Congress Investigating secrecy arround security flaw

News that do not fit in elswhere

Moderators: b1o, jkerr82508

User avatar
viking60
Über-Berserk
Posts: 9351
Joined: 14 Mar 2010, 16:34

Congress Investigating secrecy arround security flaw

Postby viking60 » 28 Jan 2018, 02:05

The US Congress wants to know why the Tech companies knew about the Intel CPU flaws since June 2017 and kept it secret until January 2018.

The U.S. House Energy and Commerce Committee sent letters to Apple, Amazon, AMD, Arm, Google, Intel and Microsoft asking why they agreed to keep details of the Meltdown and Spectre vulnerabilities secret.


Intel is dancing for joy and "welcomes the opportunity" to continue their dialogue with Congress. :liar:

Either they are lying - because it is obvious that nobody looks forward to something like that..or they have a really good reason for this monumental failure...like being instructed by government agencies to leave some back-doors open.

It is clear that they have expressed their wishes to that affect before.
OutlawCountry
30 June, 2017
Today, June 30th 2017, WikiLeaks publishes documents from the OutlawCountry project of the CIA that targets computers running the Linux operating system. OutlawCountry allows for the redirection of all outbound network traffic on the target computer to CIA controlled machines for ex- and infiltration purposes. The malware consists of a kernel module that creates a hidden netfilter table on a Linux target; with knowledge of the table name, an operator can create rules that take precedence over existing netfilter/iptables rules and are concealed from an user or even system administrator.

The installation and persistence method of the malware is not described in detail in the document; an operator will have to rely on the available CIA exploits and backdoors to inject the kernel module into a target operating system. OutlawCountry v1.0 contains one kernel module for 64-bit CentOS/RHEL 6.x; this module will only work with default kernels. Also, OutlawCountry v1.0 only supports adding covert DNAT rules to the PREROUTING chain.

So maybe they forgot to inform Congress. :confused

According to Wikileaks the agencies are not content with the "voluntary sharing" and created the ExpressLane project:
B But this 'voluntary sharing' obviously does not work or is considered insufficient by the CIA, because ExpressLane is a covert information collection tool that is used by the CIA to secretly exfiltrate data collections from such systems provided to liaison services.

ExpressLane is installed and run with the cover of upgrading the biometric software by OTS agents that visit the liaison sites. Liaison officers overseeing this procedure will remain unsuspicious, as the data exfiltration disguises behind a Windows installation splash screen..


Pure speculation - of course as it is if your Passwords have already been stolen - since there is no way of knowing.

More here
Manjaro 64bit on the main box -Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz and nVidia Corporation GT200b [GeForce GTX 275] (rev a1. + Centos on the server - Arch on the laptop.
"There are no stupid questions - Only stupid answers!"

User avatar
R_Head
Berserk
Posts: 2818
Joined: 17 Mar 2010, 15:40

Re: Congress Investigating secrecy arround security flaw

Postby R_Head » 29 Jan 2018, 02:04

Another Circus... they know, so why pretend they have no clue. The backdoor is there because they were told to do so. :twisted:

I wonder what Internet Port is used... :think:

User avatar
viking60
Über-Berserk
Posts: 9351
Joined: 14 Mar 2010, 16:34

Re: Congress Investigating secrecy arround security flaw

Postby viking60 » 29 Jan 2018, 02:17

I don't know.
The CPU flaw is un-traceable. All your info may be stolen and there is no way of knowing it.
Manjaro 64bit on the main box -Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz and nVidia Corporation GT200b [GeForce GTX 275] (rev a1. + Centos on the server - Arch on the laptop.
"There are no stupid questions - Only stupid answers!"

User avatar
R_Head
Berserk
Posts: 2818
Joined: 17 Mar 2010, 15:40

Re: Congress Investigating secrecy arround security flaw

Postby R_Head » 29 Jan 2018, 20:32

FEBRUARY 17, 2011 | 11:31 AM

Here's the official list of attendees of Thursday evening's meeting of technology industry chiefs with President Obama in San Francisco. It includes many of Silicon Valley's biggest names.

John Doerr, partner, Kleiner Perkins Caufield & ByersCarol Bartz, president and CEO, Yahoo!John Chambers, CEO and chairman, Cisco SystemsDick Costolo, CEO, TwitterLarry Ellison, co-founder and CEO, OracleReed Hastings, CEO, NetFlixJohn Hennessy, president, Stanford UniversitySteve Jobs, chairman and CEO, AppleArt Levinson, chairman and former CEO, GenentechEric Schmidt, chairman and CEO, GoogleSteve Westly, managing partner and founder, Westly GroupMark Zuckerberg, founder, president and CEO, Facebook

From a description of the meeting by a White House official:

The meeting is a part of our ongoing dialogue with the business community on how we can work together to win the future, strengthen our economy, support entrepreneurship, increasing our exports, and get the American people back to work. The President and the business leaders will discuss our shared goal of promoting American innovation, and discuss his commitment to new investments in research and development, education and clean energy."


http://latimesblogs.latimes.com/technol ... thers.html

All techies salivated over this... to me was, what heck this joker is doing? I wonder Steve Jobs paid the ultimate price, he was very picky with his products :think:

User avatar
viking60
Über-Berserk
Posts: 9351
Joined: 14 Mar 2010, 16:34

Re: Congress Investigating secrecy arround security flaw

Postby viking60 » 02 Feb 2018, 00:41

This is me wearing my tinfoil hat two years ago:
:A
viewtopic.php?f=22&t=4014

Somehow - nothing about this has been able to calm me down.... :wall:
Manjaro 64bit on the main box -Intel(R) Core(TM) i7 CPU 920 @ 2.67GHz and nVidia Corporation GT200b [GeForce GTX 275] (rev a1. + Centos on the server - Arch on the laptop.
"There are no stupid questions - Only stupid answers!"

User avatar
R_Head
Berserk
Posts: 2818
Joined: 17 Mar 2010, 15:40

Re: Congress Investigating secrecy arround security flaw

Postby R_Head » 02 Feb 2018, 13:09

That is not a Tin Foil thing. The conspiracy theory meme was coined by CIA back in the 60s. The purpose is to redicule anybody that has a different view and force people to stick what they are told.

I say, good post and good that you pointed out a vulnerability :cheers

User avatar
dedanna1029
Sound-Berserk
Posts: 8780
Joined: 14 Mar 2010, 20:29
Contact:

Re: Congress Investigating secrecy arround security flaw

Postby dedanna1029 » 25 Nov 2018, 19:06

I was going to ask how anyone can call it "secret" when everything about it is out in the open here. I see it now; however, R-head's article is dated 2011, viking's is just 2018. So, has this been known about for quite some time, or ?
I'd rather be a free person who fears terrorists, than be a "safe" person who fears the government.
No gods, no masters.
"A druid is by nature anarchistic, that is, submits to no one."
http://uk.druidcollege.org/faqs.html

User avatar
R_Head
Berserk
Posts: 2818
Joined: 17 Mar 2010, 15:40

Re: Congress Investigating secrecy arround security flaw

Postby R_Head » 26 Nov 2018, 03:32

The burden and price of secrecy is becoming too big and expensive to maintain. More weird and interesting crap will come out.

Blackcrack
Posts: 300
Joined: 02 Apr 2013, 08:31

Re: Congress Investigating secrecy arround security flaw

Postby Blackcrack » 26 Nov 2018, 11:16

Under the tutu of Safety and security is many nonsense and money-making in the free economy
and also to take it money from various peoples want set up behaver and want make what they want, to make money or become or rob money..
it have all nonsense sense for anyone who want manipulate in different way's in them foreign own opinions and world view..
i guess, this fit's so far .. the most dangerous people are in their own country, they who want to come in the own land
with other religion and a totally other attitude from other lands and country's and wants to pack everything in one country, just to make money again..

security is not give on Computers, as soon as the current flows can it be manipulate ..
Safety is not give as soon the Informations goes in the ear .. It can only be averted by knowledge and feeling.

A Computer is build by Human and a AI is Build by Humans .. only a tree is build by Nature .. but the Human kill's the Tree and use it according to their sense .. Boards and funiers the same with Animals.. food and furs .. and this most in this times for "Luxus" and no more for real to survive..

Make the Human scare, sell them Safety and Security and make money.. or tell you will what they have to do.. and get then the do what you want.
it's a ooold f... game..

the first security was the caveman , Man and Woman, giving safety ..
And the Man becomes what he whant.. and give the Woman something.. and this is not only S3curity .. - - - - - - Baby ..

best regards
blacky

User avatar
R_Head
Berserk
Posts: 2818
Joined: 17 Mar 2010, 15:40

Re: Congress Investigating secrecy arround security flaw

Postby R_Head » 26 Nov 2018, 14:47

Like a great US presie said...Image

You want free, a nanny state, lots of security? :T

Try that. :A

Blackcrack
Posts: 300
Joined: 02 Apr 2013, 08:31

Re: Congress Investigating secrecy arround security flaw

Postby Blackcrack » 26 Nov 2018, 16:24

*lol* Totally Correct *thumpsup* :s :mrgreen: +1

User avatar
dedanna1029
Sound-Berserk
Posts: 8780
Joined: 14 Mar 2010, 20:29
Contact:

Re: Congress Investigating secrecy arround security flaw

Postby dedanna1029 » 01 Dec 2018, 03:43

dedanna1029 wrote:I was going to ask how anyone can call it "secret" when everything about it is out in the open here. I see it now; however, R-head's article is dated 2011, viking's is just 2018. So, has this been known about for quite some time, or ?

Can someone answer this please? Thanks.
I'd rather be a free person who fears terrorists, than be a "safe" person who fears the government.
No gods, no masters.
"A druid is by nature anarchistic, that is, submits to no one."
http://uk.druidcollege.org/faqs.html


Return to “General News”