Have a Privacy-Invasion Wishlist? Peruse NSA's Top Secret Catalog
An anonymous reader writes with a link to Der Spiegel, which describes a Top-Secret spy-agency catalog which reveals that the NSA "has been secretly back dooring equipment from US companies including Dell, Cisco, Juniper, IBM, Western Digital, Seagate, Maxtor and more, risking enormous damage to US tech sector." Der Spiegel also has a wider ranging article about the agency's Tailored Access Operations unit.
The NSA has been "secretly back-dooring" the American people for years.
The NSA will achieve the opposite for the USA, not more security but less, with the rest of the world now keen to do their own thing, the NSA are a loose cannon on a rolling ship.
Don't use US service providers. It should be obvious by now, but the reason why the US warn about all kinds of subversion and attacks is that they know what they themselves are doing to the rest of the world.
I own a Dell system and since purchase, once in a while, the hard drive starts churning. Perhaps this is why.
Jokes on them, though. I use the system for work and often read the news -- and that's about all I do.
The dangers of knowledge trigger emotional distress in human beings.
If you actually go to the referenced article and read it you will see that these are exploits, not backdoors, and they apply to equipment from non-US manufacturers as well as from US manufacturers, for example Samsung and Huawei.
Good job slashdot. NOT. A nice raspberry for Der Spiegel too.
Even the delusionals that thinks of this is ok because "it is the NSA after all", it means that more people and agencies have access to those backdoors too, and more chances that it end in the hands of the guys with bad intentions, wherever they are or work for, using them for fun, profit or whatever.
I wonder what will do companies where their first line of "protection" is tools and hardware from cisco, juniper, dell or IBM (or engineers certified on them), now that is official that they are remote access tools for others, bury their heads on the sand or try something else.
At earlier convenience we need to tell to IT non-savy senators and congressmen. The backdoor is like an all purpose key. Now all the criminals and agencies will exploit this.
Such a simple explanation and analogy should be adequate to deliver the point.
I was working for a software company specializing in network security back in the post 2001 period. I recall that we had more than a few discussions with the unskilled egomaniac in charge of the marketing of that firm that many competitors were using their Canadian branch office addresses 'front and centre' in their marketing to the European market.
Why? Because one doesn't always want to be perceived as an American.
The myth of Americans with Canadian flag stickers on their passports is not completely false.
Well, he was horrified at the notion. In fact, if you want to see how existential angst can be suddenly manifest in someone's behaviour in an unexpected setting, try this. I expect that we'll see more of the same in the next year. Ultimately, countries will roll their own code, and have their own Silicon Valleys because of the national security issue. A few years ago I remember seeing an ad from I believe a Swedish firm selling routers and switches that were 'designed and built' in Europe with each unit only delivered to a physical address in Europe. Does anyone else remember this outfit?
---- The above post was generated by the Turing Institute. Maybe.
Looks like this is a loud and clear call for more intensive open source BIOS development.
Don't think for a second that these back-doors that companies put in at the behest of the NSA aren't also being used to the benefit of those companies.
So, if the NSA were shuttered tomorrow, what makes you think those back-doors are going to go away? How much is it worth to those tech companies to know exactly what their customers are doing? How much is it worth to their institutional shareholders?
See, the ugliest part of this is that it's a two-headed monster. Fight one head and the other one will come around and bite you. Both government and corporations have come to believe that they are beyond our reach, above reproach and entitled to everything you have.
You are welcome on my lawn.
Unfortunately I don't have the skill set and there doesn't seem to be any other way to support them.
If you have a machine that supports it, Coreboot could be a very interesting solution.
Learning HOW to think is more important than learning WHAT to think.
Didn't say the summary was wrong. What it said was perfectly correct, but leaving out the fact that the article didn't just talk about US companies made it misleading.
So all those shows we have mocked, like 24, csi, etc, because their tech "hacks the firewall" in 15 seconds were actually accurate? Crap. That changes some things..
What are we going to do tonight Brain?
I'm not sure if the NSA seeking to exploit technology is particularly damaging to US firms. The NSA is seeking to exploit all technologies, not just American-based ones.
I think the part that does damage American firms, was the end of the second article. It read that the NSA has been redirecting the shipping of some computers to their address, installing software or hardware, repacking the device, and shipping it to the purchaser.
Well, if you put it that way... it certainly sounds easier to just let the government keep fucking me up the ass.
By now I'm used to it. And your way sounds like work. Yuck.
Let's compromise. How about every now and then we turn over and let the government look us in the face while they fuck us?
TFA does not give a link to this so-called catalog. Does anyone here have the link?
SELinux is not under suspicion. Putting backdoors in it would be glaringly obvious to anybody halfway competent doing an analysis, as it is just an access control layer and hence rather simple. Being hard to find is a critical characteristic of any professionally placed backdoor, and hence a backdoor in SELinux is very unlikely. You are barking up the wrong tree.
Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
"loose cannon"? Bullshit.
Don't you think for one damn minute that the NSA is "off the ranch" with their programs. They were implemented at the behest of our beloved and benevolent leaders.
The "justice" branch (haha) just declared everything is just fine after all. The executive branch and legislative branch has already said time and time again that the NSA is doing useful and important work.
What really chaps my ass, is not that the government tells people these programs are for the so-called "war on terror" or that certainly, the government would never use it against non-terrorist, but the that nearly every poll indicates that most 'mericans fucking believe them!
I know they have done their best over the last 40 years to indoctrinate kids starting in kindergartener, but it is sad that so many folks just close their eyes and refuse to ask hard questions.
Think about it...forcing children to pledge allegiance to a government... It is fucking crazy. We are brainwashed never to question our masters, and it is working. Fuck, look at the shit your facebook friends post! That is a representation of America.
Disclosure, I feel I have the right to bitch. I did my 4 years in the services and about half that was in the shitty hotspots of the world keeping and eye on brown people.
Modern laptops and desktops come with remote administration tools built into the chips on the board. (The vendors tout this as a feature, simplifying administration of a large company's workstations. It's easier and cheaper to build it into everything than to be selective, so it's in the machines sold to individuals, too.)
One example: Intel Active Management Technology (AMT) and its standard Intelligent Platform Management Interface (IPMI), the latter standardized in 1998 and supported by "over 200 hardware vendors". This is built into the northbridge (or, in early models, the Ethernet) chip).
Just TRY to get a "modern laptop" (or desktop), using an Intel chipset, without this feature.
You can't disable it: Dumping the credentials or reverting to factory settings just makes it think it hasn't been configured yet and accept the first connection (ethernet or WiFi, whether powered up or down) claiming to be the new owner's sysadmins.
If the NSA doesn't know how to use this to spy on, or take over, a target computer, they aren't doing their jobs.
Some of the things this can do (from the Wikipedia articles - see them for the footnotes):
Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way
One item on every computer user's wishlist would be to use some of that Internet metadata to identify the gang behind the Cyptolocker virus and have them rendered to some regime that will torture them to death live on Al Jazeera while the whole world applauds.
Time to support the open router project! If we want to change the world we will need to rebuilt the internet from the ground up.. starting with the devices in our homes.
http://orp1.com/
A trustworthy, open-source software & hardware router
ORP1 is a high performance networking router that allows you to run a firewall, IPSec VPN (virtual private network), and a TOR server for your home network. Its easy-to-use web interface will make encrypted and anonymised communications for your entire network easier to set up and manage. Now you don’t need to be a geek to be able to ensure that every device you use at home uses the internet with privacy, whether it’s your home PC, smartphone or tablet.
You have a sick, twisted mind. Please subscribe me to your newsletter.