Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

191–200 of 1001 posts

Re: CIA malware and hacking tools

#191
post #9

- Smart TV turned into listening devices with fake off mode? - Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc. - Dozens of O-day attacks again Andriod and iPhone. Pretty powerful stuff.

> Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc.

This basically means if your device is compromised, expect malware to be able to read all content (including Signal, WhatsApp messages). Nothing new. The way it's phrased makes it sound like Signal, WhatsApp have vulnerabilities, but no, the intention is sensationalism over sound analysis.

Re: CIA malware and hacking tools

#192
post #171

Earlier quoted context omitted.

> This means that cyber 'arms' manufactures and computer hackers can freely "pirate" these 'weapons' if they are obtained. Does the author really think that if the tools were exposed then people who wanted to use these tools actually wouldn't simply because they were labelled "classified" somewhere?

The bigger issue I think is when the prosecution of the CIA leakers happens. If the material is unclassified, they're just distributing materials that are public domain and definitely in the interest of the public. If it's classified, it's a breach and they should be punished in some way.

Shirley your joking, you think they give a shit

Re: CIA malware and hacking tools

#193
post #5

Based on the overview alone (of course I can't read the entire report that fast!), this is exactly what I expect a spy agency would be doing -- if they were not then I would be disappointed. What exactly in the admittedly shortened list am I supposed to be upset about? It makes no distinction between US citizens and overseas parties. If these actions are being done domestically against US citizens, with no just cause…

You don't have to be upset to find something interesting and worthy of discussion.

Re: CIA malware and hacking tools

#194
post #170

Earlier quoted context omitted.

I didn't flag it, but I'd imagine a lot of people don't trust the source (any more). Edit: Why the downvotes? I didn't indicate my position, I pointed out that some people don't trust WikiLeaks any more, which is obvious - go and look at the responses they get on twitter.

Did I miss a memo? Wikileaks has done tireless work in this field and has largely been correct about its claims and the authenticity of its documents. If not Wikileaks, whom do we trust for this sort of info?

Wikileaks' 'analysis', which is what this link is about, has always been fanciful and shoddy. I don't trust them to be doing any kind of 'analysis'.

Re: CIA malware and hacking tools

#196

Earlier quoted context omitted.

In that case, you say "I can't answer that question" and let the system do its job. You don't lie.

No. The only way he couldn't answer the question was if the program existed, thus revealing the existence of the program, so he had to lie.

Thus my point. The CIA should not be running programs that "do not exist". Classified, sure, but not hidden programs nobody knows about. That is not what we are paying them for.

Re: CIA malware and hacking tools

#197

Earlier quoted context omitted.

> I'm not sure how Trump's election is going to change that; if anything it might produce the opposite effect since these agencies seem to be feuding with Trump on some level A big part of Trump's appeal is that he's seen as anti-establishment. I don't think it's unreasonable to expect that he may make significant changes at those agencies as a result of their "feuding" with him. > wikieaks is a pro-Trump organizatio…

> I don't think it's unreasonable to expect that he may make significant changes at those agencies as a result of their "feuding" with him. And? What does that have to do with the tech community being critical of three letter agencies? > but their reason for doing so was orthogonal to Trump himself. I don't care what the reasoning is, Assange explicitly stated that he wasn't going to release info on Trump because he…

Can you source Assange stating this? As far as I remember, his explanation was that since there was already a bevy of mainstream media ready to publish any dirt on Trump, leakers did not have to go to Wikileaks to publish their stories, therefore it was unlikely anyone would send their leaks there.

Re: CIA malware and hacking tools

#198
post #100
post #32

Earlier quoted context omitted.

> this is exactly what I expect a spy agency would be doing From Wikileaks' overview: "In the wake of Edward Snowden's leaks about the NSA, the U.S. technology industry secured a commitment from the Obama administration that the executive would disclose on an ongoing basis — rather than hoard — serious vulnerabilities, exploits, bugs or "zero days" to Apple, Google, Microsoft, and other US-based manufacturers. ... "Y…

Again, I think there is a difference between the desired and realistic roles of an intelligence agency in disclosing exploits. Sure, I would hope they disclose them. But at the same time if they are actively using an exploit, I have pretty much no expectation of them disclosing it. I think this has way more to do with our reference-point than anything else. My expectations were never quite as high!

In other words, you feel attempting to constrain the operations of intelligence agencies is equivalent of asking nicely, and that's the way is should be?

Re: CIA malware and hacking tools

#199
post #66

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation. With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from. Th…

I'm wondering if these documents are going to match the same ones that were taken by Harold Martin III and if the CIA will out him as the Wikileaks source.

These documents were being passed around by former CIA hackers. It says this right on the page. Harold has already been disproven to have any connection to leaks. He was just a hoarder with a mental illness.

This hasn't stopped people from connecting every leak since his arrest to him.

Re: CIA malware and hacking tools

#200
post #32
post #5

Based on the overview alone (of course I can't read the entire report that fast!), this is exactly what I expect a spy agency would be doing -- if they were not then I would be disappointed. What exactly in the admittedly shortened list am I supposed to be upset about? It makes no distinction between US citizens and overseas parties. If these actions are being done domestically against US citizens, with no just cause…

> this is exactly what I expect a spy agency would be doing From Wikileaks' overview: "In the wake of Edward Snowden's leaks about the NSA, the U.S. technology industry secured a commitment from the Obama administration that the executive would disclose on an ongoing basis — rather than hoard — serious vulnerabilities, exploits, bugs or "zero days" to Apple, Google, Microsoft, and other US-based manufacturers. ... "Y…

by definition a zero day is unknown, if they detect that it's being used in the wild then they can easily trigger the software vendor to issue emergency patches or plant the story somewhere - hell, they can even release counter malware that can mitigate

they have absolutely no reason to reveal their inventory of zero daze; that's not to say they're not morally obligated to do so, but when have morals driven their actions?

Post reply on HN