10 ms·
NSA director finally greets Defcon hackers
- mettle 14y agoI saw the talk. Much of the talk made the assumption that the hacker community has the same goals and values of the NSA. This NEEDS to be justified. This is a hacker community and while not a single minded collective I believe there are many popular views that are diametrically opposed to some of the goals of the NSA. He mentioned that he wished the internet would be perfectly secure and then went on to mention how this would protect American IP laws. His definition of secure internet does not include values such as censorship resistance or freedom of expression/information. He also tried to tell everything how great it would be if we all had IDS's that reported back to the NSA in realtime. We were not allowed to ask questions. They brought up a paper with questions that must have been determined BEFORE the talk happened which isn't fair to the attendees. I wish there was a DEFCON panel to discuss this. Everyone just clapped and seemed cool with him from my perspective. I'm not against the director talking at DEFCON, but I don't think we shouldn't be accepting his ideas without more public criticism and discourse.
- tcoppi 14y agoThe questions weren't scripted, at least some of them weren't. DT was checking his twitter and I saw at least dave aitel's one about Cyber Command growth/size on there.
- ipsin 14y agoEven if they weren't scripted, they were mostly softballs, and the talk was more an introduction than a detailed roadmap. The most interesting question was about whether the NSA would prefer a perfectly secure internet or a usefully insecure one (roughly paraphrased). That's not far from what I wanted to ask: given the offensive value of 0-day exploits (as seen with Stuxnet, regardless of who actually did it), can agencies in "Cyber Command" really be trusted to give theirs up via responsible disclosure?
- lawnchair_larry 14y agoYour definition of "responsible" is not the same as everyone else. Try asking an actual question, not a question disguised to inject a moral judgment and re-ignite the disclosure debate that everyone was sick of 20 years ago.
- ipsin 14y agoLate to the party, but... you really couldn't find a question in there? Let me try again. My definition of "responsible" doesn't matter. I was suggesting that the government could adopt a policy it considers responsible, rather than just sitting on the exploits and using them for strategic advantage. Unless there's a definition of "disclosure" that involves failing to disclose things to those in a position to fix the problems.
- mindcrime 14y agoIMO, when the director of the NSA goes on-stage at DEFCON and the result is anything other than tomatoes being thrown and him being booed off the stage, something is wrong. While it is true that hackers are not a single minded collective, and some hackers may have sympathy for the NSA, I'd hope that most hackers would see the NSA as what it is: just one more head of the Medusa that is the US government, in all it's civil liberty infringing, experimenting on it's own citizens program, illegal wiretapping, constitution ignoring glory. The NSA are not - so far as I'm concerned - the "good guys." Some individuals in the NSA may be "good guys" but the agency is just a tool of a government that is out of control. "We don't keep files on every American citizen" Yeah, right... this guy would have had more credibility if he'd just said "Yeah, of course we do. You know it, we know it, so why beat around the bush."
- sliverstorm 14y agoI'd hope that most hackers would see the NSA as what it is: just one more head of the Medusa that is the US government, in all it's civil liberty infringing, experimenting on it's own citizens program, illegal wiretapping, constitution ignoring glory. The NSA does some questionable stuff, but it also does some awesome stuff. The first thing that comes to mind is SELinux. On a tangent, don't forget that we need an organization like the NSA (or at least like what the NSA should be). The more ubiquitous computing becomes, the more important that role will become. So, don't advocate chopping off a head of the Medusa; advocate fixing what you see as wrong.
- derrida 14y agoWe need it? Who is 'we'? The government? To what degree is that need necessary, and not merely contingent?
- rdl 14y agoWe absolutely need defense for government IT. That should still be smaller than what the government devotes to that task now, but at the NSA level, I get the feeling that most dollars and head count is not going to defense. I think it is a legitimate question how much of an offensive information warfare standing capability a country needs when not at war, and what level of dirty tricks intelligence agencies should pull in peacetime to monitor adversaries. Particularly due to the non financial costs of this monitoring -- losing our moral standing as a free and fair country, incidentally monitoring citizens or those present in the USA, in violation of the constitution (especially due to the tortured "five eyes" sharing agreements, which, if they weren't governments, would be viewed as a conspiracy and some kind of constructive crime), etc. I judge all of this stuff by "does it make us safer", and at some point, it clearly goes the other way. I think that point is several hundred billion dollars a year less spending than what we have now (well in excess of a trillion). Maybe 50-75% less spending.
- derrida 14y ago"We don't keep files on every American citizen": depends how you define 'files' and perhaps there is 1 American citizen they don't keep files on, so not 'every'. But we have on sworn testimony that the NSA keeps all of your emails [1] & a large chunk of your electronic communications & spies on American citizens[2][3]. [1] https://www.eff.org/files/filenode/att/section1006summary101608.pdf https://www.eff.org/files/filenode/att/section1006summary101... See in particular ex-NSA officer William Binney's testimony. [2] https://www.eff.org/node/55051 https://www.eff.org/node/55051 [3] https://www.eff.org/deeplinks/2012/03/nsa-chief-denies-ability-warrantlessly-wiretap-despite-evidence https://www.eff.org/deeplinks/2012/03/nsa-chief-denies-abili...
- Joakal 14y agoThere's also the aspect about law, allowing warrantless wiretapping of anyone, or, everyone[1]. [1] http://www.washingtonpost.com/world/national-security/us-intelligence-collection-initiative-violated-rights-at-least-once-government-says/2012/07/20/gJQAtJjFzW_story.html http://www.washingtonpost.com/world/national-security/us-int...
- rhizome 14y agoHe not only said files, but also "dossiers," which is even more formal. Nothing about having huge buckets of already-collected data from which these files and dossiers can be compiled later.
- runjake 14y agoThere's a lot of angry comments, but this is a step in the right direction for the NSA. Hayden would've never showed. He had a disdain for hacker types and so-called privacy advocates.
- mcantelon 14y agoIt's pragmatic to bring one's propaganda to every available avenue and to try to coopt movements with anti-authoritarian roots.
- learc83 14y agoI can't believe the director of the NSA (also an Army General) showed up in bluejeans and a t-shirt. I'm sure it was a PR move, but I still can't believe it.
- eliasmacpherson 14y agoprobably a recruitment drive for the interception center they are building. That 260 million people statement is pretty stupid, considering facebook is in and around 4 times that. How stupid does he think people are? http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/ http://www.wired.com/threatlevel/2012/03/ff_nsadatacenter/
- nikcub 14y agoNot just for the interception center, but they are recruiting the best pen testers and vulnerability writers since they run the main offensive arm for the US Government. Stuxnet was written at the NSA, the other worms were almost certainly were partially written there. The MD5 signature collision attack was almost certainly developed there. You could imagine that they now have dozens, if not hundreds of developers working on finding 0day and integrating new exploits into their attack arsenal of worms. I suddenly have a handful of friends form the old underground who went from working openly in the security industry on papers, audits etc. to no longer talking about who they work for. I can only put two and two together and conclude that the NSA has been on a hiring binge the past few years and are hiring all the best security guys (exploit developers, more specifically).
- hobin 14y agoI do. You don't show up in a suit at DEF CON, you just don't.
- Joakal 14y agoThere's more said here: http://www.abc.net.au/news/2012-07-28/hackers-asked-to-help-us-secure-internet/4160966 http://www.abc.net.au/news/2012-07-28/hackers-asked-to-help-... "He held firm that the internet defences could be ramped up without sacrificing privacy or civil liberties." However, he seems to be a staunch pro-IP advocate with this statement: "Look at all the intellectual property we've lost over the past decade," He should be asked how does one prevent an idea from being easily copied. Because, that's the fundamental problem behind criminalising altruistic IP infringements. Personally; my hunch is that congress has no idea how to tackle widespread piracy, even NSA doesn't. There's also many 'cyber' companies that are complaining about security issues (Decentralised/Centralised attackers such as Anon/Wikileaks). So, NSA is requested to get into those. One step is a careful PR spokesperson to recruit (Notably, the clothes and charm). Also, to instil uncertainty and doubt among hackers.
- deleted 14y ago[deleted]
- jauer 14y agoIf you watch some of his earlier speeches it is pretty clear that "intellectual property loss" is code for "chinese industrial espionage". This guy doesn't care about your game of thrones torrents.
- rdl 14y agoIt was the most condescending speech I've ever witnessed given to adults. It certainly didn't raise my opinion of the NSA. Once you see the video, you will agree.
- ipsin 14y agoIt did seem half-aimed at children. Especially after the corny opening to introduce one of the Defcon Kids ("help grandpa find his arrow keys", or whatever he was going for). Right. Defcon Kids. An actual con within DEFCON sponsored by the NSA and AT&T, among others. That alone is the creepiest thing I've seen all week, enough so that the first time I saw the posters I was absolutely sure they were some kind of vicious parody.
- comex 14y agoI think Defcon Kids is awesome - hacking is a very fun skill which, like programming in general, interested kids should be encouraged to learn. That said, don't be dishonest. The media should not be calling someone who discovered they could make time-based events in games happen by changing the time a "hacking prodigy"[1], and the website of a hacking con, whose others should know better, should not be saying it "allow[s] for exploit code to run on servers"[2]. It devalues the real thing :) [1] http://www.darkreading.com/blog/231300589/tween-hacker-s-time-travel-trick.html http://www.darkreading.com/blog/231300589/tween-hacker-s-tim... [2] http://www.defconkids.org/?page_id=505 http://www.defconkids.org/?page_id=505
- bashzor 14y agoOnly, what has this 10 year old to do with it?
- chickenhead 14y agoQue crazy libertarian mantras in 3... 2... 1...
- sp332 14y agoFabio Pietrosanti pointed out on twitter https://twitter.com/fpietrosanti/status/229113274698981376 https://twitter.com/fpietrosanti/status/229113274698981376 "My view from Italy (without ever crossing US border): DEFCON: NSA is a friendly agency to work for HOPE: NSA is a unfriendly agency to fight". There was a NSA whistleblower at HOPE Number Nine barely 2 weeks ago, William Binney. He detailed some of the abuses there. http://www.hopenumbernine.net/speakers/#binney http://www.hopenumbernine.net/speakers/#binney You can listen to his talk here http://www.hopenumbernine.net/schedule/#binney http://www.hopenumbernine.net/schedule/#binney