Is Your Mac Reporting Back to the US Army?是您的Mac报告回美国军队?
December 4th, 2007 · by David Bradley 2007年12月4日,由大卫布拉德利
Despite anecdotal claims to the contrary Apple Mac computers are not invulnerable.尽管有传闻声称,相反苹果的Mac电脑并非无懈可击。 As Sig Figs’ guest blogger作为SIG的无花果'客户的Blogger Jenny Oliver has reported previously珍妮奥利弗报道,以前 there are many security issues for Mac users.有很多的安全问题为Mac用户。 She sent me an update recently in which she seems to have uncovered a very worrying conspiracy surrounding a cluster of machines with an inbuilt trojan apparently reporting back to the US government.她寄给我的一更新最近,她在其中似乎已发现了一个非常令人担忧的阴谋,周围的一组机器与内在的木马报告,显然回向美国政府。
“It is now almost two months since I have been “现在是近两个月以来,我一直 unable to use my Macbook Pro online无法使用我的MacBook Pro在线 ,” she says. , “她说。 “After various offers to allow anti-cybercrime persons access to my computer for information-gathering purposes in the interests of national and international security, I realized that my personal and business needs were obviously greater and did a total erase and reinstall this week. “之后的各种优惠,让反网络犯罪的人进入我的电脑,为收集资料的目的,在利益的国家和国际安全,我意识到我的个人和企业的需要,显然更大,做了总擦除并重新安装这个星期。 The unidentified Trojan (or equivalent) had zombified my laptop, and the agency involved had jammed open ssh (secure shell handling)… this meant that they had complete control over it.身份不明的木马(或同等学历) ,已zombified我的笔记型电脑,该机构所涉及的已挤满了开放的SSH (安全壳处理) … …这意味着他们已经完整的控制权。 Indeed, if I had not used it in a while, it would hopefully switch itself on (even disconnected from the ‘net!), lid closed and all!事实上,如果我没有用它在一则,它希望切换本身就(甚至断开,从净! ) ,盖封闭,所有! Some programming skills there… note that the said ‘agency’ was waiting for a passing Mac-user to drop by.”一些编程技巧有…注意,该说'机构'正在等待路过的Mac用户,以减少“ 。
The panic begins when you do more digging than you should inside your machine.恐慌开始,当您做更多的挖掘比你应该内您的机器。 “When I first got my Mac, I did lots of exploring. “当我第一次得到我的Mac ,我没有很多的探索。 I noticed that if I fired up Network Utility, under the Info tab it would report a network connection which looked quite alien,” she adds, “This would only be visible if examined when completely disconnected from the Net.我注意到,如果我发射了网络实用工具,根据信息标签,它会报告网络连接,其中不少外国人看, “她补充说, ”这样做只会可见,如果审查时,完全断开净。 “Odd!” I thought, and supposed then that it must connect with Apple for some reason, and did not take the matter further. “奇怪! : ”我认为,假定,然后,它必须连接与苹果出于某种原因,并没有采取进一步行动。 It was only after I accidentally clicked on the bogus, malicious link in Google in September that I did some more investigation.这只是后,我不小心点击了假,恶意链接在Google在9月,我做了一些更多的调查。 The ‘default’ IP address was there after the hack, but it was then I recalled seeing it from the first … and the reinstall established that. '默认'的IP地址是有后开刀,但当时我记得看到它从第一… …和重新确立。 I looked up the address on www.arin.net - the American Registry of Internet Numbers.我翻查的地址www.arin.net -美国登录互联网的人数。 144.3.8.0. 144.3.8.0 。 The US Corps of Infrastructure and Engineers.美国兵团的基础设施和工程师。 This Corps is responsible for rebuilding in places such as Iraq and Afghanistan.”这个团是负责重建的地方,如伊拉克和阿富汗的“ 。
I did a quick Google for that IP address and discovered a discussion我做了快速Google的IP地址,并发现了一个讨论 forum论坛 talking rather haphazardly about the issue way back in November 2004, well before Jenny’s Mac purchase.谈,而不是胡乱对这个问题,早在2004年11月,以及前,珍妮的Mac购买。 Apparently the Apple Firewire TCP/IP defaults to a 144.xxx number on all Macs.显然苹果的FireWire的TCP / IP默认为1 144.xxx的数目对所有互委会。 What at first appears to be a US government conspiracy actually turns out to be nothing more than a legacy of the fact that the US government ran the first internet machines and these 144.xxx addresses are just some of the earliest IPs handed out to organisations, such as Apple, early on.是什么在第一次出现了美国政府的阴谋,其实原来是只不过是一个遗产的事实,即美国政府然第一次互联网机器和这些144.xxx的地址,只是一些最早的IPS移交给组织,如苹果,早在上。
Anders HiPhi speaking on that forum points out that, “The server is part of the European ORSN network - a 13 strong server array network - through which all European internet traffic passes.安德斯hiphi在谈到这个论坛指出, “服务器的一部分,欧洲orsn网络-一个1 3强S erver阵列的网络-通过所有的欧洲互联网流量通过。 The ORSN say they need the US side servers as they don’t have enough resources.” However, he asks, “Even if this is the reason for the IP to be a default in the OS, Apple has it’s own ORSN servers, so why should they program US ARMY servers as their deafult?该orsn说,他们需要美方的服务器,因为他们没有足够的资源。 “不过,他问道: ”即使这是理由的IP是一个默认情况下,在操作系统,苹果它自己的服务器orsn ,所以他们为何要计划,美陆军的服务器作为其deafult ? USACE are almost certainly responsible for Cyber Operations as part of their brief, so why have APPLE put US ARMY CyOps servers as a default when they could have used their own?” usace是几乎可以肯定,负责网络业务的一部分,他们的简短,那么,为何有苹果把美国军队cyops服务器作为默认时,他们可以用自己的“ ?
What does Apple have to say on this subject?什么是苹果不得不说关于这个问题的呢? Apparently, just because the machine defaults to this IP when it doesn’t have a real address to hook into does not mean it is an active address being packet sniffed by a US government employee.显然,仅仅因为机器默认为这个IP时,它没有一个真正的施政报告中钩到,并不意味着它是一个积极的地址被包sniffed由美国政府雇员。 It’s an它的一 inactive address无效地址 . 。
Who knows?谁知道? Maybe Jenny is right and there is a conspiracy.也许珍妮是正确的和有一个阴谋。 I’m of a mind to assume that it’s nothing more than a pingback address to an ancient timeserver that is no longer used by Apple’s Firewire drives but that was hardwired in early in the design and is so low priority that there is no impetus to remove it now.我的心态,假设它的只不过是一个pingback地址,以一个古老的时间服务器是不再使用苹果的FireWire硬盘,但被硬年初,在设计和是如此之低的优先是有没有动力,以消除现在。 Except that it would stop Mac users who dig too deep from worrying needlessly that the US Army is watching their every move.除外,它将停止Mac用户谁挖太深,从不必要的担心,美国军队正在注视他们的一举一动。 Indeed, I just spoke to Jenny Oliver again and she is relieved that I found this information but wonders why it is not more widely known and readily available to paranoid Mac users.事实上,我刚才的发言,以珍妮奥利弗再次和她是宽慰的是,我发现这方面的资料,但不知道为什么,这是不是更广为人知,而且现成的,以偏执的Mac用户。 Maybe there really is a conspiracy after all!也许真的是一个阴谋,毕竟!






















6 responses so far ↓六月的反应,到目前为止↓
David Bradley 大卫布拉德利 // / / Dec 4, 2007 at 10:55 am 2007年12月4日在上午10时55分
Similarly, scary news emerged in November that Maxtor, Seagate external hard drives were pre-loaded with同样地,可怕的新闻出现在11月,迈拓,希捷外置式硬盘驱动器被预先载入与 trojan horse software特洛伊木马病毒软件
Andy 安迪 // / / Dec 4, 2007 at 11:00 am 2007年12月4日上午11:00
Macs look nice inside and out - granted.互委会看看尼斯内-是理所当然的。
They get the job done, but I just can’t drag myself away from Bill’s Monopoly.他们完美地完成工作,但我只是不能拖到自己远离条例草案的垄断。
Windows has got all the options, dials, switches and levers that I crave to set things up just how I want them Windows已得到所有选项,拨号,交换机和杠杆,我渴望设置的东西,只是如何,我想他们
It will suck up every virus in sight, slow to a crawl and cause my hair to fall out sometimes but it’s become a habit - for better or worse - Bill’s got me right where he wants me它会抽走了每一个病毒的视线,缓慢,检索和事业,我的头发下降了,有时但它成为一种习惯-为更好或更坏-条例草案的了我的权利,他要我
I know that Macs have come forward a million miles and can run most Windows programs very well because of the Intel processors and the software available, but I just can’t do it.我知道,互委会有挺身而出, 1万英里,并可以运行大部分的Windows程序很清楚,由于英特尔处理器和软件可用,但我不能这样做。
As for anti virus software - I can recommend Panda.至于反病毒软件-我可以推荐大熊猫。
Jenny Oliver // 珍妮奥利弗 / / Dec 4, 2007 at 12:19 pm 2007年12月4日在下午12时19分
Thanks for publishing this, David.感谢发布此,大卫。 Well researched!经过充分研究的! I hope this reassures others like myself who perhaps did a little too much digging!我希望这放心别人像我这样谁,也许做了小太多挖! However, given the current high state of alert re cyber-crime and terrorist activities, it is highly negligent of Apple not to explain this in a more public way.然而,鉴于目前的高警戒状态,重新网络犯罪和恐怖活动,这是非常疏忽,苹果没有解释这在一个更公开的方式。 Their response to my attempts to communicate with them has been less than helpful until very recently… and no-one apart from you has given the above detailed answer, even now.他们的反应我试图与他们沟通已少于帮助,直到最近… …并没有一个人,除了你有鉴于上述详尽的答复,即使是现在。
I hope the lack of information will be rectified very soon, as it has been the absence of any knowledgeable response which has intensified the concern.我希望缺乏信息,将予以纠正很快,因为它已没有任何反应,知识化加大了关注。
With regard to Mac security, other users like myself might like also to keep an eye on a blog in the Washington Post by Brian Krebs, who reports on various computer security issues, including Macs.关于Mac安全性,其他用户可能会像我一样,也留意就一个博客在华盛顿邮报由Brian krebs ,谁报告,对各种电脑安全问题,包括互委会。
The latest item, just this November, is here:最新的项目,只是今年11月,是在这里: http://blog.washingtonpost.com/securityfix/2007/11/apple_plugs_44_security_holes_1.html
All the best!所有最好的!
Jenny Oliver // 珍妮奥利弗 / / Dec 4, 2007 at 4:16 pm 2007年12月4日在下午4时16分
Hi, again.您好,再次。
On re-reading this I seem to come over as mildly paranoid!关于重新读,这点我似乎来作为轻度偏执! To set the record straight, although I did wonder initially about being linked to the US Army, my major concern was that there might have been a considerable abuse of trust by Chinese manufacturers (given the nature of the Google hacks in Sept 07).设置纪录,虽然我本来不知道最初大约有联系的美国军队,我主要关注的问题是有可能已相当滥用信任由香港中华厂商(由于性质的Google黑客在9月7日) 。 The principal worry was that it might have been an outside agency which was misusing Macs to hack the west, not so much the US authorities snooping on us (which I find mildly preferable!).主要担心的是,它可能已外部机构是误用Mac电脑向哈克西,没有那么多美国当局对我们的窥视(我觉得轻度可取! ) 。 This was reinforced by reading about the head of MI5 voicing concerns on 1/12/07 in The Times.这是钢筋通过阅读有关负责人的MI5表达关切, 1/12/07在的时代。 http://business.timesonline.co.uk/tol/business/industry_sectors/technology/article2980250.ece
A few things are also still a little disturbing.几件事也仍然有点不安。 If the address is ‘not used’, why does it resolve?如果地址是'没有用' ,为何不解决呢? Why would ‘tracert’ try to find it?为什么会' TRACERT将尝试找到它呢? It gets as far as the Veterans Association and then bounces.它对于退伍军人协会,然后退回。 This seems to suggest it is valid, even if general public can’t reach it.这似乎表明,它是有效的,即使一般市民不能达到它。
Now back to restoring everything to my poor depleted Mac…..现在又回到恢复,一切为了我的穷人枯竭的Mac … .. :-[ : -[
David Bradley 大卫布拉德利 // / / Dec 4, 2007 at 5:15 pm 2007年12月4日下午5时15分
Yes Jenny, you maybe came across as slightly paranoid in my write-up…but as you know, just because you’re not paranoid doesn’t mean they aren’t out to get you.是珍妮,你可能遇到的作为略有偏执,我写了… …但如你所知,只是因为你长得很帅,不偏执,并不意味着他们是不是让你。 144.xxx may yet turn out to be some secret window through which Pentagon spooks are watching Mac users…I’ll keep digging, there are lots of references to that IP address on the web. 144.xxx还可能又被一些秘密的窗口,通过它,五角大楼spooks观看Mac使用者… …我会继续挖掘,有很多的提述,该IP地址在网站上。
Jenny Oliver // 珍妮奥利弗 / / Dec 5, 2007 at 9:25 am 2007年12月5日在上午09时25分
I know it’s unladylike, but我知道它的unladylike ,但
! !
OK, ‘business’.确定, 『商贸』 。 The matter has indeed been around for some time: snippet from an Apple Insider forum, from ‘John’:此事实际上已靠近一些时间:片段,从一个苹果内幕论坛,从'约翰' :
‘I got curious about this, so I e-mailed the contact person for the IP address: '我好奇这一点,所以我电子邮箱及联络人,为IP地址:
“This IP address is showing up on my Ethernet Interface (fw0) (Firewire or high-speed IEEE 1394 Serial Bus) on my Apple Computer. “这个IP地址是显示我的以太网接口( fw0 ) ( FireWire或超高速的IEEE 1394串行总线)对我的苹果电脑。 This is the contact e-mail given by whois for that IP address.这是联系人电子邮件所给予的WHOIS为IP地址。 Do you have any idea why your IP address is showing up my computer?你有什么想法,为什么您的IP地址是显示我的电脑吗?
John”约翰“
Reply:答复:
From:来自: Gary.W.Decoff@us.army.mil gary.w.decoff @ us.army.mil
Date: January 3, 2005 4:36:02 AM PST日期: 2005年1月3日上午04时36分02秒太平洋标准时间
Subject: RE: IP Address 144.3.8.0主题: Re : IP地址144.3.8.0
Cc:抄送: Gerald.G.Roy@erdc.usace.army.mil gerald.g.roy @ erdc.usace.army.mil
“John, “约翰,
Yes I do know why.__ Apple Computer is using my IP space as a default for some of their interfaces….是我所知道的why.__苹果电脑是用我的IP地址空间作为默认为他们的一些接口… … 。
Please bring this to the attention of Apple Computer…__ If enough people tell them about this then just maybe they will stop doing it…请携带注意这一点,苹果电脑… __如果有足够的人告诉他们,这只是也许他们将停止这样做…
Thanks谢谢
Gary”程介南“
Go figure.去的数字。
Edited: I sent it in as a bug report to Apple.’编辑:我发出它在作为一个bug报告中,苹果。
Several years later and the message still hasn’t got through!数年后,和讯息至今仍没有获得通过! Perhaps it will now?也许它现在将?
Leave a Comment留下意见