mercurial
MyBB Legend
Not sure if already posted...
Microsoft Windows crash reporting system used by NSA for ‘passive’ spying, report says
Read more at source
Microsoft Windows crash reporting system used by NSA for ‘passive’ spying, report says
Agents with the U.S. National Security Agency are able to intercept crash reports from specific Microsoft Windows-based machines to better understand how to exploit a computer with spyware, according to the latest revelations about the U.S. government’s electronic surveillance program, published this weekend by Der Spiegel newsmagazine.
The system is the one encountered by users after a program crashes, asking if they want to send information to Microsoft about the problem. The NSA tactic, revealed in a presentation viewed by Der Spiegel, reportedly uses the agency’s high-tech spying tools to access a machine being used by someone targeted in an NSA investigation. The tools allow NSA agents to receive notifications when the target’s computer crashes.
Here is Der Spiegel’s explanation of how the information is used:
The automated crash reports are a “neat way” to gain “passive access” to a machine, the presentation continues. Passive access means that, initially, only data the computer sends out into the Internet is captured and saved, but the computer itself is not yet manipulated. Still, even this passive access to error messages provides valuable insights into problems with a targeted person’s computer and, thus, information on security holes that might be exploitable for planting malware or spyware on the unwitting victim’s computer.
Although the method appears to have little importance in practical terms, the NSA’s agents still seem to enjoy it because it allows them to have a bit of a laugh at the expense of the Seattle-based software giant. In one internal graphic, they replaced the text of Microsoft’s original error message with one of their own reading, “This information may be intercepted by a foreign sigint system to gather detailed information and better exploit your machine.” (“Sigint” stands for “signals intelligence.”)
The same Der Spiegel report said that a special NSA unit can also intercept computer shipments to plant malware on a machine being sent to someone they want to spy on.
Read more at source
