Hacker News new | ask | show | jobs
by mantas 1082 days ago
Maybe German state itself is the actor.
3 comments

My bet is Russia.

I work in a German institution. I was recently hacked by such a botnet recently (lessons learned: use AuthorizedKeys, allow only one SSH user, proxy all http connections to a webhoster, and check your SSH and UFW logs often!)

It setup a virtual environment where it downloaded some kind of Tor node and ran some sort of code that used 100% of my CPU. My guess is crypto-mining. I purged the account, deleted everything before I could do forensics, but I checked the logs for the connections and they all came from Russia.

What state actor doesn’t understand statistical deanoymization attacks against tor?

(e.g., if you single-handedly double the network traffic, then an outside observer can figure out what ingress/egress traffic is yours)

Why pay attention to this if you can simply blame another state actor?

And German federal government have a history for covert shitposting.

    And German federal government have a history for covert shitposting.
Wow, I never heard this before. Can you provide some examples famous examples?
I remember there was a series of articles several years ago that German intelligence officers generated a lot activity in far-right websites. To the point that frequently it was mostly undercover „extremists“ discussing between themselves.

The closest article I can quickly find is about Germany intelligence informants doing the same in meatspace though.

> There was a "risk that sources of the intelligence service (Office for the Protection of the Constitution) could goad each other on to undertake bigger actions;" in other words, the system threatened to create an "incendiary effect."

https://www.spiegel.de/international/germany/german-police-d...

Can you explain more?