Slashdot Mirror


US Government Checking Up On Vista Users?

Paris The Pirate writes "This article at Whitedust displays some very interesting logs from Vista showing connections to the DoD Information Networking Center, United Nations Development program and the Halliburton Company; for no reason other than the machine was running Vista. From the article 'After running Vista for only a few days — with a complete love for the new platform the first sign of trouble erupted. I began noticing latency on my home network connection — so I booted my port sniffing software and networking tools to see what was happening. What I found was foundation shaking. The two images below show graphical depictions of what has and IS trying to connect to my computer even in an idle state'."

20 of 291 comments (clear)

  1. I call bullshit. by XorNand · · Score: 5, Insightful

    I swear this place is becoming more and more like Digg everyday. I'm no longer renewing my Slashdot subscription while I can get this same quality news for free elsewhere. Where do I start?

    1.The screenshots clearly show WinXP, not Vista. In fact, this guy's ultra-leet "port sniffing software and networking tools" is PeerGuardian 2. Straight from the product's home page: Note: PeerGuardian 2 does not support Windows Vista at the moment. This is a top priority, and we hope to have a Vista download soon.

    2. Lame screen shots from some Windows app isn't enough to validate a conspiracy theory. Where's the complete traffic dump? And not from some random guy and his "fanboy" friend; how about a creditable network security organization? Hell, I'd even settle for an intern with his CCNA.

    3. Hard to tell because all we have are screen shots, but it looks like nothing more than port scans. ::yawn::

    (Guess is this is what I get for spending a beautiful Sunday afternoon indoors, on my computer).

    --
    Entrepreneur : (noun), French for "unemployed"
    1. Re:I call bullshit. by igotmybfg · · Score: 5, Insightful

      1.The screenshots clearly show WinXP, not Vista. In fact, this guy's ultra-leet "port sniffing software and networking tools" is PeerGuardian 2. Straight from the product's home page: Note: PeerGuardian 2 does not support Windows Vista at the moment. This is a top priority, and we hope to have a Vista download soon.

      The screenshots also clearly show another computer is involved, since he is remoting from his Vista PC to his Windows PC. Perhaps they are both on the same network, and he has reason to believe that these connections are being caused by having Vista on the network.

    2. Re:I call bullshit. by Anonymous Coward · · Score: 5, Insightful

      I agree, but .. you missed the best part.
      PeerGuardian is for blocking *incoming* connections, this has nothing to do with Vista *AT ALL*.
      The names that show up against the IP are taken from user submitted rule files(In case you didn't know this is so that IP's from RIAA/MPAA employed companies can be blocked-who log all ip's connected to any torrent as seeds/leeches). There is no validation on the name corresponding to the IP. Complete and utter FUD.
      Even the IPs DID correspond to DoD etc.. there is a completely plausible reason for that.
      Bit torrent clients cache IP addresses so that they can connect to all the seeds/leeches in case the torrent managing host goes down. All this has proven is that the US Government uses Bit torrent.

    3. Re:I call bullshit. by SocialEngineer · · Score: 4, Insightful

      Maybe he's got multiple machines hooked up to a hub, with the XP machine sniffing in promiscuous mode. Maybe he's tunneling the connection through the XP machine. Who knows. While I too am inclined to call BS, the XP argument doesn't fly.

      --
      "Better to be vulgar than non-existent" -Bev Henson
    4. Re:I call bullshit. by guardiangod · · Score: 5, Insightful

      For the first time in many years, I agree that /. ain't what it used to be.

      Blah how does this make the front page? There are million of reasons for these connections.

      Maybe he is using a dynamic ip based isp and he just got a new ip? Maybe the last person who used that ip was using bittorrent? Botnets trying to reconnect to this ip?

      Aside from those "Remote Desktop" xp screenshots, I noticed there are Hei Long Jiang education committee, UN Development program, China Edu and Research Network, and whatever.

      I guess the DoD and the "Chinese intelligence agency" are both attacking his computer.

      UN probably sent some people to infiltrate his computer as well.

      Wait, Hei Long Jiang is right next to Russia? Maybe the KGB is using China's network to go after him as well!*roll eyes*

      Even if they are not bt, they might just as well be port scans.

      News for nerds, indeed.

    5. Re:I call bullshit. by gujo-odori · · Score: 5, Insightful

      Yeah, I looked at the wide-ranging place he's getting connections from and asked myself, "Now, what do IPs in all those places - especially China - tend to have in common?" I've been working in email security for four years and was a postmaster before that, so I had a ready answer to that question; zombies.

      P2P and fast-flux networks is the current cutting edge of botnets, and that fits with all the inbound connections he's seeing.

      The explanation that fits best with his experience is that his Vista box has already been owned and has become part of a botnet.

      While his conspiracy theory that Microsoft is in bed with DoD, DOHS, and Haliburton (gimme a break!) is clearly anti-MS FUD, there is good reason to draw a bad conclusion about Vista from this. One of Vista's big selling points was better security, yet here we have somebody stepping up front and center with an apparently freshly installed and freshly owned Vista box.

      The article doesn't speak well of Vista, but not for the tinfoil hat theory advanced by its author.

      The other leading theory, which has been advanced by a number of others, is that he's running bit torrent or another P2P app. This is also plausible, and if the zombie theory is wrong, then the P2P app theory still holds. Bhy far the least likely explanation is the conspiracy theory advanced by the author.

    6. Re:I call bullshit. by Ravnen · · Score: 3, Insightful

      For the first time in many years, I agree that /. ain't what it used to be.

      I'm afraid I have to agree. The misleading article summaries are bad enough, ranging from being irrelevant to actually implying the opposite of what the articles in question say, but I find it hard to believe the Slashdot editors would really believe the sort of claptrap written in this article. I think the sad reality is that they know it's drivel, but also that it will generate traffic, especially from the nutter contingent, and this, in my view, reflects poorly on their integrity.

    7. Re:I call bullshit. by KDR_11k · · Score: 3, Insightful

      there is good reason to draw a bad conclusion about Vista from this. One of Vista's big selling points was better security, yet here we have somebody stepping up front and center with an apparently freshly installed and freshly owned Vista box.

      However, we don't know how much user error was involved.There's always the chance that he was running admin and clicked yes when it asked him whether vista_activation_keygen.exe should be allowed to run with full admin rights...

      --
      Justice is the sheep getting arrested while an impartial judge declares the vote void.
    8. Re:I call bullshit. by uvajed_ekil · · Score: 3, Insightful

      He said the traffic in question related to his home network, not necessarily the machine that was running Peer Guardian 2 for the screenies, right? I don't know how much difference this makes, just playing devil's advocate and trying not to dismiss every concern as BS. It's easy to ignore everyone's alarming claims as over zealous, misunderstood data, but maybe we should take this type of thing more seriously until we have all the facts.

      --
      This is a hacked account, for which the owner can not be held responsible.
    9. Re:I call bullshit. by smilindog2000 · · Score: 4, Insightful

      I found the responses to this article very informative. The article itself was just some college kid, probably not the world's greatest network analyst. However, the responses include some very insightful comments. I think it's wise of /. to pick articles that invoke interesting dialog, and if you take that measure into account, this article isn't half bad. In particular, if I similar connections to my home network in the future, my first thought will be "zombie or P&P", rather than "world governments are spying on me".

      Actually, my first reaction to this article was "What! The US doesn't need to make connections to spy on me!" With AT&T's big fat pipe to the NSA, the government get's all the data it wants about me, even though I run Ubuntu.

      --
      Beer is proof that God loves us, and wants us to be happy.
  2. Highly Suspicious to me... by tgatliff · · Score: 5, Insightful

    Either M$ is the dumbest company on earth, or this is a scam article. I would assume that if M$ was in fact monitoring users, which I think is quite possible, then all of the information would go back to Redmond and then distributed to the appropriate groups. At least this way they have plausible deniability....

    Also, "Halliburton"? Give me a break.... First, what type of tool is going to return a text output so blunt... Not is not "HA-39214", but instead is just "Haliburton" the evil company.... Also, I am certainly not a fan of the company and its former involvement with the vice president which just smells bad to begin with, but what in the world would a military contracting company that fufills soft drinks, food, oil, and other supplies to military groups want to monitor computers... This is just unrealistic...

    1. Re:Highly Suspicious to me... by Anonymous Coward · · Score: 3, Insightful

      whois 34.60.236.180
      [Querying whois.arin.net]
      [whois.arin.net]

      OrgName: Halliburton Company
      OrgID: HALLIB-1
      Address: 10200 Bellaire Blvd
      City: Houston
      StateProv: TX
      PostalCode: 77072-5299
      Country: US

      NetRange: 34.0.0.0 - 34.255.255.255
      CIDR: 34.0.0.0/8
      NetName: HALLIBURTON
      NetHandle: NET-34-0-0-0-1

      and so on. So, yes, it's in Halliburton's IP range. That still does not mean anything, though. PG as a traffic analysis tool is a joke, as others pointed out already. At least he could have displayed the destination port and check what service is supposed to listen to it, if any. This way it might very well be just a bunch of zombies portscanning away[*] - there are a bunch of University addresses (Purdue, Athens, Rio) and a couple of Chinese IPs. Wow, MS must have really sold out to the barbarian invaders, right?

      [*] I'm giving the guy the benefit of the doubt about these not being attempts to connect to his previously-running p2p application, although with the carefully-trimmed destination ports from his screen-captures maybe I shouldn't. After all, he was clever enough to tune this blog entry to the net-herd paranoia and get hits from at least /.

  3. Re:PeerGurdian is not a legitimate investigative t by CastrTroy · · Score: 4, Insightful

    Which when you think of it, makes complete sense, because the Internet was invented for and by the military.

    --

    Anthropic principle: We see the universe the way it is because if it were different we would not be here to see it.
  4. I was going to mod you down... by msimm · · Score: 4, Insightful

    Just as over-rated. But I realized leaving your post modded higher makes more sense anyway (since you obviously weren't ust trying to be a prick and this why the whole conversations is easy to read).

    As you'll see in one of the follow-up posts to this parent the software is being run on a second systems (since as you point out Vista isn't supported the listener is XP).

    As to the credibility of the rest of the story I suppose that's up for grabs. Or rather reproducibility. Sniffing software is easy enough to install/use. Maybe the poster of the original story is being watched via a government trojan. Maybe there is a backdoor for the government to use to monitor potential criminal. I imagine if ALL Vista systems phoned home like this they'd be drown in data so it's either addition software, activated existing feature or hoax/fluke.

    --
    Quack, quack.
  5. Connection to or from? by Britz · · Score: 4, Insightful

    I guess all those computers are botnets (check out the other connections, DoD is only one among a whole bunch of seemingly random international sites including a couple universities from Brazil and China) trying to get more bots using security holes and trying if they have yet been patched on random IPs.

    Because those are trying to connect TO his computer from the outside, not the other way around.

    What a load of bullcrap. Where does /. pick up its editors?

  6. Statistics by tsa · · Score: 4, Insightful

    Those are some very strong allegations. I can't understand why /. soiled its pages with this. The guy didn't even try other machines and other operating systems. No statistics at all. This is the worst 'article' I've seen so far on /., and I have seen some really bad stuff here already. Indeed, as one poster said, /. is becoming more and more like Digg. And that is NOT a compliment, Taco at al.!

    --

    -- Cheers!

    1. Re:Statistics by TopSpin · · Score: 4, Insightful

      I can't understand why /. soiled its pages with this.

      As I see it, there are two possibilities:

      The first is that the story actually had credibility with Zonk and he was more than happy to put it up. Put Halliburton in a story and the truthers soil themselves. The second; Zonk saw through it like any other technically savy grownup and knew it would be ridiculed. In that case it is a sort of April Fools joke.

      Anyhow, there are plenty of reasonable explanations already posted for the 'evidence' provided. Here is one I didn't notice; why would 'they' use easily identified domains to spy on people? 'They' run the world so clearly 'they' could arrange for something less obvious, no?

      Finally, is there any recourse for a business that has had it's products publicly slandered? I'd hate to see Microsoft get a piece of /. in court, but it wouldn't surprise me if they tried.

      --
      Lurking at the bottom of the gravity well, getting old
  7. Halliburton? by Jeian · · Score: 3, Insightful

    Halliburton?

    He's really grasping, isn't he.

  8. No Destination Ports by tiny69 · · Score: 5, Insightful

    The screenshots conveniently leave out the destination ports. With out that information and without knowing what programs the user had installed or running, the entire article is a waste of time. We have no idea if the traffic is associated with a program he's running or if it's something else. He's concerned about connections that appear to originate from the U.S. Government, but isn't phased by the connections appearing to come from China. Oh noes!?! China has a backdoor in Vista!!

    My guess is that he's running some P2P software. Guess what? The U.S. Government does get 0w3nD and does have problems with viruses, trojans, and P2P software.

    Nothing to see here. Move along....

    --
    Go not unto/. for advice, for you will be told both yea and nay (but have nothing to do with the question)
  9. Re:think again by Fallingcow · · Score: 4, Insightful

    Peerguardian2 under WinXP commonly shows DoD and other odd incoming requests. Let's see what's on my log of recent attempts right now...

    Kuwait Ministry of Communications
    AAFES/Barracks
    Military Medical Academy

    And a host of other weird entries. I know I've seen DoD on there before... let's check my older logs:

    Federal Electric and Water Authority (WTF?)
    Saudi ARAMCO (oil company)

    OK, no DoD now, but the point is that weird crap shows up in Peerguardian all the time. DoD entries appear fairly frequently. If this guy's run any P2P software in the last, oh, week or two, that'll cause this to happen.