Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

61–70 of 1001 posts

Re: CIA malware and hacking tools

#61
post #53

>"As of October 2014 the CIA was also looking at infecting the vehicle control systems used by modern cars and trucks. The purpose of such control is not specified, but it would permit the CIA to engage in nearly undetectable assassinations." Reminds me of the reporter who was supposedly working on a massive investigation and then died in a flaming car crash while skipping town. Forgot his name

Michael Hastings? [0] [0] https://en.wikipedia.org/wiki/Michael_Hastings_(journalist)

I had the same thought. Rest in peace.

Re: CIA malware and hacking tools

#62

This had the potential of being a positive development brought by Trump's election: many behaviors by the US three letter agencies that were glossed over for the past 8 years (due to the party in power being "on the right side of history") are again reprehensible and deemed a threat to be fought by the tech community.

Do you have any examples of them being glossed over?

Re: CIA malware and hacking tools

#63
post #38

Earlier quoted context omitted.

After Snowden, the Obama administration made a commitment to the tech community that it would not hoard security vulnerabilities, and would instead pass them on to vendors to fix. This release shows that they did not honour that commitment.

A government would only ever disclose a vulnerability once it has a better one to replace it. The government needs a method to counteract an attack from another source(thats their reasoning).

Not necessarily. The reasoning should surely be that if we can discover it and use it against them, then they can discover it and use it against us, therefore we should notify the vendors and have the vulnerability removed.

Re: CIA malware and hacking tools

#65
post #5

Based on the overview alone (of course I can't read the entire report that fast!), this is exactly what I expect a spy agency would be doing -- if they were not then I would be disappointed. What exactly in the admittedly shortened list am I supposed to be upset about? It makes no distinction between US citizens and overseas parties. If these actions are being done domestically against US citizens, with no just cause…

So you didn't read any of it nor wait for anyone else to but have already come to a number of overarching conclusions and dismiss the release as whole? I guess we can go ahead and close this particular thread then. If you don't want to read any of the source materials, you could possibly at least make the effort to respond to the various philosophical or policy questions this poses, that takes only an opinion.

They provided an overview which I read through, but I find it a bit silly to expect any single person to read through the entire report and fact-check it as well. That is what journalists are for.

Re: CIA malware and hacking tools

#66
The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation.

With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from.

This has interesting implications for the claim that "Russians" hacked the election (although I can't imagine the CIA wanting to hack the election in Trump's favour).

Re: CIA malware and hacking tools

#67

This had the potential of being a positive development brought by Trump's election: many behaviors by the US three letter agencies that were glossed over for the past 8 years (due to the party in power being "on the right side of history") are again reprehensible and deemed a threat to be fought by the tech community.

The tech community has been pretty up in arms against the three letter agencies ever since Snowden's revelation, so I'm not sure how Trump's election is going to change that; if anything it might produce the opposite effect since these agencies seem to be feuding with Trump on some level. Besides, wikieaks is a pro-Trump organization so I doubt that Trump losing the election would have caused them to go more softly with their criticisms of the government.

Re: CIA malware and hacking tools

#69
post #66

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation. With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from. Th…

Well you need to make it seem as if "the bad guys" are a threat regardless of the attack vector, digital or otherwise.

Re: CIA malware and hacking tools

#70
So will this zero days be reported to Google,Apple,Microsoft & Co.? Or is this more a "FYI document"? It seems you can be on the safer side if you use a more exotic phone OS which is not widely used or a more dumb feature phone.
Post reply on HN