Announcement

Collapse
No announcement yet.

Russian spy ring needed some serious IT help

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Russian spy ring needed some serious IT help

    So much for all those movie images of spies handling serious tech with aplomb, all while sipping a drink, or playing hide the salami with a member of the opposite sex. These people definitely weren't from SMERSH. Actually, it seems they were just short of "Natasha! Am cooking up big trouble for Moose and Sqvirrel!"

    Russian spy ring needed some serious IT help

    By Tim Greene
    Network World
    June 30, 2010

    The Russian ring charged this week with spying on the United States faced some of the common security problems that plague many companies -- misconfigured wireless networks, users writing passwords on slips of paper and laptop help desk issues that take months to resolve.

    In addition, the alleged conspirators used a range of technologies to pass data among themselves and back to their handlers in Moscow including PC-to-PC open wireless networking and digital steganography to hide messages and retrieve them from images on Web sites.

    They also employed more traditional methods including invisible ink, Morse Code and ciphers, according to assertions made by federal agents in court papers seeking arrest warrants for the suspected spies.

    One of the most glaring errors made by one of the spy defendants was leaving an imposing 27-character password written on a piece of paper that law enforcement officers found while searching a suspect's home.
    They used the password to crack open a treasure trove of more than 100 text files containing covert messages used to further the investigation.

    [...]
    The full story is here: http://www.networkworld.com/news/201...-spy-ring.html

    It's actually pretty amusing from the standpoint of people in our line of work. They apparently did some things right: Steganography was used, and encrypted peer-to-peer wireless networks were employed to limit other people connecting. On the other hand, they made the same operational security mistakes that we see a lot of users make: things like posting passwords on sticky notes, and using bad encryption on the peer-to-peer networks.

    Of course this raises a question: If real life, deep cover sleeper spies are making those mistakes, can we ever get regular users to get security right?
    Thorn
    "If you can't be a good example, then you'll just have to be a horrible warning." - Catherine Aird

  • #2
    Re: Russian spy ring needed some serious IT help

    When I heard about some of the methods they used, I was pretty impressed. Until I saw the thing about the password being written down. Then I fell over laughing. That was all in a mainstream news article though. Glad you posted this article - it seems they were not as clever as I had initially thought.
    "Why is it drug addicts and computer afficionados are both called users? " - Clifford Stoll

    Comment


    • #3
      Re: Russian spy ring needed some serious IT help

      It seems the Russian's main plan was to socially engineer their way into places using a hot chick.
      45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B0
      45 5F E1 04 22 CA 29 C4 93 3F 95 05 2B 79 2A B1
      [ redacted ]

      Comment


      • #4
        Re: Russian spy ring needed some serious IT help

        Originally posted by bascule View Post
        It seems the Russian's main plan was to socially engineer their way into places using a hot chick.
        Yeah, she's the one who apparently can't figure out how to use strong encryption on an ad-hoc WLAN.
        Thorn
        "If you can't be a good example, then you'll just have to be a horrible warning." - Catherine Aird

        Comment


        • #5
          Re: Russian spy ring needed some serious IT help

          -- Judge: 10 spy suspects pleaded guilty and will be deported to Russia, which in turn will release four prisoners to U.S.

          That's one heck of a trade policy we have. Either that or we don't have very many spies.

          xor
          Last edited by xor; July 8, 2010, 16:55.
          Just because you can doesn't mean you should. This applies to making babies, hacking, and youtube videos.

          Comment


          • #6
            Re: Russian spy ring needed some serious IT help

            Originally posted by xor View Post
            -- Judge: 10 spy suspects pleaded guilty and will be deported to Russia, which in turn will release four prisoners to U.S.

            That's one heck of a trade policy we have. Either that or we don't have very many spy's.

            xor
            ... that got caught

            Fixt'
            Originally posted by Ellen
            Do I wish we could all be like hexjunkie? Heck yes I do. :) That would rock.

            Comment


            • #7
              Re: Russian spy ring needed some serious IT help

              Originally posted by xor View Post
              -- Judge: 10 spy suspects pleaded guilty and will be deported to Russia, which in turn will release four prisoners to U.S.

              That's one heck of a trade policy we have. Either that or we don't have very many spy's.

              xor
              We get a scientist. They get a group of ten useless parasites consisting of lawyers, journalists, and a party girl. That sounds like a fair trade to me.
              Last edited by Thorn; July 8, 2010, 16:57. Reason: Typo
              Thorn
              "If you can't be a good example, then you'll just have to be a horrible warning." - Catherine Aird

              Comment


              • #8
                Re: Russian spy ring needed some serious IT help

                Originally posted by Thorn View Post
                We get a scientist. They get a group of ten useless parasites consisting lawyers, journalists, and a party girl. That sounds like a fair trade to me.
                If only we could apply that to China.

                xor
                Just because you can doesn't mean you should. This applies to making babies, hacking, and youtube videos.

                Comment


                • #9
                  Re: Russian spy ring needed some serious IT help

                  All the technology in the world can be rendered worthless by careless users. I have seen many people (in the military nonetheless) think that they were being brilliant by putting all of there log-in credentials in a spreadsheet saved on a LAN instead of using post-it notes.
                  There was no foul on the play. It was not a hold. The defender was just overpowered.
                  -Ed Hochuli

                  Comment


                  • #10
                    Re: Russian spy ring needed some serious IT help

                    Sounds like someone ignored their mandatory IA awareness brief's. The weakest element in any secure system is always the people. Whether it's disgruntled personnel purposely compromising the system, someone who's easily social engineered, or just someone who doesn't care enough about security over convenience. There's simple no way to keep anything secure when more then one person is involved or requires access.

                    Comment

                    Working...
                    X