17 ms·
Snowden: Hack of an NSA server is not unprecedented, publication of the take is
- peterkelly 10y agoIt also highlights the risks of NSA exploiting zero-days and creating malware to conduct offensive operations, rather than reporting vulnerabilities to the vendor to make everyone safer. Now these tools have been stolen by one of their adversaries, and may make it out into the public for anyone to take advantage of. I just watched an excellent documentary called "Zero Days" (https://weshare.me/823adb83b8e98628 https://weshare.me/823adb83b8e98628) this morning about the whole Stuxnet (aka Olympic Games) debacle. They really are playing with fire.
- 2close4comfort 10y agoA fire that they are showing they do not know how to control.
- derpadelt 10y agoThey do not know how to perfectly control it. Given the obviously huge scale at which they operate, it seems to work reasonably well. Yet the huge scale is exactly what scares the socks off of knowledgable people - even more than a fire here and there. Their PR problem is that the number of times they successfully work in the dark is somehow confidential...
- 2close4comfort 10y agoYou have got it right there! Breaking into a system is easy keeping yours intact is not. That is part that the US GOV still doesn't get the defensive part of the equation. BS (Before Snowden) people suspected but now we know people are listening everywhere. And even the NSA is not immune...that is scary that no matter how good your InfoSec is that your IA is lagging far behind.
- marcosdumay 10y agoIt's the consequences, not their size. "Look, we've put off 99.9% of the fires we started last week. Your complaint about we completely burning 2 cities down is baseless, you can't reasonably expect our fire-control to get any better."
- diggan 10y agoSlightly off-topic but I also tried to watch "Zero Days" since the subject interest me. But, with the constant exaggeration and dumbing down of the subject, I could only watch about 20 minutes before I turned it off. If you want something technical that is not exaggerated, you better watch something else. If someone have an recommendation, please share.
- peterkelly 10y agoI recommend sticking through till the end. The first 20 minutes just sets the scene - the story gets a lot more interesting once it links up the technical stuff with geopolitics and the relationship between US & Iran, and what they did to the centrifuges. The last part has some insightful commentary by a number of experts on the new world of so-called "cyber warfare" that we're entering into.
- wepple 10y agohave you read Countdown to zero day: https://www.amazon.com/dp/B00KEPLC08/ref=dp-kindle-redirect?_encoding=UTF8&btkr=1#nav-subnav https://www.amazon.com/dp/B00KEPLC08/ref=dp-kindle-redirect?... ? It is ultimately penned for the masses, but even if you're technical you'll likely enjoy it. And there's plenty of scope for going off and doing your own research about bits and pieces.
- dmix 10y agoThe book '@War: The Rise of the Military-Internet Complex' by Shane Harris from The Daily Beast is very good and talks about the obsessions with offensive weapons. And the embarrassingly bad defensive posture the US has via policy failure (ie: focusing on private-public info sharing deals that do nothing, instead of real defence) and inter-agency fighting. https://www.amazon.com/War-Rise-Military-Internet-Complex/dp/0544570286/ https://www.amazon.com/War-Rise-Military-Internet-Complex/dp...
- linkregister 10y ago> focusing on private-public info sharing deals that do nothing, instead of real defence Can you elaborate? I haven't been exposed to any ideas that address this without compromising civil liberties. That is, "real defence" sounds like the government monitoring internet connections to my company for malicious activity. I don't think that's good for business. I might be thinking a little close-minded about it though. Please share what you mean.
- JustSomeNobody 10y agoQuestion: Does the NSA have an obligation to be ethical?
- peterkelly 10y agoI would argue yes, in the sense that all of us do (both in our professional and personal lives). The US likes to promote itself as the "good guys", and if they want that reputation, they have to earn it. NSA's activities are in direct conflict with that ideal. Society only functions properly when people act ethically. We have laws in place for punishing those who harm others in various ways (financially, physically, etc.), as a means to discourage bad behaviour. In theory there's supposed to be international law, but sadly no-one seems to pay much attention to it.
- 2close4comfort 10y agoI would only add that the NSA has politicized themselves in exchange for the expansion of their powers. Now as a political entity it seems they have a much lower standard of ethics and now it is about maintaining power.
- ajdlinux 10y agoDoes anyone on earth not have an obligation to be ethical? (Yes, I know there is no universally accepted definition of "ethical".)
- thecatspaw 10y agoYes, noone does. You are not bound by law to be ethical. There's no law about it. Are you _supposed_ to act ethical? absolutely. but you dont have an obligation
- ajdlinux 10y agoLegal obligation being the only possible meaning of "obligation", obviously.
- 10y ago
- wepple 10y agoTheir adversaries likely won't make use of the tools for anything serious. They know the NSA already have detection capabilities for their own 0days, and using these tools is a dead giveaway to the NSA that they've been made. An adversary would do well to be very careful about their use of stolen knowledge. As for it hitting the public like this; I'm not sure we'll see this happening incredibly regularly.
- drzaiusapelord 10y ago>and may make it out into the public for anyone to take advantage of. Why would they do that? Its more likely they'll be kept for other attacks or sold to nation states for vast profits. I also suspect there's nothing magical going on at the NSA. Whatever zero days they have are probably had by other intelligence agencies and hacking groups. Whether to report them publicly is a political decision that these groups have zero incentive to make. Ethical researchers and white hats, from my understanding, are a very small part of the scene, or at least the part of the scene that gets real results.
- ikeboy 10y ago>8) Circumstantial evidence and conventional wisdom indicates Russian responsibility. Here's why that is significant: Interesting that he's not afraid to point the finger at Russia while still relying on them for protection. My respect for him just went up.
- ptest1 10y agoUnless this leak was part of that very protection arrangement, or part of some larger play. It's possible Snowden had all this stuff and the timing works out (right?). And let's not forget the mysterious "it's time" tweets from Snowden a few weeks ago. Edit: I don't know why I'm being downvoted here. Isn't this a plausible explanation until we have more evidence?
- noir_lord 10y agoUnless you have evidence for any of that you are just playing the "Lets pull out a wild conspiracy card" game. Personally I think Snowden is the Lemming Prophet of the Epsilon-Tau Lizard People.
- ptest1 10y agoSnowden worked at the NSA and took a bunch of stuff. These leaks are from that time period. This isn't crazy. Edit: His "it's time" tweet happened less than 48 hours after the first TheShadowBrokers account (reddit) was created, prior to activity. Those accounts were dormant until the drop. It's also possible the timestamps on the files match up to Snowden's leaks because the NSA stopped using that server / etc. But the "it's time" tweet seems to imply Snowden may have known this was coming. It could also be a conincidence, of course.
- kushti 10y agoThe more interesting question is that are any proofs behind the theory around? For DNCLeaks, for example, not really.
- audeyisaacs 10y ago
- deleted 10y ago[deleted]
- imglorp 10y agoHis complete post (just in case) original 4:40 AM - 16 Aug 2016 from @Snowden: The hack of an NSA malware staging server is not unprecedented, but the publication of the take is. Here's what you need to know: (1/x) 1) NSA traces and targets malware C2 servers in a practice called Counter Computer Network Exploitation, or CCNE. So do our rivals. 2) NSA is often lurking undetected for years on the C2 and ORBs (proxy hops) of state hackers. This is how we follow their operations. 3) This is how we steal their rivals' hacking tools and reverse-engineer them to create "fingerprints" to help us detect them in the future. 4) Here's where it gets interesting: the NSA is not made of magic. Our rivals do the same thing to us -- and occasionally succeed. 5) Knowing this, NSA's hackers (TAO) are told not to leave their hack tools ("binaries") on the server after an op. But people get lazy. 6) What's new? NSA malware staging servers getting hacked by a rival is not new. A rival publicly demonstrating they have done so is. 7) Why did they do it? No one knows, but I suspect this is more diplomacy than intelligence, related to the escalation around the DNC hack. 8) Circumstantial evidence and conventional wisdom indicates Russian responsibility. Here's why that is significant: 9) This leak is likely a warning that someone can prove US responsibility for any attacks that originated from this malware server. 10) That could have significant foreign policy consequences. Particularly if any of those operations targeted US allies. 11) Particularly if any of those operations targeted elections. 12) Accordingly, this may be an effort to influence the calculus of decision-makers wondering how sharply to respond to the DNC hacks. 13) TL;DR: This leak looks like a somebody sending a message that an escalation in the attribution game could get messy fast. Bonus: When I came forward, NSA would have migrated offensive operations to new servers as a precaution - it's cheap and easy. So? So... The undetected hacker squatting on this NSA server lost access in June 2013. Rare public data point on the positive results of the leak. You're welcome, @NSAGov. Lots of love.
- irishcoffee 10y ago> 5) Knowing this, NSA's hackers (TAO) are told not to leave their hack tools ("binaries") on the server after an op. But people get lazy. I know enough to say that this sentence reveals a lot about what snowden knows, and what he doesn't. Mostly the latter. He doesn't seem to understand the context and meaning of acronyms he uses.
- shireboy 10y agoWhere is the leak he's referring to?
- ajdlinux 10y agohttp://pastebin.com/JBcipKBL http://pastebin.com/JBcipKBL
- jmnicolas 10y agoIMHO Twitter is the worst media for this kind of discussion : I would have loved to read something more substantial but being limited to 140 char forces you to omit a lot of details. Why use something like 10 tweets where a blog post lets you have as many words as necessary. You can still be concise but 140 char is too short, it's just for people that have uninteresting things to say and Snowden is certainly not one of them (unless he starts to comment about the weather in Russia).
- abstractbeliefs 10y agoBecause twitter has a vast public reach, more so than an individuals blog. It's also really easy to use by journalists who get pre-made sound bites, which is a bonus for the sources too - they can more easily edit and shape how they are quoted. While a blog would be much better quality, quality journalism doesn't sell nearly as well as highly-polarised, bite-sized clips.
- leephillips 10y agoThe obvious solution is to use Twitter to link to your longer article. Isn't it?
- abstractbeliefs 10y agoIdeally, yes, although I can't actually imagine how any interesting discussion could come of this particular information in either medium - the "good" stuff will be on satellite communities like HN, reddit, 4chan. While a blog is a better authoring medium, it's still shit for discussion, and loses some of the media impact benefits that Snowden probably intends to leverage here.
- wepple 10y agoI think people fear the rather nasty experience of embedded webview when you click a link. It seems to be a bit of a barrier to entry.
- 10y ago
- coldcode 10y agoThis is no different than the constant "war" between military offense and defense. "Good guys" and "bad guys" constant try to get the upper hand leading to temporary winners and losers. You build a fatter castle wall, I build a stronger cannon. The NSA and its adversaries are no different.
- matt_wulfeck 10y agoExcept usually when you build a bigger canon you point it at people outside your castle.
- ex_amazon_sde 10y agoNot at all. This are governments attacking citizens, both in the same and other countries. Secretly, and without a declaration of war. Targeting activists, political targets, financial institutions to exploit them, not to win a war. And the victims cannot even surrender.
- jordigh 10y agoEd was a Booz Allen Hamilton employee only for a couple of months. He wasn't even out of his probation period as an employee. It's really amazing that in such a short time he was able to siphon all this information out of the NSA. I wonder what more information could he have collected if he had spent a longer time contracting for the NSA. I wonder how much more about the NSA we could know if people who have dedicated their entire careers to the NSA would whistleblow.
- secfirstmd 10y agoOr what damage a normal spy could have done...
- balabaster 10y agoWhat makes him different than a normal spy? It's just the adversary he worked for was the public. I'd say "instead of an enemy of the U.S. Government," but I'm hard pushed to separate that distinction somehow. The NSA's behaviour would seem to point to its considering the U.S. people as enemies of the state... rather than the people being the state and themselves being the enemy. I suppose it's not beyond belief that Snowden _could_ have been a CIA operative the entire time he was in the NSA and "blowing his cover" by going public was just the endgame to move scrutiny of CIA projects to NSA projects. Of course, there's a thousand conspiracy theories. What if that wasn't the endgame? What if "defecting" to Russia is still part of a bigger operation? Just to be clear, I have no evidence supporting this theory, nor do I believe he's any more than he suggests. But we'd all do well to evaluate what and why we trust the things we do from time to time.
- pducks32 10y agoOr is doing.
- chatmasta 10y agoIf you want to put on your tinfoil hat for a second, consider the fact that Snowden started his career in the military, then moved to CIA, then moved to Booz Allen. It's entirely possible that Snowden is an ongoing CIA op to discredit their rival NSA as part of a turf war.
- lucb1e 10y agoMany people complain about the Twitter format and I agree. Fortunately, Twitter allows people to use about 2KB of text in a tweet, if you encode it as a URL: The URL: http://because.a.tweet.doesnt.fit.lucb1e.com/?text=From%3A+https%3A%2F%2Ftwitter.com%2FSnowden%2Fstatus%2F765513662597623808%0D%0A%0D%0AThe+hack+of+an+NSA+malware+staging+server+is+not+unprecedented%2C+but+the+publication+of+the+take+is.+Here%27s+what+you+need+to+know%3A+%281%2Fx%29%0D%0A%0D%0A1%29+NSA+traces+and+targets+malware+C2+servers+in+a+practice+called+Counter+Computer+Network+Exploitation%2C+or+CCNE.+So+do+our+rivals.%0D%0A%0D%0A2%29+NSA+is+often+lurking+undetected+for+years+on+the+C2+and+ORBs+%28proxy+hops%29+of+state+hackers.+This+is+how+we+follow+their+operations.%0D%0A%0D%0A3%29+This+is+how+we+steal+their+rivals%27+hacking+tools+and+reverse-engineer+them+to+create+%22fingerprints%22+to+help+us+detect+them+in+the+future.%0D%0A%0D%0A4%29+Here%27s+where+it+gets+interesting%3A+the+NSA+is+not+made+of+magic.+Our+rivals+do+the+same+thing+to+us+--+and+occasionally+succeed.%0D%0A%0D%0A5%29+Knowing+this%2C+NSA%27s+hackers+%28TAO%29+are+told+not+to+leave+their+hack+tools+%28%22binaries%22%29+on+the+server+after+an+op.+But+people+get+lazy.%0D%0A%0D%0A6%29+What%27s+new%3F+NSA+malware+staging+servers+getting+hacked+by+a+rival+is+not+new.+A+rival+publicly+demonstrating+they+have+done+so+is.%0D%0A%0D%0A7%29+Why+did+they+do+it%3F+No+one+knows%2C+but+I+suspect+this+is+more+diplomacy+than+intelligence%2C+related+to+the+escalation+around+the+DNC+hack.%0D%0A%0D%0A8%29+Circumstantial+evidence+and+conventional+wisdom+indicates+Russian+responsibility.+Here%27s+why+that+is+significant%3A%0D%0A%0D%0A9%29+This+leak+is+likely+a+warning+that+someone+can+prove+US+responsibility+for+any+attacks+that+originated+from+this+malware+server.%0D%0A%0D%0A10%29+That+could+have+significant+foreign+policy+consequences.+Particularly+if+any+of+those+operations+targeted+US+allies.%0D%0A%0D%0A11%29+Particularly+if+any+of+those+operations+targeted+elections.%0D%0A%0D%0A12%29+Accordingly%2C+this+may+be+an+effort+to+influence+the+calculus+of+decision-makers+wondering+how+sharply+to+respond+to+the+DNC+hacks.%0D%0A%0D%0A13%29+TL%3BDR%3A+This+leak+looks+like+a+somebody+sending+a+message+that+an+escalation+in+the+attribution+game+could+get+messy+fast.%0D%0A%0D%0ABonus%3A+When+I+came+forward%2C+NSA+would+have+migrated+offensive+operations+to+new+servers+as+a+precaution+-+it%27s+cheap+and+easy.+So%3F+So...%0D%0A%0D%0AThe+undetected+hacker+squatting+on+this+NSA+server+lost+access+in+June+2013.+Rare+public+data+point+on+the+positive+results+of+the+leak.%0D%0A%0D%0AYou%27re+welcome%2C+%40NSAGov.+Lots+of+love http://because.a.tweet.doesnt.fit.lucb1e.com/?text=From%3A+h... Example tweet: https://twitter.com/lucb1e/status/765544321747718144 https://twitter.com/lucb1e/status/765544321747718144 This uses a third party site to display, but the data is all in the URL. Anyone could verify that the site (my site in this case) is not tampering with the content.
- em3rgent0rdr 10y agoThe National Insecurity Agency is more interested in creating and trading exploits than protecting citizens' security, which ends us putting everyone at greater risk.
- ianhawes 10y agoThere was another article posted that pointed to the DoD-assigned IP of (something like) "30.40.50.60" that was referenced in one of the files. I'm fairly certain that was just a coincidence. However, I did find that one of the autogenerated shellcodes for EXTRABACON contained this DoD-assigned IP: 155.222.211.8 (http://whois.domaintools.com/155.222.211.8 http://whois.domaintools.com/155.222.211.8). The OrgName is "DoD Network Information Center". This appears to be run by DISA which is also headquartered at Ft. Meade.
- matt_wulfeck 10y agoI do appreciate your sleuthing, but the cidrs used by the government are public, and including them in files like this is trivial and ultimately means nothing for attribution.
- then_you_wink 10y agoI posted about this in a different thread with a different throwaway, because I had suspicions that Snowden knew about the whole EG auction thing anyways. The writing has been on the walls. This is why there is so much hype over what appears at a first glance to be an obvious scam, because there is a lot of potential for civilians to learn a lot about how state-sponsored hacking actually operates. It's very different from how it's portrayed in the movies, and you really wouldn't be any wiser from not having been tainted by the movies anyways just due to the ridiculous amount of stealth involved in day-to-day operations. If rumors are to be believed, then it means that EG can't possibly be crazy enough to make such a (relatively) rudimentary mistake like leaving behind binaries to tools that they KNOW only they have access to. These binaries don't seem like such a big deal, but the real situation is this: these binaries are the ONE thing that can tie all the dots together about all the different attacks that have happened. IRATEMONK, Stuxnet, Flame, etc. All these crazy "unprecedented" hacks that have just popped up out of nowhere could potentially be linked together with these binaries that may or may not exist. On top of that, with enough analysis, it's possible to even identify different programmers just from their stylometry, even through code, so if these binaries are detailed enough there could be the potential for correlation of the author(s). That auction is really interesting.
- matt_wulfeck 10y agoTying them together wouldn't be very interesting. Am I wrong on this? Don't we already "know" that the US is behind stuxnet? I don't think that makes the front pages. Struxnet was used against a foreign adversary to disable nuclear bomb-making capabilities. That sounds pretty useful to me. What would be interesting is learning where these came from and how they were used. If Ed's musing is right and there's evidence these exploits were used in democratic elections here in the US then there's going to be hell to pay.
- then_you_wink 10y agoI logged back into this one just for you! That is a big no-no, so I sure hope I don't go mysteriously missing after this! Anyways, I don't "know" anything that isn't out there to be found. It's a reasonable assumption to assume that you've already assumed that I work in/around the intelligence industry/community, but this is hardly the reason I'm so interested in all of this. Anyways, to your remark, yes absolutely Stuxnet was contracted or engineered by the US. We're completely positive that our hands are dirty in that aspect, but the real question is whodunnit. The beauty of all these state-sponsored hacks is that they can be waved away as some """rogue""" like Snowden from the outside-looking-in. What we really want to know is how deep the roots of the tree go, and how many of these cells actually exist. How many contractors are there? Where did they come from? What are their backgrounds? What are their ethnic backgrounds? How were they recruited? What changes in their online presence can we observe around the time that they were recruited? To be perfectly, brutally honest, I could give half a shit what happens in the election. The clinton mafia has been writing on the wall for literally decades at this point, what's another snippets? On the other hand, somebody is out there issuing commands to potentially DOZENS of the most elite, sought-after, highly-educated, intelligence-savvy hackers. Maybe they report to a secret committee that controls them, and that committee is composed of only perfect operators. People who wouldn't fuck up and let slip that it even exists. That seems unlikely, and just from a logistical standpoint, it's complex to organize that kind of effort. In the IT world, there are project managers that went to university to learn how manage teams effectively, there's a huge science behind it and I can't bring myself to believe that a committee is capable of the watertight operations that would be necessary for this. That leads me to believe that one of several scenarios is the truth: A) EG doesn't exist. It's another smoke-and-mirrors trick, and there are many squads like mine that use the same name to avoid correlation, and "play characters." There is no secret mastermind, just some intel-oriented director issuing objectives, and that's it. B) EG does exist, and is controlled by one single person, probably well-guarded, and he/she manages other smaller splinter groups, and are doing their own thing. Maybe they made a dirty deal with some USG official, and whomever that was managed to not fuck it up. C) EG doesn't exist, and the entire thing is carefully organized by some special-purpose squad within the NSA or some such branch that we don't know about. I think this is the most likely option given some of the tactics we've seen so far, and the level of caution and just the overall "flavor" of how these hacks seem to happen. Stuxnet for example, was ALL about collecting information and guerilla operation within "hostile" nuclear environments. Prevent danger and gather as much actionable intelligence as possible. IRATEMONK, for example, was all about spreading through networks, through USB, that sort of thing. Imagine a secure facility, guarded by soldiers, operated by intelligence professionals or nuclear scientists, or some such "high-value" people. IM was capable of spreading quickly, persistently, flexibly, etc. Just digs in and gathers it all up. That's how modern US intelligence work is done. It's how most government work is done, period. OODA is as relevant today as it ever has been, and people like me, people like snowden that have seen those environments and those sorts of people, just recognize right out of the gate that something is a bit too familiar about it all. I don't know very much about the election side of things. I'm certain some sneaky shit is going on, but it always has been. Nothing new. What I really want to know, and what I think these binaries can tell us all, is who is behind these hacks. Where the power is coming from. If even just a single author is identified and correlated with something on the inside of the intelligence universe, then this whole thing is blown wide open. These guys know how close they're cutting it, that's why this auction is so interesting because if it's real, if they're taking these risks to make money, or just to get the binaries out somehow, then there are some HEAVY implications that they might realize that they're in danger. If the auction proves to be real, it'll speak VOLUMES over something that has been previously unobservable. I'm assuming of course that the secret mastermind behind EG doesn't want the binaries out to the public, and so if they somehow make it out, then someone who had access to them did, maybe as a call for help, as revenge, whatever. Regardless, it's a sign of unrest, and that the cat's claws are indeed tearing the bag. My handles are always snips from the Mary Poppins films. There's multiple people, but you'll get the idea. It's going to be a very interesting couple weeks! Cheers
- matt_wulfeck 10y agoO government, tell us again how you keep all of the dragnet data collected on Americans safe from hackers.
- deleted 10y ago[deleted]
- clintonhalpin 10y agoHere's the full thread - http://quote.ms/2bkM2HW http://quote.ms/2bkM2HW
- MichaelMoser123 10y agoin the early nineties all this security stuff was about writing mostly harmless MS/DOS viruses. Who would have imaged that this business was going to get politicized to such a degree - that could only happen once all these machines got onto the net. Now its all as paranoid as 'Mother Night' by Vonnegut.
- sys32768 10y agoI suspect it was an inside job. The NSA.GOV site is down ATM probably as they do a sweep. A Twitter user inactive since 2005 said it was an inside job and the file naming conventions in the leaks are internal only.
- fl0wenol 10y agoWhy does the idea persist in this day and age that because the public-facing component of an organization's website is down or being DDoS'd that it has anything to do with the internet or non-internet facing operations otherwise? The NSA, White House, and State Department currently use Akamai for their public websites, for example.
- doctorshady 10y agoBut Twitter was founded in 2006...
- msane 10y agoThere are a lot of little gems in the wording of the auction message. (http://pastebin.com/raw/JBcipKBL http://pastebin.com/raw/JBcipKBL) If it is Russia there will be some content that only the US gov will understand. I wonder which portions those would be. The "message to wealthy elites" portion of the auction message is also interesting. "Do you feel in charge?" in quotes suggests a reference with a pretty relevant top hit (https://www.google.com/search?q="Do+you+feel+in+charge" https://www.google.com/search?q="Do+you+feel+in+charge")
- fixermark 10y ago> Elites call top friends at law enforcement and government agencies, offer bribes, make promise future handjobs, (but no blowjobs). That also feels like a pretty thinly-veiled reference to current events in the US election cycle.
- matt_wulfeck 10y agoIt's ridiculously written to the point of being a parody at guessing who did it. That's my takeaway.
- msane 10y agoAttribution security is the meta-message. Perhaps that's the best attribution. It could be someone else taking advantage of the timing but that is definitely the intended frame. "Better than stuxnet" is also quite the claim.