5 ms·
> The command located every Flame file sitting on a PC, removed it and then overwrote memory locations with gibberish to thwart forensic examination. I'd like
by fl3tch 14y ago
> The command located every Flame file sitting on a PC, removed it and then overwrote memory locations with gibberish to thwart forensic examination.
I'd like to know how many writes it did since this would finally settle the issue of whether FBI / NSA can read erased data. If one write is good enough for them, you know they can't recover anything with one write either.
- tjohns 14y agoResearchers already have samples of Flame saved. Nobody needs to do forensic analysis to try and recover deleted files here. In all likelihood, all the Flame authors are trying to do is prevent computer owners from casually detecting that they were infected, now that Flame is public knowledge.
- robocat 14y agoPresumably it is purging machine specific (targeted) configuration, code updates, and spooled data too, i.e. not just the virus code. Knowing specfically what the virus was looking for, which machines were infected, and what data was snarfed is of critical importance to the targets. Purging makes the targets job of forensics much much harder. Edit: flame code is not monolithic - forensics would be very interested in getting code for all modules: "Later, the operators can choose to upload further modules, which expand Flame’s functionality. There are about 20 modules in total and the purpose of most of them is still being investigated." - http://www.richardsilverstein.com/tikun_olam/2012/05/28/flame-israels-new-contribution-to-middle-east-cyberwar/ http://www.richardsilverstein.com/tikun_olam/2012/05/28/flam...
- sp332 14y agoStuxnet was US-funded, Flame wasn't.
- morsch 14y agoAnd you know this... how?
- sp332 14y agoWell, it could have been funded by Martians :) But the main suspect right now is Israel, not the US. This guy clearly has an agenda, but claims "My major scoop is that my senior Israeli source confirms that it is a product of Israeli cyberwarfare experts." http://www.richardsilverstein.com/tikun_olam/2012/05/28/flame-israels-new-contribution-to-middle-east-cyberwar/ http://www.richardsilverstein.com/tikun_olam/2012/05/28/flam...
- fl3tch 14y agoIf it was Israel, I'd bet dollars to donuts that they got help from American agencies. Either way, a professional government agency somewhere, which apparently knows a lot about cryptology and presumably computer forensics, designed this thing and issued a data shredding command. My point still stands in that the number (and types) of writes they did would be very informative.
- Tangaroa 14y agoSilverstein often quotes a senior Israeli official to say it's Israel's fault whenever something goes wrong in the Middle East, but he never produces evidence and his assertions are rarely backed up by independent reporting. I suspect he's making it all up, or his senior official source is a senior official in a political action group and not the government. In any case, he is not a reliable source.
- richards1052 14y agoYou know nothing about me or my source. But I'll correct your many errors. My source doesn't say it's Israel's fault "whenever something goes wrong in the Middle East." That's only your distorted interpretation. But when he does inform me of an imporant development related to Israeli national security, I report it. Sometimes I agree with my source, sometimes not. My source, for example, supports Israel's covert war against Iran. I don't. But I report it because I'm a good journalist. Second, my source has extensive Israeli military, political & intelligence experience. Third, almost all his scoops have turned out to be true. None have been proven false. Now, what are your bona fides & do they match his?