Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

171–180 of 1001 posts

Re: CIA malware and hacking tools

#171
post #92

In what is surely one of the most astounding intelligence own goals in living memory, the CIA structured its classification regime such that for the most market valuable part of "Vault 7" — the CIA's weaponized malware (implants + zero days), Listening Posts (LP), and Command and Control (C2) systems — the agency has little legal recourse. The CIA made these systems unclassified. Why the CIA chose to make its cyberar…

> This means that cyber 'arms' manufactures and computer hackers can freely "pirate" these 'weapons' if they are obtained. Does the author really think that if the tools were exposed then people who wanted to use these tools actually wouldn't simply because they were labelled "classified" somewhere?

The bigger issue I think is when the prosecution of the CIA leakers happens. If the material is unclassified, they're just distributing materials that are public domain and definitely in the interest of the public. If it's classified, it's a breach and they should be punished in some way.

Re: CIA malware and hacking tools

#172

EDIT: This post is no longer relevant. Meta: 351 points in Conclusion: HN is flagging this fairly aggressively. Question: Why? This is not overtly political, and it is definitely in the interest of the community, with the potential to be at least half as interesting as the Snowden documents or the hack of Hacking Team.

I'd be interested in PG doing a vote analysis on this particular thread to see if comment downvotes are concentrated from a particular source/region or spread evenly.

Re: CIA malware and hacking tools

#173
post #92

In what is surely one of the most astounding intelligence own goals in living memory, the CIA structured its classification regime such that for the most market valuable part of "Vault 7" — the CIA's weaponized malware (implants + zero days), Listening Posts (LP), and Command and Control (C2) systems — the agency has little legal recourse. The CIA made these systems unclassified. Why the CIA chose to make its cyberar…

Classified or not, works of the federal government are all in the public domain. And classification is not legally relevant to anyone except to those entrusted with protecting classified data.

Re: CIA malware and hacking tools

#174

So will this zero days be reported to Google,Apple,Microsoft & Co.? Or is this more a "FYI document"? It seems you can be on the safer side if you use a more exotic phone OS which is not widely used or a more dumb feature phone.

Security through obscurity isn't a thing

It's not security through obscurity (which I agree is bad). It's more like "more security" through "less market share".

Re: CIA malware and hacking tools

#175
post #170

Earlier quoted context omitted.

I didn't flag it, but I'd imagine a lot of people don't trust the source (any more). Edit: Why the downvotes? I didn't indicate my position, I pointed out that some people don't trust WikiLeaks any more, which is obvious - go and look at the responses they get on twitter.

Did I miss a memo? Wikileaks has done tireless work in this field and has largely been correct about its claims and the authenticity of its documents. If not Wikileaks, whom do we trust for this sort of info?

The infosec community has this insane conspiracy theory that Assange is owned by Putin.

Re: CIA malware and hacking tools

#176
post #83

This had the potential of being a positive development brought by Trump's election: many behaviors by the US three letter agencies that were glossed over for the past 8 years (due to the party in power being "on the right side of history") are again reprehensible and deemed a threat to be fought by the tech community.

I'm not a US citizen, but if I was, I would want professionals sworn to defend my country and the constitution to be able to modernize their capabilities. Today, these tools are essential to defense. It may turn out to have been the best defense against RU attempt to Balkanize USA.

The best offense is a good defense. Improving the quality of software in general would be far more beneficial than developing zero-day short-sighted tools.

Re: CIA malware and hacking tools

#177
Well, traveling to the US I have had to fill out a green form stating that I'm not a terrorist or a 40-45 Nazi. I guess they capture a lot of pathological truth-telling terrorists/Nazis with this piece of paper

Re: CIA malware and hacking tools

#178

EDIT: This post is no longer relevant. Meta: 351 points in Conclusion: HN is flagging this fairly aggressively. Question: Why? This is not overtly political, and it is definitely in the interest of the community, with the potential to be at least half as interesting as the Snowden documents or the hack of Hacking Team.

There are multiple articles for this topic on the front page. This is currently the top post but I think they're having issues merging in other discussions into this one. I keep seeing this flash in the top spot then see it redirect incorrectly/disappear temporarily.

Thanks for this. It has suddenly shot up to position #1, possibly due to resolution of reasons you cite.

Re: CIA malware and hacking tools

#179
post #66

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation. With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from. Th…

The term "hacked the election" goes beyond the literal computer hacking of the dnc. It also covers the well-targeted "fake news" propoganda program ... something not touched by the release of these tools.

The "hack" of the election was trickery to twist a system to a desired end. Like all good hacks it ignored definitions to employ whatever techiques were availible regardless. That some were not traditionally called "hacking" means nothing given the overall effectiveness of the program.

Re: CIA malware and hacking tools

#180
post #123
post #12

Wow this is really big. There are tons of documents about the various tools they use, but it seems the majority of the actual source code is still being reviewed and the links just show a link to the file list. I hope they eventually release the source code, as a lot of these tools seem very interesting. I can imagine that many at the CIA are running around on fire, as this seems like a big problem for them.

I'm pretty okay with wikileaks not releasing hundreds of zero day exploits into the wild en mass.

I'd like to hear a security expert's opinion on whether releasing even patched 0-days could be considered harmful ? even if the 'sploits dont work out of the box, it seems like they would still advance the state of the art, and allow moderately-skilled hackers to build on very sophisticated designs, adapt and make them effective again - "stand on the shoulders of giants" kind of thing.
Post reply on HN