Slashdot Mirror


The NSA Leak Is Real, Snowden Documents Confirm (theintercept.com)

Sam Biddle, reporting for The Intercept: On Monday, A hacking group calling itself the "ShadowBrokers" announced an auction for what it claimed were "cyber weapons" made by the NSA. Based on never-before-published documents provided by the whistleblower Edward Snowden, The Intercept can confirm that the arsenal contains authentic NSA software, part of a powerful constellation of tools used to covertly infect computers worldwide. The provenance of the code has been a matter of heated debate this week among cybersecurity experts, and while it remains unclear how the software leaked, one thing is now beyond speculation: The malware is covered with the NSA's virtual fingerprints and clearly originates from the agency. The evidence that ties the ShadowBrokers dump to the NSA comes in an agency manual for implanting malware, classified top secret, provided by Snowden, and not previously available to the public. The draft manual instructs NSA operators to track their use of one malware program using a specific 16-character string, "ace02468bdf13579." That exact same string appears throughout the ShadowBrokers leak in code associated with the same program, SECONDDATE. SECONDDATE plays a specialized role inside a complex global system built by the U.S. government to infect and monitor what one document estimated to be millions of computers around the world. Its release by ShadowBrokers, alongside dozens of other malicious tools, marks the first time any full copies of the NSA's offensive software have been available to the public, providing a glimpse at how an elaborate system outlined in the Snowden documents looks when deployed in the real world, as well as concrete evidence that NSA hackers don't always have the last word when it comes to computer exploitation.

10 of 146 comments (clear)

  1. Witty comment here... by wbr1 · · Score: 5, Insightful

    The real interesting thing will be when detection tools for this malware are created. Then we will see how many people -without warrants- the NSA is using this on.

    --
    Silence is a state of mime.
    1. Re:Witty comment here... by PolygamousRanchKid+ · · Score: 4, Interesting

      The real interesting thing will be when detection tools for this malware are created.

      Well, in order for detection tools to be developed . . . folks will need access to the NSA toolkit code. The honorable thing for the ShadowBrokers to do, would be to make this freely and openly available for all.

      But the fact that they are offering this as an auction, shows us that the ShadowBrokers are just in it for the money.

      I'm guessing that China, Russia and the NSA itself will create bidding "fronts" to bid for them, and no private entities will be able to match their funds. So whatever is in that toolkit will still stay secret.

      --
      Schroedinger's Brexit: The UK is both in and out of the EU at the same time!
    2. Re:Witty comment here... by pz · · Score: 3, Interesting

      How quickly can a tool be built that scans all of memory for that string?

      --

      Put my fist through my alarm clock with its ding-dong death inside my ear. - The Blackjacks.
  2. Re:Censorship? by b0bby · · Score: 5, Informative
  3. Re:code by imatter · · Score: 5, Funny

    So the combination is... A, C, E, zero, two, four, six, eight, B, D, F, one, three, five, seven, nine. That's the stupidest combination I've ever heard in my life! That's the kind of thing an idiot would have on his luggage!

  4. Re:Censorship? by clubby · · Score: 5, Insightful

    At this point, anything broadly considered to be a "major US news outlet" has, at best, a tangential relationship with "news." CNN is hopelessly clueless and out of touch, while Fox & MSNBC are the propaganda arms of their respective parties. The NYT sat on a vitally important story, clearly in the public interest, in order to help GWB's re-election campaign. These groups are marketing organizations, who sometimes publish news as a means of promoting their brand.

    On the plus side, a major US journalism outlet, The Intercept, is on it.

  5. Re:Soooo by TheCarp · · Score: 4, Insightful

    When the paychecks stop coming.

    Its very easy to ignore the truth when your salary requires it to not be taken into account.

    --
    "I opened my eyes, and everything went dark again"
  6. Re:Censorship? by quantaman · · Score: 4, Interesting

    Ok, abcnews does have it on front page, CNN, wsj, nytimes do not.

    Blame readers.

    At the end of the day newspapers are in the business of attracting readers. A story about NSA hacking tools is too esoteric for most of their readers and lacks the cool characters or personalized villains that drive narratives.

    Even the last /. story only had 130 comments, and it's a story specifically about the NSA and hackers. If it barely interests the /. audience I don't imagine it's going to be a hit with the general public.

    --
    I stole this Sig
  7. Re:Soooo by maharvey · · Score: 4, Insightful

    Its not surprising, as the signal to noise ratio is very low, and only a professional watchdog can begin to sort it all out. And even that doesn't help because there are also liars posing as watchdogs.

    The internet only makes it worse, spewing like a fire hose.

  8. Re:Soooo by harrkev · · Score: 4, Interesting

    Facts are not unfair or biased. However, media can (and often does) choose which facts need to be reported.

    As a quick example, homicides are down over 50% since their peak around 1992 or 1993. The last time homicides were this low was 1957 (facts, based on FBI statistics). However, I have actually seen articles about "What (insert candidate name here) is going to do about gun violence?" This already assumes several things, and it is possible that NONE of them are true:

    1) Gun deaths are somehow worse than knife deaths

    2) A criminal without a gun will suddenly stop being a criminal

    3) That doing something will automatically make the public safer, instead of just disarming the honest people.

    4) Gun laws will actually affect criminals, whose job actually involves breaking the law.

    Each of those points could be a discussion by itself, and yet some "news" pretends that all assumptions are already decided.

    That is now news, that is propaganda. It is actually shaping the discussion to stack the deck in your favor.

    --
    "-1 Troll" is the apparently the same as "-1 I disagree with you."