Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

261–270 of 1001 posts

Re: CIA malware and hacking tools

#261
When will people stop pretending that Wikileaks is anything other than an anti-American political faction that is allied with Russia?

If Assange truly believed in transparency and a new kind of open democracy, he would stop preferentially targeting the US and get on with showing the world how all of our governments are the same in this regard.

Re: CIA malware and hacking tools

#262

Earlier quoted context omitted.

Think about it. Having the code copyrighted, would leave a paper trail.

Not really; copyright is mostly implicit. If US law made all code developed for the purposes of the CIA automatically copyrighted, the code would be copyrighted. Right now the law says it isn't, so it isn't. Having code be copyrighted does not require any explicit registration.

Yes and no. The law says that works of federal government employees arent to be protected. But it is unclear whether this only applies within the US or whether the US governmemt can assert those copyrights against non-us entities. It's a constitutional question never clearly addressed. Also, these tools could easily be the work of contractors rather than government employees. The fed can own/purchase/assert copyrights in such works. We do not have enough facts to say they are surely public domain.

Re: CIA malware and hacking tools

#263

Earlier quoted context omitted.

Think about it. Having the code copyrighted, would leave a paper trail.

Not really; copyright is mostly implicit. If US law made all code developed for the purposes of the CIA automatically copyrighted, the code would be copyrighted. Right now the law says it isn't, so it isn't. Having code be copyrighted does not require any explicit registration.

Perhaps what parent meant was that exclusive use of the code by agency would lead to easy post attack origin analysis, so by leaking the code in obfuscated form a few other people inevitably stumble on it and use it which generates a form of cover traffic for the original agents.

Re: CIA malware and hacking tools

#264
post #204

Earlier quoted context omitted.

There also still hasn't been any public evidence that Wikileaks got their Podesta email data from Russians yet. So far we only know the DNC leaks were very likely Russian. That means until today only about ~50% of the 'election hacks' have been attributed to Russia with public evidence. Now this leak calls into question some of the evidence about the DNC hack [1]. This evidence being the malware was Russian. But ther…

> So far we only know the DNC leaks were very likely Russian. We don't know that at all. There isn't a single piece of evidence for it anywhere.

https://arstechnica.com/security/2016/12/the-public-evidence...

There is some evidence, but no definitive evidence.

'"[SecureWorks] researchers assess with moderate confidence that the group is operating from the Russian Federation and is gathering intelligence on behalf of the Russian government," the report from SecureWorks concluded.'

Re: CIA malware and hacking tools

#265
post #92

In what is surely one of the most astounding intelligence own goals in living memory, the CIA structured its classification regime such that for the most market valuable part of "Vault 7" — the CIA's weaponized malware (implants + zero days), Listening Posts (LP), and Command and Control (C2) systems — the agency has little legal recourse. The CIA made these systems unclassified. Why the CIA chose to make its cyberar…

That passage is just dumb. Copyright would not stop hackers from using the tool once it is leaked.

Re: CIA malware and hacking tools

#266
post #142

Earlier quoted context omitted.

> Command & Control and Listening Post software were classified, then CIA officers could be prosecuted or dismissed for violating rules that prohibit placing classified information onto the Internet. Consequently the CIA has secretly made most of its cyber spying/war code unclassified. This is almost hilarious. Not that being classified would make any difference: cyber-"weapons" have something in common with biologic…

The US chemical weapons program is downright frightening. Unlike these exploits which you can just leave in an office and never use (and which con subsequently go stale as people find and patch exploits), chemical weapons were stored in massive US facilities and many of them have started leaking over the years: https://www.youtube.com/watch?v=FjA0EQPeUGM

That is one of the saddest 30 minutes of video I have seen up to date.

Re: CIA malware and hacking tools

#267
post #66

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation. With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from. Th…

> that "Russians" hacked the election That's not the claim. In fact, multiple people have said that is not the claim. The claim is that the Russians influenced the election in favor of Trump by promoting propaganda against Clinton.

Yeah it's irritating how our media is ignoring the propaganda machine and looking at "hacks" instead.

Re: CIA malware and hacking tools

#268

Earlier quoted context omitted.

Germany knows they're there, are you kidding?

A slight correction: "Germany is an US occupied country since the end of WWII". This is the truth about Nato, friendship between US and Japan, EU countries, South Korea, etc... There are no friends in geopolitics, only masters and slaves.

So.. Switzerland is free, since they aren't in the EU, nor NATO, but Finland and Norway are slaves, right?

Where would you rather live, India or any EU country?

Oh and Ukraine isn't in the NATO or the EU either, see how free they are?

Re: CIA malware and hacking tools

#269

Earlier quoted context omitted.

I believe that in my heart as well. However, we don't currently live in a world with a federated global government. The recent election in the US highlighted that people do divide the world into imaginary lines on maps and it had a slogan: AMERICA FIRST. It's not just the political class that sees these divisions, it's a majority of the citizens. How would you spark a revolution in people's thinking?

I have written about this in the past. I believe I proposed something like a "no executive" world government, where you had international laws, defined by treaties, and a commitment by some treaty signatories to "arrest" any state actor which broke them. If this coalition of "world police" (which are, of course, armies) were powerful enough, I believe this could lead to less lawbreaking by governments (from the USA t…

You know that what you're doing here is creating a world-dominating monopoly on the use of force, and whomever ran that army would be the defacto leader of the world, right?

We're organized as nation-states in the first place so we can protect (generally) and pursue interests based on some sort of shared goal or value. For the United States, it's the constitution (ostensibly), for others it's different reasons. Federations of nation-states contributing to a global force might work without totally corrupting, but not a single "no-executive" force. Further, if everyone contributes forces then countries can opt-out and go their own way... for their own interests. (See the UN)

Coming to an understanding between 10 people on what pizza to order is hard. Coming to an understanding between 8 Billion on who should be able to arrest them is extremely difficult.

Re: CIA malware and hacking tools

#270
post #204

Earlier quoted context omitted.

There also still hasn't been any public evidence that Wikileaks got their Podesta email data from Russians yet. So far we only know the DNC leaks were very likely Russian. That means until today only about ~50% of the 'election hacks' have been attributed to Russia with public evidence. Now this leak calls into question some of the evidence about the DNC hack [1]. This evidence being the malware was Russian. But ther…

There is no hard evidence where the DNC/Podesta leaks came from. However, Julian Assange has repeatedly said that the source is not the russian goverment or a affiliated state party [1] and in a other interview has hinted that the source may be Seth Rich [2], a former DNC staff member that was murdered in Washington DC. [1] https://www.youtube.com/watch?v=uyCOy25GdjQ [2] https://www.youtube.com/watch?v=Kp7FkLBRpKg

Attributing the release of such secrets to someone who is already dead seems like it could be a very effective way of hiding one's source. ;)
Post reply on HN