In what is surely one of the most astounding intelligence own goals in living memory, the CIA structured its classification regime such that for the most market valuable part of "Vault 7" — the CIA's weaponized malware (implants + zero days), Listening Posts (LP), and Command and Control (C2) systems — the agency has little legal recourse. The CIA made these systems unclassified. Why the CIA chose to make its cyberar…
> Command & Control and Listening Post software were classified, then CIA officers could be prosecuted or dismissed for violating rules that prohibit placing classified information onto the Internet. Consequently the CIA has secretly made most of its cyber spying/war code unclassified. This is almost hilarious. Not that being classified would make any difference: cyber-"weapons" have something in common with biologic…
CIA malware and hacking tools
221–230 of 1001 posts
Re: CIA malware and hacking tools
#222Well, traveling to the US I have had to fill out a green form stating that I'm not a terrorist or a 40-45 Nazi. I guess they capture a lot of pathological truth-telling terrorists/Nazis with this piece of paper
That's form I-94W [1] for those who are curious. We also had to promise we'd not been traficking drugs and were not planning on engaging in illegal or immoral activities, and more. I always wonder how many idiots have been denied entry because they were dumb enough/drunk enough to think it'd be fun to tick the wrong box on that form. I also love how under the Paperwork Reduction Act they have had to estimate the burd…
Re: CIA malware and hacking tools
#223Well, traveling to the US I have had to fill out a green form stating that I'm not a terrorist or a 40-45 Nazi. I guess they capture a lot of pathological truth-telling terrorists/Nazis with this piece of paper
That's form I-94W [1] for those who are curious. We also had to promise we'd not been traficking drugs and were not planning on engaging in illegal or immoral activities, and more. I always wonder how many idiots have been denied entry because they were dumb enough/drunk enough to think it'd be fun to tick the wrong box on that form. I also love how under the Paperwork Reduction Act they have had to estimate the burd…
Re: CIA malware and hacking tools
#224Re: CIA malware and hacking tools
#225Earlier quoted context omitted.
Lol like anyone in this field cares about copyrights. It is like suggesting that North Korea cannot build nuclear bombs because doing so would infringe US patents. Some things are above IP rules.
Think about it. Having the code copyrighted, would leave a paper trail.
Having code be copyrighted does not require any explicit registration.
Re: CIA malware and hacking tools
#226Earlier quoted context omitted.
> Command & Control and Listening Post software were classified, then CIA officers could be prosecuted or dismissed for violating rules that prohibit placing classified information onto the Internet. Consequently the CIA has secretly made most of its cyber spying/war code unclassified. This is almost hilarious. Not that being classified would make any difference: cyber-"weapons" have something in common with biologic…
Obviously there's a difference between cyber and conventional weapons, but imagine if the same rationale were extended to physical munitions: "We can't drop this bomb on the enemy, it contains classified technology"
Re: CIA malware and hacking tools
#227Re: CIA malware and hacking tools
#228Based on the overview alone (of course I can't read the entire report that fast!), this is exactly what I expect a spy agency would be doing -- if they were not then I would be disappointed. What exactly in the admittedly shortened list am I supposed to be upset about? It makes no distinction between US citizens and overseas parties. If these actions are being done domestically against US citizens, with no just cause…
Re: CIA malware and hacking tools
#229This may sound stupid, but I'm wondering if using Windows Phone 8 (not Windows 10 mobile) might be a strong measure for protecting oneself against such attacks. First, it's quite restricted in terms of deep system access towards devs and users. Apps are sandboxed and extremely isolated from each other. Then, its market share is so low that probably no one makes an effort to build targeted attacks towards it.
Because few people use it, security testers probably don't spend much time on it. So it could be easier to find vulnerabilities.
It's also end of support 7/11/2017, so nothing will get patched after (unless you pay for extended support). That leaves you exposed to any critical vulnerability found after that point.
So obscurity might save you from widely targeted attacks at the majority (android, iOS), but wouldn't stop any targeted attack against you.