Skip to main content

Home/ Future of the Web/ Group items tagged Intellectual

Rss Feed Group items tagged

Paul Merrell

He Was a Hacker for the NSA and He Was Willing to Talk. I Was Willing to Listen. - 2 views

  • he message arrived at night and consisted of three words: “Good evening sir!” The sender was a hacker who had written a series of provocative memos at the National Security Agency. His secret memos had explained — with an earthy use of slang and emojis that was unusual for an operative of the largest eavesdropping organization in the world — how the NSA breaks into the digital accounts of people who manage computer networks, and how it tries to unmask people who use Tor to browse the web anonymously. Outlining some of the NSA’s most sensitive activities, the memos were leaked by Edward Snowden, and I had written about a few of them for The Intercept. There is no Miss Manners for exchanging pleasantries with a man the government has trained to be the digital equivalent of a Navy SEAL. Though I had initiated the contact, I was wary of how he might respond. The hacker had publicly expressed a visceral dislike for Snowden and had accused The Intercept of jeopardizing lives by publishing classified information. One of his memos outlined the ways the NSA reroutes (or “shapes”) the internet traffic of entire countries, and another memo was titled “I Hunt Sysadmins.” I felt sure he could hack anyone’s computer, including mine. Good evening sir!
  • The sender was a hacker who had written a series of provocative memos at the National Security Agency. His secret memos had explained — with an earthy use of slang and emojis that was unusual for an operative of the largest eavesdropping organization in the world — how the NSA breaks into the digital accounts of people who manage computer networks, and how it tries to unmask people who use Tor to browse the web anonymously. Outlining some of the NSA’s most sensitive activities, the memos were leaked by Edward Snowden, and I had written about a few of them for The Intercept. There is no Miss Manners for exchanging pleasantries with a man the government has trained to be the digital equivalent of a Navy SEAL. Though I had initiated the contact, I was wary of how he might respond. The hacker had publicly expressed a visceral dislike for Snowden and had accused The Intercept of jeopardizing lives by publishing classified information. One of his memos outlined the ways the NSA reroutes (or “shapes”) the internet traffic of entire countries, and another memo was titled “I Hunt Sysadmins.” I felt sure he could hack anyone’s computer, including mine.
  • I got lucky with the hacker, because he recently left the agency for the cybersecurity industry; it would be his choice to talk, not the NSA’s. Fortunately, speaking out is his second nature.
  • ...7 more annotations...
  • He agreed to a video chat that turned into a three-hour discussion sprawling from the ethics of surveillance to the downsides of home improvements and the difficulty of securing your laptop.
  • In recent years, two developments have helped make hacking for the government a lot more attractive than hacking for yourself. First, the Department of Justice has cracked down on freelance hacking, whether it be altruistic or malignant. If the DOJ doesn’t like the way you hack, you are going to jail. Meanwhile, hackers have been warmly invited to deploy their transgressive impulses in service to the homeland, because the NSA and other federal agencies have turned themselves into licensed hives of breaking into other people’s computers. For many, it’s a techno sandbox of irresistible delights, according to Gabriella Coleman, a professor at McGill University who studies hackers. “The NSA is a very exciting place for hackers because you have unlimited resources, you have some of the best talent in the world, whether it’s cryptographers or mathematicians or hackers,” she said. “It is just too intellectually exciting not to go there.”
  • The Lamb’s memos on cool ways to hunt sysadmins triggered a strong reaction when I wrote about them in 2014 with my colleague Ryan Gallagher. The memos explained how the NSA tracks down the email and Facebook accounts of systems administrators who oversee computer networks. After plundering their accounts, the NSA can impersonate the admins to get into their computer networks and pilfer the data flowing through them. As the Lamb wrote, “sys admins generally are not my end target. My end target is the extremist/terrorist or government official that happens to be using the network … who better to target than the person that already has the ‘keys to the kingdom’?” Another of his NSA memos, “Network Shaping 101,” used Yemen as a theoretical case study for secretly redirecting the entirety of a country’s internet traffic to NSA servers.
  • “If I turn the tables on you,” I asked the Lamb, “and say, OK, you’re a target for all kinds of people for all kinds of reasons. How do you feel about being a target and that kind of justification being used to justify getting all of your credentials and the keys to your kingdom?” The Lamb smiled. “There is no real safe, sacred ground on the internet,” he replied. “Whatever you do on the internet is an attack surface of some sort and is just something that you live with. Any time that I do something on the internet, yeah, that is on the back of my mind. Anyone from a script kiddie to some random hacker to some other foreign intelligence service, each with their different capabilities — what could they be doing to me?”
  • “You know, the situation is what it is,” he said. “There are protocols that were designed years ago before anybody had any care about security, because when they were developed, nobody was foreseeing that they would be taken advantage of. … A lot of people on the internet seem to approach the problem [with the attitude of] ‘I’m just going to walk naked outside of my house and hope that nobody looks at me.’ From a security perspective, is that a good way to go about thinking? No, horrible … There are good ways to be more secure on the internet. But do most people use Tor? No. Do most people use Signal? No. Do most people use insecure things that most people can hack? Yes. Is that a bash against the intelligence community that people use stuff that’s easily exploitable? That’s a hard argument for me to make.”
  • I mentioned that lots of people, including Snowden, are now working on the problem of how to make the internet more secure, yet he seemed to do the opposite at the NSA by trying to find ways to track and identify people who use Tor and other anonymizers. Would he consider working on the other side of things? He wouldn’t rule it out, he said, but dismally suggested the game was over as far as having a liberating and safe internet, because our laptops and smartphones will betray us no matter what we do with them. “There’s the old adage that the only secure computer is one that is turned off, buried in a box ten feet underground, and never turned on,” he said. “From a user perspective, someone trying to find holes by day and then just live on the internet by night, there’s the expectation [that] if somebody wants to have access to your computer bad enough, they’re going to get it. Whether that’s an intelligence agency or a cybercrimes syndicate, whoever that is, it’s probably going to happen.”
  • There are precautions one can take, and I did that with the Lamb. When we had our video chat, I used a computer that had been wiped clean of everything except its operating system and essential applications. Afterward, it was wiped clean again. My concern was that the Lamb might use the session to obtain data from or about the computer I was using; there are a lot of things he might have tried, if he was in a scheming mood. At the end of our three hours together, I mentioned to him that I had taken these precautions—and he approved. “That’s fair,” he said. “I’m glad you have that appreciation. … From a perspective of a journalist who has access to classified information, it would be remiss to think you’re not a target of foreign intelligence services.” He was telling me the U.S. government should be the least of my worries. He was trying to help me. Documents published with this article: Tracking Targets Through Proxies & Anonymizers Network Shaping 101 Shaping Diagram I Hunt Sys Admins (first published in 2014)
Gonzalo San Gil, PhD.

Company Uses DMCA to Censor and Expose Critical Blogger - TorrentFreak - 0 views

  •  
    " By Ernesto on June 17, 2016 C: 25 News Marketing and sales company Smart Circle is using the DMCA to uncover the identity of a critical blogger. The company obtained a subpoena directed at WordPress, stating that the blogger in question violates their copyrights by publishing modified images of its key employees."
Gonzalo San Gil, PhD.

Huge Artists Coalition Piles Pressure on Congress Over DMCA - TorrentFreak [# ! Note] - 0 views

  •  
    " Andy on June 21, 2016 C: 132 Breaking A coalition of 186 artists, bands and songwriters have penned an open letter to Congress complaining about the ineffectiveness of the DMCA. From Taylor Swift, Trent Reznor, deadmau5 and U2, to Sirs Paul McCartney and Elton John, the message is clear: The DMCA allows tech companies to make huge profits while artists and creators suffer."
Gonzalo San Gil, PhD.

All Nations Lose with TPP's Expansion of Copyright Terms | Electronic Frontier Foundation - 0 views

  •  
    "EFF has previously written about various troubling provisions of the Trans-Pacific Partnership Agreement (TPP) that is being negotiated under wraps. One other major concern is that TPP seeks to propagate the excessive copyright terms currently found in American copyright legislation, and will become yet another tool of the second enclosure movement: "the enclosure of the intangible commons of the mind.""
Gonzalo San Gil, PhD.

Google Refuses to Take Down Pirate-Movies-on-YouTube Sites | TorrentFreak - 0 views

  •  
    " Andy on March 18, 2014 C: 8 Breaking Following today's copyright settlement between Google and Viacom, it's interesting to note that YouTube still has plenty of illicit Hollywood content online. The MPAA has certainly noticed, with an effort last week to have several Popcorn Time-style dedicated web interfaces de-listed by Google, a request that was declined."
Gonzalo San Gil, PhD.

Stop the Secrecy | OpenMedia - 0 views

  •  
    "Right now, Obama is meeting with leaders in Asia to finalize the secretive Trans-Pacific Partnership (TPP) agreement. The TPP threatens to censor your Internet1, kill jobs, undermine environmental safeguards, and remove your democratic rights2. We're going to get the attention of decision-makers and the media by projecting a Stop The Secrecy message on key buildings in Washington D.C. - but we need you to add your voice now. First name Last name Email Country "
Gonzalo San Gil, PhD.

Shutting Down Pirate Sites is Ineffective, European Commission Finds | TorrentFreak - 0 views

  •  
    " Ernesto on May 14, 2015 C: 0 Breaking Shutting down pirate websites such as The Pirate Bay is high on the agenda of the entertainment industries. However, according to research published by the European Commission's Joint Research Centre, these raids are relatively ineffective and potentially counterproductive."
  •  
    " Ernesto on May 14, 2015 C: 0 Breaking Shutting down pirate websites such as The Pirate Bay is high on the agenda of the entertainment industries. However, according to research published by the European Commission's Joint Research Centre, these raids are relatively ineffective and potentially counterproductive."
Gonzalo San Gil, PhD.

Cox Accuses Rightscorp of Mass Copyright Infringement - TorrentFreak - 0 views

  •  
    " Ernesto on September 24, 2015 C: 7 Breaking Internet provider Cox Communications has hit back at anti-piracy company Rightscorp. While denying responsibility for the alleged copyright infringements of its subscribers, Cox turns the tables, accusing Rightscorp of sharing thousands of copyrighted works without permission."
  •  
    " Ernesto on September 24, 2015 C: 7 Breaking Internet provider Cox Communications has hit back at anti-piracy company Rightscorp. While denying responsibility for the alleged copyright infringements of its subscribers, Cox turns the tables, accusing Rightscorp of sharing thousands of copyrighted works without permission."
Gonzalo San Gil, PhD.

Lessig for President | Enrique Dans | LinkedIn - 0 views

  • Lawrence Lessig is, without doubt, one of America’s most respected and prestigious intellectuals.
Gonzalo San Gil, PhD.

EU Starts Geo-Blocking Antitrust Case Against U.S Movie Studios - TorrentFreak - 0 views

    • Gonzalo San Gil, PhD.
       
      # ! Oh, Oh: #IntellectualProperty 'Enforcers' # ! don't agree even among themselves...
  •  
    [ By Ernesto on July 23, 2015 C: 41 Breaking The European Union has today launched an antitrust investigation against several large U.S. movie studios and Sky UK. The European Commission wants to abolish geographical restrictions and has sent a statement of objections over the geo-blocking practices of six major US film studios including Disney, Paramount Pictures and Warner Bros. ...]
Gonzalo San Gil, PhD.

MPAA Emails Expose Dirty Media Attack Against Google - TorrentFreak - 0 views

  •  
    "New emails have revealed how the MPAA and Mississippi Attorney General Jim Hood orchestrated a PR smear campaign against Google in order to push through their anti-piracy measures. "
  •  
    "New emails have revealed how the MPAA and Mississippi Attorney General Jim Hood orchestrated a PR smear campaign against Google in order to push through their anti-piracy measures. "
Gonzalo San Gil, PhD.

Google Asked to Remove 18 'Pirate Links' Every Second - TorrentFreak - 0 views

  •  
    " Ernesto on August 2, 2015 C: 13 News Copyright holders continue to increase the number of copyright takedown requests they send to Google. As a result the company is currently asked to remove a record breaking 18 links to "pirate" pages from its search results every second, a number that is still increasing at a rapid pace."
  •  
    " Ernesto on August 2, 2015 C: 13 News Copyright holders continue to increase the number of copyright takedown requests they send to Google. As a result the company is currently asked to remove a record breaking 18 links to "pirate" pages from its search results every second, a number that is still increasing at a rapid pace."
Gonzalo San Gil, PhD.

Bitdefender Blocks Anti-Piracy Website as Malware - TorrentFreak - 1 views

  •  
    " rnesto on August 1, 2015 C: 8 Breaking Rightscorp, the piracy monetization company that works with Warner Bros and other prominent copyright holders, has had to deal with its fair share of setbacks recently. The company is publicly condemned for its "extortionist" practices and now anti-virus vendor Bitdefender has started to brand the company's website as malware. "
Gonzalo San Gil, PhD.

Google DMCA Notice Record Smashed Again - But Why? - TorrentFreak - 1 views

  •  
    " Andy on September 6, 2015 C: 17 Breaking Despite scaling dizzy heights in recent months, the record for DMCA notices being sent to Google's search engine has been smashed again. In a single week Google just processed a mind-boggling 13.68 million URLs, or to put it another way, almost 23 copyright complaints every second. So what's behind the massive surge?"
Gonzalo San Gil, PhD.

Sex Cams at NASA & Library of Congress, Anti-Piracy Outfit Says | TorrentFreak - 1 views

  •  
    " Andy on May 27, 2014 C: 27 Breaking An adult media company's hiring of an anti-piracy outfit to blitz the Internet for content infringing on its webcam copyrights has produced ridiculous results."
Gonzalo San Gil, PhD.

[hub] TTIP: Commission intends to place secret, corporate "Christmas list" of IPRs in t... - 1 views

  •  
    "quotes the Commission and OHIM officials as they are advising on how to work against civil society and why it is good that the public is kept in the dark on negotiations"
Gonzalo San Gil, PhD.

Leaked TPP Draft Reveals Tough Anti-Piracy Measures | TorrentFreak - 1 views

  •  
    "options currently on the table are life of the author plus 50, 70 or 100 years" [# ! ... but don't say these 'measures' are aimed to 'stimulate creation' # ! but to fill the deep pockets of a few... with the hard work of many others. [... options currently on the table are life of the author plus 50, 70 or 100 years...]
Paul Merrell

LocalOrg: Decentralizing Telecom - 0 views

  • SOPA, ACTA, the criminalization of sharing, and a myriad of other measures taken to perpetuate antiquated business models propping up enduring monopolies - all have become increasingly taxing on the tech community and informed citizens alike. When the storm clouds gather and torrential rain begins to fall, the people have managed to stave off the flood waters through collective effort and well organized activism - stopping, or at least delaying SOPA and ACTA. However, is it really sustainable to mobilize each and every time multi-billion dollar corporations combine their resources and attempt to pass another series of draconian rules and regulations? Instead of manning the sandbags during each storm, wouldn't it suit us all better to transform the surrounding landscape in such a way as to harmlessly divert the floods, or better yet, harness them to our advantage? In many ways the transformation has already begun.
  • While open source software and hardware, as well as innovative business models built around collaboration and crowd-sourcing have done much to build a paradigm independent of current centralized proprietary business models, large centralized corporations and the governments that do their bidding, still guard all the doors and carry all the keys. The Internet, the phone networks, radio waves, and satellite systems still remain firmly in the hands of big business. As long as they do, they retain the ability to not only reassert themselves in areas where gains have been made, but can impose preemptive measures to prevent any future progress. With the advent of hackerspaces, increasingly we see projects that hold the potential of replacing, at least on a local level, much of the centralized infrastructure we take for granted until disasters or greed-driven rules and regulations upset the balance. It is with the further developing of our local infrastructure that we can leave behind the sandbags of perpetual activism and enjoy a permanently altered landscape that favors our peace and prosperity. Decentralizing Telecom
  • As impressive as a hydroelectric dam may be and as overwhelming as it may seem as a project to undertake, it will always start with but a single shovelful of dirt. The work required becomes in its own way part of the payoff - with experienced gained and with a magnificent accomplishment to aspire toward. In the same way, a communication network that runs parallel to existing networks, with global coverage, but locally controlled, may seem an impossible, overwhelming objective - and for one individual, or even a small group of individuals, it is. However, the paradigm has shifted. In the age of digital collaboration made possible by existing networks, the building of such a network can be done in parallel. In an act of digital-judo, we can use the system's infrastructure as a means of supplanting and replacing it with something superior in both function and in form. 
Paul Merrell

Why the Sony hack is unlikely to be the work of North Korea. | Marc's Security Ramblings - 0 views

  • Everyone seems to be eager to pin the blame for the Sony hack on North Korea. However, I think it’s unlikely. Here’s why:1. The broken English looks deliberately bad and doesn’t exhibit any of the classic comprehension mistakes you actually expect to see in “Konglish”. i.e it reads to me like an English speaker pretending to be bad at writing English. 2. The fact that the code was written on a PC with Korean locale & language actually makes it less likely to be North Korea. Not least because they don’t speak traditional “Korean” in North Korea, they speak their own dialect and traditional Korean is forbidden. This is one of the key things that has made communication with North Korean refugees difficult. I would find the presence of Chinese far more plausible.
  • 3. It’s clear from the hard-coded paths and passwords in the malware that whoever wrote it had extensive knowledge of Sony’s internal architecture and access to key passwords. While it’s plausible that an attacker could have built up this knowledge over time and then used it to make the malware, Occam’s razor suggests the simpler explanation of an insider. It also fits with the pure revenge tact that this started out as. 4. Whoever did this is in it for revenge. The info and access they had could have easily been used to cash out, yet, instead, they are making every effort to burn Sony down. Just think what they could have done with passwords to all of Sony’s financial accounts? With the competitive intelligence in their business documents? From simple theft, to the sale of intellectual property, or even extortion – the attackers had many ways to become rich. Yet, instead, they chose to dump the data, rendering it useless. Likewise, I find it hard to believe that a “Nation State” which lives by propaganda would be so willing to just throw away such an unprecedented level of access to the beating heart of Hollywood itself.
  • 5. The attackers only latched onto “The Interview” after the media did – the film was never mentioned by GOP right at the start of their campaign. It was only after a few people started speculating in the media that this and the communication from DPRK “might be linked” that suddenly it became linked. I think the attackers both saw this as an opportunity for “lulz” and as a way to misdirect everyone into thinking it was a nation state. After all, if everyone believes it’s a nation state, then the criminal investigation will likely die.
  • ...4 more annotations...
  • 6. Whoever is doing this is VERY net and social media savvy. That, and the sophistication of the operation, do not match with the profile of DPRK up until now. Grugq did an excellent analysis of this aspect his findings are here – http://0paste.com/6875#md 7. Finally, blaming North Korea is the easy way out for a number of folks, including the security vendors and Sony management who are under the microscope for this. Let’s face it – most of today’s so-called “cutting edge” security defenses are either so specific, or so brittle, that they really don’t offer much meaningful protection against a sophisticated attacker or group of attackers.
  • 8. It probably also suits a number of political agendas to have something that justifies sabre-rattling at North Korea, which is why I’m not that surprised to see politicians starting to point their fingers at the DPRK also. 9. It’s clear from the leaked data that Sony has a culture which doesn’t take security very seriously. From plaintext password files, to using “password” as the password in business critical certificates, through to just the shear volume of aging unclassified yet highly sensitive data left out in the open. This isn’t a simple slip-up or a “weak link in the chain” – this is a serious organization-wide failure to implement anything like a reasonable security architecture.
  • The reality is, as things stand, Sony has little choice but to burn everything down and start again. Every password, every key, every certificate is tainted now and that’s a terrifying place for an organization to find itself. This hack should be used as the definitive lesson in why security matters and just how bad things can get if you don’t take it seriously. 10. Who do I think is behind this? My money is on a disgruntled (possibly ex) employee of Sony.
  • EDIT: This appears (at least in part) to be substantiated by a conversation the Verge had with one of the alleged hackers – http://www.theverge.com/2014/11/25/7281097/sony-pictures-hackers-say-they-want-equality-worked-with-staff-to-break-in Finally for an EXCELLENT blow by blow analysis of the breach and the events that followed, read the following post by my friends from Risk Based Security – https://www.riskbasedsecurity.com/2014/12/a-breakdown-and-analysis-of-the-december-2014-sony-hack EDIT: Also make sure you read my good friend Krypt3ia’s post on the hack – http://krypt3ia.wordpress.com/2014/12/18/sony-hack-winners-and-losers/
  •  
    Seems that the FBI overlooked a few clues before it told Obama to go ahead and declare war against North Korea. 
Gonzalo San Gil, PhD.

MPAA Secretly Settled With Hotfile for $4 Million, Not $80 Million | TorrentFreak - 0 views

  •  
    [# ! Is this the exemplary IP Enforcement aimed to 'Save The Culture'...? # It seems more a weird #wangle... # ... or, perhaps, it is that a bunch of bucks is what matters.... # ! #artists and #creators shouldn't support such #hoax.] " By Ernesto on December 24, 2014 C: 0 Breaking Last December the MPAA announced one of its biggest victories to date. The Hollywood group won its case against file-hosting site Hotfile, who agreed to a $80 million settlement. However, this figure mostly served to impress and scare the pubic, as we can now reveal that Hotfile agreed to pay 'only' $4 million." [# ! Yup! Why "#secretly"...?]
  •  
    [# ! '#Tricky' IP #enforcement...] " By Ernesto on December 24, 2014 C: 0 Breaking Last December the MPAA announced one of its biggest victories to date. The Hollywood group won its case against file-hosting site Hotfile, who agreed to a $80 million settlement. However, this figure mostly served to impress and scare the pubic, as we can now reveal that Hotfile agreed to pay 'only' $4 million." [# ! Yup! Why "#secretly"...?]
« First ‹ Previous 41 - 60 of 75 Next ›
Showing 20 items per page