Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

271–280 of 1001 posts

Re: CIA malware and hacking tools

#271

Earlier quoted context omitted.

> So far we only know the DNC leaks were very likely Russian. We don't know that at all. There isn't a single piece of evidence for it anywhere.

https://arstechnica.com/security/2016/12/the-public-evidence... There is some evidence, but no definitive evidence. '"[SecureWorks] researchers assess with moderate confidence that the group is operating from the Russian Federation and is gathering intelligence on behalf of the Russian government," the report from SecureWorks concluded.'

The "evidence" appears to be simply that one anonymous group about which nothing is known was going after targets that would presumably be of interest to Russia.

But that's simply heresy: such targets might also be of interest to western intelligence, or really anyone who wanted to stir up trouble by framing another country.

All we can say is that the correlation is interesting, but that's about it.

Re: CIA malware and hacking tools

#273
post #120

One of the findings: Notepad++ has a DLL hijack [1] [1] https://wikileaks.org/ciav7p1/cms/page_26968090.html

Any executable is vulnerable to DLL hijacking, they're just looking for easier targets that load known DLLs (with known function signatures) from their own folders (NOT system folders). I'm assuming the goal is to minimise detection by what they call PSPs (av / security products) This is not a flaw within notepad++

Arguably loading DLLs from non-system folders is bad design in this day and age.

Re: CIA malware and hacking tools

#274
post #66

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation. With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from. Th…

> that "Russians" hacked the election That's not the claim. In fact, multiple people have said that is not the claim. The claim is that the Russians influenced the election in favor of Trump by promoting propaganda against Clinton.

Through leaks like this one. Leaks that can be partially validated or corroborated, but which (by their nature) cannot be entirely proven true.

And those leaks were very transparently beneficial to a person/group who are also going to benefit from this one.

I don't trust the CIA at all. But I don't trust Wikileaks either. I see way too many self-described "skeptical" types who aren't approaching any of this with any shred of skepticism.

Re: CIA malware and hacking tools

#275
Glad to see CIA hackers are Dr. Who fans!

"Weeping Angel" makes it look like a Samsung television is off while it is really on and recording the room. Precisely what the Weeping Angel does during the Dr's first encounter.

Re: CIA malware and hacking tools

#276
post #53

Earlier quoted context omitted.

Michael Hastings? [0] [0] https://en.wikipedia.org/wiki/Michael_Hastings_(journalist)

While the above is certainly plausible(killing someone with a car), I highly doubt this is the case here: https://www.metabunk.org/debunked-michael-hastings-crash-car...

While I don't think the CIA is above killing a US citizen on US soil (you know, for "security" or something), I don't think they need to hack a vehicle to do it, nor would they want to draw the unnecessary speculation and attention. I would expect antics like that to be reserved for high-ranking foreign officials or other hard-to-reach people. If there's one thing that agency should be expected to excel in, it's untraceable targeted killings.

Re: CIA malware and hacking tools

#277

Earlier quoted context omitted.

As nuclear proliferation becomes more and more common, "regular warfare" is going to become impossible. The reality is that there isn't going to be a traditional war with any nuclear power. WW2 was the last big state on state conflict -- that cannot happen again. Since 1948, the US vs. USSR model has applied, where nuclear powers have proxy wars at the fringes with various minor states. As nukes become available to 2…

Ok, but the current trend seems to suggest a strong preference for SIGINT, ELINT, ... over traditional HUMINT. Isn't this overestimating only a peculiar aspect ?

I think what we're seeing is that "SIGWAR" is a thing. Why blow up something if you can undermine it?

If you think about it, it's similar to how the physical world evolved. I was recently up at Fort Ticonderoga, which is an example of a fort designed to resist and leverage the cannon as a defensive weapon. In Europe forts of similar design were nearly impregnable, but ultimately obsolete -- mobility and artillery rendered fixed positions useless. There's a similar thing at play here!

Re: CIA malware and hacking tools

#278
post #238

>These techniques permit the CIA to bypass the encryption of WhatsApp, Signal, Telegram... So much for guaranteed encryption and safety.

Control of the local device has always meant game over. How could it be otherwise?

Re: CIA malware and hacking tools

#279
post #5

Based on the overview alone (of course I can't read the entire report that fast!), this is exactly what I expect a spy agency would be doing -- if they were not then I would be disappointed. What exactly in the admittedly shortened list am I supposed to be upset about? It makes no distinction between US citizens and overseas parties. If these actions are being done domestically against US citizens, with no just cause…

I don't understand making this point unless it's to give yourself permission not to think about this. Feel free not to.

Re: CIA malware and hacking tools

#280

This idea that the government should somehow be exempt from proper cybersecurity ethics is disgusting. When the CIA or the NSA find zero day attacks in software, they should report them immediately to be fixed, not build tools specifically to exploit them. It's only a matter of time before these attacks either leak or are rediscovered by other malicious parties. The government is effectively turning their own people…

I think that's an absurd position. The government has a need to be able to access hostile systems. A hacked computer can avoid armed conflict where people die. A better question is... why aren't major vendors devoting a fraction of the resources to find this stuff and fix t on their own?

> why aren't major vendors devoting a fraction of the resources to find this stuff and fix it on their own?

I'm pretty sure most of the competent ones are... it's just really slow, expensive, hard work, with little financial upside (beyond preventing the financial downside of disastrous long-tail exploits). Spending ever more on it probably isn't an easy sell to business people with normal (read: bad) human probabilistic intuitions. And a lot of the people best at it probably just choose to work for themselves because they can auction their work to IC or criminal collectors for much more than they'd get from a fixed rate bug bounty.

Post reply on HN