Unsolved

Showing posts with label NSA hack. Show all posts
Showing posts with label NSA hack. Show all posts

Monday, August 22, 2016

Hacking the NSA is so easy a child could do it...from the inside.

NSA hack an inside Job
data-encryption-thecrimeshop

or is the Russian Government using hackers to breach everything

A newly published article today accuses Russian hackers of breaching the Olympic drug testing agency…
Many assumed that Russia was behind the hack of the DNC.
Headlines last Friday suggest that Russia has hacked The Donald’s campaign.
Everyone assumes that Russia is behind the hack of the NSA and Edward Snowden has reportedly issued a statement that indicates Russia was most likely responsible for the hack at the NSA.
What the hell haven’t they hacked? Wait, they have not hacked Starbuck’s making it so that I have a lifetime supply of coffee.
It could have been Russia who by the way denies any involvement in these hacks.
What was the loot in the NSA hack?
Well as it so happens the hack exposed cyber-weapons intel. That intel reveals just how the NSA hacks suspects and enemies and further details a tracking code that just so happens to reveal the fingerprints of the NSA's malicious software.
So we really have to wonder what Russia might have to gain if they are truly behind the hack of the NSA? I mean the DNC might have been a just for fun type of thing if Russia was behind it, but what about the NSA? Does Russia feel the NSA had at one time infiltrated them and downloaded some type of malicious software?
To fully understand that, you need to get to know The Equation Group and TAO, two branches of the NSA.
Kaspersky labs describes The Equation Group as “one of the most sophisticated cyber attack groups in the world.” The Equation Group according to Kaspersky labs has operated alongside Stuxnet and Flame.
TAO identifies, monitors and has a nasty little habit of infiltrating and gathering intelligence on computer systems used by foreign entities to the US.
Anyone who has seen the Stuxnet documentary knows that it is widely believed that Stuxnet was created jointly by the US and Israel.
Which makes total sense because Israel is reportedly 15 years ahead of everyone else in terms of Cyber-Defense and Security.
Russia however, was one of the named 42 countries that the Equation Group infiltrated over the course of its 14 year project creating backdoors to foreign Government networks.
Not only did the Equation Group create backdoors, they also seemed to enjoy intercepting hardware from IT companies, globally.
It’s also worth mentioning that the Equation Group has a pretty good reputation for using strong ENCRYPTION methods. They just can’t seem to figure out a way around encryption when folks like Apple create it for consumers to use.
So who kicked in the door at the NSA?
A group called Shadow Brokers took the credit for hacking the NSA. Things got a little crazy when they came out because they boasted rather audaciously and offered to auction off the goods for $576 Bitcoins.
Bidders backed way off and the general consensus has been that those responsible for the breach were not just some run of the mill hackers but a foreign Government, hiding behind the idea the breach was caused by a group of nobody hackers.
From that, another theory sparked a lot of interest and that was, that someone inside of the NSA was in fact responsible for the leaked intel.
Out of all of the theories, this is actually what more than likely happened.
The NSA stores sensitive information on air-gapped networks, which are networks that are not connected to the internet, i.e. the outside world. They also have other security measures, not to mention despite being a pain in the ass to crack, it’s still doable.  
They can be cracked through the use of undetected malware, cell phones, as Edward Snowden proved a flash drive, even a sim card can do the trick.
The point is, it’s pretty clear that the responsible party is within the ranks at the NSA.  
snowden-thecrimeshop
Now, I am not saying that I am convinced that Edward Snowden had anything to do with it however…
A strange sequence of events happened shortly before the breach.
On 8/5, Edward Snowden reached out through Twitter, with an odd message to those that knew him or who ever worked with him asking them to contact him followed by 64 characters of code. That message lead many to believe that Edward had been captured or killed and failed to do a check-in prompting his account to send out a dead man’s switch. His account went silent after the odd tweets.
Shortly after that, at least 8 torrent sites had been taken down or slowed. The sites are well known to distribute large files.
News of  the hack and leak at the NSA broke on 8/15
Edward Snowden began tweeting again on 8/15
Edward Snowden seems to think that the Russian Government is behind some of these hacks and has said as much through the media....initially it was almost as if he was handing out the idea like we hand out candy at Halloween.
And I, don’t believe in coincidence.  
I also don’t believe that the Russian Government was behind the hacks. It’s too neatly wrapped with the bow neatly tied on top.
Blaming the Russian Government seems too easy, too perfect and too convenient.
The hack came from the inside and the NSA just got owned again.
Cristal M Clark



Tuesday, August 16, 2016

US Government start using encryption

US Government to change mind on encryption
data-encryption-thecrimeshop
Well at the very least, they should.  
Ahhh the hacking over at the DNC, the hacking of the NSA linked spies, the IRS, the US military last year...it amazes me that our own government has not warmed to the idea of encryption.
One of the most appealing reasons consumers love encryption is because we feel safer having it.
In today’s world we have moved to a more technological way of living.
We shop online, pay for things with watches or phones, start cars with both, we can turn the air on or off in our homes from a phone, I can order Starbucks and pay for it all day long and go get it without having to say two words to anyone, we can even check our refrigerators from our phones.  
We can can monitor how well we brush our teeth or not, from a phone app, check our health, heart rate, eating habit, calorie intake, workout routine, or get a new routine, yoga instructions and start a pot of coffee all from a phone, watch or tablet, if not all three.
The way we communicate with one another is also a lot less verbal than it was 10 years ago and why pay for a stamp or actually talk on the phone when it’s just as easy to send a quick text or email, or chat on Facebook or Whats App?
While we are at all of this, we choose encrypted devices and services so as to better protect ourselves from hackers. We lock our cars, our homes, we keep our money in banks instead of under a mattress and we do that why?  
To keep it all safe from thieves of course. And that is how we view our messages, our data, our emails, our ability to shop online, to pay for things with our devices instead of a plastic card or paper and coin currency.
We have James Comey who still seeks a backdoor to encrypted devices and services when it’s warranted but we also see a telling reality that our government simply lacks the ability to be trusted should they ever be granted these backdoors. jc say what
For the sake of argument if a government can’t bother to encrypt it’s own devices and data, any backdoor they were given, well that would be gone and into the hands of hackers at some point.
Last August FBI Director James Comey testified before Congress and said that that terror groups are in fact, using encrypted programs to hide their communications from prying eyes and that they are aggressively targeting young Americans online and they are succeeding.
So that really even last year wasn’t new news. If you ever ventured onto the dark web into the right places, you sort of already knew that.
So instead of look at the actual real underlying issues as to why any young American would want to join a terror group like ISIS, we want to tout that encryption is bad. It’s evil and so so bad and it allows these bad guys to communicate...secretly.
That means, our government fears it. Rather than try to learn it much less outsmart it, they want to instill this fear. Yet I look around me and I see the guys at organizations like Apple, Whats App, Facebook, as well as many others working with encryption daily, making it smarter, easier for me to work with, understand and use. 
And I along with many others trust it. 
Ahh but here is the catch, these organizations make encryption user friendly to a consumer, instead of something to be feared. They are giving me exactly what I want and they have a great track record so I trust it.
So personally, I tend to feel that our government needs to come forward a few decades in terms of really understanding encryption, society and how we use things like, technology. 
Some within our Government think that encryption puts us all at risk. I beg to differ, it’s our government’s lack of knowledge that does, not encryption.
Should companies like Apple, work with any government entity when faced with an issue like opening an iPhone for let’s say a person who committed an act of terror?
I vote for yes but only to an extent. They should help them open a device or message only if certain extreme conditions have occurred such as an act of terror.
Should they create backdoors and hand them to the FBI? Not at this point because our own government can’t be trusted with it and simply does not have the ability to secure it.
If a backdoor is needed to get into anything, its much safer at the company that created it and not ever in the hands of anyone at our government. 
If our government creates a backdoor at some point (highly doubtful, very highly doubtful) fine. 
The biggest issue however, is that our own government lacks the knowledge to deal with encryption, they can’t use it, don’t understand it and are reacting more out of fear than with knowledge.
snowden-thecrimeshop
According to Edward Snowden the recent hack of the NSA could be a warning from Moscow. By the way it's good to see Edward back and tweeting again. 
If what he says is true, our government truly doesn't have what it takes to defend us when it comes to the cyber world. 
As far as I can tell the issues and problems are not encryption, not in the least.
It’s the criminals and more importantly, that our government has been caught with it’s pants down over things like emails where what was said in them should have never been sent in an email if you didn’t want to get caught in the first place.
Emails that should have never been on a server that could be hacked, messages that should have been on an encrypted device, maybe?
If the most recent hacks have not opened our government's eyes from the slumber of ignorance they have been in, I am not sure what will. 
I really think that our government needs to start being part of the solution instead of the problem since hackers keep catching them with their pants down. 
Cristal M Clark
IOS users can find The Crime Shop onApple News
@thecrimeshop