Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

31–40 of 1001 posts

Re: CIA malware and hacking tools

#31

This idea that the government should somehow be exempt from proper cybersecurity ethics is disgusting. When the CIA or the NSA find zero day attacks in software, they should report them immediately to be fixed, not build tools specifically to exploit them. It's only a matter of time before these attacks either leak or are rediscovered by other malicious parties. The government is effectively turning their own people…

LoL why are you so naive? It's CIA, not google Zero day project

Re: CIA malware and hacking tools

#32
post #5

Based on the overview alone (of course I can't read the entire report that fast!), this is exactly what I expect a spy agency would be doing -- if they were not then I would be disappointed. What exactly in the admittedly shortened list am I supposed to be upset about? It makes no distinction between US citizens and overseas parties. If these actions are being done domestically against US citizens, with no just cause…

> this is exactly what I expect a spy agency would be doing

From Wikileaks' overview:

"In the wake of Edward Snowden's leaks about the NSA, the U.S. technology industry secured a commitment from the Obama administration that the executive would disclose on an ongoing basis — rather than hoard — serious vulnerabilities, exploits, bugs or "zero days" to Apple, Google, Microsoft, and other US-based manufacturers. ... "Year Zero" documents show that the CIA breached the Obama administration's commitments. Many of the vulnerabilities used in the CIA's cyber arsenal are pervasive and some may already have been found by rival intelligence agencies or cyber criminals."

By not releasing this information to technology companies affected, they are increasing the risk of the same exploits being used against high profile US targets.

Re: CIA malware and hacking tools

#34

This idea that the government should somehow be exempt from proper cybersecurity ethics is disgusting. When the CIA or the NSA find zero day attacks in software, they should report them immediately to be fixed, not build tools specifically to exploit them. It's only a matter of time before these attacks either leak or are rediscovered by other malicious parties. The government is effectively turning their own people…

True, but that's a general indictment of any spy agency for any country. More broadly than just software, their mission is to control information...who gets it / who doesn't.

Re: CIA malware and hacking tools

#35
This is an incredible and sensational claim that, if true, can quite literally "break the internet". Makes me very sad to imagine that CIA grade cyber weapons for getting into iPhones are now in the hands of heaven knows who. Hope Apple security teams are on this.

EDIT: To clarify, I'm commenting on the original situation of the tools getting out of CIA to the entities it was "circulated to", not this leak later by WikiLeaks - presumably the damage has already been done.

Re: CIA malware and hacking tools

#36

This idea that the government should somehow be exempt from proper cybersecurity ethics is disgusting. When the CIA or the NSA find zero day attacks in software, they should report them immediately to be fixed, not build tools specifically to exploit them. It's only a matter of time before these attacks either leak or are rediscovered by other malicious parties. The government is effectively turning their own people…

LoL why are you so naive? It's CIA, not google Zero day project

The parent isn't being naïve, they take issue with the current state of affairs and tell how they would like it to work. They're not surprised that that's not the case.

Re: CIA malware and hacking tools

#38

This idea that the government should somehow be exempt from proper cybersecurity ethics is disgusting. When the CIA or the NSA find zero day attacks in software, they should report them immediately to be fixed, not build tools specifically to exploit them. It's only a matter of time before these attacks either leak or are rediscovered by other malicious parties. The government is effectively turning their own people…

LoL why are you so naive? It's CIA, not google Zero day project

After Snowden, the Obama administration made a commitment to the tech community that it would not hoard security vulnerabilities, and would instead pass them on to vendors to fix.

This release shows that they did not honour that commitment.

Post reply on HN