6 ms·
This article reads pretty lazily in my opinion. It fails to mention that the CIA had an internal hunt for the contractors which leaked the "Vault7" arsenal - c
by jwtadvice 9y ago
This article reads pretty lazily in my opinion.
It fails to mention that the CIA had an internal hunt for the contractors which leaked the "Vault7" arsenal - confirming that indeed it was a contractor and indeed that they had mishandled the arsenal by providing global access to the weapon cache.
It also failed to mention the full original story provided by the Shadow Brokers and those that reported on them: that NSA had (similarly) mishandled hacking tools by loading too many of them onto attack staging servers. This story has not changed, nor have the recent publications contradicted it. In fact the Shadow Brokers said exactly what they were going to publish when they first went public and have followed through with what they said they were going to publish exactly.
The author speculates and conspires that both of these must be Russia. Mostly it's the standard fare conspiracy theorist "to whose benefit" but it's clear the author doesn't understand whether and how Russia would benefit from these disclosures.
Finally, after all the public panic induced over "Russian hacking" during the election, there's been no intelligence summary, statement, or even Congressional statement to the affect that either the Shadow Brokers or the Vault7 leaks are in any way attributed to Russia. Wouldn't that have been fuel for that fire?
My guess is that the Shadow Brokers are a criminal organization with informal relationships with state intelligence services. My guess is that Vault7 was a CIA and contractor who shared the massive trove too broadly, where it ended up in the hands of the Wikileaks journalism reporting outlet.
The author appeals to Occam's Razor only by name. The lack of careful analysis in the article insists, unfortunately, in using unfounded speculation in the place of evidence, and horror, to then appeal to Occam's Razor on behalf of assumptions.
- frabbit 9y agoI like this theory: "My guess is that the Shadow Brokers are a criminal organization with informal relationships with state intelligence services." But weirdly, why are any of us including Bruce discussing this? It's almost as though we believed that we live in some sort of democracy where we have access to information and a legal system which could act on that information instead of an oligarchy ruled by a small elite with the aid of various armed enforcers... some secret some not. Silly proles.
- meesles 9y agoUnfortunately that attitude does little to help or try to discover what has happened. Cynicism is a double-edged sword. Once you give up the will to question and criticize, that's when democracy truly fails.
- frabbit 9y agoI disagree that I am "giving up the will to question and criticize". On the contrary I criticize the fevered speculations in the media based upon unverifiable sources reputedly in secret agencies over which most elected lawmakers have little or no control and oversight, let alone civilians peeking at the shadows on the window blinds. It's a disgusting situtation of asymmetrical information which ought to cause outrage, indignation and fear in anyone that considers themselves free and sovereign. Steepling learnedly on HN, or in "security blogs" may stroke the egos or pump the reputations of the aediles gazing upon the entrails of our democracy, but it does little to expose what only a fully legally empowered commission akin to the Church commision could determine. The only thing we know for sure thanks to Snowden and Wikileaks is that there are large numbers of dominant authoritarians spying on us and and an even large number passive authoritarians settling comfortably into their dungeon. Meanwhile: THE RUSSIANS ARE COMING!!!!
- walshemj 9y agoThat's a "brave" assertion to make about Bruce Schneier
- jwtadvice 9y agoI've been following Bruce Schneier's blog for a long time. He is a decent cryptographer, and a notable personality and technical expert. He's very new to "geopolitics". In fact, he's published a number of corrections on his blog about fundamentally incorrect predictions he's made about Shadow Brokers in particular (he predicted that their encrypted file they published was just random garbage and didn't actually contain any cyberweapons). Here Bruce is speaking about things beyond his expertise. It's not particularly brave to point out the flaws in his analysis.
- thraway2016 9y agoIt's not just Schneier. Seems that nearly everybody in infosec is convinced of Russia's complicity in everything from the DNC leaks, to Vault7, to ShadowBrokers, and now allegedly the Macron campaign. Listening to the RiskyBusiness podcast, for instance, it's incredibly obvious that the community is fully in the tank for the Russian attribution hypothesis, and habitually carries the water for FiveEyes IC. Meanwhile, we mere plebs have very little evidence to judge the community's beliefs by, other than blind faith in, say, CrowdStrike. If the infosec community would like to actually state their case to the plebs, I would love to hear it. But all I've ever been able to find is "the phishing email is a little similar to something produced by APT28, and there was an IP once used by FancyBear like 5 years ago, so it's 99.9999% certainly Russia". And nobody seems to care enough about those outside the community to even try to state the case.
- jwtadvice 9y agoI wouldn't characterize everything-is-Russia complicity as an infosec community consensus. I'm in the infosec industry and disagree. In fact, my colleagues and coworkers tend to have far more nuanced and informed positions than what mass media has inappropriately characterized as the infosec consensus. I remember when Wasthington Post and others were claiming that Russia had hacked voting machines and that the infosec community agreed with that. All kinds of researchers reached out to complain but their voices were never heard. Instead the story was quietly dropped when it turned out it was PR and propaganda bullshit. I'm sorry that you have an impression that there's an infosec consensus on this. It doesn't exist.
- hackuser 9y agoThe following comment might seem off-topic, but it's not. There are well-known techniques to propaganda, and it is important that we recognize them by now or we will continue to be victimized by it. Also, we cannot wait until we have certain evidence of propaganda to point it out: It's very rarely certain that something is propaganda - that would be poor execution indeed, violating its basic purpose - so we cannot give propaganda the benefit of the doubt, wait for certainty to call it what it is, and therefore empower it. That benefit of the doubt is normal, healthy good faith, but propaganda is a parasite on good faith; good faith is a tool of manipulation for propaganda, used to take advantage of others. Here are some techniques I know; I'd be interested in more or where I can find useful research and expertise about it: * Create uncertainty. The strategy is not to persuade people, but to create enough uncertainty to disable them and disable debate. One way to do this is to question every possible flaw in the evidence; in reality, nothing is so clear-cut that there aren't questions (and that especially applies to intelligence operations). * Make many baseless claims in order to force others onto defense and occupy all their resources. A baseless allegation takes seconds to make but hours or days to defend. Also, many people remember only the first headline, the baseless allegation, and don't see the followup story. Again, it's a way of disabling debate. By design, it's tough to deal with propaganda - it's tough to continue intelligent, valuable discussion in the face of it. I'm not sure of the answer, but comments matching those techniques, such as the parent, seem to appear when Russia is discussed, for example. One thing I do is to look for whether the comment adds substantive knowledge to the debate, or whether it just increases uncertainty about others and includes baseless information (unsubstantiated claims and rumors). Do I know more about the subject after reading the comment, or less? EDIT: Clarified my purpose in the first paragraph.
- jwtadvice 9y agoHi! I'm the parent user you've implied may be a propagandist for Russia. Your comment does the following: * Create uncertainty. * Make many baseless claims in order to force others onto defense and occupy all their resources. And we can seriously ask the question "Do I know more about the subject after reading (your) comment, or less?" (I think the answer is less - there's a great many things we could discuss about propaganda techniques that look nothing like the sophomoric list you've supplied). Are you a propagandist, by your own criteria? I don't think so. Can you see how your criteria for finding propagandists isn't even useful? I'm not one either. In fact, if you think I am the appropriate avenue is to alert the moderators. In any case my comment is extremely informative and adds substantive knowledge to the debate, and people know more about the subject after reading my comment. Figure I need to get in here to reply before this whole thread turns into a witch-hunting exercise.