Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

241–250 of 1001 posts

Re: CIA malware and hacking tools

#241
post #176
post #83

Earlier quoted context omitted.

I'm not a US citizen, but if I was, I would want professionals sworn to defend my country and the constitution to be able to modernize their capabilities. Today, these tools are essential to defense. It may turn out to have been the best defense against RU attempt to Balkanize USA.

The best offense is a good defense. Improving the quality of software in general would be far more beneficial than developing zero-day short-sighted tools.

I've never heard the phrase "the best offense is a good defense," but I have heard a great many times the phrase "the best defense is a good offense." I don't have any data to back it up, but inclined to believe the more popular form of the statement.

Re: CIA malware and hacking tools

#242

I wonder if, supposing a legit war use, those tools would work. Maybe in taking down some enemy tech infra, but on collecting information, i really have doubts. That would be too much data to process unless they had specific targets. Human intelligence would be much more effective. Anyway, I remember a story of a US submarine that hacked soviet cables in the 70s or 80s.

  > Anyway, I remember a story of a US submarine that hacked soviet cables in the 70s or 80s.
Operation Ivy Bells https://en.wikipedia.org/wiki/Operation_Ivy_Bells

One of the tapping devices http://i.imgur.com/PgOJSTp.jpg

I believe a few of those devices are on display in some museum in Russia.

Re: CIA malware and hacking tools

#243
post #204
post #66

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation. With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from. Th…

There also still hasn't been any public evidence that Wikileaks got their Podesta email data from Russians yet. So far we only know the DNC leaks were very likely Russian. That means until today only about ~50% of the 'election hacks' have been attributed to Russia with public evidence. Now this leak calls into question some of the evidence about the DNC hack [1]. This evidence being the malware was Russian. But ther…

The circumstantial evidence in the Podesta phishing is pretty decent, not really 'up in the air'.

https://www.secureworks.com/research/threat-group-4127-targe...

https://twitter.com/pwnallthethings/status/81662155364329472...

(the second link is a lengthy thread)

Re: CIA malware and hacking tools

#244
Had the CIA's efforts been targetted towards improving encryption and security, US citizens and its government may well have had the ability to communicate safely. They may well have been able to trust new smart gadgets such as smart TVs and smart phones. Instead the CIA aided the nefarious people of the world by not reporting and exploiting security holes in devices used by the citizens it should protect. Now it has leaked said exploits and the CIA has helped their enemies in spying on every aspect of US life to a degree never seen before.

Re: CIA malware and hacking tools

#245
I looked through the leak, they promised source codes, all I found was source codes from various public projects.

For the CIA tools, there was only descriptions and guides to how to get it implemented and in use, not the actual source code.

Re: CIA malware and hacking tools

#246
post #204

Earlier quoted context omitted.

There also still hasn't been any public evidence that Wikileaks got their Podesta email data from Russians yet. So far we only know the DNC leaks were very likely Russian. That means until today only about ~50% of the 'election hacks' have been attributed to Russia with public evidence. Now this leak calls into question some of the evidence about the DNC hack [1]. This evidence being the malware was Russian. But ther…

> So far we only know the DNC leaks were very likely Russian. We don't know that at all. There isn't a single piece of evidence for it anywhere.

Unfortunately for this we aren't going to get some 1080p video of someone in a mask sneaking into the DNC server room, just the fact that the 17 agencies all agree based on what they've seen believe that to be the case.

Unfortunately everyone these days think everything is a conspiracy or has to have HD recordings of something they think happened as public evidence or it is false, but that's not how the world really works...

Re: CIA malware and hacking tools

#247

Earlier quoted context omitted.

> Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc. This basically means if your device is compromised, expect malware to be able to read all content (including Signal, WhatsApp messages). Nothing new. The way it's phrased makes it sound like Signal, WhatsApp have vulnerabilities, but no, the intention is sensationalism over sound analysis.

No mention of Windows Phone. I guess I'm safe =)

Sure, maybe, but there are very few of your kind left. ;)

Re: CIA malware and hacking tools

#248
post #204
post #66

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation. With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from. Th…

There also still hasn't been any public evidence that Wikileaks got their Podesta email data from Russians yet. So far we only know the DNC leaks were very likely Russian. That means until today only about ~50% of the 'election hacks' have been attributed to Russia with public evidence. Now this leak calls into question some of the evidence about the DNC hack [1]. This evidence being the malware was Russian. But ther…

There is no hard evidence where the DNC/Podesta leaks came from. However, Julian Assange has repeatedly said that the source is not the russian goverment or a affiliated state party [1] and in a other interview has hinted that the source may be Seth Rich [2], a former DNC staff member that was murdered in Washington DC.

[1] https://www.youtube.com/watch?v=uyCOy25GdjQ

[2] https://www.youtube.com/watch?v=Kp7FkLBRpKg

Re: CIA malware and hacking tools

#249

Well, traveling to the US I have had to fill out a green form stating that I'm not a terrorist or a 40-45 Nazi. I guess they capture a lot of pathological truth-telling terrorists/Nazis with this piece of paper

The question also has a ham-fisted phrasing:

> Have you ever been or are you now involved in espionage or sabotage; or in terrorist activities; or genocide; or between 1933 and 1945 were you involved, in any way, in persecutions associated with Nazi Germany or its allies?

My grandfather, who lost his German citizenship in the 30s and had to leave Germany for England due to the persecutions associated with Nazi Germany would technically have to answer that he was involved (as a victim).

Re: CIA malware and hacking tools

#250
post #197

Earlier quoted context omitted.

> I don't think it's unreasonable to expect that he may make significant changes at those agencies as a result of their "feuding" with him. And? What does that have to do with the tech community being critical of three letter agencies? > but their reason for doing so was orthogonal to Trump himself. I don't care what the reasoning is, Assange explicitly stated that he wasn't going to release info on Trump because he…

Can you source Assange stating this? As far as I remember, his explanation was that since there was already a bevy of mainstream media ready to publish any dirt on Trump, leakers did not have to go to Wikileaks to publish their stories, therefore it was unlikely anyone would send their leaks there.

“I mean, it’s from a point of view of an investigative journalist organization like WikiLeaks, the problem with the Trump campaign is it’s actually hard for us to publish much more controversial material than what comes out of Donald Trump’s mouth every second day," Assange said.

So this seems like a clear admission that they are in possession of controversial material regarding Trump, but Assange figures, why bother publishing it, it's not much more controversial than what comes out of Trump's own mouth, so we won't bother publishing it, nothing to see here.

Post reply on HN