6 ms·
Even crazier is that this is a noob mistake. There are better ways to hide. From experience (I work in security), the ones I would use are (individually or com
by tr4cefl0w 9y ago
Even crazier is that this is a noob mistake.
There are better ways to hide. From experience (I work in security), the ones I would use are (individually or combined):
- Have the VPN set up in my router using OpenWRT (the R7000 is great for that) and drop all connections when VPN disconnects (with a script).
- Rent a VPS on a botnet friendly host that accepts Bitcoins (i.e Hostsailor).
- Then do all my shady stuff from the VPS or even better, configure Tor and proxychains on the VPS then use proxychains when doing anything on a remote host.
I think the guy was just lazy and preferred convenience.
- ajross 9y agoYou're overthinking this and getting lost in technology. The guy surely did that stuff. What likely happened is that the guy pasted an URL into the wrong browser window. Having a separate browser that jumps through all the well-audited crypto hoops you want doesn't really help you if you have a native Safari window sitting next to it where you read your gmail.
- viraptor 9y agoSetting up the VPN at the router level doesn't allow mistakes like that. Browser doesn't matter anymore - all the traffic goes out only via that VPN.
- roel_v 9y agoSure, and then one day you sit with your laptop in a park on your company's campus and you are accidentally connected to the wrong wifi hotspot and you leak some info that way. Opsec is hard. Technology can only solve so much, the weak link will always be the wet spongy tissue.
- viraptor 9y agoIf you're running an operation with international political implications, you don't sit with your laptop in the park. There's "opsec is hard", and there's "you're an idiot".
- roel_v 9y agoDo you think these large government agencies with hundreds or thousands of employees are some sort of magical super-organizations where everything and everybody is 100% on, all the time? These are all regular people like you and me working there. We're talking about the world's most organized agencies, yet who put or leave an internet-connected webcam with a default password in front of their building; or hire someone who will copy gigabytes of data and run off with it - and fail to notice; or give their most secret and valuable spyware to an ally who then gets impatient and exposes it with some stupid mistake. This is not about being an 'idiot', this is perfectly normal behavior to happen once in a few years over hundreds or thousands of people.
- viraptor 9y agoI think these are all separate cases. Yes, opsec is hard in general. There's a scale of how hard some problems are to prevent - what you listed is in various places on it. The specific case I responded to with laptop in the park while you're trying to mess with foreign governments would be at one extreme of that scale.
- bryanrasmussen 9y agothey're all separate cases of people doing stupid shit while working doing this kind of stuff. The laptop in the park was an example of how someone could do stupid shit while working on this kind of stuff, it was of course an example plucked from thin air of one kind of stupid shit one could do and get caught out, not necessarily the stupid shit that actually got him caught. The point is that at least most people, even if most of the time highly competent, slip up some times and it seems this guy slipped up one time which really thinking about it starts to make me suspicious because if you slip up once in hundreds of times why not 3-7 times. why only one time. but anyway the point is intelligent most of the time, stupid once is all it takes to get caught and nearly everyone does it. And now I'm defending a Russian agent doing stuff I think sucks.
- notfromhere 9y agoeven intelligence agents are human. how many spies were caught by doing stupid shit? For example, Rudolf Abel was caught because he paid with a fake nickel on accident.
- jorvi 9y agoYou can prevent this by running Little Snitch and only allowing outbound traffic if you are connected to GRUfi. Hell, Little Snitch even has a mode that blocks all but the core services on your Mac. Do that combined with a router-VPN with a kill switch and a hardened browser I don’t see how you would leak your location. Edit: you could even configure Little Snitch to ask for permission for every app and domain your Mac wants to connect to. That way you would even catch yourself accidentally surfing to the wrong URL or using the wrong browser.
- roel_v 9y agoYes yes yes - you're completely missing the point. The point is that it's easy to come up with some sort of contained scenario in which you can devise a perfect technical solution for a well-defined problem. But it's hard to get groups of hundreds of people to always behave perfectly according to protocol, every time, everywhere, with not a single slip-up over several years.
- petegrif 9y agoYou are absolutely correct. People make mistakes. Even very well trained professionals make mistakes. Incredibly experienced skydivers die. Industrial safety is tough despite well designed processes and constant training. Tradecraft slipups happen. etc etc The weak link is the human being.
- masklinn 9y agoThe problem is that all of a sudden your side-searches for rash treatments or your checks on your gmail account go through that VPN as well, linking your identities temporally.
- AFNobody 9y agoIt does if you do not have your personal stuff on the same physical network/equipment as your professional stuff.
- themihai 9y agoEven so it's still likely to type the wrong url/login on the wrong device(i.e by reflex). The only safe choice you have is to not have any "personal stuff"(i.e. personal twitter account).
- AFNobody 9y agoPossible, I know that a couple times a year but I would think a professional in that situation would use a completely different service for personal use. (I.e. Personal Twitter, Professional Reddit)
- themihai 9y agoWell if the job requires you to use all of them(twitter, facebook, reddit) you are left with no service for personal use only. Usually you don't have a choice, you use what your friends use.
- Tuna-Fish 9y agoThe solution to that is to use a password manager, and save all your (randomly generated, long and unmemorizable) professional passwords only on the device that cannot connect into the open internet.
- apexalpha 9y agoIt doesn't even need to be a fuck up. Knowing the scrutiny this hack would trigger means he could've easily left a single connection to a russian IP address as false bread crumb trail for investigators.
- varjag 9y agoSo you seriously mean he logged in from GRU HQ in Moscow to frame Russia years later?
- BTinfinity 9y agoVery possible that he felt something was off and left a breadcrumb just in-case.
- lostcolony 9y agoOnce, I might add. He did it once, and was willing to wait years with no reason to believe anyone noticed. That totally says "false trail" rather than "fuck up" to me. /sarcasm
- cix_pkez 9y agoWhy is it so easy to spoof a phone number and robocall people, yet not to spoof an IP? Everyone's talking about the machine attribution as a given.
- mbreese 9y agoMuch more difficult to spoof an IP than a phone number. Once you’re behind a NAT, all bets are off, but the public IP has to be routable back to you in order to be usable. Instead of phone number, think port on the phone company’s switch or a specific pair of wires. That’s hard to spoof. It’s much easier to spoof a MAC address, which can identify specific hardware associated with the IP address, but that doesn’t make the IP any more difficult to identify.
- ryanlol 9y agoA company like hostsailor will sell anyone access to your server for a few thousand $.