposes. But it's done on everyone, without warrant, it's a recipe for a huge political mess.
This risk is way too high, compared to its advantages. You can't dismiss that risk.
First of all, having being part of the action arm of the government (Marine Corps) I can say from experience that I don't trust any of the fuckers in DC, and I think your attitude is naive. Secondly, you are setting up a strawman fallacy by saying that the comments you most frequently see assume that if leaders are being watched they are all afraid. I haven't seen that claim made anywhere, even on conspiracy websites.
No, control is about a toolbag, and some tools work on some people and some tools work on others. Just like if you were trying to recruit a spy to spy on his country for you. Maybe blackmail works on person A, but maybe person B just wants his kids to go to a good US college. Maybe person C just needs some money. Not all the politicians needs to fear surveillance blackmail because there are other methods for those who don't succumb to that particular tactic.
"The simple fact is that there is value system diversity in the United States electorate, and there is personal conduct probity variance among United States politicians,..."
More strawmen. What does "probity variance" even mean? Probity means completely honest, so how can there be variance on being completely honest? Not to mention even saying the word probity in a sentence targeted at US politicians falls flat on the face of history.
"and there isn't any universal way to unduly influence politicians merely through even the most diligent efforts to discover personal secrets"
Nobody is saying there is a universal way to compromise or unduly influence politicians, as per my previous statements. The fact that you are ignoring all the other ways to unduly influence them seems striking, especially given your own claimed position as a judicial clerk for your states supreme court. Either you know about them and are omitting them on purpose, which is dishonest conversation (I'll refrain from lawyer comments), or you don't, in which case you are out of your depth in your commenting. All I see in your statements is a string of logical fallacies with no substantive comment of any note. (your first paragraph excepted)
Also, regarding the idea that there are a handful of straight arrow politicans. I don't disagree entirely, though I may question how straight, but I think you might misunderstand their power position in the beltway. They may be upright, but if they sit back and don't do anything about the egregiously unconstitutional acts occurring around them they are guilty by association.