Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

221–230 of 1001 posts

Re: CIA malware and hacking tools

#221
post #142
post #92

In what is surely one of the most astounding intelligence own goals in living memory, the CIA structured its classification regime such that for the most market valuable part of "Vault 7" — the CIA's weaponized malware (implants + zero days), Listening Posts (LP), and Command and Control (C2) systems — the agency has little legal recourse. The CIA made these systems unclassified. Why the CIA chose to make its cyberar…

> Command & Control and Listening Post software were classified, then CIA officers could be prosecuted or dismissed for violating rules that prohibit placing classified information onto the Internet. Consequently the CIA has secretly made most of its cyber spying/war code unclassified. This is almost hilarious. Not that being classified would make any difference: cyber-"weapons" have something in common with biologic…

Obviously there's a difference between cyber and conventional weapons, but imagine if the same rationale were extended to physical munitions: "We can't drop this bomb on the enemy, it contains classified technology"

Re: CIA malware and hacking tools

#222
post #208

Well, traveling to the US I have had to fill out a green form stating that I'm not a terrorist or a 40-45 Nazi. I guess they capture a lot of pathological truth-telling terrorists/Nazis with this piece of paper

That's form I-94W [1] for those who are curious. We also had to promise we'd not been traficking drugs and were not planning on engaging in illegal or immoral activities, and more. I always wonder how many idiots have been denied entry because they were dumb enough/drunk enough to think it'd be fun to tick the wrong box on that form. I also love how under the Paperwork Reduction Act they have had to estimate the burd…

The purpose of these forms is to have an excuse to deport or deny your entry if it becomes convenient. The excuse will be that you lied on your form, regardless of what you put in it.

Re: CIA malware and hacking tools

#223
post #208

Well, traveling to the US I have had to fill out a green form stating that I'm not a terrorist or a 40-45 Nazi. I guess they capture a lot of pathological truth-telling terrorists/Nazis with this piece of paper

That's form I-94W [1] for those who are curious. We also had to promise we'd not been traficking drugs and were not planning on engaging in illegal or immoral activities, and more. I always wonder how many idiots have been denied entry because they were dumb enough/drunk enough to think it'd be fun to tick the wrong box on that form. I also love how under the Paperwork Reduction Act they have had to estimate the burd…

You misunderstand the point of the form. The point is that if later you are suspected of one of those activities, you can be deported because you lied on the form, even though it might be impossible to convict you for the activity itself.

Re: CIA malware and hacking tools

#225

Earlier quoted context omitted.

Lol like anyone in this field cares about copyrights. It is like suggesting that North Korea cannot build nuclear bombs because doing so would infringe US patents. Some things are above IP rules.

Think about it. Having the code copyrighted, would leave a paper trail.

Not really; copyright is mostly implicit. If US law made all code developed for the purposes of the CIA automatically copyrighted, the code would be copyrighted. Right now the law says it isn't, so it isn't.

Having code be copyrighted does not require any explicit registration.

Re: CIA malware and hacking tools

#226
post #142

Earlier quoted context omitted.

> Command & Control and Listening Post software were classified, then CIA officers could be prosecuted or dismissed for violating rules that prohibit placing classified information onto the Internet. Consequently the CIA has secretly made most of its cyber spying/war code unclassified. This is almost hilarious. Not that being classified would make any difference: cyber-"weapons" have something in common with biologic…

Obviously there's a difference between cyber and conventional weapons, but imagine if the same rationale were extended to physical munitions: "We can't drop this bomb on the enemy, it contains classified technology"

While the weapon too secret to use sounds very Dr Strangelove, there have been slightly similar things with real weapons. The one I remember is when radar-triggered proximity shells were invented at the end of WW2 they were only issued for use on ships, so that undetonated shells would fall into the sea, so couldn't be recovered and investigated by the enemy.

Re: CIA malware and hacking tools

#227
I am completely bemused that on the one hand the CIA is quite happy to literally murder, rape and and torture left right and centre, overthrow foreign governments, interfere with elections etc ... but is careful about adhering to the finer points US Constitution.

Re: CIA malware and hacking tools

#228
post #5

Based on the overview alone (of course I can't read the entire report that fast!), this is exactly what I expect a spy agency would be doing -- if they were not then I would be disappointed. What exactly in the admittedly shortened list am I supposed to be upset about? It makes no distinction between US citizens and overseas parties. If these actions are being done domestically against US citizens, with no just cause…

I believe the revelation here is the the CIA has built a duplicate version of the NSA, but with much further reach and less accountability.

Re: CIA malware and hacking tools

#229

This may sound stupid, but I'm wondering if using Windows Phone 8 (not Windows 10 mobile) might be a strong measure for protecting oneself against such attacks. First, it's quite restricted in terms of deep system access towards devs and users. Apps are sandboxed and extremely isolated from each other. Then, its market share is so low that probably no one makes an effort to build targeted attacks towards it.

Security through obscurity isn't a good practice in general.

Because few people use it, security testers probably don't spend much time on it. So it could be easier to find vulnerabilities.

It's also end of support 7/11/2017, so nothing will get patched after (unless you pay for extended support). That leaves you exposed to any critical vulnerability found after that point.

So obscurity might save you from widely targeted attacks at the majority (android, iOS), but wouldn't stop any targeted attack against you.

Post reply on HN