Slashdot Mirror


No One's Bidding on The Shadow Brokers' Stolen NSA Hacking Tools (vice.com)

That group auctioning the NSA's hacking tools is "very upset" no one's bidding on them. An anonymous Slashdot reader quotes Motherboard: "TheShadowBrokers" authored another bizarre rant expressing their annoyance at the seeming lack of interest in ponying up bitcoins to release their full set of stolen files. "Peoples is having interest in free files ... But people is no interest in #EQGRP_Auction," the mysterious hacker group complained in a ranting post on Medium, which seems to be purposely written in Borat-style broken English. "TheShadowBrokers is thinking this is information communication problem."

The message also blindly lashes out at hackers, foreign intelligence services, and basically anyone else who hasn't bid on the files... At the time of this writing, TheShadowBrokers have only received bids for a total of 1.76 bitcoins -- or about $1,082 -- far below the group's asking price of $1 million.

At least five transactions came from a prankster who was trying to Rickroll the group with bitcoin addresses containing the words "Never Gonna Give You Up."

51 comments

  1. In other words by Dunbal · · Score: 4, Insightful

    FBI upset that no one is going for the honey-pot.

    --
    Seven puppies were harmed during the making of this post.
    1. Re: In other words by Anonymous Coward · · Score: 0

      CIA. The FBI doesn't give a shot about such things.

    2. Re:In other words by Stan92057 · · Score: 3, Insightful

      Could be a honey pot but really, what idiot is going to spend 1 million dollars/bitcoins on a criminals/nsa/fbi/cia word lol. It might be all just a file with the sentance, got ya thanks for the coins SUCKA ....lol

      --
      Jack of all trades,master of none
    3. Re:In other words by dpilot · · Score: 1

      Even if it's real, even if it's not a honey-pot, anyone want to bet that everybody's metadata collection systems aren't watching for bids?

      --
      The living have better things to do than to continue hating the dead.
    4. Re:In other words by ShanghaiBill · · Score: 1

      An obvious explanation for no bids, is that other interested parties already have the tools. If some amatuer hackers were able to steal them, it is likely the Russians and Chinese got them long ago.

    5. Re:In other words by Anonymous Coward · · Score: 0

      Besides that, its anno 2011/12 Cybertech for sale. Chances are this is by now completely worthless, unless you have network intrusion capabilities like nsa.

    6. Re:In other words by Stan92057 · · Score: 1

      Ok,how would they know they have the same tools? Again totally unwilling to pay that kinda money on a hunch or good guess. Seems the vulnerabilities are the real buy. not the tools.

      --
      Jack of all trades,master of none
    7. Re:In other words by AHuxley · · Score: 4, Interesting

      Re: "Could be a honey pot"
      Yes. Recall the watch on onion routing using XKeyscore.
      "How the NSA Targets Tor Users" (July 4, 2014)
      http://motherboard.vice.com/re...
      "... and logs the IP address of people searching for various other privacy and encryption software."
      NSA classifies Linux Journal readers, Tor and Tails Linux users as "extremists" (July 4, 2014)
      http://www.in.techspot.com/new...
      "... program marks and tracks the IP addresses of those who search for..."

      --
      Domestic spying is now "Benign Information Gathering"
    8. Re:In other words by Anonymous Coward · · Score: 0

      How about crowd funding and we all buy it together with our real names, maybe 100 000 of us.

    9. Re: In other words by Anonymous Coward · · Score: 0

      Anyone who could use the tools is already a l33t hacker and therefore has no need for them or already has them

    10. Re: In other words by Z00L00K · · Score: 1

      Anyone that have an interest in such tools already have them - or better alternatives.

      --
      If builders built buildings the way programmers wrote programs, then the first woodpecker would destroy civilization.
    11. Re:In other words by Coisiche · · Score: 1

      Says AC...

    12. Re:In other words by SadButResolved · · Score: 0

      Actually it appears someone is already using the NSA and its TOOLs for the Benefit of Hillary's Troll Army Brigade, I wonder who these people are? ??
      NSA TOOLS for TROLLS Or is iT??

      Quote: We have the use of an NSA intrusion package. We are going to find the thought leaders. the meme-generators. the shit-posters. I need a target analysis for reddit, twitter, and the chans by tomorrow 5 PM.

    13. Re: In other words by Anonymous Coward · · Score: 0

      They are going to erase it so even god can't recover it?
      They are going to ask questions about it for 11 hours to test her stamina?
      They are going to make the Hackers wear pant suits?

  2. Good! by Mister+Transistor · · Score: 2

    This is great, I hope this happens more often. Maybe these shitbags will stop bothering to mine/phish/malware/etc. for identities and data once they find out they don't have the wealth of Croesus on their hands and no one wants to pay for it.

    --
    -- You are in a maze of little, twisty passages, all different... --
    1. Re:Good! by 93+Escort+Wagon · · Score: 1

      ... no one wants to pay for it.

      It's possible no one wants to put a target on their back.

      --
      #DeleteChrome
    2. Re:Good! by KiloByte · · Score: 1

      You got it wrong: the shitbags here are NSA, yet somehow they go unpunished. I have far less scorn for criminals who hurt criminals than for taxpayer-funded officers gone rogue.

      --
      The creatures outside looked from Alt-Right to Antifa; but already it was impossible to say which was which.
    3. Re:Good! by HBI · · Score: 4, Insightful

      nope. Making it an open auction was not the brightest of moves if you wanted a payday...it advertises the shelf life of your information too honestly, and lets people watch who pays. Anyone who might have been tempted to pay a lot for it...isn't going to do it this way.

      I suspect we are supposed to think that this is just someone who didn't know how to market it properly. I doubt that. Someone is embarrassing, provoking, or lulling someone into a false sense of security, and had an interest in making it as public as possible. The Borat note seems to support that thesis.

      --
      HBI's Law: Frequency of calling others Nazis is directly correlated with the likelihood of the accuser being Communist.
  3. It's unethical to ask for payment by Anonymous Coward · · Score: 0

    It makes you as bad as those who wrote and used these tools in the first place.

    Want to do the right thing? Release with them, for free, with no names attached to the process.

  4. Well if what I've read is true by Anonymous Coward · · Score: 0

    Why would anyone want to pay so much for low grade code...

    1. Re:Well if what I've read is true by Opportunist · · Score: 1

      I often wonder the same with some code we produce here...

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  5. Cpt Obvious by Anonymous Coward · · Score: 0

    No one is dumb enough to take the bait. They are surprised by this???

  6. Perhaps by SeattleLawGuy · · Score: 4, Insightful

    FBI upset that no one is going for the honey-pot.

    To be fair, it may be the NSA is upset that nobody is going for the honey-pot.

    Surely the auction is either a honey-pot or very closely watched. It would be a bad investment for most people to try buying it under such circumstances, and may even result in criminal prosecution.

    --
    Real lawyers write in C++
    1. Re: Perhaps by Anonymous Coward · · Score: 0

      Not sure I agree. Bitcoin transactions are easy to do anonymously, and I'm assuming anyone with an interest in this kind of information would know how to securely and confidentially receive/transfer the information from the sellers once the auction is won.

    2. Re:Perhaps by Anonymous Coward · · Score: 0

      So we won't know if it's the FBI or the NSA until... when? Someone falls for it?

    3. Re: Perhaps by Anonymous Coward · · Score: 0

      Its very hard to buy a million dollars worth, even a few thousand there is usually a visa, bank transfer, PayPal record, if it is done in person, witnesses.

      Bitcoin is not anonymous at all.

  7. I'll swap by Anonymous Coward · · Score: 0

    I'll swap it for a Unicorn. It's the real deal. Really.

    1. Re:I'll swap by Anonymous Coward · · Score: 0

      I'll throw in two bridges and a whole case of bottled cobra virility extract.

  8. No cash out for Eddie by Anonymous Coward · · Score: 0

    This was supposed to make living in Russia tolerable. Sucks to be him.

  9. Rickroll by CODiNE · · Score: 3, Interesting

    I'm not familiar with bitcoin address generation. Can someone estimate the amount of computing power required to come up with those wallet addresses? Is this just a quick script that takes a minute at most or something like a hash collusion?

    --
    Cwm, fjord-bank glyphs vext quiz
    1. Re:Rickroll by Anonymous Coward · · Score: 1

      Check the link, each address starts with 1$n where n is a single word of the song. These are wallet addresses.

      He probably used exactly this guide followed it to the letter, or number 1 in this case.

  10. a lot of people dont have bitcoins by Anonymous Coward · · Score: 0

    i have some wow gold tho, wanna make a deal?

  11. CORRECTION by Anonymous Coward · · Score: 1

    They're not asking for $1 million -- they are asking for 1 million BTC. 1 million BTC is roughly $600 million. It's also ~1/15th of all bitcoins in existence. Trying to acquire that many bitcoins on the open market would send the price to Jupiter. It would be way, way, way over $600 million when all was said and done. My guess is that the Shadow Brokers know this well, and have something other than bitcoin remuneration in mind as an endgame.

  12. In other news... by Anonymous Coward · · Score: 0

    Kidnappers recently got Hillary Clinton and discovered that no one wants to pay the ransom, including Bill.

  13. Value = zero by RubberDogBone · · Score: 1

    Something is worth what someone is willing to pay. That's all.

    For something like this, if one group stole it, then another group can also steal it and not pay a dime. You can't sell something if your buyer can obtain it for free. Why would they pay? Makes no sense.

    Anyway, I would not want anything to do with this stuff. Somebody ELSE can find out if it's a honey pot and somebody ELSE can stick their finger up the NSA's butt hole and make them mad. Making the NSA mad at you is not a game.

    --
    Sig for hire.
  14. And when you say "One Million Dollars"... by Burz · · Score: 1

    ...don't forget the pinky.

  15. Its been said before but... by Anonymous Coward · · Score: 0

    ...the tools are worthless. There is nothing unique about the code, its not magic. Detect flaw, write code to exploit flaw and deploy. Much of this is automated with neural networks classifying flaws in machine code, then even writing the exploit code. Create and sell an AI that does this...it will be worth more than amything you'll get from the NSA.

  16. Hero vs. Criminal (simple) by burni2 · · Score: 1

    Everyone likes heros, no one likes criminals.

    - If you free & release these files into the general public, you are a - and my - hero.
    - If you extort these files for a fee, you are just a criminal.

    It is simple as that.

    And the "non-interested" people seem not to be dumb:

    No refunds .. paying for something that you most likely won't get. Hahahahahahahha .. and they call it crowd funding .. ok crowdfunding sounds like that, but if a crowd funds something the funding crowd gets a piece.
    Or nobody gets a piece and is ripped off.

    Not here. Two get a piece (Winner & Shadowbrokers) and the others are ripped-off.

    This would be the only good choice a real hero would take:
    Put it up on many many many many many many OCHs and Freenet. And post the link & get the fame for fighting evil.

  17. Auction terms were ridiculous! by Anonymous Coward · · Score: 1

    Why would anyone "bid" when the "bid" amount is unconditionally given to the auctioneer for all participants in the auction?! This is especially bad given that there is no assurance that the auctioneers will actually hand over the goods to anyone. Also, the auctioneers could hand over the goods to multiple parties, perhaps offering the goods for sale elsewhere. And the auctioneers themselves can make use of the technology. And, depending on the nature of the tools, the auctioneers might even have the ability to monitor or exploit whatever the "winner" of the auction does with the tools (e.g., collect data from whatever streams the winner creates, or even infiltrate the users of the tools (i.e., a backdoor to the backdoor)).

    If the goods were put in to some kind of escrow, outside the control of the auctioneers, and it were conducted as a true auction (i.e., only one winner, and only the winner pays any money), and delivery to the one winner were assured, AND the anonymity of bidders could be reasonably assured, only then would bidding not be entirely ridiculous. It would help also if some independent party could at least inspect fragments of the goods to estimate the likely quality and capabilities of the overall package.

    Of course, these guys are criminals, but their "auction terms" are so obviously preposterous, even for nation-states with ludicrous financial resources (who could throw $1 million at this auction as a long shot gamble), that their surprise at the lack of interest is itself shocking.

  18. Even under the assumption it's real by Opportunist · · Score: 1

    Let's play pretend for a moment and say that this ain't a honeypot.

    First, the "samples" released were crappy. Really crappy. A few router security holes, few of them unknown in the relevant circles. Nobody who could pay for that would.

    Then there's the fact that you're fully dependent on the word of criminals. First, that they deliver in the first place, and second, that they only deliver to you. That's two things nobody in their right mind would put his money on.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    1. Re:Even under the assumption it's real by TheDarkMaster · · Score: 1

      The logic of this people sounds like the logic of a 9 years-old brat that believes to be the "Haxxor".

      --
      Religion: The greatest weapon of mass destruction of all time
    2. Re:Even under the assumption it's real by Opportunist · · Score: 1

      Them posting in a faux Borat-speak also does not really increase their credibility.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
  19. I'll bid by Anonymous Coward · · Score: 0

    I bid 900 Ningies, you can pick them up at your local planning department at alpha centari

  20. riiight by Anonymous Coward · · Score: 0

    Buy said tools, get a whole lot more of the NSA/FBI; etc etc's attention. No thanks

  21. BS by Anonymous Coward · · Score: 0

    Despite the belief of the Obama administration, most of us are not fooled by their lies.

  22. Dealing w/ the devil, p/o'd elepant in the corner by Anonymous Coward · · Score: 1

    But this isn't buying some random items stolen from someone you don't know. This is personal, sentimental loot from Vito Corleone-- and Vito knows it's missing and up for sale.

    Would you buy under those circumstances?

  23. Make it free! by Anonymous Coward · · Score: 0

    I can have honey pot for free?

    You want bitcoins? Any idiot with a bitcoin knows they are more easily traceable than cash (except those who only read MSM propaganda).

    It would no doubt be interesting code to read though, even if its crap code.

    IMO if the alphabet group behind this wanted any kind of gain by letting this code out in the wild they should just open a github account and make it free. At least then you could get some public commentary on whats good and bad about it.

    As it seems, right now all you have is something nobody wants anyway; especially not anyone who would even know how to use it?

  24. because... by JustNiz · · Score: 1

    they are already valueless because once stolen/leaked the exploits immediately become common knowledge so will be defended against.

    Presuming the NSA has at least half a braincell, you can bet they will have already totally defused the situation by telling all the appropriate manufacturers about any/all loopholes all the stolen tools exploited.

    1. Re:because... by Anonymous Coward · · Score: 0

      I'd expect a largish company such as MS to buy it just to patch their software ... I mean, if NSA lacks their braincell.

  25. Re:Dealing w/ the devil, p/o'd elepant in the corn by Anonymous Coward · · Score: 0

    This auction is more toxic than a whore's crotch. No one in their right mind is getting near it.