Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

211–220 of 1001 posts

Re: CIA malware and hacking tools

#211
post #9

- Smart TV turned into listening devices with fake off mode? - Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc. - Dozens of O-day attacks again Andriod and iPhone. Pretty powerful stuff.

The iOS attack breakdown lists a combination of vulnerabilities in very old versions of iOS, vulnerabilities first published by jailbreak teams, and a couple purchased vulnerabilities. The breakdown ends with a publicly jailbroken iOS version.

The Smart TV implant appears to just be a modified version of an open source firmware replacement project.

Re: CIA malware and hacking tools

#212
post #170

Earlier quoted context omitted.

I didn't flag it, but I'd imagine a lot of people don't trust the source (any more). Edit: Why the downvotes? I didn't indicate my position, I pointed out that some people don't trust WikiLeaks any more, which is obvious - go and look at the responses they get on twitter.

Did I miss a memo? Wikileaks has done tireless work in this field and has largely been correct about its claims and the authenticity of its documents. If not Wikileaks, whom do we trust for this sort of info?

Why trust any one source? Multiple sources is the way to go. And yes I am aware of what Wikileaks is and it's hard to find an alternative if there even is any. But my point is some day you'll be burned by relying only on a single source.

Re: CIA malware and hacking tools

#213
post #171

Earlier quoted context omitted.

> This means that cyber 'arms' manufactures and computer hackers can freely "pirate" these 'weapons' if they are obtained. Does the author really think that if the tools were exposed then people who wanted to use these tools actually wouldn't simply because they were labelled "classified" somewhere?

The bigger issue I think is when the prosecution of the CIA leakers happens. If the material is unclassified, they're just distributing materials that are public domain and definitely in the interest of the public. If it's classified, it's a breach and they should be punished in some way.

From the article it says that the files were circulating in the wild, so if this was not leaked to Wikileaks then "the bad guys" would continue using this and the public would not know.

Re: CIA malware and hacking tools

#214
post #60

Earlier quoted context omitted.

> If these actions are being done domestically against US citizens, with no just cause sure I will get upset, but that has yet to be seen. May I just ask, why does this distinction matter? Why do you believe the world should be divided into "people who were issued bits of paper by my overlords" and "people who weren't"? I never understood this division in other people's heads. It leads to all sorts of philosophical p…

That has less to do with how I feel and more to do with how the CIA is setup. Their role in domestic affairs is severely restricted, that is primarily the job of the FBI which has more requirements to conduct "searches". For them to be operating to the fullest extent of their perceived role, I can't find myself to be upset.

As you accept elsewhere, there is the law, and there is reality. Oversight is captured; the intelligence agencies and surrounding industry has been given almost everything they wanted, even retroactively[1].

Information sharing has also removed a lot of practical barriers; what does it mean for the CIA to be constrained if they can use other agencies for domestic work? Interdepartmental rivalry is still a constraint, but hardly one to count on.

When thinking about the value-add of agencies like this, analyzing black-letter law is close to useless. You have to look at what actually happens. Tricky, that, when talking about spies.

[1] One interesting question is how, as a practical matter, to provide systematic oversight of spies with the ability to monitor and anonymously leak details of the overseer's lives, blackmail/manipulate third parties, and selectively leak to the media.

Re: CIA malware and hacking tools

#215
post #198
post #100

Earlier quoted context omitted.

Again, I think there is a difference between the desired and realistic roles of an intelligence agency in disclosing exploits. Sure, I would hope they disclose them. But at the same time if they are actively using an exploit, I have pretty much no expectation of them disclosing it. I think this has way more to do with our reference-point than anything else. My expectations were never quite as high!

In other words, you feel attempting to constrain the operations of intelligence agencies is equivalent of asking nicely, and that's the way is should be?

I mean the mentioned attempt was not as general as it was made out to be. Obama placed an exception for “a clear national security or law enforcement need”. Pretty much what my expectations were set at. Again I am reluctant to take anything that Wikileaks says as absolute truth, they love to spin.

https://www.nytimes.com/2014/04/13/us/politics/obama-lets-ns...

Re: CIA malware and hacking tools

#216
post #195

OS-level backdoors can be easily patched. Unlike hardware based backdoors, curtesy of Intel AMT.

And yet the leaked tools don't seem to have much in the way of hardware-based exploits, which might say something about the feasibility of this kind of thing on actual systems. Obviously it can be done, but it were as pervasive as the tinfoil hatters believe, surely it would have shown up here. No?

Re: CIA malware and hacking tools

#217
post #92

In what is surely one of the most astounding intelligence own goals in living memory, the CIA structured its classification regime such that for the most market valuable part of "Vault 7" — the CIA's weaponized malware (implants + zero days), Listening Posts (LP), and Command and Control (C2) systems — the agency has little legal recourse. The CIA made these systems unclassified. Why the CIA chose to make its cyberar…

Classified or not, works of the federal government are all in the public domain. And classification is not legally relevant to anyone except to those entrusted with protecting classified data.

That is the fun part, attacking with a virus is basically the same as releasing the code (modulo IDA pro). So a US government official can not use a classified virus, while everybody else can.

Re: CIA malware and hacking tools

#218
post #170

Earlier quoted context omitted.

I didn't flag it, but I'd imagine a lot of people don't trust the source (any more). Edit: Why the downvotes? I didn't indicate my position, I pointed out that some people don't trust WikiLeaks any more, which is obvious - go and look at the responses they get on twitter.

Did I miss a memo? Wikileaks has done tireless work in this field and has largely been correct about its claims and the authenticity of its documents. If not Wikileaks, whom do we trust for this sort of info?

At best, Wikileaks has a strong political leaning that clouds their whistle-blowing mission and leads some to question their motivation (even several years ago, some commentators saw Wikileaks as less whistle-blower and more anti-United States -- http://foreignpolicy.com/2012/08/16/how-wikileaks-blew-it/). At worst, some charge that Wikileaks is essentially working for Russia at this point. (http://thehill.com/policy/cybersecurity/312964-us-finds-link...)

I've personally become convinced that the best way to release "leaks" of this nature is via the Panama Papers approach -- anonymously.

Re: CIA malware and hacking tools

#219
post #170

Earlier quoted context omitted.

I didn't flag it, but I'd imagine a lot of people don't trust the source (any more). Edit: Why the downvotes? I didn't indicate my position, I pointed out that some people don't trust WikiLeaks any more, which is obvious - go and look at the responses they get on twitter.

Did I miss a memo? Wikileaks has done tireless work in this field and has largely been correct about its claims and the authenticity of its documents. If not Wikileaks, whom do we trust for this sort of info?

Getting dumps and sitting on them/grooming/timing releases during the election, their twitter jumping on the Sweden bashing bandwagon [1-3] (because Assange was accused of rape there?), linking back to old Prism dumps after Trump tweets about wiretapping after reading an Infowars "article" [4] and speculating about it [5], etc etc.

I'm not sure if he's buttering up the administration to get out of Ecuador, but regardless, I trusted Wikileaks when they were [input] -> check for mostly pertinent info/responsible leaking -> [output].

The concept of wikileaks is crucial to a democracy, I'm just not sure that Assange's current Wikileaks is that thing anymore.

[1] https://twitter.com/wikileaks/status/838287615929499648

[2] https://twitter.com/wikileaks/status/837686443329859585

[3] https://twitter.com/wikileaks/status/837269295797309441

[4] https://twitter.com/wikileaks/status/838298128419852288

[5] https://twitter.com/wikileaks/status/838648893436903424

Re: CIA malware and hacking tools

#220
Just something totally ridiculous. These spyware / malware competitions remind me of poker in that these are games of imperfect information and we just throw hoops tring to gain a tiny bit more information than the next guy, to improve our bets.
Post reply on HN