4 ms·
> the NSA boogeyman is hiding behind every rock and tree are starting to become quite tiresome. Yeah indeed, they have backdoor-ed every ISP, nation, router, H
by rantanplan 9y ago
> the NSA boogeyman is hiding behind every rock and tree are starting to become quite tiresome.
Yeah indeed, they have backdoor-ed every ISP, nation, router, HDD, what-have-you in existence and these people keep telling boogeyman tales.
Tsk tsk tsk. How tiresome.
- Ajedi32 9y ago> they have backdoor-ed every ISP, nation, router, HDD, what-have-you in existence This is exactly the kind of hyperbolic nonsense I'm talking about. You can't claim that every HDD in existence has an NSA-installed backdoor installed in it without providing any evidence. If the NSA's capabilities were nearly as extensive as you're claiming, the US wouldn't need to bother maintaining a military. They could just remotely command all of North Korea's computers to shut themselves off, then sit back and wait around for their surrender. I'm not saying mass surveillance isn't a problem, or even that the NSA doesn't have a backdoor installed in IME (I certainly don't have evidence to the contrary); just that people need to stop exaggerating the threat, or making claims about the NSA having compromised any specific system without providing any evidence to back those claims up.
- rantanplan 9y agohttps://www.theregister.co.uk/2015/02/17/kaspersky_labs_equation_group/ https://www.theregister.co.uk/2015/02/17/kaspersky_labs_equa... There is an equivalent article from Ars technica, if "theregister" isn't to your liking. As for the evidence on routers and Internet infrastructure, you should pay more attention to leaks of state-sponsored tools, like the equation group leaks and the CIA one.
- Ajedi32 9y ago"possibly tens of thousands of Windows computers" is not anywhere near the same thing as "every HDD in existence".
- roblabla 9y agoRemember when the NSA crippled a standardized CSPRNG ? http://www.reuters.com/article/us-usa-security-nsa-rsa/exclusive-nsa-infiltrated-rsa-security-more-deeply-than-thought-study-idUSBREA2U0TY20140331 http://www.reuters.com/article/us-usa-security-nsa-rsa/exclu... Remember when the US shut down NK's internet ? https://gizmodo.com/so-who-shut-down-north-koreas-internet-1674589139 https://gizmodo.com/so-who-shut-down-north-koreas-internet-1... Remember when the NSA was revealed to have a malware that could infect hard drives, being potentially undetectable ? https://motherboard.vice.com/en_us/article/ypwkwk/the-nsas-undetectable-hard-drive-hack-was-first-demonstrated-a-year-ago https://motherboard.vice.com/en_us/article/ypwkwk/the-nsas-u... Remember PRISM ? How about stuxnet, and the other couple of viruses that are almost surely the NSA's. Sure, those are not backdoors installed by the OEM, rather they are malware that the NSA can use to infect (lots of) systems. But let's not kid ourselves, the NSA does have a ridiculous amount of power, and we have lots of evidence of it. At this point I'd be rather surprised if the NSA haven't hacked my fridge yet somehow.
- Ajedi32 9y agoAnd I agree, those are some pretty impressive feats. Whenever your threat model includes state actors, it's probably not a bad idea to be paranoid. Let's not carry that paranoia to ridiculous extremes though. _Could_ the NSA have the ability to utilize IME somehow as a means to infect computers? Certainly. Do they _actually_ have that capability? We have no idea. Same goes for your motherboard's firmware, your hard drive's hardware, and any number of other possible vectors. They _could_ be compromised somehow, yes, but let's not claim that any specific motherboard firmware, HDD model, or CPU processor brand definitely _is_ compromised without evidence.