NSA Uses Windows Error Messages To Spy On Users

mercurial

MyBB Legend
Joined
Jun 12, 2007
Messages
40,900
Reaction score
2,694
Location
/\/¯¯¯¯¯\/\
Not sure if already posted...

Microsoft Windows crash reporting system used by NSA for ‘passive’ spying, report says

x2622_nsa.jpg

Agents with the U.S. National Security Agency are able to intercept crash reports from specific Microsoft Windows-based machines to better understand how to exploit a computer with spyware, according to the latest revelations about the U.S. government’s electronic surveillance program, published this weekend by Der Spiegel newsmagazine.

The system is the one encountered by users after a program crashes, asking if they want to send information to Microsoft about the problem. The NSA tactic, revealed in a presentation viewed by Der Spiegel, reportedly uses the agency’s high-tech spying tools to access a machine being used by someone targeted in an NSA investigation. The tools allow NSA agents to receive notifications when the target’s computer crashes.
Here is Der Spiegel’s explanation of how the information is used:

The automated crash reports are a “neat way” to gain “passive access” to a machine, the presentation continues. Passive access means that, initially, only data the computer sends out into the Internet is captured and saved, but the computer itself is not yet manipulated. Still, even this passive access to error messages provides valuable insights into problems with a targeted person’s computer and, thus, information on security holes that might be exploitable for planting malware or spyware on the unwitting victim’s computer.
Although the method appears to have little importance in practical terms, the NSA’s agents still seem to enjoy it because it allows them to have a bit of a laugh at the expense of the Seattle-based software giant. In one internal graphic, they replaced the text of Microsoft’s original error message with one of their own reading, “This information may be intercepted by a foreign sigint system to gather detailed information and better exploit your machine.” (“Sigint” stands for “signals intelligence.”)

The same Der Spiegel report said that a special NSA unit can also intercept computer shipments to plant malware on a machine being sent to someone they want to spy on.

Read more at source
 
I don't quite see the benefit they could derive from this info tbh. Its just dumps of boring DLL crap. I suppose you could maybe get some info on what versions of components the PC is running and then hopefully find/have a suitable exploit...but really that sounds like way to much hassle.
 
I think a lot of the reports were written to justify various NSA agent's cushy existence. More about the capabilities/possibilities rather than something they would ever take the effort to put into practice. Tens of thousand of employees, tens of billions of budget dollars and very little to show for it... they have to talk a good game to keep the good times rolling.
 
Anyway, if they really do intercept this info, then I think we should be careful about letting other applications submit "annonymous" usage info, as that will possibly be a lot more interesting to the ###.
 
Does anyone actually ever submit these? :confused:
Yep. Depends on the program though - e.g. in windows I do because its painless. A certain other corporate email program's bug submissions thing is a PoS and takes long though so there...no.

Bwahahahaha.

Those errors contain a lot of useless DLL's and code (where the problem occurred) ....
And yet they really seem to be doing this...I guess they really want *all* the info.
 
Top
Sign up to the MyBroadband newsletter
X