the grugq's newsletter

Subscribe
Archives
March 5, 2024

March 5, 2024

March 5, 2024

Update: my editor canceled. I got a new editor. I’ve managed, through hard work and judicious use of the delete key, to squeeze my manuscript from 13k words down to just 17k. Absolutely on track for the 12k target.

Let’s do another thread on the Soviet NC3.

One may have noticed that Soviets have shifted to highly automated main NC3 system for the SMFs starting from late 1960s.

Communications for this (and follow up) system(s) were built upon data exchange via formalised messages.

1/8 pic.twitter.com/QgDheIXMaj

— krakek (@krakek1) March 2, 2024


Breaking bare metal firmware encryption (FortiGate firewalls) for security research.
Credits Jon Williams (@bishopfox)https://t.co/IezIyMddWF#Fortinet #infosec pic.twitter.com/wuoOskEIZk

— 0xor0ne (@0xor0ne) March 4, 2024


The dork who leaked classified United States military documents on a Minecraft Discord server has plead guilty. He is facing 10 years in prison.https://t.co/uQDw2cOIYO

— vx-underground (@vxunderground) March 5, 2024


Which way, Western Intelligence Officer? https://t.co/yx43ZswArk pic.twitter.com/QflZosfKQo

— Michael Senters the Sigillite (Yang Wen-Li stan) (@mike_senters) March 4, 2024

BREAKING: U.S. Air Force employee charged with giving classified information to woman he met on dating site pic.twitter.com/NMavGaL1Xp

— BNO News (@BNONews) March 4, 2024


This is probably the best media write-up on the Taurus leaks, what comms are allowed in the Bundeswehr, and why ppl dont use more secure comms.
Link (in German)https://t.co/5V4yG9lnnB

— Stefan Soesanto (@iiyonite) March 5, 2024

Clearly Germany needs some sort of secure communications platform. There’s no better time for:

EncroChat, GmbH

— thaddeus e. grugq thegrugq@infosec.exchange (@thegrugq) March 5, 2024


“why do you have a messy pile of clothes in the chair?”

it’s L1 cache for fast random access to our frequently used clothes in O(1) time

— ash (@ashleyyjoelle) March 4, 2024


stop ✋ be so real with me right now.. you guys did NOT try to make polyamory into an optimization problem pic.twitter.com/6j0BIyxOaY

— cora kyler // (@KylerCora) March 4, 2024

"feds screwed us over" pic.twitter.com/iwfGkagVFu

— 𝕯𝖒𝖎𝖙𝖗𝖞 𝕾𝖒𝖎𝖑𝖞𝖆𝖓𝖊𝖙𝖘 (@ddd1ms) March 5, 2024

This is about a 22M payment that was owed to an affiliate but was transferred away. The affiliates claim that ALPHV stole the money. ALPHV is allegedly claiming the feds screwed them over and they’re shutting down.

Tho is how to do a cyber operation against a ransomware group. They are vulnerable, but not to deleting their servers. Instead they are vulnerable to attacks against their reputation and trust networks necessary for the system to operate.

The way that the Feds broke the New York mafia was with plea deals and witness protection. They were willing to cut a deal with anyone to get anyone. Normally the strategy was to get pleas from smaller fish to get bigger fish. What they did instead was allowed bigger fish to plea out and turn on smaller fish.

The result becomes a Capo who can tell you to go murder someone and then can testify against you and walk off free. It destroyed the trust inside the system. No one was safe from anyone, and the first person caught would get away with everything while the rest were left holding the bag.

Cite:

Bugs, Bulls & Rats. By Frank Palmeri

https://www.amazon.com/Bugs-Bull-Rats-Insiders-Self-destructed/dp/1621832821/ref=sr_1_1

Don't miss what's next. Subscribe to the grugq's newsletter:
Start the conversation:
X