I was thinking about this today and the best thing I could come up with is to volunteer at a food bank, homeless shelter, veteran assistance effort, or something meaningful to those that need it. Anything to directly connect my desire to change society to a kinetic action with real people. I’m not rich but still able-bodied and I work in tech. I’m always drifting off thinking about building something, a fence, minor repairs to a home, or even fixing a car where my hands could be more useful. Our country as portrayed through these digital devices is not the same nation we live in. Those people are there to monetize your anger and frustration, contempt, and outrage. Deny them thes responses and uplift your communities instead. You’ll feel better for it. I will feel better for it. Thank you and be safe!
HN user
jc01480
If I understand this correctly you’re saying a major cell provider is selling you access to subscriber SMS message content?
Agreed. Do your own due diligence.
Hey, hey, ho, ho, Fredo got to go! /s
You’ll be lucky if it’s any longer than 24-hours now. There’s no business use case for building and maintaining the technological infrastructure to manage it for years. It’s private info and they can’t sell it to anyone without legal liability. If LE gave them the funds to build this infrastructure and use it for retention then the service provider is essentially an agent of the state at that point.
You are correct. There’s also varying 2-party/1-party consent required depending on the state in the absence of a warrant. But unless you’re targeting the devices, you will not get much at all from service providers. They simply don’t keep it contrary to what I read here.
Major service providers do not maintain SMS history beyond 24 hours, let alone 1-7 years (last time I worked a case that is). They’re transparent about it as well. Look up the LE liaison contacts on their sites and they’ll clearly list what is available or not available. That’s why it’s crucial to get the actual devices themselves. Reason: the infrastructure to manage SMS content for every customer for 7 years with zero business justification/use case is phenomenal. They’d spend most of their time responding to civil and criminal subpoenas/warrants. That would be a feat the NSA would be proud of. Been there and done that a 100 times. (This also aligns with certain VPN providers refusing to keep logs. It’s a cost that provides zero returns, so they cut it as a business decision, not because they’re trying to stick it to the man.
From a legal perspective, internal counsel may not be able to shield certain things as attorney work product. If an outside counsel is representing the firm the attorney work product privilege is almost impenetrable (in US law). And the privilege can be asserted across all dealings around the investigation and the results. Any firm relying solely on internal counsel needs new counsel. Retainers are a thing.
Is the full analysis posted somewhere?
Are there any “start here” guides for beginning reversing? Like a break it down Barney style? I’ve done some self study and shadowing teams at work but I need to fill in the gaps. Thanks!
If I may ask, where did these come from? Some correlations are obvious but did you use OSINT tools or info posted by actor on social media?
Can you provide other domains associated with this?
It’s odd the article likens the popularity of digital currencies to a time immediately preceding the 2008 financial crisis when it is exactly such a crisis that compelled the idea. There’s no point in reading the article any further.
Wild speculation here but the days of centralized governance (banking) are numbered. Technology and communications are bringing sweeping social reforms to all the things. Cryptocurrencies are another step in that direction. Sure there will be mad attempts at regulation and control in the death spasms of centralized banking. Is it good or bad? Time (years) will tell. But one thing we know for sure is that it will change.
China has denounced crypto currencies once or twice a year since the inception of the concept. Considering they’re at the precipices of their own cryptocurrency it’s no surprise. They’re right on schedule with their denouncement.
Agreed. While the rest of the world moves toward modernizing and exploring crypto currencies the US seems to be regressing as fast and recklessly as possible.
Forgetting the keys is established as protected speech under 1A. Don’t have the case handy atm. Fairly new. Knowing the keys and intentionally withholding them has yet to be established either way. But there will be a case soon enough. Funny thing about law is that both sides (prosec. & defense) often don’t want many things clarified further because they usually have far-reaching impacts to parallel legal issues. Roe v Wade is a perfect example.
Nice article and thanks for sharing. I can relate to the article in that I’ve been a consultant for four years now. I, like many, am now remote with no foreseeable return to an office. I feel like Ive gone through so many phases of feelings since Ive been home and it’s wearing me down badly. I am ready to turn in my notice with no prospect on the horizon simply so I can go back to being normal, or as near to it as can be. I used to love my job. Now it’s this beast hiding in another room of my house and I fight with it every day.
It’s like someone just discovered life is hard and twisted it with a race factor. I honestly don’t intend for this to sound mean, but it’s probably unavoidable in modern society.
I’m noticing some very interesting attacks on blockchain technology lately. I’m willing to bet the calculations are derived from the probability theories we so dearly represent as near certainties.
Humility is a dwindling characteristic in modern times.
Given a compelling need for innovation we could potentially do that. But today’s innovation is about social equities. Billions will be pumped into that for the next decade until - heaven forbid- there’s a new need for tools to perform catastrophic things.
These government scrolls are often very dry reads. But there is some great insight if you think critically about the concepts. Our cyber adversaries read them.
The real threat is the IP obtained about leaders in key positions that will be used to blackmail the same. While that’s more of a Chinese tactic, Russia and others dabble here as well. One could say they simply instituted Assange doctrine for institutional purposes.
Given the fact their CEO is former USAF OIS and has handled this event magnificently using ethics and morals as a guide I seriously doubt they’re hiding anything. They discovered the biggest cyber espionage campaign in the 21st century. And took a few punches to the gut in the process. They are setting a model disclosure example. Unlike the other compromised organizations that won’t admit a damn thing until they’re seated in front a legislative board of inquiry or grand jury.
Or obfuscating your C&C communications in mundane hash functions that appear to be routine periodic checks of file integrity. Exfiltrating your data the same way. They lived off the land and modified code. Pure genius, yet they poked a beehive. Wait for the full disclosure on this one. Impacted agencies and businesses are still assessing the scope of compromise. If you look around and see government businesses that were down over the holidays “upgrading their environment”, that would be a clue. What is frustrating is the number of agencies fully compromised in every respect yet they’ve not disclosed anything. Congress is gonna mindblow in about 6 months. And quite a few state legislative bodies as well. All those orgs hiding what we already know.
This event will be a central security topic in academic studies for years to come. It is a literally fascinating design.
Attribution is to UNC2452 and not Cozy Bear, although there are certain shared characteristics making the source region clear.
Methods utilized in this compromise are consistent with known attributed methods used in breaches not disclosed.
The methods utilized in this compromise are consistent with methods utilized in other attributed breaches not disclosed.