Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

51–60 of 1001 posts

Re: CIA malware and hacking tools

#51

I wander what phones / computers CIA operatives use - do they have special patched versions which address the zero day exploits they are aware of.

This is a great question. Surely they look for vulnerabilities also in their own systems but then what do they do when they find them? Is there some special set of software that always gets patched because the CIA uses it?

Re: CIA malware and hacking tools

#52

This idea that the government should somehow be exempt from proper cybersecurity ethics is disgusting. When the CIA or the NSA find zero day attacks in software, they should report them immediately to be fixed, not build tools specifically to exploit them. It's only a matter of time before these attacks either leak or are rediscovered by other malicious parties. The government is effectively turning their own people…

I think that's an absurd position. The government has a need to be able to access hostile systems. A hacked computer can avoid armed conflict where people die. A better question is... why aren't major vendors devoting a fraction of the resources to find this stuff and fix t on their own?

> A hacked computer can avoid armed conflict where people die.

Yet we see armed conflicts with CIA origins within plenty of history books...

Re: CIA malware and hacking tools

#53

>"As of October 2014 the CIA was also looking at infecting the vehicle control systems used by modern cars and trucks. The purpose of such control is not specified, but it would permit the CIA to engage in nearly undetectable assassinations." Reminds me of the reporter who was supposedly working on a massive investigation and then died in a flaming car crash while skipping town. Forgot his name

Michael Hastings? [0]

[0] https://en.wikipedia.org/wiki/Michael_Hastings_(journalist)

Re: CIA malware and hacking tools

#54
post #5

Based on the overview alone (of course I can't read the entire report that fast!), this is exactly what I expect a spy agency would be doing -- if they were not then I would be disappointed. What exactly in the admittedly shortened list am I supposed to be upset about? It makes no distinction between US citizens and overseas parties. If these actions are being done domestically against US citizens, with no just cause…

So you didn't read any of it nor wait for anyone else to but have already come to a number of overarching conclusions and dismiss the release as whole?

I guess we can go ahead and close this particular thread then. If you don't want to read any of the source materials, you could possibly at least make the effort to respond to the various philosophical or policy questions this poses, that takes only an opinion.

Re: CIA malware and hacking tools

#55
I'm surprised so many acronyms from their org chart are missing.

FINO is Financial Operations Group. FIO is Field Intelligence Officer. ESD is Executive Services Directorate. Don't see a single term that anyone who spent any time in the intelligence community wouldn't recognize.

Re: CIA malware and hacking tools

#56

I hope Europe and Germany especially finally wake up and start kicking out these pests. The US/CIA is conducting crimes against humanity on foreign soil. Like the drone war. The US may not be part of the international court but Germany is.

Germany knows they're there, are you kidding?

A slight correction: "Germany is an US occupied country since the end of WWII".

This is the truth about Nato, friendship between US and Japan, EU countries, South Korea, etc... There are no friends in geopolitics, only masters and slaves.

Re: CIA malware and hacking tools

#57
post #38

Earlier quoted context omitted.

LoL why are you so naive? It's CIA, not google Zero day project

After Snowden, the Obama administration made a commitment to the tech community that it would not hoard security vulnerabilities, and would instead pass them on to vendors to fix. This release shows that they did not honour that commitment.

A government would only ever disclose a vulnerability once it has a better one to replace it. The government needs a method to counteract an attack from another source(thats their reasoning).

Re: CIA malware and hacking tools

#58

This idea that the government should somehow be exempt from proper cybersecurity ethics is disgusting. When the CIA or the NSA find zero day attacks in software, they should report them immediately to be fixed, not build tools specifically to exploit them. It's only a matter of time before these attacks either leak or are rediscovered by other malicious parties. The government is effectively turning their own people…

We are past the point of holding them to even basics ethics. The CIA and NSA already see the people as cannon fodder at best. If we can no longer expect moral behavior concerning issues like black sites for torture, drug trafficking, or setting up murder and rape regimes, then why even waste the breath asking for cybersecurity ethics?

Re: CIA malware and hacking tools

#59

I wonder if, supposing a legit war use, those tools would work. Maybe in taking down some enemy tech infra, but on collecting information, i really have doubts. That would be too much data to process unless they had specific targets. Human intelligence would be much more effective. Anyway, I remember a story of a US submarine that hacked soviet cables in the 70s or 80s.

More, being those tools not effective, development and maintenance is stupid spending, and certainly the tools are having other uses.

My conspiracy side looks at CIA like a public sector (state owned) company in Brazil: they are not owned by the government, but by the chaste of unionized workers that work there.

Re: CIA malware and hacking tools

#60
post #5

Based on the overview alone (of course I can't read the entire report that fast!), this is exactly what I expect a spy agency would be doing -- if they were not then I would be disappointed. What exactly in the admittedly shortened list am I supposed to be upset about? It makes no distinction between US citizens and overseas parties. If these actions are being done domestically against US citizens, with no just cause…

> If these actions are being done domestically against US citizens, with no just cause sure I will get upset, but that has yet to be seen. May I just ask, why does this distinction matter? Why do you believe the world should be divided into "people who were issued bits of paper by my overlords" and "people who weren't"? I never understood this division in other people's heads. It leads to all sorts of philosophical p…

That has less to do with how I feel and more to do with how the CIA is setup. Their role in domestic affairs is severely restricted, that is primarily the job of the FBI which has more requirements to conduct "searches". For them to be operating to the fullest extent of their perceived role, I can't find myself to be upset.
Post reply on HN