HN user

xnull1guest

128 karma
Posts0
Comments53
View on HN
No posts found.

I seem to be in the minority on Hacker News, but as someone in the professional computer security field I know that any company or state/department/organization can be hacked by a motivated attacker. In the case of SONY, the attackers were able to enter the network through spearphishing emails - something that essentially no investment in security is going to prevent. The malware similarly could not have been detected, as signatures for this specific compilation were not known.

I have a hard time blaming the victim of a cyber attack that would have been practically impossible to prevent. I agree that SONY made bad decisions with regard to its hording of unnecessary data, but also recognize that this is hardly unique to SONY and not standard advice given by security professionals (it should be).

Norms are important so that you can accuse 'groups with no morals or ethics' of doing something wrong. Norms may only discourage and not prevent behavior but without norms its difficult to find common ground for behavior that may otherwise be chalked up to 'culture' or 'tradition' or 'nature'.

We can't really know. There is no way to be perfectly certain.

That said one can apply an Occam's calculus using whatever information and reasoning you do trust. I personally trust that, whomever the #GOP was, they were motivated by SONY's role in developing "the movie of terrorism". This seems to me to be consistent with what the group published and with their 'Christmas surprise' showing collaboration between the State Department and SONY on the development of the movie related to its diplomatic value - something I don't think the NSA or allies would do. So I think the group had NK sympathies in mind. Granted, this doesn't rule out attribution to other states or hacktivists who hold these sympathies.

Thank you again for your reply. I am aware of the confusion regarding PRISM and its 'vernacular' use to encompass the activities from other disclosed programs in addition to confusion about its particular details.

In your haste I'm afraid you may have drafted a response that is not on the topic of its parent, though this is okay since it appears the conversation found a natural and agreeable conclusion.

The norms in question are those of cyber attacks. This includes but is not limited to intelligence operations. The SONY attack, for example, was not an intelligence operation. The downing of the Syrian airforce was not an intelligence operation. Nor was Stuxnet or the the Georgia cyberattack.

Norms are important because they are precursors to law (in this case international law). Norms create ground upon which a country can accuse another, a ground upon which you can achieve consensus among many parties, and norms set expectations of behavior that if loosely followed every country can benefit from.

Thank you for mentioning international cyber operation norms. This is the center of US international cyberpolicy efforts. Ontologies describing categories of cyber operations often place destructive attacks like the one against SONY into a category of its own and these are usually considered fair only in very particular scenarios of provocation.

An addendum here regarding 'free speech'. There is some question about The Interview being a propaganda effort on behalf of the US State Department (which was given a preview as early as July) since #GOP released emails where CEO Lynton discusses the effects of the ending with RAND Corporation strategist and nuclear deterrence specialist Bruce Bennett and Lynton confirmed analysis of its effectiveness with Senior State Department officials. (It also doesn't help that the script writer was asked specifically to consider changing his character from an anonymous leader of NK to Kim Jong-Un).

The sophistication of the attack is pretty questionable IMO. The malware used can be purchased by anyone on the black market and had been used before by Iranian hackers in 2012. Furthermore, spearphishing emails were used to get inside the network. Furthermore, how would sophistication be evidence against a State actor with (a reported) 7,000 personnel?

I similarly don't see the risk (and collateral damage) v. reward pan out. Plus there are so many legitimate cyber attacks against the United States, it would seem like a waste of resources. And it doesn't seem to me like the NSA would so joyously release the Lynton/Bennett/State Department emails. If they wanted to paint NK in a bad light this would seem so counter to that goal.

Interesting. I had thought it was common knowledge at this point that the US regularly hacks and is hacked by other nations.

I think the biggest splash this article may have is added narrative supporting the truthiness of USG attribution to NK - something that seems to be held in high doubt by a large percentage of the technical crowd (but that I think seems pretty reasonable).

I absolutely believe that attacks are used as conveniences to justify legislative wishlists, but question whether such things are planned in advance like you are suggesting or are opportunistic responses to actual events.

Regarding encryption bans I've mostly seen justification referencing the Charlie Hebdo attacks (which are assuredly not a false flag).

Personally I believe that North Korean sympathizers were behind the SONY attacks given a number of pieces of evidence, but most heavily the #GOP leaks of emails detailing SONY collaboration with the US State Department and RAND Corporation that point toward The Interview being a strategic diplomacy product.

Certainly false flag operations are a tactic that has seen reliable and regular use, especially in counterintelligence. But what purpose exactly would a false flag operation against SONY serve? Definitely not as a pretext to take action against North Korea - the US could much more easily justify actions against NK than it has many other nations in its history.

We know that the NSA tapped into computer systems and the backbone of essentially every country on Earth - I don't see how NK would have somehow been excluded.

What's interesting is what information the New York Times includes that is not covered in the NSA document, presumably from unidentified officials and former officials.

The document on Der Speigel speaks primarily about taking copies of intelligence from SK hacking efforts against NK and also taking copies of intelligence from NK hacking efforts that had in turn been hacked by SK (and in turn by NSA - "fifth party collection").

The document mentions the NSAs unwillingness to rely on intelligence filtered through so many third parties and made efforts to establish its own foothold.

Essentially none of the article is backed by the document as a first source and must have come from the unnamed sources.

Thanks. From what I can tell you agree with:

there is no encryption for there to be escrowed for large or critical parts of the infrastructure

That is to say that TLAs get access to records before encryption is ever applied to them (I would tend to agree with this) thus obviating the need for escrow. Laws requiring key escrow, then, become red herrings to the larger discussion about the legality of access.

I personally would classify 'partnerships' under extralegal pressure. Under this interpretation you do seem to agree with the GP comment - though I would understand if one were to argue that for some important semantic reason I asked the question with the wrong word. I would probably agree that 'partnerships' are only a strict subset and not synonyms for extralegal pressure.

It does appear that there are partnerships with some digital corporations and that PRISM is a program for corporations that resist 'partnered' access to records. Given the history of telecoms and their development of partnerships, current development of partnerships in our industry and known applications of extralegal pressure in our industry, we ought to be especially watchful.

I agree with the author that in the short game not providing your own accounts is attractive. However in the long game it doesn't look so good. Unfortunately there are problems with using federated auth everywhere.

* It's a single place for a compromise to occur - the devastation of a serious identity provider hack completely upends the security of huge swaths of the internet in a single shot

* Breaks in fedauth protocols and implementations, similarly, presents a large auth crisis for the entire Web

* It's a single place for legal or extralegal pressure for governments to access services and data on behalf of everyone

* It creates market friction. If federated login had been around in large numbers when Myspace was the big social platform we'd still be using Myspace for the sheer reason we need it to vouch for our identity. It makes the big fedauth players 'too important to fail'

One should consider options carefully and determine whether a good user experience can be offered without further centralizing the Web.

- The malware used by the group had fingerprints and components of known Iranian, Korean and Russian malware and is a package sold on black market forums.

- The malware used was nearly identical to the that used by the Iranian group who attacked the Aramco oil company in Saudia Arabia in 2012.

- Linguistic analysis of the communications by #GOP suggest a native Russian author.

- SONY had given the US State Department a preview of The Interview in July 2014 (after the Mundt-Smith anti-propaganda law was immolated) and SONY was contracting with RAND Corporation specialist Bruce Bennett, a specialist on nuclear deterrence (NK is a nuclear state) and North Korea.

- Leaked emails with Bennett have him discussing the effectiveness of the movie to cause instability in North Korea.

Now McAfee is claiming the group had anti-trust motivations?

The SONY hack gets more and more interesting.

somebody should tell Obama

Oh he knows. Lip service to the public about terrorism is just that.

Is anyone going to attempt to argue that encryption facilitates more fraud than it prevents?

No idea.

Keeping things on topic financial fraud, insider trading, etc is an example where strong encryption does complicate the state's ability to enforce and investigate illegal activity. The purpose here is to draw from a well of motivation other than oft cited but never seen use of encryption in 'terrorism'.

The government's fear is that ubiquitous access to these tools will deprecate the executive branch. All tools from nuclear enrichment to hammers to animal husbandry have noble and malicious potential. Encryption is no different. The executive branch's job is to allow the noble purposes and to discourage, prevent, investigate and indict the malicious.

From the perspective of the executive, encryption presents a serious hurtle to the pursuit of the malicious.

Yet disagreements between the public and the executive about the the scope and breath of executive practices along with the US incarceration rate, of legal exceptionality of the rich and powerful, and general unease with current power structure coupled with traditional mythical US values means that the public would like guarantees about their ability to communicate without being searched.

The US public wants its cake and to eat it too. Secure and private communication for the masses that can not be intercepted. But it wants the executive branch to be able to enforce the law and to investigate broadly.

The executive branch has made many proposals to this middle ground: the clipper chip and key escrow, proliferation of weak cryptography and the use of third party doctrine as a buffer zone mechanism all represent compromises the executive branch has made.

What it comes down to is that the US public does not trust the executive branch not to abuse a middle ground - it points to historical and current examples of extralegal abuse - and in general feels that its government represents their interests but only after compromises with other 'more important' interests (international and domestic elite).

That is to say that the current state of "front door" encryption is a compromise made by the executive but one that the public does not trust.

Yet the public still wants law enforcement to be able to investigate insider trading.

So the government is in a bind. The government is justified to the people by its ability to enforce the laws of the land - if it can't, even for technical reasons - it will have difficulty seeming justified. The government's solution is to invoke the boogieman. 'Terrorists' will get you if we don't compromise. 'Pedophiles' will get your kids if we don't compromise.

But no, it's not about terrorism - it's that the government does not know how it will be able to stand up to proper strong cryptography in the case of true and perceived malicious use.

Freedom is like a dove, yadda yadda.

Encryption is like osteoporosis.

Right. I find it hard to believe that Obama and Cameron are going to take away our encryption and someone convince our adversaries to abide by those rules.

Entirely. Historically this has been achieved by subversion of cryptographic methods, consumer products and standards and misinformation about security margins. It has made legitimate strong cryptography hard to come by but not specifically illegal. It is likely to become more and more difficult to perform this sort of influence now that the cat is out of the bag.

This is sort of off topic, but it is amusing.

I would guess that it is a combination of:

- A deemphasis of poetry and literary studies in the concept of being educated and cultured

- The rise of writing staff and PR professionals in the practice of engaging with the public

- The relative lack of importance writing has today compared to newer picture and video delivery (media is message, etc)

- Inherited nostalgia for forms associated with 'classic' art styles

It is not about terrorism - it is that technology like this threatens the current level of the capability of the state to enforce its laws. Imagine instead the use of encryption among the financial elite to conspire to defraud speculation markets or manipulate stock prices. Or enemy states using encryption to thwart espionage attempts. Or insurgents and soldiers engaged with US troops around the world to organize efforts to put up resistance.

Remember that Julius Caesar famously sought to make pen and paper illegal because he saw such low barriers to fast potentially secret communication a threat to Rome's security.

I know of no case reasonably called terrorism where encryption played a role in thwarting intelligence efforts.

I suppose if we make it illegal, the terrorists will just have to make do with weak encryption.

When encryption is outlawed, only outlaws will have encryption.

This kind of "privacy" (lack of the existence of institutionalized absolute compelled disclosure to law enforcement and along with broadly cast suspicion less search) was once called liberty and freedom by American mythological forefathers.

James Risen tried to publish it in 2004 but the Times fell to government pressure and refused to make the information public until over a year later (only because Risen threatened to tarnish their image over it); when the Times did publish it but buried under other stories.

So... both.

Certainly information from these businesses on how they believe different legislation will effect them is useful to voters, their representatives and their appointees in performing a legislative calculus.

But what certain companies 'advocate' for? This is hardly useful information for the design of legislation...

We agree. I'm not saying ignore everything they possibly say. What I am saying is ignore what they merely advocate for and pay attention to why they advocate for it and what information they can give relevant to the design of a healthy and flourishing industry.

When political discussion devolves into a series of corporate for-against it looks more like a sport and cheerleaders than a democracy. Legislation can not be about deciding who wins in the market but about designing markets that eliminate rent seeking, moral hazard, and externalization of costs while promoting fair competition between businesses of all sizes. You can't know how to design such legislature without understanding the conditions of an industry and how changes will effect current players. But you also can not design markets within the confines of regulatory capture or by merely noting which current players will stand to benefit or lose from a given legislative delta.

The word insanity here is meant to convey a lack of grounding in the reality of the situation: advocation doesn't signal whether legislation will make a market healthier or serve customers/citizens/nations. We know what Sprint wants - more money. What we need to know from Sprint is not whether given legislation will or will not lead to their getting more or less money but details that clarify how proposed legislation will or will not "eliminate rent seeking, moral hazard, and externalization of costs while promoting fair competition between businesses of all sizes."

It's a sort of an accepted insanity that the positions which these large businesses take are considered important.

Certainly information from these businesses on how they believe different legislation will effect them is useful to voters, their representatives and their appointees in performing a legislative calculus.

But what certain companies 'advocate' for? This is hardly useful information for the design of legislation (it's a single bit, and a complicated one). As these large businesses should have no direct say in how they are regulated, I don't see why we the people should care what companies 'endorse'. They don't get a vote.

Whether Google or Sprint or AT&T or Comcast sanctions or opposes net neutrality should mean nothing and should not be worthy of news. The companies that happen agree with the general public do not do so on the ground of ideals or liberty or heroism but on the ground of profit. They are not the stewards of public interest or champions of the public - only the public can do and be this. We can't count on Sprint or Google or any other company to get the legislation we want passed - because if we condone that we also condone their passing of legislation we don't.

What exactly makes privately run VCs more efficient than government run VCs exactly? They are both centrally managed and entirely top-down. There are plenty of examples of horribly run, crash-inevitable private VC.

I can think of two possible differences but perhaps there are more:

A) For independently wealthy VCs, the money comes directly from personal funds, so investment is presumed to made carefully

B) For VCs where a panel/firm decides how to invest capital provided from someone else's fund, commission on success and legal contract may provide incentive for firm members to be careful

In theory, similar leverage (bonuses, legal trouble) applied to those making analogous top down decisions in a governmental organization would produce like incentives and therefore competitive efficiency.

Theoretically the public/governmental investment model could have other benefits. For example projects like Wikipedia, which provide 'social' income rather than 'financial' income, can be invested in. Another benefit is that the VC is more free to ignore investment bubbles (hyperlink, ad space, 'social', big data). Finally, since private VC circumvents the IPO process and is able to capture the majority of growth value of new businesses, it highly concentrates wealth. This caustic side effect may be side stepped by public programs.

First, note how the only numbers addressed are the '2,776 instances publicly known'. So from the start we're working with unreasonable numbers. But let's run with it.

Hmm. If the average number of mistakes an analyst makes is 0.1 per year and there were 700 mistakes only, this means 7000 analysts (or do we need to model this as a poisson distribution?). Is 7,000 analysts reasonable? Anyone have more details on this?

The NSA has said that it performs about 20 million queries a month, or 240 million queries a year. If these are done by analysts that's 16 manual queries an hour or 130 a day assuming a standard work week. That seems reasonable. Or at least reasonable"ish". [240,000,000 / 7,000 / (5/7 * 8 * 365)]

But it would also imply an error rate of 700/24,000,000 = 0.000002917 (which is absurd, if the error are presumably due to 'typos').

Even for the NSA the potential of a backdoor is a problem, because every division has to trust the person that has actually generated the points. And as the Dual_EC_DRBG was used by the DoD, this person potentially has the keys to some very sensitive parts of the kingdom.

While this is generally true, it is possible for a person or organization to remove the backdoor by generating their own point and/or by reducing the number of bits generated from curve points at each RNG step (which NIST had pushed for an insecure number of).

I can't claim to know for sure, but it would be my guess that the implementations used at the Federal Reserve, the DoD and other highly sensitive areas of government that use public algorithms highly vetted to remove known implementation problems and weak parameterizations.

I absolutely acknowledge that bad regulation is a problem, and wish more liberal minded folk would as well. But the problem is again not a binary one: the 'free' market also favors monopolies and incumbents and without a system of punishment and enforcement it is fact (historical and current) that companies will do everything in their power to externalize costs, fix their own success and seek rent.

So it's more a matter of creating 'good' regulation and designing markets (think cap-and-trade) that meet all criteria. It's not easy and you are right to be skeptical of industry's current role in designing its own regulation.

The Net Neutrality 'debate' is an example of politics I'm beginning to see all the time in the United States. A real problem is presented along with a single problematic solution from which voters, with as much or little influence they actually have, and their representatives are asked to select the 'lesser of two evils'.

The real discussion is not whether the country's big media duopoly should be forced to conduct their business model like a public utility or not, but whether a duopoly is healthy at all. If communication infrastructure requires few large investors and centralized ownership it is a natural monopoly and should be managed as such (and in fact resold on a market of small service providers a la the UK's internet and American power). If it does not, let anti-trust law hammers fall. Comcast and Time Warner consistently collect the very worst consumer reviews (Comcast was the worst of all corporations for year running). They are both larger and more predatory than Ma Bell was leading up to 1984.