That student's account of meeting those AIVD suits reads like a spy-thriller fanfic, but if it's true then he's pretty brave publishing it like this.
I'm sure the AIVD's cyber division has some talent, but the AIVD leadership is pretty naive about the internet. Last year the director publicly criticized WhatsApp for providing end-to-end encryption because it makes his job harder. Sure. It's not as if any half-decent terrorist wouldn't use advanced cryptography or simply use burner phones to plan and coordinate their attacks.
Pushing a narrative to people who are naive themselves or pushing a narrative about pushing a narrative to people who are naive themselves to people who are naive themselves.
Maybe, but remember that people used to laugh about the capacities of the FBI (and to some extent the NSA) before the Snowden leaks...
Besides, high level statements like that (that make the main stream media) aren't meant to be factually correct or framed considering all nuances. It's political maneuvering. People don't always mean literally what they say; part of social intelligence is understanding this, and being able to read between the lines. I wish I had learned about this 2 decades ago. I guess us computer types aren't predisposed to have this come natural to us.
I doubt a judge would find that this article of law applies here; for relaying what a private citizen was told by two strangers who approached him for a job offer without any prior contact, without engaging his professional services or hearing him formally as part of an ongoing investigation, and without formally requesting his cooperation in keeping certain information private. If someone from an agency such as the AIVD tells you something in public, you can reasonably assume (one of the definitions of that article) that it is not subject to secrecy.
Having more encrypted traffic definitely makes spying harder.
It's a lot easier to track, store, and attempt to crack one single terrorist's encrypted traffic in a sea of non-encrypted traffic, than try to pick out the terrorist's encrypted traffic in a sea of other encrypted traffic.
If terrorists are the only ones using encryption, then their traffic will stick out like a sore thumb. While if everyone uses encryption, their traffic will simply blend in.
I'm surprised they're interested in infiltrating hackerspaces.
Is this where they spend our tax money on?
Our surveillance state is going in the wrong way.
If your goal is to collect everything like the western intelligence services, infiltrating hackerspaces and the CCC seems like a very efficient use of resources. Especially if they're focusing on Tor and related projects, which they seem to be.
I assume they're interested in acquiring information and techniques from these hacker gatherings, rather than hoping to find a terrorist there. The attendees are probably/hopefully not the target.
I am really not sure how I feel about this, being dutch myself. Isn't this how any country would recruit new people? I don't see what is so wrong about it. Isn't it logical for secret agencies to monitor possible recruits? Isn't that what other companies do as well, to an extent? (Using linkedIn, buying data from Facebook/Twitter/whoever sells).
I am not really patriotic, but this is about 'protecting' your country, right? And if we will have some WWIII I think it will be mostly 'cyber'.
Regarding the threat: well duh, you are doing something that might make you an accomplice of a crime (with whatever law they make) so yeah, they could arrest you then. How is that even surprising?
But eh, I am not an (ethical) hacker, I just build software...
Running a Tor node doesn't make you an accomplice of a crime. That's like saying a taxi driver is an accomplice because he (unwittingly) drove a terrorist around.
Define "subversive." Does politically organizing against Putin count as "subversive"? Does not wanting everything you read online to be tracked and recorded by the NSA/Obama/Trump count as "subversive"? Does not wanting a large fraction of your browsing habits to be added to marketing databases count as "subversive"?
Honestly, I would suggest that more people ought to consider encrypting more of their communications just for day to day use.
More people ought to - but the extent to which everyday people attempt this (even if aware that they might want to) is probably no more extensive than searching via duckduckgo and/or browsing with a private window/incognito mode.
It doing so is much more difficult than these options, then it seems unlikely to happen.
Edit: that said, if there are - in fact - simple ways of achieving this goal I'd like to hear so I can share them.
> Edit: that said, if there are - in fact - simple ways of achieving this goal I'd like to hear so I can share them.
Here are some things which aren't too hard, but which provide a reasonable improvement in security:
1. The easiest thing to do is replace your current SMS application with Signal, and to encourage your less technical friends to do likewise. You can still send regular SMS messages, but if both people have Signal, it will switch to encrypted messages. I've talked a fair number of non-technical, non-paranoid users into doing this and they all seem pretty happy.
2. Tor is surprisingly easy to set up and use these days, it works well, and it uses DuckDuckGo search by default. Again, it won't provide flawless protection against a sufficiently powerful adversary, and it's obvious you're using Tor. But still, launching Tor and using it is pretty easy. And it will definitely keep, for example, web advertising companies or ISPs from building detailed dossiers on your behavior.
Again, if you just want something easy to use and you don't pay attention to the fine print, you're not necessarily going to be well-protected against sophisticated adversaries. But you can improve your security a lot for relatively little effort.
We do have standards in place for monitoring the movement of large sums of cash through the system, and those are well accepted... So are you OK with something similar for encrypted traffic?
The article does not mention surveilling all civilians, only that they look for new recruits which is reasonable.
The article also talks about going to other countries and looking for advancements among hackers. Sounds reasonable to do as well. You want to know what others know.
> The article does not mention surveilling all civilians
He is not being recruited as a soldier, but as a civilian. This works by drip feed. To simplify, let's assume the agents are actually from the AIVD (versus a foreign government or criminal syndicate) and that the account is 100% true.
First, he might be asked to recruit. A few months in, he may be asked to "to "crash a system in a public place". Then he will be told to dragnet his Tor exit nodes. If he says no the agents may be unable to continue protecting him from prosecution for crashing that system earlier. He did it as a civilian, after all.
These are people used to total impunity from our rules of law. They will be self-serving and deceptive. You make your own bed by heeding the sirens' calls.
There's nothing particularly wrong with them trying to recruit him (though opinions regarding covert internal observation services differ), but they're not just interested in him for his technical prowess. They're asking him to report on people in hacker spaces, hacker conventions, etc; ie. to spy on many of the people that participate in this forum.
There's always been running gags about spooks at hacker conventions, but it's "nice" to have a confirmation (even if it's hard to verify).
>There's always been running gags about spooks at hacker conventions, but it's "nice" to have a confirmation (even if it's hard to verify).
Was the 'meet the feds' panel at DEFCON not enough of a confirmation? I've seen people at academic security conferences wearing name-tags with "National Security Agency" right in the employer field.
This reminds me of G. K. Chesterton's The Man Who Was Thursday[1] where a government spy infiltrates an anarchist organization only to find out that the other members are also government spies.
What 'running gags'? I've been to cons in Europe in the late 1990's where people would openly say they were from special departments of the police or intelligence services, and that they were there to recruit, learn about what's going on in the scene and to keep tabs on groups and 'scene' dynamics. This has been common practice and knowledge for 15+ years. I don't even see what's surprising about it.
Who said anything about being surprised? And are you saying there were no running gags about it?
FWIW, I'm assuming they would have asked him to report on fellow hackers without openly saying so. I got that implication from the article, but it doesn't say so and presumably they wouldn't have made that explicit when they approached him.
Theoretically, yes. But when you have agents allegedly asking civilians to "crash a system in a public place" while promising they won't "get arrested and nobody will know about it, not even the police," other possibilities emerge.
You may be deployed for political or commercial purposes, domestically or abroad. If you push back, your prior assignments, done while you were a civilian, could be used against you. Consider, too, how easy it is for foreign governments or criminal syndicates to pose as the AIVD and recruit patriotic civilians thusly.
> WWIII will be mostly 'cyber'
We are not at war and he was not being recruited to be a soldier. He was allegedly being asked, as a civilian, to commit crimes, domestically and abroad, under the alleged cover of an intelligence agency.
---
Buro Jansen & Janssen only verified "the existence of this person and confirmed their existence." We should consider this account plausible but unconfirmed.
If it was reported correctly, to me the conversation sounded more like an attempt to subvert Tor nodes and perhaps get access to the Tails developers and repositories or similar projects in the long run. Not that I know anything about this, but it may be better to counter such attempts not in an adversarial manner, but by playing such a dumb idiot and making so stupid jokes that they lose interest in you. Talk them down with irrelevant bullshit. After all, these kind of conversations really are sort of job interviews or attempts to intimidate to coerce cooperation, so any behavior is fine that would definitely spoil a job interview and make you unhirable. (Unless you want to work for them, of course...)
Regarding the threat: well duh, you are doing something that might make you an accomplice of a crime (with whatever law they make) so yeah, they could arrest you then. How is that even surprising?
Running a Tor exit node is probably not a crime in the Netherlands - I haven't checked on this. In any case, if it's a crime, it should maybe worry you that they also promised to protect the guy against police if he works for them. That's at least dubious. If on the other hand running an exit node is not a crime, which seems more likely to me, then the guy was really just threatening and harassing him.
Instead of talking about the hacker community, lets talk about HN community which we are all part of.
How would we all feel if secret service people were recruiting moderators/ycombinator people that wrote paid comments and informed on the content of private conversation between founders and investors?
Personally I would trust the community less. I would expect contributions to have lower quality, be less insightful and more hostile, resulting in a general distrust that in the long runs kills the community from within.
Anyone can sign up and comment here, and it's a public forum with no private messaging capability, so I don't really see what would be changed by your scenario.
Its about trust. Even on a site where anyone can contribute (like Wikipedia), the community still operate on assumptions of good faith. Wikipedia is also a interesting example in how aggressively the community feel about paid, puppet or other from of dishonest contributions. Without trust the community fall apart.
The only effect it might have to slightly alter the overall bias of the site. Which is not necessarily a bad thing.
HN already has something of a negative bias towards the work of the various security services (that is, the mood is largely pro-Snowden and anti-NSA) - having a better balance of views may well be a positive effect.
Similarly for the pro-capitalist bias here, and what almost amounts to a religious veneration for VCs and the very wealthy. Then again, HN is a bit of a chimera in the topics it covers. So we do have some diversity of interests and opinions.
It's their job to secure 'assets' and they have a near endless amount of resources, influence and leverage to do so. It's anyone's guess how many 'assets' secret service around the world have on their rolls.
While its easy to give in to paranoia or a witchhunt it would be equally amiss to pretend these things don't happen regularly. Things positioned as privacy centric would especially have a lot of attention on them from services around the world.
Few would be able to resist, the money, power, purpose and if they have leverage less so. Which makes privacy that much more important, its easy to get leverage if everyone is on file.
Trust is a huge premium. For those who need privacy or secrecy better to trust yourself. You don't need any specific technology or project to get those things.
Something very similar happens in the movie The Recruit. Must watch for hackers.
I hope the authorities don't go after him for making this public though.
I don't know what it would take for Governments around the world to acknowledge the importance of encryption and anonymity tools. Access to private data cuts both ways, if the Government can do it so can the black hats. Maybe a large scale hack of Government networks devastating the economy will bring them to their senses.
Given the allegations of Russia's involvement in the recent election, whether true or not, I was expecting Governments around the world to think deeply about cyber security issues. Looks like that won't happen anytime soon.
This is a new strategy of AIVD and MIVD, they are desperately trying to hire skilled hackers.
He thinks that AIVD wants him to infiltrate hacker scenes. Reality is probably that they want him to recruit more hackers.
Same story about the tor nodes, AIVD knows that hackers want to have tor nodes. They obviously do not care about Tor, thus want to look like they are cool.
Note they did offer him a position to manage young hackers.
I guess the sad part is the threat. Hackers have to decide for themselves if they want to work for the government or not. But is bad if part of recruitment is making threats (and demanding that those threats kept secret).
Euhm no... not trolling (at least, not aware of it). I just assume that country governments just want to know what other governments are capable of... I mean, it would be great if such a thing was not necessary and there would not be any nation states acting against other nation states.
And no, I have not been recruited or work for any other company than my own (which is not in the security business)
EDIT: can't reply anymore. But I seem to be wrong indeed. hackerspaces are probably not the best place to look what other gov. can do. Maybe it is for recruiting instead?
We (the Dutch) have one of the most watched societies and it's never enough. All phone/internet data is saved for years with almost dragnet like strength, even though it was deemed excessive by judges. The police buy their traffic information from TomTom, the highways are littered with camera's with licence plate-scanning abilities, cities have permanent bluetooth capable scanners around them (to monitor traffic it is said) and there are there is talk to add a RIFD chip to the official licence plates... And still it's not enough...
It's nothing new. It has gone on amongst the NGO and activist community for many years. Especially the aid worker (in places like Pakistan) and environmental defender community (all over the world). We have investigated a number of instances of pitches by both government and corporate intelligence human penetration over the years in many different countries. In fact we cover it quite extensively in our security training programs that we teach. I think people are often surprised to know that we've seen nearly as many human penetration attempts as digital. The activist space is full of (mostly) good hearted humans who are as vulnerable as any normal person to flattery, money, ego etc (the common and preferred pitching point of a service) and weaknesses like crime, blackmail, revenge etc (the lesser preferred pitching point).
On a side note, it's always worth pointing out, especially in Europe, that direct attitribution to a service making a pitch is never so sure. Many countries make pitches pretending to be other (usually local) services. For example the US and Israelis are often aware that Europeans often take personal political stances against their government policies so they will impersonate a local service like AVID. People have spent years not realising what service or country they are really working for.
> People have spent years not realising what service or country they are really working for.
Imagine someone's surprise when they get arrested. They thought they were doing their country a service and it turns out they were actually aiding the enemy...
I am a dutch citizen as well, and thought we were doing quite well. Do you have sources for the TomTom, bluetooth scanners and most importantly phone/internet data being saved?
If this stuff is true, I need to start weighing digital rights a lot more in my politics.
Gives information on the telecom metadata retention directive: 12 months for telephony, 6 months for all Internet traffic.
Note: "In addition to this retention directive, all communication providers are required to submit a daily copy of their entire customer base to the DOJ, including name, address, phone number, email and assigned IP".
About the recent addition that traffic cameras may be used to record and store all license plates passing the camera. This data is accessible to enforcement agencies without warrant.
Thanks for the info. Luckily, after some digging, there is no current data retention. It was struck by european courts in 2015. There is a new bill currently in the 'tweede kamer' (our house of representatives) to reinstate the data retention. I'm not sure what the expected status of it is. (The fact that the minister who proposed it just resigned probably hurts the prospects of this law.)
When it comes to passive surveillance (cameras, dragnet internet tapping) probably not that far behind.
But when it comes to more invasive measures like internet censorship [1], or requiring suspects to give over encryption keys (else potentially put them in jail if they refuse) [2] or simply the way you are treated at an airport. The UK is much, much worse.
I'm a little surprised by this, and skeptical of your claims. The Dutch have one of the strongest advocacies in the world for privacy. This is evidenced by many policies, some seemingly trivial, others not, such as:
1) All ISPs are supposed to delete all logs of customers within 6 months.
2) All websites that deposit a cookie on your machine are required by law to require user consent before doing so (which is why so many American websites become a bit different when browsing them from the Netherlands -- all those popups requesting consent).
While I know the Dutch basically invented the wire tap decades ago, and I have no reason to believe they don't have an advanced spy mechanism in their government, your claims seem to go much further than reason, and feel a bit tabloid to me. You need to provide some concrete evidence about this.
The claims are true as far as I know. The police did get (or try to get) data from TomTom. In addition the tax office got data that was collected to check if people pay for parking.
There are license plate scanners in lots of places. The total number of taps is mostly undisclosed. The police routinely tap conversations between suspects and lawyers. Those are supposed to be deleted but sometimes end up in a file anyhow.
There are limits on what the police can do, but by and large there are only very vague limits on what intelligence agencies can collect.
So it is safest to assume that all information that is collected in digital form is available to the government in one way or another and only occasionally are there enough protests that some data is not used anymore (such the tax office using information related to parking)
Note, the government has no problem restricting what companies can do with data as long as gets what it needs.
Could the moderators please investigate why this deliberately naive comment "And if we will have some WWIII I think it will be mostly 'cyber'." is repeatedly upvoted to the top?
I've rarely read such garbage as the top comment here.
Please don't comment uncivilly like this. You've gone way too far in assuming malice on behalf of both the parent commenter and the voting community members. In addition, please don't create throwaway accounts for every comment like this—we ban them. Hacker News is a community site and, while pseudonymity is fine, users should be able to expect a mostly continuous identity in their fellow community members.
So they have looked at publicly available information and asked them to work for them. What's the surprise? That the intelligence agencies have people working for them that go to security conferences? That they will say that if you hack a system under their responsibility they will shield you and otherwise they won't? I don't really see the problem here.
> That they will say that if you hack a system under their responsibility they will shield you
Promises are cheaper than deeds. You don't need to actually protect anyone. It's actually better, from the agency's perspective, if they can convert an asset from an honest law-abiding man to someone who has "crash[ed] a system in a public place". They have leverage over the latter.
This is how criminals work. Given the secrecy involved, you could never be sure you weren't working for one.
Except recently a widely-publicized law was introduced that actually allows the intelligence agencies to break into computers. So the offer is legitimate and the rest is paranoid superstition.
> the offer is legitimate and the rest is paranoid superstition
How do you know it's the Dutch intelligence agency recruiting him and not a foreign agency or criminal group? It's unlikely AIVD would put him on their official payroll. From an asset's perspective it will always be difficult to tell--that's how the handler maintains deniability.
Many in the Dutch hacker scene would never work for the Dutch government (at least, the more sensitive parts such as intelligence agencies, police, etc.).
So mostly likely he didn't want to work for them anyway and was very unhappy about the implicit threats related to his tor exit-nodes.
For IT professionals the risk doesn't seem very high. Just running tor exit-nodes is not illegal. There are enough jobs in IT where you don't have to worry about any kind of government approval.
There are lots of stories about people who in one way or another got in contact with the intelligence agencies and nothing really bad happened to them.
Of course, agreeing to secrecy and then spilling the beans is not recommended. But in this case the agents decided to tell him stuff without any kind of agreement.
Tor is a huge inconvenience to a government that wants to suppress the exchange of controversial ideas within the civilian population.
It is also a huge problem to a government struggling to halt, for instance, Islamic terrorists that are well established within that population and potentially use Tor for communication.
I think this is a case of the latter and I don't disagree with the sentiment 100%. The region faces some substantial challenges and we're going to see civil liberties erode.
> If you work with us there are benefits, for example if we ask you to crash a system in a public place and you would be arrested for that, we make sure you don’t get arrested and nobody will know about it, not even the police
"If you do us a favor, there's the amazing perk that you might not even go to jail for it!"
Yeah but that sort of thing is also a hook...once you do it once they begin to own and have greater control over you. Similar to how even when the individual might not want to take anything in return for information, they will want to get the individual to take money or something else in return (free trips to stuff, ego stroking, sex, drugs etc). Especially on a regular basis.
This means the individual has a) compromised themselves and now cannot feel "clean" in this previous environment and b) are starting to get used to/spend the new perk/cash so pretty soon they can't live without it. The power relationship then swings more towards a needs based one. Suddenly the handler(s) are the only people who really know the truth about how the informant truly is. Also the handler(s) are the only people how can meet the new need that the person has got hooked on.
My basic understanding of this matter is this: never co-operate with the intelligence community.
Shit on these people and burn their identities whenever you can because they're not your friends. You might even be able to limit the future career opportunities of a younger intelligence officer who's approached you by not only telling your friends, but informing the entire internet.
These people may be a necessary extension of diplomacy, but history shows that it's likely toxic for any individual to be ensnared as an asset in any kind work for this sector of the government, foreign or domestic.
There are enough 'useful idiots' who will fall for this, you don't need to be one of them. Unless you're an actual employee of an intelligence agency or a contractor, these people will fuck you over in a heartbeat.
Anyone unfamiliar with this line of business could do worse than to read any old basic textbook on intelligence and counter-intelligence work (such as 'Thwarting Enemies at Home and Abroad', linked below. There's a good audiobook version on Audible).
Training in this business is based on cultivating anti-social behavior in susceptible individuals. Just as you don't want any garden variety sociopaths in your life, you don't want to deal with people who've been trained to fuck with you.
Dutch Pirateparty founder and sometimes information broker here. During my 10+ years of both national and international activism, politics and intelligence trade I came to realize that approximately 2 out of 3 people, NGO's, etc. is compromised. Furthermore, the report is matching what I encountered in reality.
Been working on security for NGOs and activist groups all over the world and in every part of the space for a long time. I think your figure is on the high side and overly alarmist. Perhaps with Pirateparty-style groups it is higher than most but not across the whole sector. It's certainly not the case that two-thirds of all groups and activists have been compromised. People forgot that human intelligence operations are actually pretty cost intensive and fairly difficult to pull off well. Some parts of the community make the problem worse once a genuine compromise is found by then creating biases and accusations where none can be confirmed.
It really depends on many factors - location, group activities, training, personal, the threats they pose to the actors with the will/desire etc to target them, also how you define compromised (a cleaner keeping tabs? a phishing email opened? a disgruntled volunteer? a paid staff member who walks out the door with data? a leader who has been turned?)
>I think your figure is on the high side and overly alarmist.
This is actually my gripe with the Dutch pirate party. They are often very alarmist and exaggerate problems in the same way the parties they oppose do. I wish there was a party that's focuses on major issues in stead of exaggerating a small number of issues in order to get popular with a specific market.
You are right when it comes to the alarmism and exaggeration, it's a populist policy choice, detrimental to the roots of the party and something I totally disagree with.
Very much agreed. If the Dutch PP was anything like the German, Swedish, Icelandic (to name a few) ones, I'd vote for them in a heartbeat, no second thoughts. But they just keep on making blunder after (sometimes well-intentioned, sometimes plain stupid) blunder, and it's just sad and disorganised.
I admit I might still vote for them anyway if I can't find a party that better represents me. Fortunately we get quite a few to choose from! Dutch might want to take a moment and be thankful we have that :)
Compromised does not have to be destructive intent. It can be nothing but passive intelligence gathering for example. Furthermore, compromised entities are rarely compromised by just one entity. For example national intelligence agencies are obligated to monitor new and rising political or activistic activities in order to asses if they are threat or not.This raises the % of compromised entities a lot. And then there is private intelligence & interest groups; same story. Yet in general, I do agree with your conclusions. Often the fear of being compromised is more dangerous than actually being compromised.
This is true and many NGOs pursue security strategies of "acceptance" or openness in order to deal with this issue. Essentially going along to the policy-maker and telling them what they are doing, which sometimes works to reduce the information gathering operations against them by cutting out the middle layer (intel organisations).
It is dishonest and dangerous to claim that NGOs are compromised without providing any proof. I've worked in that space, and it is critically important that aid workers are seen as politically neutral and with pure intentions.
As an example the Taliban was targeting NGOs in the Afghanistan/Pakistan region because they believed efforts to vaccinate against polio were in fact an attempt to poison Muslims. Dozens of doctors, nurses, and volunteers were killed because someone like you decided to start a baseless rumor.
Most first world intelligence agencies have policies against embedding spies in aid operations. When it became common knowledge we used a vaccination campaign to collect on UBL, many people resigned from the Agency.
> because they believed efforts to vaccinate against polio were in fact an attempt to poison Muslims
Or more likely a terrorist organization in those countries started such rumors to turn public sentiment against the west. Oh, and then the USG used a vaccination program to attempt to track down terrorists, which played a role in the take-down of Osama Bin Laden.
It's fair to say that there are compromised NGOs, based on the OBL incident alone.
My current understanding is the vaccine doctor story was a cover for the fact that Bin Laden was brought in trough a walk-in. But that's Seymour Hersh' story so who knows.
hm, what's wrong ycombinator? Is that a technically/database problem? I don't no it's possible to post double content, with same headline and same link. I mean, that's (in my personal opinion) bad database design.
It's always hard to believe a second-hand story on the Internet, but suspending skepticism for a moment: kudos to the guy for telling this. There's easily enough information in there to be identified by the agents he spoke to. He's taking a huge risk.
Or maybe he included some false info for noise injection... if so, how do we know which parts to believe? Skepticism suspension lifted, I suppose.
I understand how it can be viewed that way and it's certainly a bit of a risk but realistically it's not a huge risk.
If this is AVID, at the end of the day, despite what many may think due to outlying examples, they are an intelligence organisation working in a democracy and their agents aren't normally going to be in the business of retribution for someone turning down a pitch. Plus, if they became known for unnecessary retribution for minor things like someone saying no to a pitch, it would damage their long-term efforts in other areas.
They will expect that probably the majority of the pitches they make will be rejected. It's not something new to them. Similarly they will have risk assessed and planned for the eventuality of it being made public. Yes, it will annoy them but they will still just keep on moving through the social network analysis diagrams until they find and pitch the right people they are looking for.
Plus, while it will make some people more weary in future, occasionally exposure of efforts like this often leads to a softening up of others who might be interested in doing this sort of thing for them in future. Maybe a few months down the line someone in the community gets pissed off with others and remembers this article and drops AVID a mail........
It's always hard to believe a second-hand story on the Internet, but suspending skepticism for a moment: kudos to the guy for telling this. There's easily enough information in there to be identified by the agents he spoke to. He's taking a huge risk.
Or maybe he included some false info for noise injection... if so, how do we know which parts to believe? Skepticism suspension lifted, I suppose.
I may be wondering because I'm standing on an atoll of ignorance in a sea of knowledge, but I wonder why the intelligence themselves can't became Tor admins and do away with needing to recruit anyone.
This isn't that strange. The police (more public than secret service) and national cyber crime team (also public) are very open in hiring IT and especially infosec talent from the industry, universities and at conferences. They even commercially sponsor IT related news outlets and communities and organise hacker challenges to recruit talent in that space.
By far the biggest part of what those teams do isn't secret and fits within the law. The "problem" is that Dutch law is very liberal on wire tapping, decryption etc as long as there is a reasonable suspicion and/or court order. Actually not far behind the rubber stamping in the US, but without the limitation that they can't target our own citizens (so: much worse than the US for locals, but similar for foreigners)
Obviously the military and domestic secret service hire the same people and have even wider abilities within the law and quite a wide grey area. Most of the public doesn't care enough to make it a political topic, so nobody stops them.
114 comments
[ 3.5 ms ] story [ 234 ms ] threadI'm sure the AIVD's cyber division has some talent, but the AIVD leadership is pretty naive about the internet. Last year the director publicly criticized WhatsApp for providing end-to-end encryption because it makes his job harder. Sure. It's not as if any half-decent terrorist wouldn't use advanced cryptography or simply use burner phones to plan and coordinate their attacks.
Besides, high level statements like that (that make the main stream media) aren't meant to be factually correct or framed considering all nuances. It's political maneuvering. People don't always mean literally what they say; part of social intelligence is understanding this, and being able to read between the lines. I wish I had learned about this 2 decades ago. I guess us computer types aren't predisposed to have this come natural to us.
I wonder if he could (potentially) be prosecuted for it; the exchange includes "information reasonably assumed confidential."
Artikel 85 Wet op de inlichtingen- en veiligheidsdiensten 2002 http://wetten.overheid.nl/BWBR0013409/2017-01-01#Hoofdstuk7
It's a lot easier to track, store, and attempt to crack one single terrorist's encrypted traffic in a sea of non-encrypted traffic, than try to pick out the terrorist's encrypted traffic in a sea of other encrypted traffic.
If terrorists are the only ones using encryption, then their traffic will stick out like a sore thumb. While if everyone uses encryption, their traffic will simply blend in.
I am not really patriotic, but this is about 'protecting' your country, right? And if we will have some WWIII I think it will be mostly 'cyber'.
Regarding the threat: well duh, you are doing something that might make you an accomplice of a crime (with whatever law they make) so yeah, they could arrest you then. How is that even surprising?
But eh, I am not an (ethical) hacker, I just build software...
What % of Tor traffic is for illegal/immoral/subversive activities?
Honestly, I would suggest that more people ought to consider encrypting more of their communications just for day to day use.
It doing so is much more difficult than these options, then it seems unlikely to happen.
Edit: that said, if there are - in fact - simple ways of achieving this goal I'd like to hear so I can share them.
Here are some things which aren't too hard, but which provide a reasonable improvement in security:
1. The easiest thing to do is replace your current SMS application with Signal, and to encourage your less technical friends to do likewise. You can still send regular SMS messages, but if both people have Signal, it will switch to encrypted messages. I've talked a fair number of non-technical, non-paranoid users into doing this and they all seem pretty happy.
2. Tor is surprisingly easy to set up and use these days, it works well, and it uses DuckDuckGo search by default. Again, it won't provide flawless protection against a sufficiently powerful adversary, and it's obvious you're using Tor. But still, launching Tor and using it is pretty easy. And it will definitely keep, for example, web advertising companies or ISPs from building detailed dossiers on your behavior.
Again, if you just want something easy to use and you don't pay attention to the fine print, you're not necessarily going to be well-protected against sophisticated adversaries. But you can improve your security a lot for relatively little effort.
What % of $100 bills are used for illegal/immoral/subversive activities?
Conclusion: Anyone handling a $100 bill is a criminal.
He is not being recruited as a soldier, but as a civilian. This works by drip feed. To simplify, let's assume the agents are actually from the AIVD (versus a foreign government or criminal syndicate) and that the account is 100% true.
First, he might be asked to recruit. A few months in, he may be asked to "to "crash a system in a public place". Then he will be told to dragnet his Tor exit nodes. If he says no the agents may be unable to continue protecting him from prosecution for crashing that system earlier. He did it as a civilian, after all.
These are people used to total impunity from our rules of law. They will be self-serving and deceptive. You make your own bed by heeding the sirens' calls.
There's always been running gags about spooks at hacker conventions, but it's "nice" to have a confirmation (even if it's hard to verify).
Was the 'meet the feds' panel at DEFCON not enough of a confirmation? I've seen people at academic security conferences wearing name-tags with "National Security Agency" right in the employer field.
[1] - https://en.wikipedia.org/wiki/The_Man_Who_Was_Thursday
FWIW, I'm assuming they would have asked him to report on fellow hackers without openly saying so. I got that implication from the article, but it doesn't say so and presumably they wouldn't have made that explicit when they approached him.
Theoretically, yes. But when you have agents allegedly asking civilians to "crash a system in a public place" while promising they won't "get arrested and nobody will know about it, not even the police," other possibilities emerge.
You may be deployed for political or commercial purposes, domestically or abroad. If you push back, your prior assignments, done while you were a civilian, could be used against you. Consider, too, how easy it is for foreign governments or criminal syndicates to pose as the AIVD and recruit patriotic civilians thusly.
> WWIII will be mostly 'cyber'
We are not at war and he was not being recruited to be a soldier. He was allegedly being asked, as a civilian, to commit crimes, domestically and abroad, under the alleged cover of an intelligence agency.
---
Buro Jansen & Janssen only verified "the existence of this person and confirmed their existence." We should consider this account plausible but unconfirmed.
Regarding the threat: well duh, you are doing something that might make you an accomplice of a crime (with whatever law they make) so yeah, they could arrest you then. How is that even surprising?
Running a Tor exit node is probably not a crime in the Netherlands - I haven't checked on this. In any case, if it's a crime, it should maybe worry you that they also promised to protect the guy against police if he works for them. That's at least dubious. If on the other hand running an exit node is not a crime, which seems more likely to me, then the guy was really just threatening and harassing him.
> this is about 'protecting' your country, right?
Something like: "If you do illegal things for us we'll protect you from the police. If you don't... be a shame if you get raided for your exit nodes."
This sounds like setting up a criminal organization. Not sure you want that "protection"
Nor is blackmail very good way to recruit
How would we all feel if secret service people were recruiting moderators/ycombinator people that wrote paid comments and informed on the content of private conversation between founders and investors?
Personally I would trust the community less. I would expect contributions to have lower quality, be less insightful and more hostile, resulting in a general distrust that in the long runs kills the community from within.
HN already has something of a negative bias towards the work of the various security services (that is, the mood is largely pro-Snowden and anti-NSA) - having a better balance of views may well be a positive effect.
Similarly for the pro-capitalist bias here, and what almost amounts to a religious veneration for VCs and the very wealthy. Then again, HN is a bit of a chimera in the topics it covers. So we do have some diversity of interests and opinions.
If others do it, you have to do it too.
And this is why war exists.
While its easy to give in to paranoia or a witchhunt it would be equally amiss to pretend these things don't happen regularly. Things positioned as privacy centric would especially have a lot of attention on them from services around the world.
Few would be able to resist, the money, power, purpose and if they have leverage less so. Which makes privacy that much more important, its easy to get leverage if everyone is on file.
Trust is a huge premium. For those who need privacy or secrecy better to trust yourself. You don't need any specific technology or project to get those things.
I hope the authorities don't go after him for making this public though.
I don't know what it would take for Governments around the world to acknowledge the importance of encryption and anonymity tools. Access to private data cuts both ways, if the Government can do it so can the black hats. Maybe a large scale hack of Government networks devastating the economy will bring them to their senses.
Given the allegations of Russia's involvement in the recent election, whether true or not, I was expecting Governments around the world to think deeply about cyber security issues. Looks like that won't happen anytime soon.
He thinks that AIVD wants him to infiltrate hacker scenes. Reality is probably that they want him to recruit more hackers.
Same story about the tor nodes, AIVD knows that hackers want to have tor nodes. They obviously do not care about Tor, thus want to look like they are cool.
Note they did offer him a position to manage young hackers.
I guess the sad part is the threat. Hackers have to decide for themselves if they want to work for the government or not. But is bad if part of recruitment is making threats (and demanding that those threats kept secret).
EDIT: "You want to know what others know." is bound to be a troll (or worse).
EDIT: can't reply anymore. But I seem to be wrong indeed. hackerspaces are probably not the best place to look what other gov. can do. Maybe it is for recruiting instead?
How does sniffing around hackerspaces tell them what other governments are capable of?
On a side note, it's always worth pointing out, especially in Europe, that direct attitribution to a service making a pitch is never so sure. Many countries make pitches pretending to be other (usually local) services. For example the US and Israelis are often aware that Europeans often take personal political stances against their government policies so they will impersonate a local service like AVID. People have spent years not realising what service or country they are really working for.
Imagine someone's surprise when they get arrested. They thought they were doing their country a service and it turns out they were actually aiding the enemy...
If this stuff is true, I need to start weighing digital rights a lot more in my politics.
https://www.privacybarometer.nl/maatregel/37/Bewaarplicht_te...
Gives information on the telecom metadata retention directive: 12 months for telephony, 6 months for all Internet traffic.
Note: "In addition to this retention directive, all communication providers are required to submit a daily copy of their entire customer base to the DOJ, including name, address, phone number, email and assigned IP".
https://www.privacybarometer.nl/maatregel/45/Kentekenregistr...
About the recent addition that traffic cameras may be used to record and store all license plates passing the camera. This data is accessible to enforcement agencies without warrant.
https://www.privacynieuws.nl/internet-en-telecom/bewaarplich...
- news aggregator for various privacy issues
But when it comes to more invasive measures like internet censorship [1], or requiring suspects to give over encryption keys (else potentially put them in jail if they refuse) [2] or simply the way you are treated at an airport. The UK is much, much worse.
[1]: https://en.wikipedia.org/wiki/Internet_censorship_in_the_Uni...
[2]: https://en.wikipedia.org/wiki/Key_disclosure_law#United_King...
1) All ISPs are supposed to delete all logs of customers within 6 months.
2) All websites that deposit a cookie on your machine are required by law to require user consent before doing so (which is why so many American websites become a bit different when browsing them from the Netherlands -- all those popups requesting consent).
While I know the Dutch basically invented the wire tap decades ago, and I have no reason to believe they don't have an advanced spy mechanism in their government, your claims seem to go much further than reason, and feel a bit tabloid to me. You need to provide some concrete evidence about this.
There are license plate scanners in lots of places. The total number of taps is mostly undisclosed. The police routinely tap conversations between suspects and lawyers. Those are supposed to be deleted but sometimes end up in a file anyhow.
There are limits on what the police can do, but by and large there are only very vague limits on what intelligence agencies can collect.
So it is safest to assume that all information that is collected in digital form is available to the government in one way or another and only occasionally are there enough protests that some data is not used anymore (such the tax office using information related to parking)
Note, the government has no problem restricting what companies can do with data as long as gets what it needs.
I've rarely read such garbage as the top comment here.
I do have heard of voting rings, yes, of course. However, just because an idea which you dont like is upvoted, doesnt mean its a voting ring.
edit: I also find it kinda interesting that an account which is 25minutes old talks about voting rings
We detached this subthread from https://news.ycombinator.com/item?id=13490564 and marked it off-topic.
Promises are cheaper than deeds. You don't need to actually protect anyone. It's actually better, from the agency's perspective, if they can convert an asset from an honest law-abiding man to someone who has "crash[ed] a system in a public place". They have leverage over the latter.
This is how criminals work. Given the secrecy involved, you could never be sure you weren't working for one.
How do you know it's the Dutch intelligence agency recruiting him and not a foreign agency or criminal group? It's unlikely AIVD would put him on their official payroll. From an asset's perspective it will always be difficult to tell--that's how the handler maintains deniability.
So mostly likely he didn't want to work for them anyway and was very unhappy about the implicit threats related to his tor exit-nodes.
There are lots of stories about people who in one way or another got in contact with the intelligence agencies and nothing really bad happened to them.
Of course, agreeing to secrecy and then spilling the beans is not recommended. But in this case the agents decided to tell him stuff without any kind of agreement.
It is also a huge problem to a government struggling to halt, for instance, Islamic terrorists that are well established within that population and potentially use Tor for communication.
I think this is a case of the latter and I don't disagree with the sentiment 100%. The region faces some substantial challenges and we're going to see civil liberties erode.
> If you work with us there are benefits, for example if we ask you to crash a system in a public place and you would be arrested for that, we make sure you don’t get arrested and nobody will know about it, not even the police
"If you do us a favor, there's the amazing perk that you might not even go to jail for it!"
This means the individual has a) compromised themselves and now cannot feel "clean" in this previous environment and b) are starting to get used to/spend the new perk/cash so pretty soon they can't live without it. The power relationship then swings more towards a needs based one. Suddenly the handler(s) are the only people who really know the truth about how the informant truly is. Also the handler(s) are the only people how can meet the new need that the person has got hooked on.
Shit on these people and burn their identities whenever you can because they're not your friends. You might even be able to limit the future career opportunities of a younger intelligence officer who's approached you by not only telling your friends, but informing the entire internet.
These people may be a necessary extension of diplomacy, but history shows that it's likely toxic for any individual to be ensnared as an asset in any kind work for this sector of the government, foreign or domestic.
There are enough 'useful idiots' who will fall for this, you don't need to be one of them. Unless you're an actual employee of an intelligence agency or a contractor, these people will fuck you over in a heartbeat.
Anyone unfamiliar with this line of business could do worse than to read any old basic textbook on intelligence and counter-intelligence work (such as 'Thwarting Enemies at Home and Abroad', linked below. There's a good audiobook version on Audible).
Training in this business is based on cultivating anti-social behavior in susceptible individuals. Just as you don't want any garden variety sociopaths in your life, you don't want to deal with people who've been trained to fuck with you.
http://press.georgetown.edu/book/georgetown/thwarting-enemie...
It really depends on many factors - location, group activities, training, personal, the threats they pose to the actors with the will/desire etc to target them, also how you define compromised (a cleaner keeping tabs? a phishing email opened? a disgruntled volunteer? a paid staff member who walks out the door with data? a leader who has been turned?)
This is actually my gripe with the Dutch pirate party. They are often very alarmist and exaggerate problems in the same way the parties they oppose do. I wish there was a party that's focuses on major issues in stead of exaggerating a small number of issues in order to get popular with a specific market.
I admit I might still vote for them anyway if I can't find a party that better represents me. Fortunately we get quite a few to choose from! Dutch might want to take a moment and be thankful we have that :)
As an example the Taliban was targeting NGOs in the Afghanistan/Pakistan region because they believed efforts to vaccinate against polio were in fact an attempt to poison Muslims. Dozens of doctors, nurses, and volunteers were killed because someone like you decided to start a baseless rumor.
Most first world intelligence agencies have policies against embedding spies in aid operations. When it became common knowledge we used a vaccination campaign to collect on UBL, many people resigned from the Agency.
I wrote about one aspect of that specific case here:
https://medium.com/@roryireland/latest-wikileaks-documents-i...
Or more likely a terrorist organization in those countries started such rumors to turn public sentiment against the west. Oh, and then the USG used a vaccination program to attempt to track down terrorists, which played a role in the take-down of Osama Bin Laden.
It's fair to say that there are compromised NGOs, based on the OBL incident alone.
Is it after tax?
> https://news.ycombinator.com/item?id=13484071
https://news.ycombinator.com/item?id=11273241#11273580
Or maybe he included some false info for noise injection... if so, how do we know which parts to believe? Skepticism suspension lifted, I suppose.
I understand how it can be viewed that way and it's certainly a bit of a risk but realistically it's not a huge risk.
If this is AVID, at the end of the day, despite what many may think due to outlying examples, they are an intelligence organisation working in a democracy and their agents aren't normally going to be in the business of retribution for someone turning down a pitch. Plus, if they became known for unnecessary retribution for minor things like someone saying no to a pitch, it would damage their long-term efforts in other areas.
They will expect that probably the majority of the pitches they make will be rejected. It's not something new to them. Similarly they will have risk assessed and planned for the eventuality of it being made public. Yes, it will annoy them but they will still just keep on moving through the social network analysis diagrams until they find and pitch the right people they are looking for.
Plus, while it will make some people more weary in future, occasionally exposure of efforts like this often leads to a softening up of others who might be interested in doing this sort of thing for them in future. Maybe a few months down the line someone in the community gets pissed off with others and remembers this article and drops AVID a mail........
Or maybe he included some false info for noise injection... if so, how do we know which parts to believe? Skepticism suspension lifted, I suppose.
By far the biggest part of what those teams do isn't secret and fits within the law. The "problem" is that Dutch law is very liberal on wire tapping, decryption etc as long as there is a reasonable suspicion and/or court order. Actually not far behind the rubber stamping in the US, but without the limitation that they can't target our own citizens (so: much worse than the US for locals, but similar for foreigners)
Obviously the military and domestic secret service hire the same people and have even wider abilities within the law and quite a wide grey area. Most of the public doesn't care enough to make it a political topic, so nobody stops them.