7 ms·
How the US Hacked ISIS
- bashinator 6y agoHere's another account in the form of an extended interview with one of the commanders of US Cyber Command at the time. https://darknetdiaries.com/episode/50/ https://darknetdiaries.com/episode/50/
- jonnyreiss 6y agoHighly recommend this podcast---Ep 29: Stuxnet is another episode worth checking out
- Robotbeat 6y ago"ISIS" is an acronym and should be capitalized. (Isis is an Egyptian goddess of no relation to ISIS.)
- mikeyouse 6y agoIsis is also an unfortunately common name. Most of my coworker's apps stopped working and her banking became much more difficult sometime around 2012.
- FooBarBizBazz 6y agoThis seems dumb on the part of the bank. Unless terrorists are really, really stupid, classifying the first name "Isis" as "terrorist" is bound to have a 100% false positive rate.
- mikeyouse 6y agoYou're not wrong - but try to Venmo somebody funds for a "Cuban Sandwich" or an "Iranian restaurant" and see what happens though.
- creddit 6y agoI just did the Cuban Sandwich one without a problem. What should I be expecting?
- macintux 6y agoI did that with PayPal a couple of years ago and the transaction was flagged for review.
- leereeves 6y agoNot long ago there was a similar discussion here because > PayPal is currently blocking all transactions containing the word “tardigrade” https://news.ycombinator.com/item?id=24450828 https://news.ycombinator.com/item?id=24450828 And one of the top comments said: > PayPal gets a list of banned strings from the Office of Foreign Asset controls. If any match those strings it's flagged for a review.
- srtjstjsj 6y agoUSA had (has?) sanctions banning trading with Cuba.
- creddit 6y agoI know. I'm just not sure why the OP is so confident that me putting "Cuban Sandwich" in the memo is going to get me flagged. Still good so far.
- dilyevsky 6y agoDunno why this is being downvoted - i once jokingly added a note mentioning “meth” paying someone for dinner (in reference to our conversation at said dinner) and google suspended my account temporarily and cancelled the transaction
- 29athrowaway 6y agoPersian food is kind of a synonym
- aaomidi 6y agoIt's cause the banks keep getting sued by the US govt and the US govt keeps siding with the US govt that the banks violated sanctions. So banks then do ridiculous things like checking your timezone and checking your name and the memo fields so they get to have a stronger defense in court.
- deleted 6y ago[deleted]
- gnat 6y agoClassic case of the Scunthorpe Problem. https://en.m.wikipedia.org/wiki/Scunthorpe_problem https://en.m.wikipedia.org/wiki/Scunthorpe_problem
- segfaultbuserr 6y agoIt was (probably) capitalized in the original submission. But Hacker News's title autoformatting screwed it up, again. It's known to capitalize individual words but removing all-caps acronyms.
- BenJong-Il 6y agoUS ist still capitalized. Or am I missing something?
- segfaultbuserr 6y agoIt's the annoying part. The anti-all-caps-clickbait system knows some common abbreviations, but not others. For example, on multiple occasions, "MIT" was not unaffected but "CSAIL" was turned into "Csail", see [0]. [0] https://news.ycombinator.com/item?id=20482855 https://news.ycombinator.com/item?id=20482855
- TeMPOraL 6y agoIt's the first time I hear HN has title autoformatting.
- segfaultbuserr 6y agoThere is definitely some find-and-replace code. After you click the submission button, the title is immediately "corrected" (submitters can manually edit the title back later), with good intention - anti-clickbait. It basically does three things: remove superfluous words, remove superfluous caps, and properly capitalize the title. Most of the time it works well, but annoying when there's a false-positive. Examples I've seen so far (note that it's not always triggered, there must be some "if" conditions here. It's not always reproducible). * All lower-case titles are capitalized. Generally good, but not always enforced, it's strange. * Unnecessary caps are removed. Many false positives. "MIT CSAIL" becomes "MIT Csail", DARPA becomes "Drapa", etc. * "%d Ways To Do X" and "How To Do X" becomes "Do X", per Guideline. It misfired when I tried to submit "20 °C – A Short History of the Standard Temperature for Dimensional Measurements" by NIST. The "20" was removed and I had to edit it back! A submission of "How we threat model" by GitHub became "We threat model", makes the already-short title unreadable. * Clickbait words are removed. Generally good. But false positives exist. For example, "Massive Parallel" is a legitimate concepts in computing, but the word "massive" will be removed. I just tried "Massive MIMO", which is similarly a legitimate concept in communication, got removed as well. Try submitting this paper "Pilot Optimization and Channel Estimation for Multiuser Massive MIMO Systems" (https://arxiv.org/abs/1402.0045 https://arxiv.org/abs/1402.0045), you'll see that the word "massive" is deleted immediately after submission (but as I said, the reformatter is not always triggered and not always reproducible, perhaps your high karma will stop the filter from doing it). * "Your Statement is 100% correct" becomes "Statement is 100% correct". This is a good one, the unnecessary personal element is removed.
- bassman9000 6y agoAnd we should use Daesh anyway.
- dmurray 6y agoPlenty of style guides [0] recommend lower case or title case for acronyms or initialisms pronounced as words (e.g. Nasa, Opec, scuba, radar in increasing order of how likely you are to actually see them written that way). It's silly to insist that HN follow your preferred style. [0] one example: https://www.theguardian.com/guardian-observer-style-guide-a https://www.theguardian.com/guardian-observer-style-guide-a
- jimbob45 6y agoI thought we agreed on ISIL? ISIS doesn’t make any sense to me since they clearly haven’t succeeded in taking or holding Syria.
- _-___________-_ 6y agoNor the Levant, nor Iraq, and they're not a state, either. The name is clearly aspirational.
- 29athrowaway 6y agoAnd because of that it is also a given name for many people, believe it or not.
- nimbius 6y agoFriendly reminder: the US basically created ISIS through it's hamfisted invasion of Iraq. Cheerleading tbis sort of effort is like congratulating a child when they decide to eat their peas.
- qntmfred 6y agoand I'd still rather they eat the peas than throw them at their brother.
- thefounder 6y agoI believe the issue is not the invasion itself but what they did/didn't do after they "won". It's indeed sad to see no good side/party. Just a mess that brought a lot of misery.
- pazimzadeh 6y agoLet's agree that it's the result of short term thinking
- Yc4win 6y agoNot sure if the article mentions it (haven't read it yet) but JTF-ARES was the force tasked with sabotage and often it was against targets such as the militants video (propaganda) productions. Edit: Really not sure why I got downvoted, as I provided accurate info?
- _-___________-_ 6y agoCan't speak for anyone else but I didn't understand the purpose of your comment; it merely restates one fact from the article, which you didn't bother to read before commenting.
- Yc4win 6y agoIt was just something I remembered that I found interesting when I first learned about it prior to this article.
- canada_dry 6y agoTL;DR: "Fire" (from the first sentence) wasn't shooting something but the beginning of a cyber exercise. Started with a successful phishing email and got lucky because an ISIS operative was re-using the same password in several places. That article was painfully too long.
- 1vuio0pswjnm7 6y agoWhat is the point of using an http:// http:// URL with a website like NPR. These popular sites all redirect to https:// https:// Headers will be sent over the wire in the clear before any redirection can occur. A localhost-bound proxy can fix this before the request leaves network interface. I guess the "modern" browser fixes this for everyone else not using a ("modern") proxy.
- Drip33 6y ago> I guess the "modern" browser fixes this for everyone else not using a ("modern") proxy. Only if the site owner wants it so https://hstspreload.org/ https://hstspreload.org/
- 082349872349872 6y ago> "The United States is the country most highly dependent on these technologies," Deibert said. "And arguably the most vulnerable to these sorts of attacks. I think there should be far more attention devoted to thinking about proper systems of security, to defense." It's all fun and games until someone melts down a reactor. The journalist is probably playing with Cunningham's Law, but I distinctly recall the doomsday gap scene ( https://news.ycombinator.com/item?id=24481298 https://news.ycombinator.com/item?id=24481298 ) as having been closer to the middle of Dr. Strangelove. The end came after the referent of https://www.youtube.com/watch?v=K10pdj5YOy0 https://www.youtube.com/watch?v=K10pdj5YOy0 . Bonus clip (note the lack of any source attribution problem in these cases): https://www.youtube.com/watch?v=nZ8oA9-OQrg https://www.youtube.com/watch?v=nZ8oA9-OQrg
- alexpotato 6y agoFor the audio version of this story from a different source, I highly recommend the Darknet Diaries podcast episode: https://darknetdiaries.com/episode/50/ https://darknetdiaries.com/episode/50/
- jtchang 6y agoIn a way doesn't this just cause the adversary to adopt better operational practices? Persistent access and monitoring would probably be better long term.
- mhh__ 6y agoYou have to make that tradeoff. Think about Enigma and Lorenz, or any cold war double agent - you've got this fountain of knowledge but if you start burning assets left right and centre they'll realize something's wrong (Or in the case of MI6 they'll get embarrassed and allow the double agent to slip away as long as they shut up)
- 082349872349872 6y agoHaving been thinking that cyberwar could be a wonderful thing if it keeps everyone occupied and well away from civilian lives, as long as I was in cloud cuckoo land I figured we (the non-inclusive we, meaning: anyone but me) ought to set up a giant (bits, not atoms, remember?) online honeypot that gets spooks in so deep that they become N-tuple agents (where N is chosen sufficiently large to overflow their mental stacks, allowing us to set them to chasing each other in cyclical patterns) and eventually wind up typing in gibberish in grand operations that, like the coruscating beams of an E.E. "Doc" Smith novel, escalate to grappling with networks of cosmic proportions, but in truth are on the wrong side of an impedance mismatch to affect the real world. Inspired by a low-tech single-ply version: https://en.wikipedia.org/wiki/Operation_Scherhorn https://en.wikipedia.org/wiki/Operation_Scherhorn and Linebarger's suggestion for how to drive enemy intelligence mad: http://www.gutenberg.org/files/48612/48612-h/48612-h.htm#Page_132 http://www.gutenberg.org/files/48612/48612-h/48612-h.htm#Pag... > "If you feel like showing off, average everything into everything else and call it the Gross Index of Total Enemy Morale. This won't fool anyone who knows the propaganda business, and you won't be able to do anything with or about it, but you can hang it on a month-by-month chart in the front office, where visitors can be impressed at getting in on a military secret. (Incidentally, if some smart enemy agent sees it and reports it back, enemy intelligence experts will go mad trying to figure out just how you got that figure. It's like the old joke that the average American is ten-elevenths White, 52% female, and always slightly pregnant.)" TIL CthulhuPunk is a thing. Anyone familiar enough with the Cthulhu-mythos to tell me if there are any impediments in canon to the following retcon: what if Great Old Ones are Scissor Entities, and appear to xenophobes as horrific monsters of vaguely anthropoid outline, with octopus-like heads and prodigious claws, but to xenophiles as animated pegasus unicorns, and, as part of their eternal struggle against the Blue Meanies, drive the former to gibbering madness but invite the latter over for tea? https://i.pinimg.com/originals/e9/a4/fa/e9a4fae35f467f77b98b738d7b4a7569.jpg https://i.pinimg.com/originals/e9/a4/fa/e9a4fae35f467f77b98b...
- boomboomsubban 6y agoSo how long until it comes out that this was all a lie, and really they just flipped one of the server admins?
- Aperocky 6y ago> I mean, I’m just guessing here but here’s an attack I think they probably did; first, imagine if they hacked into the phone of one of these ISIS media people and then on that phone, they stole the private decryption keys for that phone. This would be the key used to decrypt messages to that phone. Then, imagine they hacked into the WiFi network that phone was on and somehow captured all the traffic to that phone. Somewhere in that traffic are the private chat messages to that phone and with these private keys, I’m guessing it’s technically possible to decrypt those messages. This would be a pretty complex hack but I bet it’s something that US Cyber Command could do. Yeah.. probably not how it happened.
- encom 6y agoFor EU people: https://archive.ph/XZ2Dg https://archive.ph/XZ2Dg
- joe_the_user 6y agoIt's kind of odd to think what ISIS' media operations brought it. Initially they seem to have garner a variety of international recruits, I most from a Muslim background but some not. But either way, a lot of their appeal was an absolute nihilistic rejection of "modernity". It seems like the appeal involve a kind of fundamental alienation combined with being a flavor of the month - sort of the appeal of leftism but lacking any sense that things can be improved. I suspect shutting down their media probably stopped having an effect through novelty wearing off, all the best recruits being recruited and the world moving on to (inadvertently or not) selling some other reactionary rebellion - and the group being militarily defeated in Syria.
- 082349872349872 6y agoOne of the lightly ironic points Linebarger (in his textbook, Psychological Warfare) makes is: never trust a psywar person as a reliable narrator, to accurately and straightforwardly report how effective they may have been. Their déformation professionelle is, after all, self-serving sophistry. (I trust Linebarger more than Bernays because the former also catalogues not only his failures, but sotto voce, even touches upon those of his mid-twentieth century society.) Bonus clip: https://www.youtube.com/watch?v=mLNAkPsjAEk https://www.youtube.com/watch?v=mLNAkPsjAEk (what's the hip hop equivalent?)
- segfaultbuserr 6y agoI fully understand that the operation is classified and details cannot be revealed, but I have to say: the description of the technical details is still a bad Hollywood movie [0]... > After that, the momentum started to build. One team would take screenshots to gather intelligence for later; another would lock ISIS videographers out of their own accounts. > "Reset Successful" one screen would say. > "Folder directory deleted," said another. Folder directory??? Did they also delete the "file document"? > The screens they were seeing on the Ops floor on the NSA campus were the same ones someone in Syria might have been looking at in real time, until someone in Syria hit refresh. Once he did that, he would see: 404 error: Destination unreadable. 404 error: Destination unreadable??? At least, use "unreachable"... > "Target 5 is done," someone would yell. > Someone else would walk across the room and cross the number off the big target sheet on the wall. "We're crossing names off the list. We're crossing accounts off the list. We're crossing IPs off the list," said Neil. And every time a number went down they would yell one word: "Jackpot!" [0] TV Tropes: Hollywood Hacking is when some sort of convoluted metaphor is used not only to describe hacking, but actually to put it into practice. Characters will come up with rubbish like, "Extinguish the firewall!" and "I'll use the Millennium Bug to launch an Overclocking Attack on the whole Internet!" https://tvtropes.org/pmwiki/pmwiki.php/Main/HollywoodHacking https://tvtropes.org/pmwiki/pmwiki.php/Main/HollywoodHacking
- giancarlostoro 6y agoIt is very possible they are using utilities to pull this off developed by someone else. They may have training for the utilities they have but that doesnt make them IT experts.
- the_af 6y agoAgreed. The whole article reads like a mix of Hollywood Hacking and a puff piece. Very likely something happened, but it almost certainly wasn't like this.
- acqq 6y agoThe article is different from what was aired, which appears to me to be more interesting, as it starts with: "On August 24, 2015, a 21-year-old British hacker named TriCk stepped out of an Internet cafe in Raqqa, Syria, and climbed into his car. He didn't know it, but he'd been under surveillance for days. He pulled into a gas station, and just as he started filling the tank, a single Hellfire missile came down on him like a meteor from the sky. He was killed instantly." And it seems to be longer too. https://www.npr.org/transcripts/763545811 https://www.npr.org/transcripts/763545811 They also later identify the "British hacker's" name: Junaid Hussain. A report from Britain, 2015, claims it wasn't an operation done by the U.S. alone: https://www.birminghammail.co.uk/news/midlands-news/isis-terrorist-junaid-hussain-killed-10069425 https://www.birminghammail.co.uk/news/midlands-news/isis-ter...
- septillianator 6y ago>Six years ago, it rather famously discovered that China had been hacking into the Dalai Lama's computer networks why does china care so much about the dalai lama?
- AnimalMuppet 6y agoBecause people in Tibet recognize him as a non-Beijing authority.
- acqq 6y ago> why does china care so much about the dalai lama? I'd guess because: https://en.wikipedia.org/wiki/CIA_Tibetan_program https://en.wikipedia.org/wiki/CIA_Tibetan_program "a nearly two decades long anti-Chinese covert operation focused on Tibet which consisted of "political action, propaganda, paramilitary and intelligence operations"" "Although it was formally assigned to the CIA, it was nevertheless closely coordinated with several other U.S. government agencies such as the Department of State and the Department of Defense." Dalai Lama is where he is now as the result of this.
- _kbh_ 6y agoHeres an account from the view of one of the allies involved in the same operation. https://www.abc.net.au/news/2019-12-18/inside-the-islamic-state-hack-that-crippled-the-terror-group/11792958?nw=0 https://www.abc.net.au/news/2019-12-18/inside-the-islamic-st...
- 082349872349872 6y agoUp until today, I had thought of the (obviously shopped) https://demotivation.me/images/20140405/rhq85mwjl9qh.jpg https://demotivation.me/images/20140405/rhq85mwjl9qh.jpg as inaccurate because while it seems plausible for spooks to do such things, they don't wear fatigues. (compare ops room hero photo above: is the fatigue-wearer a seppo liaison?)
- _kbh_ 6y agoAfter playing with the contrast on the image a bit it doesn't look like any American camouflage that I know, it is most likely the Australian Mulitcam (https://en.wikipedia.org/wiki/Australian_Multicam_Camouflage_Uniform https://en.wikipedia.org/wiki/Australian_Multicam_Camouflage...). https://imgur.com/y1vCFSe https://imgur.com/y1vCFSe
- acqq 6y agoThe original picture, showing the U.S. soldiers in front of the computers in the 2010 Wired article about the NSA and the Department of Homeland Security: "Doc of the Day: NSA, DHS Trade Players for Net Defense" https://www.wired.com/2010/10/doc-of-the-day-nsa-dhs-trade-players-for-net-defense/ https://www.wired.com/2010/10/doc-of-the-day-nsa-dhs-trade-p... The fatigues are common in the pictures: https://www.cyberscoop.com/us-cyber-command-nsa-government-hacking-operations-fight/ https://www.cyberscoop.com/us-cyber-command-nsa-government-h...
- 082349872349872 6y agoThanks for the op. I had been guessing (from the steering wheel) that it was a joint force LAN party, but now that I'm no longer distracted by cyrillic, I'm wondering about the yellow left-hand keycaps? > "But there are U.S. intelligence officials who still worry about what Cyber Command’s rise will mean for espionage missions." suggests another domestic explanation for revealing Glowing Symphony would be turf wars with non-concurring bureaucracies. (Apparently successfully, judging by 2020 changes to us code buried somewhere in the appropriations bill S.1790 § 1632. Poorer US HN'ers may be interested to know there's also language in that bill about cyber pay rates, which I left unread but would guess implies they're attempting to be competitive with private sector compensation.)
- kursus 6y ago> He asked us to use only his first name to protect his identity There was 80 persons inside one of the most powerful room of the world so they just use his first name to protect his identity.
- Stierlitz 6y agoReally Hackernews, do you have to repost this neocon BS on a respectable technology forum. https://theintercept.com/2018/01/29/isis-iraq-war-islamic-state-blowback/ https://theintercept.com/2018/01/29/isis-iraq-war-islamic-st...
- mrpickels 6y agoUS hacked ISIS because US made ISIS
- Lotuseater 6y agoDarknet diaries covered this story in a podcast ages ago. NPR is just recycling the content. Full episode here for those interested: https://darknetdiaries.com/episode/50/ https://darknetdiaries.com/episode/50/