back
362 comments
This is exactly what the NSA should be doing. Everyone (rightfully IMO) complains about overly broad data collection happening within the USA, but here (as with stuxnet) you have the exact opposite, a targeted foreign activity conducted with care and targeting. I know it's not for everyone (not least because not everyone is in the states, huh), and it could be considered a bad precedent, but it's not like Iran asked our permission before they launched their nuclear program, or other states are actually waiting on the US's example to have their own intelligence services do their jobs. If you hold that something like 9/11 should be prevented, and that (actual) WMD programs should be stalled, then it follows that this is a fine way to go about it.
You make a good point, but the part about Iran asking for our permission before starting the nuclear program doesn't really add much. Of course they didn't ask, just like the US didn't ask before starting our nuclear program. A nation state is an autonomous entity, and doesn't ask permission before making any action within its own borders.

The US, and any other nation state, will of course conduct covert operations, including spying on other nation states. I don't find anything inherently wrong or immoral about this, but I don't think anyone can act surprised or indignant if other nation states don't like being spied on or hacked. You don't gain the moral high ground by pointing out they didn't ask for our permission to build something in their own borders.

Yes, we spy on other nations, and we probably should; but the consequence of that is that other nations will trust you less when you are caught, and that is just the natural consequence of spying.

I am from germany and I hope most of americans don't have this point of view.

1. give up freedom for some stupid terrorist attacks? why should we? We've lost the keystone of freedom when we do this and they have already won.

2. Do you really think these extensive intelligences do stop terror? (maybe they do sometimes, but terrorists will find new ways)

3. IS and others are the result of the Iraq war which was a offensive war from the US justified by a lie (Sadam had no weapon of mass destruction). Do you still think that America is the world police? The reputation of the US has gone rapidly down in the last decade. For the most here in germany the US are not the good ones any more. Other countries have their own way of life. America has to accept that.

The problem is it undermines trust in American technology products in general. If the Snowden revelations were that the United States was bugging Iran, Libya and North Korea and monitoring all their communications, that would be one thing. However, we know now that EVERYONE is under surveillance. Therefore, how do we know they aren't doing this to everyone as well?
This statement is the most upvoted piece of propaganda I've ever seen on Hacker News. I think the shills that Greenwald told us all about are all over HN too.

There's no point in praising anything the NSA does unless you are perfectly happy with them destroying security for the entire world and spying on everybody at all. The NSA has the power to blackmail politicians and run the country. They lied to congress. They are a completely rogue agency. And you praise them!

> It's not like Iran asked our permission before they launched their nuclear program

You do realize the U.S. helped launch Iran's nuclear program, right?

http://en.wikipedia.org/wiki/Nuclear_program_of_Iran

From an American perspective you might be right. But, as a Brazilian, I'd say this is the perfect reason why the rest of the world should stop buying technology from the U.S. You are not trustworthy.

Yes, I know that "everyone does it, get over" but it doesn't make you better or even acceptable.

If you hold that something like 9/11 should be prevented, and that (actual) WMD programs should be stalled

Except nothing like 9/11 was ever prevented by broad data collection.

And: There is no "terrorist threat" to begin with, unless you also believe in Santa Claus and the Easter Bunny.

You are still more likely to be killed by a lightning strike than by a terrorist. There's still plenty more and plenty more violent killing going on in Africa than in Middle East. But there's no oil and no convenient media narrative to be had from the former.

then it follows that this is a fine way to go about it

Non sequitur.

Which countries did ask permission before starting their nuclear programs?

The countries that have nuclear weapons, who do they ask to be allowed to keep them?

How is infecting a whole telecom company like Belgacom, which then allows them to get data on everyone, a "targeted" attack?
Two problems I'm having with this argument:

(1) This does not actually look particularly targeted to me, but more like a shotgun approach. While Russia and China are the primary targets, there are also plenty of allied nations on that map. Unless, of course, you're trying to say that all non-US targets are fair game.

(2) The NSA targeting medical institutions (presumably hospitals) makes me particularly queasy, because what they are doing is not exactly passive listening, and when they screw something up there (like the router in Syria that they crashed), that could endanger human lives.

If the U.S. can do it, other entities can do it too.

I'd rather that the NSA were disclosing the vulnerabilities they discover to vendors, so they can be fixed.

Failing that, we rely on white hat researchers like those here (not to mention Snowden). They're doing really important, socially valuable, work. I wonder where they get their funding, we need a lot more of them. It's our job as software/hardware engineers to create secure software.

Maybe it is what it should be doing for you. But this is exactly what the IT community should work against. We should be able to trust our devices.
According to the report, researchers within the USA were infected with Equation Group malware too.
I really appreciate it when someone presents and argument that is from a differing point of view than mine, but is well stated and very convincing. Thank you for that.

That said, I'm not certain I agree. The part where they're intercepting mail of citizens without warrants, without much oversight, that scares me. It's one thing to be talented hackers trying to fight the good fight digitally rather than violently, but when we allow the government organizations to violate privacy to further unstated goals, we set a precedent that can be used as a basis to go further next time.

The NSA can do incredible things like this, but they need better oversight, a publicly stated set of rules that they must follow when they do their work.

> but it's not like Iran asked our permission before they launched their nuclear program

Why should they? Who died and made us the "World Police" ?

1. The NSA uses all of these offensive information security technologies in mass surveillance as well as targeted attacks. See Belgacom.

2. The more concerning thing is their appropriation of civilian infrastructure and targeting of civilians using offensive attacks.

3. The vast offensive capabilities of the US government undermine their ability to be trusted in the development of improved defensive capabilities. Defensive research and product development funded by the US govt will produce systems that undermine offensive capabilities that are a key form of US hegemony.

>It's just about impossible for an outsider to reverse engineer a hard drive, read the existing firmware, and create malicious versions.

It's hard, but it isn't like this hasn't been done before: http://spritesmods.com/?art=hddhack&page=3

And to be honest, I think what they call "about impossible" is just a question of investing enough time and having a somewhat decent understanding of microprocessors and reverse-engineering. I'm not trying to downplay Equation Group's achievement, but it feels like arstechnica is starting to exaggerate here.

The update confirms it is the NSA.

It is incredible, even the most generous estimation of the NSA's capabilities before the Snowden disclosures now look conservative. This is the stuff conspiracy theories are made of.

I think the lesson here is not so much that governments can do this, but that entities with extremely large budgets are implementing broad, interconnected initiatives like this.

I think realistically any entity with over $20M could participate meaningfully in these kinds of exploits. The key is that in order to be useful many overlapping initiatives need to exist.

It seems like exploiting things like firmware would be pretty easy: You just get a member of your team who is a bit overqualified to apply for a job at the target company. A relatively small team could accomplish this in a few years, aided by the scarcity of top tier engineering talent.

The hard part is the social aspect of the attacks, but a single clever individual can come up with many.

We should all be aware of the fact that these people are the enemy. They don't do these things to "protect freedom", they do them to destroy freedom.

Most of the people on Hackernews are uniquely placed to resist. Secure your software. Refuse to cooperate unless legally compelled. Analyze and publish any evidence of government attacks.

If you work for the NSA, understand this: you aren't American. You are the Internet Daesh. You will lose.

I would like to ask anyone reading this to hypothesize with me. What if the US government was broadly and knowingly corrupt? How comfortable would you feel knowing that they had such broad and powerful technical capabilities? How would you fight against such a machine, to uproot the corruption?

I'm in awe of these technical feats, but also cautious about the implications of an all-knowing, all-powerful government presence who can infringe on your basic rights at-will.

What is the NSA is doing here is more subtle and I do not think they fully realize it. They are heavily financing and accelerating the speed of damages that people on the dark side can do. They are "inspiring" a bunch of curious teenagers (in the best case) or a bunch of cyber criminals (in the worst case) to create another malware like that. They are putting out there first of all the ideas, second the conviction that it is possible to do so, and third sample code to study, improve and deploy. This race to being the "smarter" spy is unfortunately leading us in a very risky world to live in. A lose-lose preposition. The press and the antivirus researchers are also not being too smart here to make this public available.
Based on the article, are we to presume that this only affects tech in hostile countries? Or are they doing this to US-based equipment as well?

Seems like this will backfire spectacularly when foreign countries and companies stop buying American made tech for fear of these hardware backdoors. Spectacularly irresponsible.

This is pretty intense malware, but at some level it's reassuring how narrowly-targeted these attacks seem to be. Arguably, this is what the NSA is supposed to be doing: targeted attacks against key systems in hostile nations, not mass dragnet-surveillance of everyone on the Internet.
I don't know what's more disturbing: the fact that US government does this with impunity or the fact that a sizable group of technically competent citizens defends it.
do we really need to encourage people to go into this line of work with language like this:

>A long list of almost superhuman technical feats illustrate Equation Group's extraordinary skill, painstaking work, and unlimited resources.

with the effort these people spend contributing next to zero value in the world (strongly negative value if you add up all the energy wasted on all sides including their 'enemies'; if all these sides spent the same resources on positive constructive research instead, we would be ahead). This genius could be applied to making a compiler/interpreter that just does what you're trying to do, regardless of whether you're a programmer.

it's a binary choice: have these people perform 'superhuman' feats of self-destruction and obfuscated encryption and finding zero-days....

... or give humanity the tools that every one of the seven billion people on it can instantiate any idea in seconds and have it actually be correctly interpreted and done.

Resources are spent tricking people so they don't notice something. Where are the resources being spent helping people do what they're trying to?

The example I always go to is: since the creation of the United States, how much inter-state (Iowa and Massachusetts) spying, warmaking, border control, etc, is wasted?

Could this have something to do with its performance over the last couple of centuries?

I think of these types of programs as 'welfare for geniuses'. give them an office and something to do.

but for God's sake, spit them out again. The optimal amount of state spying is, let's face it, much closer to zero than its current levels.

Spend on enough universal education that everyone shares values and nobody is destructive; put the rest into fundamental research and development.

I don't mind that the government exists to do research, employ people, and keep the world safe. But put some limits on it, and please don't encourage this with language like I quoted at the top.

humanity has better things to do with its time. nobody wants to live in a prison.

Might as well tattoo a UUID on our foreheads and be done with it at this rate. God I hate hearing the apologists for the NSA in these threads. Are you so devoid of empathy?
Anyone get the feeling that at this point, the NSA et al, have moved onto even more sophisticated attacks?
I'm pretty sure intercepting and screwing with mail is a felony... isn't that a felony? How exactly can the US Government have it's employees committing felonies with no warrants or oversight?
Takeaway lesson #1: re-flash all HDDs/SSDs with verified vanilla firmware from original manufacturer.

Lesson #2: Beware any and all data media, CDs, DVDs (Netflix? Blockbuster? Hollywood screeners? ...?), USB drives.

One of the images [0] in the article identifies a C&C server used by the attackers, technology-revealed.com. The script appears to embed an invisible iframe pointing to a page on that domain, which probably infects the machine using some zero-day exploit on the browser or one of its plugins. The domain is still registered, but appears not to be running an HTTP server anymore. Might be interesting to investigate if someone wants to look into that.

[0] http://cdn.arstechnica.net/wp-content/uploads/2015/02/malici...

Wasn't there a demonstration of a similar HDD exploit posted on HN earlier?

edit: found it https://news.ycombinator.com/item?id=8665865

Interesting to compare the sophistication of this malware and physical weapon systems such as the Tomahawk cruise missile. One video of cluster munitions shows how the munitions try to attack armor, then vehicles, then groups of people, and then land to become pop up landmines. [1]

One has to assume that the capabilities of the other actors is similar. Makes for a pretty scary picture when you think about it.

[1] https://www.youtube.com/watch?v=CY9gojFu-_U

I feel bad for the people that work for groups like this. Sure, you get to hack every developed nation in the world and are privy to the most sensitive information in the world. You're also therefore the world's largest liability, and your life is probably very expendable compared to the data you're retrieving. They might have a unique identity just for picking up milk.
I'm surprised the CPU microcode angle isn't mentioned.
Just think, a member of the group is probably reading this thread right now...
So there is this new shodan-like database that takes data from massive scans of the Internet (I think?) etc... Might be worth running all C&Cs through it to discover more domains , for example https://rateip.com/ipv4/190.60.202.4
Equation Group: Questions and Answers by Kaspersky [pdf] --> https://cdn1.vox-cdn.com/uploads/chorus_asset/file/3415904/E...
The point isn't whether we should be surprised this is the NSA, the interesting thing is that this layered strategy is what you do if you have access to lots of money and talent.
How can one detect infection?
Scalpel, not a sledgehammer.
While this is undoubtedly scary, it looks very Windows-specific and would seem unlikely to affect a somewhat security-conscious Linux user.

Java and IE exploits, autorun files, NTFS...

> The malicious firmware created a secret storage vault that survive

> military-grade disk wiping and reformatting, making sensitive data

> stolen from victims available even after reformatting the drive and

> reinstalling the operating system.

And that's why it's possibly not the greatest idea to replace simple firmware and drivers with small operating systems (Intel AMT, microcode, SSDs, Smart TVs etc.).

What's worse is the fact that this would be more terrifying if this weren't an action to the NSA's credit. Chinese, British, and Russian governments also have the capability of developing intrusive malware at such a scale.

I see that this is confirmed as the NSA, but the world has been awfully silent on the intrusiveness of Chinese malware practices. You can not travel safely in China without your domestic devices being breached, yet we don't hear about large-scale projects from their government, which also possesses "near limitless resources" at their disposal.

I just think it's interesting there's so much attention on the NSA.

Absolutely! I live in Bulgaria, Eastern Europe, a poor, small country, which has been accepted in NATO and the European Union, but still is hosted by the past-Soviet`s secret intelligence services of Moscow, which are now illegal, but has agents and the absolute power over the legal secret services in Bulgaria. The surveillance is much larger, than in the USA, but all the info goes to Moscow.

So, what are you troubling about, when NSA is pure American, and has the purpose to protect you from the legions of Russian, Chinese hackers - officially military, or just playing and stilling criminals, and all the Islamic recruiters, who are trying to recruit American citizens for their Jihad against The Civilization...

I don`t understand, are you stupid, people, or what? NSA has the duty to protect you, and you are acting as children, whom parents has been installed a security program on your PC, to protect you from pedophiles... It`s the same case with the NSA surveillance!

We definitely throw our weight around and interfere with Iran's domestic affairs. But this is definitely a case of "we think our morals are better than yours" (and we have bigger guns so we're gonna enforce those morals).

The Iranian government funds terrorist groups around the world, and has called for the destruction of certain other countries. So yeah, if we have the ability to stifle them (particularly their nuclear ambitions) I say we go for it.

I do feel bad for many of the Iranian people. Many of them do not like their government and are therefore held hostage by the events around them, which they have no control over, and may disagree with.