Hacker News new | ask | show | jobs
by wavefunction 4755 days ago
Just looking at the disk activity of reads, inspecting the memory dumps from these periods, and picking out what I can via a hex editor as far as what the "inspection" appears to be looking for via checksums derived from file blocks, which appear to be tied to images and videos. I'm assuming that this is domestic and not foreign, which I certainly could be wrong about. I'm also assuming they're looking for kiddie fiddlers, which I doubt someone like China would be all that interested in, but maybe the PRC is for blackmail purposes.

A lot of this stuff is sort of ephemeral and I don't have any credentials to really convince anyone. That's why I would post this, maybe someone else knows more than me. Like I said, take this as anecdotal and perhaps incorrect... You'll notice a lot of assumptions by me.

1 comments

Well, the behaviour you are describing just sounds like Microsoft's anti-virus software - and they have a datacenter in Georgia - something to consider.

If you are genuinely concerned I think it is pretty simple to contact real professionals with whatever data you have.

I don't know, the name service resolution terminated in a server with an open smtp relay, which might be what you're talking about but sounds strange. Plus, it's name service resolution for _all_ outbound traffic. Thanks for the tip though. Like I said, I'm just a computer hobbyist