9 ms·
FBI Says a Mysterious Hacking Group Has Had Access to US Govt Files for Years
- lowglow 11y agoMHG sounds like a really good hacking group name.
- hackuser 11y agoIs the government or anyone else trying to develop secure systems? I don't mean stock technology (Intel/Arm + Windows/*nix/etc.) retrofitted or 'locked down', I mean new tech built from the ground up for high security. Given the exceptionally high value to foreign governents (and other actors) of breaking into US government computers, the latter approach seems like the only potential option. The stock tech just can't be secured effectively enough, IMHO. ---- EDIT: Answering my own question to a degree, here are presentations on High-Assurance Cyber Military Systems (HACMS), which apparently utilize seL4: http://www.cyber.umd.edu/sites/default/files/documents/symposium/fisher-HACMS-MD.pdf http://www.cyber.umd.edu/sites/default/files/documents/sympo... https://www.youtube.com/watch?v=YqRdbgRPYw8 https://www.youtube.com/watch?v=YqRdbgRPYw8
- paavokoya 11y agoIf you read the headlines enough, you'll notice the U.S. govt is doing the exact opposite of developing secure systems by forcing corporations to weaken their security.
- avs733 11y agoI think the commenter was generally referring to developing secure systems for themselves. The NSA 'owns' at least one semiconductor fab[1] in Texas, and used to (or still does) own another secure CMOS facility in Santa Clara [2]. Add in several facilities owned by defense contractors as well as the facilities at places such as Lincoln Lab. When you have the ability to develop and build your own secure technology, it would seem perfectly 'logical' to force others to use lesser, less secure hardware. [1] http://www.chron.com/news/houston-texas/houston/article/NSA-plant-in-San-Antonio-shrouded-in-secrecy-4604109.php http://www.chron.com/news/houston-texas/houston/article/NSA-... [2] http://www.militaryaerospace.com/articles/print/volume-9/issue-12/departments/cots-watch/nsa-seeking-new-business-for-in-house-cmos-wafer-fab.html http://www.militaryaerospace.com/articles/print/volume-9/iss...
- hellbanner 11y agoEnd of [1]: "The NSA issued a statement acknowledging that an antenna it was using interfered with garage door openers." I didn't know antennaes could interfere with transmission.?
- avs733 11y agoI would imagine it was what was coming out of the antenna... Just another one of those fantastic science/technology/journalistic chain phone calls that result in nonsense being communicated to the public.
- nickpsecurity 11y agoYes. Sandia and others have certified fabs for developing classified stuff. The NSA has their own developments called Government Off The Shelf (GOTS) tools. They also contract out developments from defense contractors through certifications like their Type 1 process. They keep the best stuff for themselves and defense contractors. Here's an interesting example I copied in a design at one point: https://www.nsa.gov/ia/programs/inline_media_encryptor/index.shtml https://www.nsa.gov/ia/programs/inline_media_encryptor/index... Compare that to the average tool for disk encryption. I bet the commercial one leaves off some requirements or countermeasures. ;)
- duaneb 11y agoThey do both. One is worrying, the other is reassuring; clickbait rules dictate the former gets the headline.
- mfoy_ 11y agoYou'd have to go REALLY back to basics... a lot of chipsets have backdoors themselves.. some of which the FBI ironically pushed for. So no matter how securely you make your own OS if you don't also make your own hardware it's all for naught. Also if the government started making its own computers then private suppliers would raise a fuss about "big government" and hurting private enterprise. Also can you imagine the shitstorm ensuing from: "Government insists every tech company bakes in backdoors. Government then has to create its own computers because consumer models are too insecure."
- hackuser 11y ago> if the government started making its own computers then private suppliers would raise a fuss I imagine they'd be designed and built by Boeing or Raytheon or some other major military contractor, just like all the other specialized government equipment.
- dbarlett 11y agoThe NSA has their own fab at Ft. Meade [1] and pays IBM to run one in Vermont [2]. [1] http://www.militaryaerospace.com/articles/print/volume-9/issue-12/departments/cots-watch/nsa-seeking-new-business-for-in-house-cmos-wafer-fab.html http://www.militaryaerospace.com/articles/print/volume-9/iss... [2] http://www.manufacturingnews.com/news/04/0203/art1.html http://www.manufacturingnews.com/news/04/0203/art1.html
- avs733 11y agoand used to have one in CA[1] and owns one in texas as well[2] [1] http://www.chron.com/news/houston-texas/houston/article/NSA-.. http://www.chron.com/news/houston-texas/houston/article/NSA-.... [2] http://www.militaryaerospace.com/articles/print/volume-9/iss.. http://www.militaryaerospace.com/articles/print/volume-9/iss....
- Spooky23 11y agoPretty sure the Vermont IBM facility is closed. Most of the surviving workers are at Global Foundries.
- 11y ago
- gherkin0 11y agoYes. One project is SeL4, which is a provably correct microkernel. I listened to a talk by one of the developers and it sounded like they were getting funding from DARPA. https://sel4.systems/About/seL4/ https://sel4.systems/About/seL4/ I also remember reading on Wikipedia about some proprietary closed-source OS that's used by the US government to work with very highly classified information. Apparently the requirement was that the kernel and every program be formally verified, so it had very limited features. IIRC, it still maintained, but newer versions support a Linux environment for less classified work. Unfortunately, I don't remember what it was called so I can't link to the page. edit: found it: https://en.wikipedia.org/wiki/XTS-400 https://en.wikipedia.org/wiki/XTS-400 https://en.wikipedia.org/wiki/Trusted_Computer_System_Evaluation_Criteria#A_.E2.80.94_Verified_protection https://en.wikipedia.org/wiki/Trusted_Computer_System_Evalua... > Examples of A1-class systems are Honeywell's SCOMP, Aesec's GEMSOS, and Boeing's SNS Server.
- chatmasta 11y agoYou mean like the kind of highly classified information that Hillary Clinton kept on her home server? :) was she running a probably secure microkernel?
- AnimalMuppet 11y agoNot a provably secure microkernel, nor even a probably secure one. Nor, probably, even a microkernel at all.
- eru 11y agoMight have run on a Windows NT variant. That was sort-of supposed to be a microkernel.
- joe_the_user 11y agoThe problem is that at a certain level of government, you will have administrators who aren't technical experts and who have no interest in deferring to the opinions of technical experts. Such folks just don't want to bother with the limitations that a secure system implies, even if such a system became much more featureful than the present ones. They want their Windows/Mac and probably want it for their work-groups. It's not just a lack of technical know-how but a variety of psychological tendencies that stands against this. It's taken a long time for companies to develop UIs that people want to use but the existence of these "easy to UIs" is a barrier to any UI which requires even a small amount of training to use.
- avn2109 11y agoSomewhere in the depths of my brain I recall IBM developing a "secure" architecture from hardware up a long time ago, but the project was killed for some reason. Pretty sure HN user nickpsecurity originally posted about it.
- skissane 11y agoAre you thinking of https://news.ycombinator.com/item?id=10823434 https://news.ycombinator.com/item?id=10823434 The famed IBM "Future Systems" project (to replace the S/360-descended mainframe architecture) was a failure, but it survived by evolving into System/38, then AS/400, later renamed to i5/OS and now IBM i. Hardware-based capability security was part of the architecture.
- nickpsecurity 11y agoWho else? :) It was this one: https://domino.research.ibm.com/library/cyberdig.nsf/papers/B9D637F6D41FD7D78525788C00525519/$File/rc25155.pdf https://domino.research.ibm.com/library/cyberdig.nsf/papers/... One of the founders and best performers of INFOSEC, Paul Karger, was on that project. Later did their smartcard OS, Caernarvon, for an anticipated EAL7 evaluation. In the past, he did MULTICS security evaluation and VAX VMM Security kernel among other things. Far as HWMAC, they sort of just dropped it on us in 2011 and I haven't heard about it since. (shrugs) Meanwhile, Cambridge already has FreeBSD running on the CHERI processor with code available and a less-aggressive, legal team. :)
- arca_vorago 11y agoThere exists a series of OS'es in use in DoD/Darpa/etc that are designed from the ground up for high security, but almost all of them are closed source/proprietary, which really frustrates me. QubesOS is promising, but has many issues to work through, and minix3 is interesting, but I'm not aware of any new FOSS secure OS movements.
- coroutines 11y agoThe NSA actually has a lot of useful PDFs related to hardening existing OS's up on its site that you can find through Google: Search: site:nsa.gov filetype:pdf hardening (works in DuckDuckGo as well) The search will probably get you noticed, but I remember spending like 2 days in highschool just scraping and going through every PDF I could find for useful things to know. ~
- actsasbuffoon 11y agoAll the more reason why the US government shouldn't be running mass surveillance programs. You may trust the US government with your data, but what if they can't protect your data once they've obtained it? Do you trust the Chinese government with your personal information? How about organized crime groups with the resources to hire expert black-hats? We're talking about people who haven't done anything wrong, and aren't suspected of any wrongdoing. Innocent people are having private data gathered without their consent (and arguably in violation of the constitution) by people who have had a series of embarrassing security blunders in recent years. You might argue that the NSA has tighter security standards than the OPM and whichever departments were compromised in this attack. In response to that, I'd point out that Edward Snowden was only a contracter, and shouldn't have had access to the information he leaked to the press. Clearly security wasn't that great at the NSA.
- deleted 11y ago[deleted]
- ihsw 11y agoForget surveillance data -- we have a veritable treasure trove of zero-day exploits. The US Gov (and many other's) are very active in the zero-day market with an impressive stockpile. We have so much effort into offence that we ended up forgetting about defence, and losing the latter makes the former largely ineffective. This completely destroys the credibility of the NSA's argument that they deserve ever-more expanding powers to reach around the globe, especially given that we will have hands following the neat trail that we have behind ourselves. Why do we give them the power to act with impunity and without oversight, trusting them to reach around the globe, when we expose ourselves the whole length of the way? It's like leaving the door open at Fort Knox because we're too busy spying on our neighbours.
- a3n 11y agoI imagine the zero days, or at least their existence, are also vulnerable to this group.
- 11y ago
- koolba 11y ago... but they still think they can keep cryptographic backdoors secret. /s
- mmaunder 11y agoThis is two months old. I guess vice made it new again.
- jonah 11y agoDupe of the same story/URL I posted yesterday: https://news.ycombinator.com/item?id=11426849 https://news.ycombinator.com/item?id=11426849 (On topic: the more data they collect, the more tempting of a target they become.)
- fishanz 11y agoWhy would you get down-voted for pointing out that this is a dupe. Maybe I'm missing something but I don't get it.
- deepnet 11y agoThe Ken Thompson Hack : http://c2.com/cgi/wiki?TheKenThompsonHack http://c2.com/cgi/wiki?TheKenThompsonHack A compiler that inserts a backdoor ( and the backdoor inserter ) into anything it compiles but contains no backdoor in the source code. Infect one compiler and then everything that follows has a backdoor.
- MikeHolman 11y agoIsn't DDC a sound countermeasure? And hasn't it been shown that up to this point that has not happened? IMO that attack is as grandiose as it is unlikely.
- ryao 11y agoThe US government should develop (when needed) and deploy everywhere things such as OSS solutions that eliminate attack vectors like the Quark web browser (formally verified via shim verification), Hardened OSS operating systems, OSS software routing (no hidden back doors in things implementing network isolation), RSA-based authentication TFA with physical elements (and physical key pads on the secure elements for pin entry, ban internal wireless communications (no office wifi and no Bluetooth equipment), destroy equipment if it is suspected to be compromised, etcetera. The idea would be to put mitigations into place for every imagationable attack vector by breaking everything but the things that are necessary and isolating the things that are left. That ought to make breaking into systems harder. It will likely never happen though. If anyone in charge of IT for even a portion of the US government did this, he would probably get fired as soon as those who can fire him experience proper security.
- vonklaus 11y agoThis shouldn't be news. Snowden broke the NSA leaks ages ago, everyone should know a mysterious hacking group has access to gov files...
- lifeisstillgood 11y agoPresumably you can never know you are clean from this point on. Any state sponsored group that has been in government servers this long will have spread to pretty much every part. is there anyway to break the cycle?
- fapjacks 11y agoGermany is buying a lot of typewriters.
- deepnet 11y agoHardly surprising when most resources are spent on mass surveillance, reliant on weak security. Snowden's leaks show the focus is to "prevent public debate about the mass surveillance program." - GCHQ, leaked slide. > "The mass surveillance program has done nothing to prevent terrorist attacks, it has not stopped a single one.", concludes Obama's 2014 report chaired by the ex-deputy director of the CIA. Compromising public safety by starving resources from real investigative intelligence. > "If you collect it all, you understand nothing." Snowden They were warned of the Belgian Bombers by Turkish Intelligence. Warned he had just returned from training camps. Warned a Tsarnev brother had been at a training camp just before he bombed Boston. Real warnings about activated radical, single dangerous individuals - not a needle in haystack - direct advance warnings. Same with London 7/7 and in all cases the response is "we didn't have sufficient resources to target these individuals." If these attacks were preventable - why weren't they ? This question must be asked again and again and we should be unsatisfied with 'closing the stable door' answers like 'because they had burner phones'. Because that is not their focus is the awful, sad, inescapable truth. All sources from this debate between Greenwald, Chomsky & Snowden: https://theintercept.com/2016/03/30/edward-snowden-noam-chomsky-glenn-greenwald-a-conversation-on-privacy/ https://theintercept.com/2016/03/30/edward-snowden-noam-chom...
- ziedzic 11y agoIncoming Patriot/USA Freedom Act 2.0
- memracom 11y agoWhen we first heard about how Snowden actually got access to the files which he leaked, I remember being astounded that the USG was so incompetent about information security. My next thought was, how could Snowden be the first to get this stuff when there are professional spies from several nations, not to mention organized crime, who also want access to the info. In fact it is entirely possible that deep cover agents within the USG had rigged the system so that info security was practically non-existent but only if you had the eyes of a UNIX system administrator like Snowden. Or some foreign spy agency operatives. Remember that supposed cyber attack on Ukraine's power systems. It is precisely the same thing. Incompetence in security administration, nobody even caring to do the simplest things to secure systems and networks, no real security audits. Just handwaving and powerpoints and lots of impressive jargon, and no doubt, impressive checks being written. Can we do better than this? Serious question, can we?
- Lawtonfogle 11y agoPeople get the security they pay for. Look how much a security expert will get paid. Look at the training offered in our society to developer people into security experts, be it during childhood, at college, or once they are part of the work force. Now look at how our society handles sport stars. Their pay. The training kids get which is needed to give rise to the stars. I'm not convince our society cares about being secure when you measure by actions instead of words.
- memracom 11y agoWhen we first heard about how Snowden actually got access to the files which he leaked, I remember being astounded that the USG was so incompetent about information security. My next thought was, how could Snowden be the first to get this stuff when there are professional spies from several nations, not to mention organized crime, who also want access to the info. In fact it is entirely possible that deep cover agents within the USG had rigged the system so that info security was practically non-existent but only if you had the eyes of a UNIX system administrator like Snowden. Or some foreign spy agency operatives. Remember that supposed cyber attack on Ukraine's power systems. It is precisely the same thing. Incompetence in security administration, nobody even caring to do the simplest things to secure systems and networks, no real security audits. Just handwaving and powerpoints and lots of impressive jargon, and no doubt, impressive checks being written. Can we do better than this? Serious question, can we?
- MikeHolman 11y agoAmazing. I can't help but wonder though why the FBI is telling us this at all. Are there disclosure laws prompting them?