3 ms·
I posted about this in a different thread with a different throwaway, because I had suspicions that Snowden knew about the whole EG auction thing anyways. The w
by then_you_wink 10y ago
I posted about this in a different thread with a different throwaway, because I had suspicions that Snowden knew about the whole EG auction thing anyways. The writing has been on the walls.
This is why there is so much hype over what appears at a first glance to be an obvious scam, because there is a lot of potential for civilians to learn a lot about how state-sponsored hacking actually operates. It's very different from how it's portrayed in the movies, and you really wouldn't be any wiser from not having been tainted by the movies anyways just due to the ridiculous amount of stealth involved in day-to-day operations.
If rumors are to be believed, then it means that EG can't possibly be crazy enough to make such a (relatively) rudimentary mistake like leaving behind binaries to tools that they KNOW only they have access to. These binaries don't seem like such a big deal, but the real situation is this: these binaries are the ONE thing that can tie all the dots together about all the different attacks that have happened. IRATEMONK, Stuxnet, Flame, etc. All these crazy "unprecedented" hacks that have just popped up out of nowhere could potentially be linked together with these binaries that may or may not exist. On top of that, with enough analysis, it's possible to even identify different programmers just from their stylometry, even through code, so if these binaries are detailed enough there could be the potential for correlation of the author(s).
That auction is really interesting.
- matt_wulfeck 10y agoTying them together wouldn't be very interesting. Am I wrong on this? Don't we already "know" that the US is behind stuxnet? I don't think that makes the front pages. Struxnet was used against a foreign adversary to disable nuclear bomb-making capabilities. That sounds pretty useful to me. What would be interesting is learning where these came from and how they were used. If Ed's musing is right and there's evidence these exploits were used in democratic elections here in the US then there's going to be hell to pay.
- then_you_wink 10y agoI logged back into this one just for you! That is a big no-no, so I sure hope I don't go mysteriously missing after this! Anyways, I don't "know" anything that isn't out there to be found. It's a reasonable assumption to assume that you've already assumed that I work in/around the intelligence industry/community, but this is hardly the reason I'm so interested in all of this. Anyways, to your remark, yes absolutely Stuxnet was contracted or engineered by the US. We're completely positive that our hands are dirty in that aspect, but the real question is whodunnit. The beauty of all these state-sponsored hacks is that they can be waved away as some """rogue""" like Snowden from the outside-looking-in. What we really want to know is how deep the roots of the tree go, and how many of these cells actually exist. How many contractors are there? Where did they come from? What are their backgrounds? What are their ethnic backgrounds? How were they recruited? What changes in their online presence can we observe around the time that they were recruited? To be perfectly, brutally honest, I could give half a shit what happens in the election. The clinton mafia has been writing on the wall for literally decades at this point, what's another snippets? On the other hand, somebody is out there issuing commands to potentially DOZENS of the most elite, sought-after, highly-educated, intelligence-savvy hackers. Maybe they report to a secret committee that controls them, and that committee is composed of only perfect operators. People who wouldn't fuck up and let slip that it even exists. That seems unlikely, and just from a logistical standpoint, it's complex to organize that kind of effort. In the IT world, there are project managers that went to university to learn how manage teams effectively, there's a huge science behind it and I can't bring myself to believe that a committee is capable of the watertight operations that would be necessary for this. That leads me to believe that one of several scenarios is the truth: A) EG doesn't exist. It's another smoke-and-mirrors trick, and there are many squads like mine that use the same name to avoid correlation, and "play characters." There is no secret mastermind, just some intel-oriented director issuing objectives, and that's it. B) EG does exist, and is controlled by one single person, probably well-guarded, and he/she manages other smaller splinter groups, and are doing their own thing. Maybe they made a dirty deal with some USG official, and whomever that was managed to not fuck it up. C) EG doesn't exist, and the entire thing is carefully organized by some special-purpose squad within the NSA or some such branch that we don't know about. I think this is the most likely option given some of the tactics we've seen so far, and the level of caution and just the overall "flavor" of how these hacks seem to happen. Stuxnet for example, was ALL about collecting information and guerilla operation within "hostile" nuclear environments. Prevent danger and gather as much actionable intelligence as possible. IRATEMONK, for example, was all about spreading through networks, through USB, that sort of thing. Imagine a secure facility, guarded by soldiers, operated by intelligence professionals or nuclear scientists, or some such "high-value" people. IM was capable of spreading quickly, persistently, flexibly, etc. Just digs in and gathers it all up. That's how modern US intelligence work is done. It's how most government work is done, period. OODA is as relevant today as it ever has been, and people like me, people like snowden that have seen those environments and those sorts of people, just recognize right out of the gate that something is a bit too familiar about it all. I don't know very much about the election side of things. I'm certain some sneaky shit is going on, but it always has been. Nothing new. What I really want to know, and what I think these binaries can tell us all, is who is behind these hacks. Where the power is coming from. If even just a single author is identified and correlated with something on the inside of the intelligence universe, then this whole thing is blown wide open. These guys know how close they're cutting it, that's why this auction is so interesting because if it's real, if they're taking these risks to make money, or just to get the binaries out somehow, then there are some HEAVY implications that they might realize that they're in danger. If the auction proves to be real, it'll speak VOLUMES over something that has been previously unobservable. I'm assuming of course that the secret mastermind behind EG doesn't want the binaries out to the public, and so if they somehow make it out, then someone who had access to them did, maybe as a call for help, as revenge, whatever. Regardless, it's a sign of unrest, and that the cat's claws are indeed tearing the bag. My handles are always snips from the Mary Poppins films. There's multiple people, but you'll get the idea. It's going to be a very interesting couple weeks! Cheers
- matt_wulfeck 10y agoCheers indeed! Thank you for the response.
- solipsism 10y agoWait, important question.. there are multiple Mary Poppins films?
- matt_wulfeck 10y agoI wish you didn't use throwaways so I could follow your posts. I assume you're the blink person from the other post. It sounds like you're someone who knows a little more than average about what's happening.
- placeybordeaux 10y agoYeah I'd totally follow this writer's stuff. Too bad...