Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

201–210 of 1001 posts

Re: CIA malware and hacking tools

#201

But considering that Wikileaks is essentially a Russian intelligence services front at this point, spreading this kind of disinformation does a great deal to muddy the waters about the hacking.

Can you point to any instance where WikiLeaks has released information that was not authentic and correct?

There's at least one case where they've deliberately excluded documents from a leak without a good explanation, which I think qualifies as a lie by omission: https://www.dailydot.com/layer8/wikileaks-syria-files-syria-...

Also, while I doubt they've ever released fake documents as part of a leak, they do often push incorrect and/or unverified theories and ideas on Twitter.

Re: CIA malware and hacking tools

#202
post #170

Earlier quoted context omitted.

Did I miss a memo? Wikileaks has done tireless work in this field and has largely been correct about its claims and the authenticity of its documents. If not Wikileaks, whom do we trust for this sort of info?

The infosec community has this insane conspiracy theory that Assange is owned by Putin.

I guess the Russians have no FSB hacking programs that Wikileaks could publish.

Re: CIA malware and hacking tools

#203
post #170

Earlier quoted context omitted.

I didn't flag it, but I'd imagine a lot of people don't trust the source (any more). Edit: Why the downvotes? I didn't indicate my position, I pointed out that some people don't trust WikiLeaks any more, which is obvious - go and look at the responses they get on twitter.

Did I miss a memo? Wikileaks has done tireless work in this field and has largely been correct about its claims and the authenticity of its documents. If not Wikileaks, whom do we trust for this sort of info?

You missed a pretty big memo.

Re: CIA malware and hacking tools

#204
post #66

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation. With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from. Th…

There also still hasn't been any public evidence that Wikileaks got their Podesta email data from Russians yet. So far we only know the DNC leaks were very likely Russian. That means until today only about ~50% of the 'election hacks' have been attributed to Russia with public evidence.

Now this leak calls into question some of the evidence about the DNC hack [1]. This evidence being the malware was Russian. But there were many other pieces of evidence that pointed to Russia so I'm personally not anymore persuaded it wasn't Russia for the DNC stuff. The Podesta stuff is still up in the air AFAIK. [edit: see pvg reply]

Either way this leak will just add to the deniability angle for the partisan hawks. Although this is probably way over the head of CNN/Fox News crowd so it's also possible it will have zero effect.

[1] Previous leaks mentioned NSA/Five Eyes collected foreign malware. This leaks adds CIA to that group and further solidifies the "misdirected attribution" angle.

Re: CIA malware and hacking tools

#205
post #107

Earlier quoted context omitted.

Can you point to any instance during the election when a leak was not precisely timed/filtered to damage the Clinton campaign and/or advantage the Trump campaign?

If anything Wikileaks presented a pretty ripe opportunity to replace Clinton with a candidate that could beat Trump in the general election. Nobody seized it and the Dem's lost. But yeah, blame Russia.

Except that they absolutely did nothing of the sort, they waited to leak their information until the primary was already over...

Re: CIA malware and hacking tools

#206

One very interesting thing is that the exploits, rootkits, etc are all unclassified and the CIA has no copyright on them either. The logic is supposedly that an agent putting a classified rootkit/trojan/whatever on a machine is mishandling classified information and thus it would be illegal.

Does that mean that someone who leaked them could not be prosecuted? Or simply that they would be prosecuted under some other law?

Or their life expectancy would decrease significantly.

Re: CIA malware and hacking tools

#207
This may sound stupid, but I'm wondering if using Windows Phone 8 (not Windows 10 mobile) might be a strong measure for protecting oneself against such attacks.

First, it's quite restricted in terms of deep system access towards devs and users. Apps are sandboxed and extremely isolated from each other. Then, its market share is so low that probably no one makes an effort to build targeted attacks towards it.

Re: CIA malware and hacking tools

#208

Well, traveling to the US I have had to fill out a green form stating that I'm not a terrorist or a 40-45 Nazi. I guess they capture a lot of pathological truth-telling terrorists/Nazis with this piece of paper

That's form I-94W [1] for those who are curious. We also had to promise we'd not been traficking drugs and were not planning on engaging in illegal or immoral activities, and more.

I always wonder how many idiots have been denied entry because they were dumb enough/drunk enough to think it'd be fun to tick the wrong box on that form.

I also love how under the Paperwork Reduction Act they have had to estimate the burden of filling it out, but seemingly not consider whether or not is serves any actual purpose to ask those questions in the first place.

[1] https://www.cbp.gov/sites/default/files/documents/%20I-94W%2...

Re: CIA malware and hacking tools

#209
I never read wikileaks but I did glance at a couple of things here - https://wikileaks.org/ciav7p1/cms/page_14587109.html

which are "do's and don't's" for malware writers. I like this:

S//NF) DO NOT perform operations that will cause the target computer to be unresponsive to the user (e.g. CPU spikes, screen flashes, screen "freezing", etc).

But the rationale is only:

(S//NF) Avoids unwanted attention from the user or system administrator to tool's existence and behavior.

It should go farther. When a user's impact is affected, this is a firm and definite step toward living in a police state.

I like the idea of a state where the director of the CIA can tell the President "We do not have private files on anyone, nor anything not directly related to imminent terror action and the like. We live in a free world, and if we didn't have people abducting others for ransom, planning terrorist activities, or the like, nobody country would need such capabilities.

Generally I am against a surveillance state and for one of these reasons I do not read these documents.

I also like this part:

(S//NF) DO make all reasonable efforts to minimize binary file size for all binaries that will be uploaded to a remote target (without the use of packers or compression). Ideal binary file sizes should be under 150KB for a fully featured tool.

To put this in perspective, if you were to load the front page of the wall street journal right now, your browser would download something like 900 KB.

I think getting 100 kb slipped in here or there that makes sure I'm not running a huge terrorist network is worse than the total inability for the government to do this if someone is.

it shouldn't impact my experience and it should be denied.

It's problematic that some of this is extralegal, but I'd rather not know about it than to have to have someone acknowledge its existence. Sorry.

if bitcoin assholes weren't ransoming people's pc's and life's work, or if people weren't being abducted for ransom, or if people weren't radicalized in a matter of weeks and then transmitted secret payments and chose to plough into a group of people celebrating independent democracy (the French 14 July thing with the truck), I might have a little more sympathy toward the idea that there doesn't need to be anything except might makes right on the Internet, letting users and terrorists do whatever they want and fend for themselves.

-

Edit: the cleanup/uninstall section explicitly mentions in the rational, not collecting private (unwanted) data. This might not be great but certainly sounds like the kind of hidden machinery you would want, in the kind of world we live in.

Re: CIA malware and hacking tools

#210
post #92

In what is surely one of the most astounding intelligence own goals in living memory, the CIA structured its classification regime such that for the most market valuable part of "Vault 7" — the CIA's weaponized malware (implants + zero days), Listening Posts (LP), and Command and Control (C2) systems — the agency has little legal recourse. The CIA made these systems unclassified. Why the CIA chose to make its cyberar…

Lol like anyone in this field cares about copyrights. It is like suggesting that North Korea cannot build nuclear bombs because doing so would infringe US patents. Some things are above IP rules.

Think about it. Having the code copyrighted, would leave a paper trail.
Post reply on HN