A Look at the NSA's Most Powerful Internet Attack Tool
realized writes in with a closer look at the NSA's QUANTUM system. "Today QUANTUM packs a suite of attack tools, including both DNS injection (upgrading the man-on-the-side to a man-in-the-middle, allowing bogus certificates and similar routines to break SSL) and HTTP injection. That reasonable enough. But it also includes gadgets like a plug-in to inject into MySQL connections, allowing the NSA to quietly mess with the contents of a third-party's database. (This also surprisingly suggests that unencrypted MySQL on the internet is common enough to attract NSA attention.) And it allows the NSA to hijack both IRC and HTTP-based criminal botnets, and also includes routines which use packet-injection to create phantom servers, and even attempting (poorly) to use this for defense."
all these software engineers that work for nsa/gov , do they have any fucking morals? do they really believe they are securing the world from the evil guys? are they kept at gunpoint? are they just plain stupid? Fail to realize that us, the makers , have all the power is the worst mistake. Plant secret backdoors, failure modes, weaknesses. Be in charge. You don't owe anything to these black suits. Wake fucking up.
I wonder what this tool will think about my encrypted archive of the proceedings of Congress that I've renamed "The_anarchists_cookbook.zip".
the Borg have won.
Now if they would just use it to actually stop botnets.
Spasibo tovarishch Snowden!
I'm American and I fully support this. This is exactly what intelligence agencies are for. Nothing in any of these leaks in the linked article suggests these capabilities are being abused. I want my government to be able to pursue foreign intelligence targets with capabilities like these and--in a time where people complain relentlessly about government agencies being ineffective--I'm glad they are able to do this.
Posting anonymously because I've lost too much karma expressing a contrarian opinion on all these Snowden articles. Frankly, I'm more scared of moderators than our government...
I don't know how much is known vs speculation here. If the NSA has some MySQL manipulation tools, it might not actually be intended for use on the actual internet. It is possible that they infiltrate networks and use these tools on the inside.
It came out that they're tapping dedicated lines, and those are often unencrypted. However, I'd expect most competent mysql use to stay confined to a LAN, even with encryption. Latency tends to cause problems if you separate the database from the application layer. But, I'm sure that not everybody the NSA targets is competent...
bruk?
If you have been on your computer, cell phone or car with EZpass or OnStar: they know a lot about you. Even if you have 7 degrees of separation from the bad guys.
You have to applaud the thoroughness. Misguided patriots, the lot.
Pay no attention to the man behind the curtain with all your metadata.
In Soviet Amerika, QUANTUM looks closely at YOU!
Stop spying on yourself dumbfucks.
Is that so hard?
Recent revelations about spying on an Indonesian clove cigarette company for the benefit of US "customers" is one example.
So that's for the private sector. How the customers in the private sector commission the work and pay for it would make an interesting story. Perhaps they pay via political campaign finance? Let's open that can of worms.
I'm starting to get the feeling the NSA is actually a criminal enterprise. I mean, take away who's paying the bills, and the description becomes that of a rather nefarious enterprise.
Let the personal Internet information scrub begin!
Or we see society as a bunch of untalented sharks circling around the few talented fish........
Sucks being a talented fish.
I can't drive the speed I want because of these small slow-brains tip-toeing around claiming that even their tip-toeing is too fast to be "safe".
I can't openly do things that are now banned because small brains can't handle a vice without doing it every day ruining their lives.....
I can't simply fix a small issue with my house because the small brains would cross wires and start fires.... Now I gotta pay for "inspections".
In some states I can't even pump my own gas.....
I'm tired of not being trusted to be smart enough to tie my own shoes..... surrounded by idiots who slow me down in every way, then complain if I find a way around their slowness.
I'm supposed to just be thankful that I'm alive by their thinking..... not upset my extra IQ is wasted by their blackhole intelligence.
If someone like me has something.... the others act like they need it too, even if I'm busting my ass in ways they aren't.
According to them I'm just a stingy self-centered person.... In reality I have morals more advanced than theirs and they are OFFENDING ME at nearly every chance. THAT is why I dislike society.
I tend to be on the giving side more than the receiving side. I didn't grow up in a fancy neighborhood, I didn't graduate high school, I got screwed by "society" at every turn yet still managed to earn $100K/year at 26 years old. And guess what..... society is PISSED about that.
They are mostly mad that I skipped their hoops and used my natural intelligence to still achieve success. When you were doing homework I wasnt. When you were going to college I wasn't. Then you got your fancy degree with large amounts of debt.... I wasn't. Instead I dropped out and earned $60,000/year less than one year after dropping out. Then raises and raises left me breaching $100,000 at 26 years old. I come to work in jeans, I sleep in, I barely put in 6 hours of work.
But I make $100K because I'm smarter than you..... not because I work harder. Hard work is for small brains..... people like you who can't fathom a guy with brains who expects to use them. So yeah I expect to use my body how I please. If I want to drive fast, MOVE. I build your society while watching you do almost nothing. It's my RIGHT to do as I please. Eventually you'll figure it out.
10 BILLION DOLLAR BUDGET, and they have a bag of Tommy 10 year old script kiddy tools to show for it...
If the NSA can bring down botnets, why don't they? Are spammers making political contributions?
My guess, as a security professional who could have been recruited for a three-letter agency, is that many of them are boiled frogs. There are technical challenges that smart geeks love, plus the whole hacker mystique, but you don't want to be criminal, so you go white-hat, hacking bin Ladin. That adds the whole "international spy" thing into it and maybe you help catch some really bad guys. That would be awesome, spying on al Qaeda. Hmm, if you expanded that technique you could catch a lot of bad guys. So you expand it to log calls to and from Iraq, Afghanistan, and Syria. After a few years, you end up in a place you never would have knowingly sought to go.
This only happens if you're an idiot, like the average libertarian that infests this site.
No. it happens when the law primarily serves the interests of those in power (or their benefactors) instead of individual liberty.
Smart socialists know how to always remain in power.
quite true. The soviet union and north korea are great examples.
The worst people in the world are those that don't know how to socialize with other members of society, and socialization is formally structured in society through a government.
That depends on your definition of 'socialize'. The word's been defined and redefined so many times for so much self serving arrogance, I'm not sure it has a valid objective meaning anymore. These days it's newspeak that really means "compliant with the norms of the group", or "team player", someone who never rocks the boat, even when it's necessary to tell the uncomfortable truth and cause someone to have to save face.
When you people state "I fear and mistrust government", what the rest of us hear is "I fear and mistrust other members of society".
No. Government is its own entity, just like any other group of people. They form hierarchies within hierarchies, complete with their own groupthink and 'mission statements.' Really, they're just the adult versions of highschool cliques, except the stakes are much higher. They share all the same low level hazing, peer-pressure, and passive aggressive politics of their adolescent counterparts. Like students who are or are not a part of these cliques, the bureaucrats of government are a distinctly separate class from everyone else. After awhile, many of them truly believe that they are a cut above everyone else by default. This is a big part of what we're facing today.
Can you explain how you benefit us? Do you think you produce more tax revenue than we pay for you? Do you think the road we paved for you all the way out to your private secluded hideout so you can avoid the rest of society came for free?
Hey, I didn't ask for anyone to spend money on my behalf. You sound like that guy who washes my windshield at a stop light when it doesn't need washing, and then gets upset when I refuse to give him $5. What a citizen typically faces in socialist nations in final stages of collapse goes like this: How do you benefit 'us', citizen? I'm sure it's insufficient compared to what The People have done for you. Report to reeducation camp #119 for 'processing'! I don't think it's that bad yet, but obviously, you are already there. Now that is sad.
Publicly funded roads are a far cry from overt surveillance and psychological manipulation (ie terrorist fear mongering) which are the precursors to extremely large powergrabs. Oh, and I never said I disagreed with public roads. You need to put down the NYT liberal talking points guide.
Is that what you want us to hear from you libertarians? That you're a precious snowflake and that you don't want to do what government tells you to do, because you're a precious snowflake?
No. The precious snowflakes are the ones who think they're owed something from taxpayers because they believe their race, gender, orientation, or some other arbitrary difference, makes them think they are perpetual victims of some paranoid conspiracy they probably picked up from public schooling or the media. The sad part is, many of them probably are victims of this brainwashing. They do make reliable voters, don't they? Gotta love identity politics. If you knew anything about them, you'd know libertarians believe in rule of law, not in identity politics. That means everyone is equal before it; no favoritism. However, they also believe that the laws that are on the books should be rational instead of based on heat of the moment politicking. They understand that when humans are packed into groups, they're pr
idk about morals (I dont want to define or discuss defining it b/c it brings out trolls something fierce)
They feel like cogs. From my short time as a DC congressional staffer & people I know in those fields, they feel like a **cog in a big machine** Their job is so abstracted that they dont really know the context of the work **or** they are doing the front line work & never see any analysis just an action order.
the intelligence community has been practicing "compartmentalization" in administering worker tasks since the Manhattan Project in the late 40s at least
one hand doesn't know what the other is doing **by design** across the whole org
it's interesting to note the paralells between:
Compartmentalization (information security): http://en.wikipedia.org/wiki/C...
The basis for compartmentalization was the idea that, if fewer people know the details of a mission or task, the risk or likelihood that such information could be compromised or fall into the hands of the opposition is decreased....(and later, re: Manhattan Project "Most did not know what, exactly, they were doing. Those that did know, did not know why they were doing it. Parts of the weapon were separately designed by teams who did not know how the parts interacted."
Compartmentalization (psychology): http://en.wikipedia.org/wiki/C...
an unconscious psychological defense mechanism used to avoid cognitive dissonance, or the mental discomfort and anxiety caused by a person's having conflicting values, cognitions, emotions, beliefs, etc. within themselves.
Compartmentalization allows these conflicting ideas to co-exist by inhibiting direct or explicit acknowledgement and interaction between separate compartmentalized self states.
Compartmentalization in orgs **can** increase security, but it **also** can be used by bad actors to **cover up bad actions**
Compartmentalization, from a cybernetic perspective, is viewed as a feedback management technique.
In any system, be it one human mind or an organization of thousands of them over decades...compartmentaliztion can be used to hide all manner of immorality
Thank you Dave Raggett
But it also includes gadgets like a plug-in to inject into MySQL connections, allowing the NSA to quietly mess with the contents of a third-party's database. (This also surprisingly suggests that unencrypted MySQL on the internet is common enough to attract NSA attention.)
When the author wrote that part of the story, he or she seemed to be unaware of what he or she had just written:
allowing bogus certificates and similar routines to break SSL
By breaking SSL, the NSA has access to SQL queries whether or not they're encrypted.
If I can be modded down for being a troll, can I be modded up for being an orc, or a balrog?
Grow the fuck up and learn some respect for a different perspective / belief.
I believe that god is seventeen giant, 65 foot long orange lizards, all who are named 'Ralph'. They have mile long, glittering prehensile cocks that drag behind them. Ralph^17 will sail invisibly across the sky once per hour, where all humans on the planet must turn to the South, and bow while chanting, 'Rubber Button' for one minute in order to avoid Ralph's divine and righteous wrath. His son is a stop sign three miles south of Yuma, and all who are able must journey to see him once in their life, lest they be dammed to spend Christmas vacation in New Jersey for all eternity. I demand the same respect that these goofy christian mono-godders get, up to and including wording on American money acknowledging Ralph^17's almighty farts. BOW, HEATHENS!
I mock you sir, for failing to respect that some people's perspective and beliefs are that 'invisible shit isn't real, and that you should call out the Emperor as naked when he is'.
HA! I just wasted some of your bandwidth with a frivolous sig!
on these goings on, including some exceptional conversations.
https://www.schneier.com/
also, search his blog entries here:
https://www.archive.is/
fantastic free page archival service.
I guess you missed the part where they admitted they have some 5 cases a year of "agents" using these systems to check up on their girlfreinds or other aquaitances.
They are just fascist pigs. Their time will come.
What I have noticed is that there is a story in the media every damn day about the over reach of NSA and arghh..people are outraged. Oh it's horrible, etc etc. Amazingly enough, no one seems to want to do anything about it. Where are those stories? Where is the demand for congressional oversight? We get the NSA we deserve because we the people are doing nothing to reign them in.
How? Well - you know (hosts with hardcoded IP addresses of my fav. sites I spend 95% of my time online @) & then OpenDNS servers (for the RARE times I do use DNS)...
How to build such a custom hosts file as easily as possible, for better:
SPEED (blocking adbanners, "good" or bad/infected + hardcoding my fav. sites @ the top of hosts to offset loss of indexing speed due to the FAULTY with larger hosts files usermode local dns clientside cache service, opting instead to use the FASTER kernelmode diskcaching subsystem + TCP/IP kernelmode PnP subsystems instead in combination)
SECURITY (vs. redirection OR "downed" DNS servers & vs. bogus roque ones malware makers/botnet herders use)
RELIABLITY (vs. redirects serverside like "beta" here which I NEVER SEE, no cookies required either)
ANONYMITY (vs. DNS request logs or to blow by DNSBLs)
?
This (courtesy of "yours truly"):
APK Hosts File Engine 9.;0++ -> http://start64.com/index.php?option=com_content&view=article&id=5851:apk-hosts-file-engine-64bit-version&catid=26:64bit-security-software&Itemid=74
* That's how, & it works vs. a LOT of this lunacy they're doing...
APK
P.S.=> On a "side note": The boys need to read a bit of Nietsche, specifically his quote of "When one fights monsters, one must take GREAT CARE, not to become a monster"... seriously:
It's VERY depressing, & full of room for abuse (which HAS already happened many times admittedly from them by their OWN FOLKS misusing it & will, with certainty, again... it's human nature, the BAD SIDE of it, & "absolute power, corrupting absolutely")... makes me depressed & it's making me lose faith in our leaders actually!
... apk
if that was a troll, I give you troll of the day, that was great
If you honestly believe what you just said though, that is the scariest thing I have ever heard
Well said. I would mod you up if I had mod points.
-kgj
That the NSA also has mind reading and mind altering radar that can hack the mind, which has no firewall, equally as efficiently as any computer system.
And they're using it today to fuck with society and to warrantlessly spy on and sabotage people.
First, read this article by Lieutenant Colonel Timothy L. Thomas, which basically examples all this in 1997. http://strategicstudiesinstitu...
Then read the original article about NSA Remote Neural Monitoring and Electronic Brain Link, published in Nexus Magazine in 1996 by John St Clair Akwei: http://www.oregonstatehospital...
Then realize that you're all mindless fucks living in the USA government Matrix system, under the full control of the Department of Defense.
NSA Whistleblower Thomas Drake even says that the USA constitution was revoked in 2001, and today we're operating under marshals law. Literally, and these guys have implemented a fake system to make the public believe they still have rights when in fact the government cannot be properly challenged because they're in complete and total control: http://www.ora.tv/offthegrid/n...
More details on the thousands of victims who've been attacked by this mind hacking tool on http://www.obamasweapon.com/ originally deployed in all radar systems in 1976, called TAMI or Thought Amplifier and Mind Interface. Allows full remote control and reading of all human thoughts and functions. Psychic attacks, paranormal and psychosis simulations, all being used today.
In no particular order:
1. Cognitive Dissonance: throw enough money/benefits at someone, and even otherwise tightly-held morals can become fluid.
2. Sociopaths: they'll do stuff simply because they can (and want to), despite the harm it could create for others.
3. Challenge: some will do things because they enjoy the challenge of seeing if it can be done, as well as the "empowerment" they feel it gives them. Note that this can be mixed in with either of the 2 points above.
4. Ignorance: for whatever reason, the people in question have no real understanding of the broader harm their actions may cause (probably a least-case scenario, since it would probably require someone who is very socially stunted, like some kind of autism and what-have-you, while still being very capable technically).
5. Coercion: out-and-out threat of bodily harm to self or loved ones, etc, if refuse to perform. Bears some similarities to #1 above, but obviously is based self-preservation/care-for-others rather than greed.
6. Apathy: they really just don't care, for whatever reason.
7. Misplaced Loyalty: failure to question the motivations and/or repercussions of orders given to them by higher-ups because questioning orders equals disloyalty.
I'm sure there may be more...
I wanted to work for one, but had too much black hat in a way that freaked out the moralists over absolutely innapropriate things. Not things like loyalty, or unauthorized access, or openly gay... but "wow, that's equivalent to stealing millions of dollars..." over a bit of high end software cracking.
As someone who knows and has done other defense and weapons work... let me put it very very clearly:
Some of us believe there are "bad guys", and while the US is not "the good guys" -- we're better than the others out there. Not morally better. Better positioned to accomplish things that need to be done.
I wanted to work NSA instead of FBI because the NSA's signals intelligence was supposedly exclusively foreign. I wanted to work the NSA over CIA -- because the NSA's mission scope includes comsec -- which should be improving things. And because the CIA ... well... they start wars and render people.
By contrast, non-cloak-and-dagger intelligence...does not bother me in the slightest. I expect routine espionage.
I don't mind making weapons platforms for our soldiers. Yes, some of them are child raping, family slaughtering motherfuckers that should be tried, taken out behind a shed, and then summarily executed by firing squad. But most of them aren't. And they need good tools.
These weapons and platforms, in the hands of the right people... are not a bad thing.
Like any and all tools, they are potentially dangerous. Like all tools that fall into the class known as "weapons", they are designed and intended to be dangerous to life and property even (and especially) when functioning correctly.
They are definitely dangerous in the wrong hands. But that is why I want my friends and allies armed with them first.
It isn't scope creep -- it's scope designation. Some of us don't mind that type of work as long as the barrel isn't pointed at our own countrymen.
Yes, what goes around comes around. I do not have the skillset, but I think I would have severe reservations about nuclears or biologicals. But basic tools for soldiers? That's how we help our country.
And the NSA...having taken those network tools, and pointed them inward and domestically... should be tried, convicted, and summarily executed -- just like any soldier that followed an unlawful order to point his rifle at not just civilians... but...his own citizens.
I don't think I'm better than a canadian, a brit, or an Iraqi, christian, muslim, jew... whatever.
I just understand which side I'm on when the thin line is drawn in the sand. The loyalty is national and to national interests -- and supporting platforms and intelligence systems that do not harm my nation is a good way to serve.
Now...about you assholes that turned those tools inward... it's time for a trip to the gallows...
The part where you said "MOVE" thats where you are wrong. Up to that point i was with you. After you said "MOVE" I began to recontextualize your rant. I could be wrong but now suspect that you are a sociopath. Perhaps those laws were meant for you after all. Come to think of it what is this occupation that is so very 'smart and easy for someone of your intellect' Is it in any way parasitical?
The goal is that everything will be surveilled, not just popular stuff.
exploit j00syt scrupty kiddeh
This may help giving them headaches: 1) Use mysql SSL with your own CA Certificate and Client Certificate signed by your CA. 2) When browsing or IRCing, use OpenSSH proxy with SSH certificates. 3) Use your own DNS resolver. There is no need in using public or ISP DNS resolvers. 4) Stop using close source OS.