5 ms·
Knock Knock Who's There? – An NSA VM
- aborsy 5y agoIt seems most vulnerabilities published by shadow brokers are on Windows. What percentage of vulnerabilities are focused on Linux or macOS? What can ordinary users do to protect themselves other than patching?
- adriancr 5y agoRootkits/exploits appear on any operating system. Wipe and reinstall often, rotate passwords at same time, also teaches good backups. ad blocker by default and always up to date system. Use VMs or other machines for dubious websites and wipe those often (like a raspberry?) Careful what you execute on your machine Then if you're really paranoid: Some external firewall running suricata for alerting Logging to an external system so you can review things in case of issues.
- CaptainJustin 5y agoIn this spirit I've been playing with spun up Firefox instances in a Google Cloud Run. The container is stateless and goes away after I close the page that connects to video stream of the other container in my browser.
- 3np 5y agoDo you find the performance satisfactory enough for daily browsing?
- genewitch 5y agoWay back in 2009 I helped design and implement basically "Firefox on AWS EC2" - I had YouTube audio and "video" working, in the subwindow, not Fullscreen. It was roughly 5-10FPS, about what you'd get with VNC, with perfect audio. I had an idea that thin clients were going to be big - and I stupidly pitched ideas for cloud based software to Adobe, Newtek, and Autodesk. Never gunna do that again.
- jmnicolas 5y agoFor all intents and purposes Google is the civilian NSA, I'm not sure you're gaining anything by creating VM in their cloud!
- 1f60c 5y agoI'm assuming they want some protection against adtech companies or the local coffee shop sysadmin. Running Firefox in the cloud "to avoid detection by the NSA" would indeed be quite foolish.
- deleted 5y ago[deleted]
- adam0c 5y ago
- gambiting 5y agoYou didn't even read the article, did you?
- aeyes 5y agoMost ordinary users will connect to the internet using a router provided by their ISP so port knocking does not work. Unless they plant the malicious code on the router - that would be even harder to detect.
- deleted 5y ago[deleted]
- bobbob1921 5y agoThis is correct, almost all user side traffic is nat’d (masquerade/Src-nat) thus port knocking nor any ports externally being open, does not apply. (NAT , in general, = how the multiple devices at your home all share a single public IP address from your ISP) This article mainly addresses servers / public facing services (which do not make use of nat)
- beermonster 5y agoFrom the article: “.. a port knocking backdoor with multiple targets such as Solaris, Linux, FreeBSD, HP-UX, JunOS, OS X” So this was far more reaching than Windows. To answer what ordinary users can do: Against a well funded adversary hell bent on getting access to your systems/data - probably not a lot! In the case of NSO group even a fully patched iPhone wasn’t going to help you. However, on reading this article my first thoughts are if this method evades detection by not having a listening port that a network scan or locally using ss/netstat can detect then perhaps you would still be able to benefit from egress filtering (only allowing outbound connections to things you need and blocking the rest). On a router most connections are through the router (FORWARD table) as opposed to directly locally originated and outbound (OUTPUT table).
- aborsy 5y agoThe NSO could get root on anyone’s device knowing only the phone number. If NSO does it, so could the intelligence agencies of dozens of countries. Looks like a hopeless situation, where a small percentage of population have access to anyone’s data (but not conversely). This is posing a threat to the democratic society. There ought to be a way to make a secure device.
- Jerrrry 5y agoThis is correct, and why many lawyers do not maintain online presences, and do not conduct business online, in any capacity.
- hnthrowaway0315 5y agoI think one way to add the difficulty is to conduct everything offline. Since they don't have a full profile for you online, they have to mobilize field teams which are scarce and expensive. On the other hand, if they can sniff you online, it's going to be automated and almost free. But again, maintaining an offline life could be very tricky given that the society as a whole is moving everything online. For example, if you earn salaries like me, there is no way to avoid a bank account and a mobile number.
- Sebb767 5y ago
- hnthrowaway0315 5y agoI don't really think ordinary people (and rich people TBF) can completely defend themselves against any state player. Anonymous guides I read mostly recommend Tor, anonymous sim card and purchasing electronics with cash. But I don't think it's going to render any state player's work impossible. I mean if they are really onto you. On the other side, three char agencies cannot waste resources on every individual, so the best way is to stay out of the radar.
- southerntofu 5y ago> I made local presentations at 0xOpoSec and BSidesLisbon but those slides were never published for obvious reasons (aka live implants all over the Internet). I don't understand. Or does this mean because the malware was being used you refused to publish documentation about it? Because you think people targeted by nation states are evil? Intelligence services are the worst terrorist organizations, and most people targeted by them are in fact very friendly persons. If only intelligence services dealt with the actual criminals and not revolutionaries, we wouldn't be having corruption and power abuse scandals every other week in all "developed" nations.
- _8j50 5y agoLive implants, means if they published you or I can access the implants and therefore the victims' systems.
- southerntofu 5y agoIf you've got root RCE can't you use it to "close" the implant and make sure noone gets hurt like some have been doing to counteract IoT botnets? How is leaving a gaping hole better? EDIT: To those saying it would be a legal liability risk, isn't it a criminal offense in your jurisdiction if you know about a danger to someone else, not to do something about it if only warn them? (non-assistance à personne en danger, in french law) Or couldn't you partner with a security research lab with better legal counsel?
- waihtis 5y agodepends if you want to take the risk of being prosecuted for illegitimately accessing multiple computer resources
- _8j50 5y agoThat's illegal. You can't break into someones house to kick out a burglar. The people that have counteracted and kicked out bots from botnets broke laws in several countries (fed crime in US), which is why they don't publicize their identity (even if they did, prosecutors may not come after them). You need the consent of the system owner to help them with the intrusion, otherwise anyone can hack into someone else's computer and say they were there to get rid of some malware.
- 101008 5y agoSlightly off topic, but at the end of the article he says he is looking for Linux devs and says something like "Send me an email to bla bla at put.as". The domain sounded wrong in Spanish (like bitch.es), and when I visited the website it had a NSFW logo. I found it strange.
- grasseh 5y agoDefinitely is the right website though... The first link on it says "Reverse" and that article is the one at the top of the list. But I agree with your sentiment, I saw the domain name on HN before even getting to the article and it did raise my brow for that same reason.
- Tepix 5y agoI guess Pedro considered it funny back in 2003? Times have changed...