6 ms·
Hector Monsegur has commented on the files & their relevance: http://www.joshwieder.net/2015/07/hector-monsegur-formerly-sabu-of.html http://www.joshwieder.net/
by joshwieder 11y ago
Hector Monsegur has commented on the files & their relevance: http://www.joshwieder.net/2015/07/hector-monsegur-formerly-sabu-of.html http://www.joshwieder.net/2015/07/hector-monsegur-formerly-s...
- themeek 11y agoIt's an interesting problem: * If Wikileaks edits the content it can be criticized for tampering. * If Wikileaks leaves malware in it can be criticized for circulating malware. It may also give an excuse to search engines and other partners of the government to block the site on account of it hosting files that are infected. A pretty nasty no-win situation. Also think about what this means for the sources of the documents. It means that the surveillance and intelligence information from these firms was likely compromised. Yikes.
- EthanHeilman 11y agowikileaks could flag infected content and force people to click a "I know what I'm doing" button to download or view.
- mikeash 11y agoWhat's wrong with providing one dump without malware, and a second dump of just the infected files, which when put together gives you the whole thing? That way you have full disclosure, the people who want the infected files can easily get it, and the people who don't want it can easily avoid it.
- themeek 11y agoI really like this solution. Critics might be able to say that Wikileaks BOTH hosts malware AND tampers with evidence - but if Wikileaks has a voice to respond it has a pretty good reply. Filters and services sometimes block entire domains because one page hosts malware. So it might be that the excuse could still be used to block Wikileaks if they did host both - but again agreed that hosting both is pretty good. It does increase the work staff at Wikileaks must do and the amount of data they have to host/manage. But yeah overall if this becomes a problem for them doing both seems like a pretty good solution. Nice!
- fineman 11y agoPractice safe computing instead of expecting others to do it for you. What malware 'is" can even be a difficult question. Is a RAT malware, or a way to log people snooping on your computer? Also, new malware is discovered. So it'd have to be a curated collection.
- themeek 11y agoUnfortunately it is more difficult than this. Even if you practice safe computing it's likely that your information will be compromised - especially in the long term and especially if you are an organization. That's not to say this practice isn't important. It's just that it's not enough. We need both of these things (and more). The state of computer security is fundamentally asymmetric.
- fineman 11y agoIn the case the pre-screener is honest, having them pre-check the work only saves you downloading a few virus executables at the cost of some work. If the case the pre-screener isn't honest, it's saved you nothing at all and cost you a lot because you're likely to be less cautious. Do you remember the tagline (roughly) "Outgoing email scanned and verified by AVG"? That was 100% worthless and actually very counterproductive. Expecting someone to check leaks like that is just as bad. Scan everything. You've got the same technology they do.
- mikeash 11y agoYou're correct but this is not an argument against screening on the distribution end. Not everybody will do this and if you can protect them from problems due to their own lack of screening then you should. Just because you can avoid problems on one end if you do everything right doesn't mean you shouldn't also try to avoid problems on the other end.
- fineman 11y agoThis very specifically is an argument against scanning on the distribution end. A false sense of security hurts more than deleting STONED.EXE (and likewise, all other malware caught by signature) helps. Point to a modern virus scanner and also list what you've found in the archive. That gives a good baseline for people to check against without promising to have made anything safe to touch without scanning.
- CONTRARlAN 11y ago> A pretty nasty no-win situation. It's a pretty easy win-win situation–offer both, inform users appropriately. And then provide a third set: a list of the sanitized files not present in the virus-free dump. I think a quick spot check through those would show whether any editorializing was going on. I have serious concerns about their publishing the private emails of employees of a private company that, from all I can gather, turned out to be pretty non-evil. But the virus issues, while not Stratfor's or Wikileaks's direct fault, could have been mitigated by Wikileaks pretty easily. (Disclosure: I've subscribed to them for many years, but have no interest beyond that.)
- themeek 11y agoThe emails from SONY had some controversial stuff in them. For example here is an interaction between the CEO and the State Department about setting up a group of media executives to develop US propaganda for the Middle East and Russia: https://wikileaks.org/sony/emails/emailid/117082 https://wikileaks.org/sony/emails/emailid/117082 Of course it was also revealed that The Interview was a propaganda product aimed at destabilizing North Korea (in anticipation of the upcoming planned unification). These sorts of things can only be found when there's wide access given to journalists. It's also true that the emails were available via torrent and hosted other places online. To play the other side, 99% of the SONY leaks were innocuous. While it is a company with management that works, like most US international corporations, with the US government on 'shady things', it is also in large part also a private company with the usual mundane concerns of a corporation.
- CONTRARlAN 11y agoSorry, I was just talking about Stratfor. > Of course it was also revealed that The Interview was a propaganda product aimed at destabilizing North Korea (in anticipation of the upcoming planned unification). I missed all that–can you point me in the right direction? > These sorts of things can only be found when there's wide access given to journalists. Sure, but there's an argument to be made that the only way to end domestic violence is to place cameras inside all homes. Obviously that tradeoff is one most people aren't willing to make, and I don't think that leaking the private emails of employees of a private company is ultimately morally defensible. Whistleblowing is one (very important) thing–bulk dumps of 99% of innocuous stuff became there's 1% of stuff in there that isn't great (but probably isn't all that bad, in the grand scheme of things) is both tactically questionable–leaking something with a 1:99 S/N ratio is a terrible way to get your message across–it's also morally suspect. If Wikileaks & Co. truly wanted to change the world (and it wasn't about garnering attention and giving indiscriminate anger an outlet), they'd be approaching things differently.