Stories
Slash Boxes
Comments

SoylentNews is people

posted by CoolHand on Saturday April 25 2015, @08:49PM   Printer-friendly
from the quantum-homework dept.

Bruce Schneier has written about The Further Democratization of QUANTUM, the NSA's program for packet injection:

...when I was working with the Guardian on the Snowden documents, the one top-secret program the NSA desperately did not want us to expose was QUANTUM. This is the NSA's program for what is called packet injection­ -- basically, a technology that allows the agency to hack into computers. Turns out, though, that the NSA was not alone in its use of this technology. The Chinese government uses packet injection to attack computers. The cyberweapons manufacturer Hacking Team sells packet injection technology to any government willing to pay for it. Criminals use it. And there are hacker tools that give the capability to individuals as well. All of these existed before I wrote about QUANTUM. By using its knowledge to attack others rather than to build up the Internet's defenses, the NSA has worked to ensure that anyone can use packet injection to hack into computers.

And now it's become a homework assignment:

Michalis Polychronakis at Stony Book has assigned building QUANTUM as a homework assignment. It's basically sniff, regexp match, swap sip/sport/dip/dport/syn/ack, set ack and push flags, and add the payload to create the malicious reply. Shouldn't take more than a few hours.

The assignment is due May 1st.

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 0) by Anonymous Coward on Saturday April 25 2015, @10:23PM

    by Anonymous Coward on Saturday April 25 2015, @10:23PM (#175182)

    I don't know why it all gets dumped on the NSA's feet. He says the Chinese have been doing it. Why didn't they build up the Internet defenses? Or why didn't Hacking Team build it up either? Or why didn't all the other countries using this form of attack not build up the Internet defenses to save us all? There are hacker tools available. Why not blame Kaspersky and others for not protecting us? What a load of shit.

  • (Score: 3, Informative) by CRCulver on Saturday April 25 2015, @10:44PM

    by CRCulver (4390) on Saturday April 25 2015, @10:44PM (#175185) Homepage
    The reason the NSA gets blamed is because its mandate requires it to both gather intelligence through exploits and strengthen the security of network technologies for the benefit of the broader public. (Though as Bruce Schneier and others have pointed out, this is a schizophrenic mandate for a single organization.) Neither the Chinese government nor Hacking Team are answerable to the American public as the NSA theoretically is, so what's the point in blaming them?
  • (Score: 3, Interesting) by Anonymous Coward on Saturday April 25 2015, @11:45PM

    by Anonymous Coward on Saturday April 25 2015, @11:45PM (#175198)

    The first time I heard (and used) packet injection was in the '90s. Up until 2006 the NSA did actively try to help secure things. Then they went silent and stopped updating some of the best hardening guides available at the time. Now we have this. I don't even have a speculative idea why, but something happened in 2005 or 2006 that changed US citizens and organizations from something worth protecting to the enemy that needs to be attacked.

    • (Score: 3, Informative) by Fauxlosopher on Sunday April 26 2015, @02:21PM

      by Fauxlosopher (4804) on Sunday April 26 2015, @02:21PM (#175344) Journal

      Up until 2006 the NSA did actively try to help secure things

      Sorry, no sale. Between beasties like Echelon (1971) and Carnivore (1997), it's been obvious for a good long while now that fedgov spy agencies have not been the friend of the little US citizen.

      • (Score: 2) by isostatic on Sunday April 26 2015, @02:39PM

        by isostatic (365) on Sunday April 26 2015, @02:39PM (#175350) Journal

        The American presidnet kills far more people than all the Mafia bosses combined, so the difference in outrage is clear, and not in the way you describe.

  • (Score: 2) by maxwell demon on Sunday April 26 2015, @07:31AM

    by maxwell demon (1608) on Sunday April 26 2015, @07:31AM (#175296) Journal

    Imagine two findings:

    Finding 1: A Mafia boss shot someone.
    Finding 2: The American president shot someone.

    Which one would you think give the greater outrage? Can you tell why?

    --
    The Tao of math: The numbers you can count are not the real numbers.
    • (Score: 4, Insightful) by arslan on Monday April 27 2015, @02:34AM

      by arslan (3462) on Monday April 27 2015, @02:34AM (#175557)

      I'd say Finding 3: The American president had an affair. The reason would be it makes entertaining news and there's no collateral damage.

      As a non-American, I find it very interesting that of all the things a President can be sacked, having an affair was the one that actually got realized.

      I suppose the only factions involved in Bill's affair were his private parts and Monica's, and tangentially Hillary's pride. So the witch hunt was easily executed. On the other hand any other shady work done in running the country would not be so easy given there are typically all sorts of factions involved that stand to bear losses as collateral damage, so its better to sweep everything under the carpet or hide it in some entertaining dog and pony show.