5 ms·
Yeah, that's bullshit. For NSA-proof personal tech stack you'd rely more on tamper-evident blocks that's all. Also, security in depth and security through obscu
by aj3 5y ago
Yeah, that's bullshit. For NSA-proof personal tech stack you'd rely more on tamper-evident blocks that's all. Also, security in depth and security through obscurity are much more applicable if you're a person and not an organization. Finally, +20 years head start does not mean much if you distrohop and FOMO into bleeding edge stuff like a tech podcaster.
- nix23 5y agoNot sure if you know what your talking about, you sound a bit like a bot #NSA-proof #distrohop
- aj3 5y agoIn case you're genuinely curious, 'NSA-proof' is a portmanteau from NSA and 'idiot-proof'. Distrohopping is when people change (usually GNU/Linux) distributions once a month or so (which is an allusion at tongue-in-cheek conjecture that one can change distributions faster than NSA can break them). Have a good day, fellow human.
- nix23 5y ago>one can change distributions faster than NSA can break them Oh man i don't know what to say. Does one distrohop the ssd/efi/net/wireless/keyboard/etc-firmware too? One distrohoped for 15 years and that vuln existed all the time..but hey it would be just that one...it's an exception right? ;) https://securityaffairs.co/wordpress/115565/security/linux-kernel-flaws.html https://securityaffairs.co/wordpress/115565/security/linux-k... How many completely different browsers exist? And how many local exploitable user to root exploits exist in the Apple/Linux/BSD world's? If your a valued target and you are connected to a network you WILL be hacked.
- aj3 5y agoBuddy, I'm not gonna follow this thread anymore because you seem to be baiting me to read you a lecture on OPSEC, security in depth and compartmentalization.
- imwillofficial 5y agoBuddy, your distro hopping advice is advice so bad, that the most charitable interpretation is you have no idea what you’re talking about. Seriously? Distro hop? My brain hurts, I need coffee.
- leucineleprec0n 5y agoLol, this is so fucking funny. Distro a day, NSA stays away! Amazing.
- imwillofficial 5y agoYeah this is bullshit. There is no demonstrated NSA proof setup. If they haven’t broken in to something, they aren’t telling us about it.
- aj3 5y agoAssuming that time travel is impossible, NSA can't break into something that does not exist anymore. Hence the idea when facing such adversary is to provide them a constantly moving target. Although NSA might be able to break any full disc encryption given enough time, they aren't able to decrypt something that no longer exists. This principle isn't scalable to every computer system out there and will definitely go against other requirements in most organizations, but if you are an individual, it's not hard to pull it off.
- imwillofficial 5y agoThis ignores the obvious. What parts are not changing with a distro hop? Are those parts vulnerable to the NSA? I believe due to what was made public, that they do have that capability. I would suggest more research. If you are actually changing distros every month, that seems like a very manual process, with many points to use an insecure config. I think your time could be better spent hardening a current system. And yes the NSA could own your box every month (and would) if it suited them. Check out this link, this stuff is fascinating. > In some cases, the NSA has modified the firmware of computers and network hardware—including systems shipped by Cisco, Dell, Hewlett-Packard, Huawei, and Juniper Networks—to give its operators both eyes and ears inside the offices the agency has targeted. In others, the NSA has crafted custom BIOS exploits that can survive even the reinstallation of operating systems. And in still others, the NSA has built and deployed its own USB cables at target locations—complete with spy hardware and radio transceiver packed inside. https://arstechnica.com/information-technology/2013/12/inside-the-nsas-leaked-catalog-of-surveillance-magic/ https://arstechnica.com/information-technology/2013/12/insid...
- aj3 5y agoYou pose the questions but do not answer them. Assuming distros are selected purposefully you do get quite a lot of variability. Recompiling the kernel with different hardening options alone makes many exploits impractical. The threat modeling that you see in this thread is laughable. Nobody has infinite resources, not even NSA. They can't throw all their capability at you alone. In fact they are not even interested in any one individual. They might be interested in some groups of people like "terrorist leadership" but even in that case they don't have the need to hack all people matching that group. So at every step of the decision making process there is a cost benefit analysis. And in the end NSA will only hack some terrorist leaders, the ones deemed sufficiently significant but not any more risky then is necessary. The amount of meetings and paperwork required for carrying out offensive action is significant and everyone involved is very risk averse. Getting superiors to sign up for an operation against an individual capable of detecting attack and thus risking attribution would only be possible if the proposed techniques can be shown to be extraordinarily stealthy. That requires replicating the system in the lab and rigorously testing methodology beforehand. Yeah, it is hard to protect organizations from nation states. Because all sufficiently complex systems have bugs and given long enough time persistent attackers will find & exploit these bugs. But that's because organizations have other real-world priorities besides fighting NSA. These organizations can't change protocols overnight and replace core systems just for fun of it. Individuals actually have an advantage here because they can rotate systems at will and have much higher control over their personal lives than any CEO/CTO/CISO has over their organization. As a result, yes you can raise the cost of an attack against you high enough that NSA won't bother hacking you - either because there are other people who are less protected but hacking them would fulfill the same objective or because your ass gets handed to another agency which is able to present more cost-effective solution. Your link demonstrates this dichotomy between options that NSA has available for hacking organizations vs individuals. Individuals rarely have well documented procurement processes available for third party auditing you know.