5 ms·
It seems ridiculous that an "intelligence" organization would upload files to a server that identified themselves so blatantly like that. Could it be that it i
by kjackson2012 14y ago
It seems ridiculous that an "intelligence" organization would upload files to a server that identified themselves so blatantly like that. Could it be that it is some ruse of some sort? I don't doubt that someone broke in, but would it really be CSIS?
- mcantelon 14y agoCSIS aren't the most competent intelligence organization in the world.
- corresation 14y agoFor the limited scope of the work that they do (which is essentially limited to what the NSA does in the US. They don't really do what the CIA does), and with a relatively small $600 million dollar public budget, they're known to be quite competent. This story sounds...weird. I doubt it is quite as he suspects it is.
- mcantelon 14y ago>which is essentially limited to what the NSA does in the US. The NSA doesn't do field intelligence work, AFAIK, unlike CSIS. >This story sounds...weird. I doubt it is quite as he suspects it is. It's weird, but I'm not sure who else other than CSIS would have the motivation to hack an activists computer so it sends data to CSIS-affiliated servers.
- corresation 14y agoThe author said "Hostnames that appear to belong to CSIS.". Reverse DNS should not be trusted. Saying that a hostname "appears to belong" to someone is a naive statement.
- strlen 14y agoIndeed, spoofing reverse DNS is not hard -- and spoofing reverse DNS to appear like an intelligence agency is straight out of every 1990s IRC script kiddie's cookbook.
- deleted 14y ago[deleted]
- fatbird 14y agoI think you've got it mixed up: CSIS [0] is the Canadian CIA, having been created in the wake of shutting down Department D of the RCMP after one too many scandals in the 1970s. The Canadian NSA is the CSE [1]. [0] http://en.wikipedia.org/wiki/Canadian_Security_Intelligence_Service http://en.wikipedia.org/wiki/Canadian_Security_Intelligence_... [1] http://en.wikipedia.org/wiki/Communications_Security_Establishment_Canada http://en.wikipedia.org/wiki/Communications_Security_Establi...
- redthrowaway 14y agoCSEC, now. I'm thinking of interning there in the summer.
- richardlblair 14y agoYou aren't now. I happen to know that upon applying you are directly told not to tell anyone you applied, or even that you were thinking of applying.
- redthrowaway 14y agoNo, only thinking of it.
- adambenayoun 14y agoThen you aren't anymore.
- lostlogin 14y agoWhich one is? I put the Mosad up there, but most are summed up by the statement: Reward for failure. Screw up, get given a bigger budget so it doesn't happen again.
- phnk 14y agoEven high-profile organizations have a spectrum of competence within their offices.
- kfury 14y agoAn actual exploit like this designed to monitor the hacked computer would likely either talk to a small range of IPs in the infiltrating organization, or a widely scattered botnet. Trying to contact a small variety of servers of various disparate government agencies seems more like an attempt to generate false evidence that the victim is actually a dangerous hacker. Or at least that's what Stephenson, Doctorow, and Gibson have trained me to think.
- chiph 14y agoI was thinking it was a false-flag scenario as well. Other than the network identifiers, there's nothing to say it was the Canadians behind it.
- perlgeek 14y agoDon't assume they act intelligently, just because they have "intelligence" in the name. Many people who make the decisions aren't IT experts at all.