13 ms·
Halluxwater: NSA Exploit of the Day
- zmh 13y agoThe picture: http://leaksource.files.wordpress.com/2013/12/nsa-ant-halluxwater.jpg http://leaksource.files.wordpress.com/2013/12/nsa-ant-hallux...
- jevinskie 13y agoThat is a somewhat confusing picture. It seems to imply that the CPU loads the OS and the OS loads the BIOS!
- rurounijones 13y agoWell the US govt has been saying that Huawei kit could not be trusted... I guess they were right...
- timsally 13y agoThis article states the NSA developed an exploit for a product made by a Chinese networking and telecommunications firm. Honest question for HN readers inside the US: does anyone seriously have a problem with this? In my mind it falls squarely within the NSA's mission, i.e. this is we pay them to do! Question for HN readers outside the US: can you credibly claim your intelligence agencies aren't trying to do the same thing? For those thinking about whether such things could be used inside the United States. Of course they can. So can all the equipment and weapons the military buys. And it's happened before! The gun in the Fort Hood shootings was bought and paid for by US tax dollars and it was used to kill a civilian. So this raises the question, is the military to be trusted with weaponry it needs for its defense mission even though they could be used in the US? Similarly, is the NSA to be trusted with exploits it needs for its SIGINT mission? Interesting question. An infantryman could go rogue at any time and use his service weapon against US citizens and someone at the NSA could use an exploit for personal gain, but on the whole I believe the system accounts for these possibilities in a reasonable and controlled way. If this information is true, it seems a little crazy to me to be propagating it since there isn't really a domestic/whistleblower angle. At least, no more of a domestic angle than the military developing a new missile. Some of Snowden's disclosures are responsible for starting a productive civil liberties debate in the United States, there's no denying that. But these disclosures are ones of a different color in my opinion.
- streetnigga 13y ago"does anyone seriously have a problem with this?" Yes. "there isn't really a domestic/whistleblower angle" As if Chinese goods don't get sold within the US[0]. [0] http://www.huaweideviceusa.com/ http://www.huaweideviceusa.com/
- tptacek 13y agoThey don't backdoor all the Huawei devices. That's not how it works.
- streetnigga 13y agoGood thing I didn't say they did. I referenced Huawei USA as to highlight there are indeed domestic facets to this story. I am going to guess given your comment you can with authority detail what devices are and are not backdoored. If you cannot I don't see what your comment is meant to convey other than that 100% of Huawai hardware has not been subverted. Don't start this tactic of distorting someone's commentary again, the last time you decided to respond to me you went about aggressively making up bull-cock as if that is what I wrote. When it was pointed out and asked of you to address the subject instead of bringing up unrelated rubbish you only dug in changing to a belittling tone. Overall I would rather you not respond to me at all. Thanks.
- tptacek 13y agoYour comment doesn't make any sense unless you believe NSA backdoors all the Huawei devices. NSA's implants aren't limited to Huawei; Cisco and Juniper implants have already been disclosed. I figured you believed they were backdooring all of them; after all, you also believe "you have NSA affiliates like Palantir mucking about with firms like Hunton & Williams. Teaming up to do attack work on generally anyone who opposes the persons who make up the facade that is US Chamber of Commerce". I don't care who you want to reply to you or not. You're writing to the thread, not just to me, and vice versa.
- 13y ago
- jevinskie 13y agoDoes anyone know the process that took this leak from the Snowden dumps to Schneier's site? Did Schneier seek consensus from the the other recipients that he should release this particular information? Did Schneier unilaterally decide to release this? Regarding the article, I think it is fascinating proof of the lengths that state-level actors will go through to backdoor their targets.
- e28eta 13y agohttps://www.schneier.com/blog/archives/2013/12/more_about_the.html https://www.schneier.com/blog/archives/2013/12/more_about_th... He's been linking to the leaked catalog entries.
- higherpurpose 13y agoSounds like typical NSA/US gov modus operandi: accuse others of stuff they're already doing.
- willvarfar 13y agoOr perhaps the NSA know China's doing in it, on account of how effectively they have infiltrated huawei?
- pistle 13y agoNSA logos are horrible.
- deleted 13y ago[deleted]
- Zarathust 13y agoSo you need access to the router first with enough power to force a firmware update. What would surprise me is if there are vendors immune from this kind of APT. Given the money and talent invested in those hacks, bricking a whole cargo container of router doesn't seem out of reach, dissolving it in acid or other potentially destructive reverse engineering. If they own the vendor source code then it is even easier, but the mere fact that it is a router/firewall and not an off the shelf Dell pc is of little importance.
- joshwa 13y agoWorth browsing the whole "catalog": http://leaksource.wordpress.com/2013/12/30/nsas-ant-division-catalog-of-exploits-for-nearly-every-major-software-hardware-firmware/ http://leaksource.wordpress.com/2013/12/30/nsas-ant-division...
- atmosx 13y agoSo if you are a company in need of some security, you'd better of with some open source alternative (i.e. Linux/*BSD?