Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

321–330 of 1001 posts

Re: CIA malware and hacking tools

#321
post #66

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation. With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from. Th…

I think it's vitally important, at least in this forum where tech knowledge is fairly high to avoid saying that "Russia hacked the election" without any sort of qualifier. Because the implication is that they hacked voter booths or somehow changed votes.

In reality they allegedly hacked computers of people related to a single party and brought to light the illicit activities that party was doing.

tl;dr Saying Russia hacked the election is the same as saying that some kid hacked the FBI when all he did was deface their website. It implies a level of sophistication that did not happen.

Re: CIA malware and hacking tools

#322
post #66

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation. With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from. Th…

> that "Russians" hacked the election That's not the claim. In fact, multiple people have said that is not the claim. The claim is that the Russians influenced the election in favor of Trump by promoting propaganda against Clinton.

Objective proof is usually not considered "propaganda". We used to call it "investigative journalism".

Re: CIA malware and hacking tools

#323

TIL that CIA is using Atlassian Stash for internal code hosting. Many references to the stash.devlan.net, would be nice to see some code, I just found some python scripts: https://wikileaks.org/ciav7p1/cms/page_9535551.html

There are even images here: https://wikileaks.org/ciav7p1/cms/page_13205694.html

Re: CIA malware and hacking tools

#324
post #204
post #66

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation. With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from. Th…

There also still hasn't been any public evidence that Wikileaks got their Podesta email data from Russians yet. So far we only know the DNC leaks were very likely Russian. That means until today only about ~50% of the 'election hacks' have been attributed to Russia with public evidence. Now this leak calls into question some of the evidence about the DNC hack [1]. This evidence being the malware was Russian. But ther…

I am nearly convinced by The Grugq's summary:

https://medium.com/@thegrugq/the-russian-way-of-cyberwar-edb...

"Alternating Competing Hypothesis"

Re: CIA malware and hacking tools

#325

"U.S. Consulate in Frankfurt is a covert CIA hacker base " Germans are usually privacy nuts. I know many who maintain no presence on Facebook, Twitter and Instagram. I wonder how Germany will react to this.

Sorry, news flash, virtually all of the countries' embassies and consulates are a natural place where a lot of intelligence operations are conducted. Counterintelligence operations watch them very closely. The fact that Frankfurt is a hub among their European intelligence operations is not terribly interesting IMO. > I wonder how Germany will react to this. Germany always knew operations were conducted there but now…

> Germany always knew operations were conducted there but now must react to this overt news.

Snowden outed Frankfurt (and Berlin) years ago. [0] There's no more interest in meaningful consequences now as it was back then.

[0] http://www.spiegel.de/international/germany/cover-story-how-...

Re: CIA malware and hacking tools

#327

Earlier quoted context omitted.

> So far we only know the DNC leaks were very likely Russian. We don't know that at all. There isn't a single piece of evidence for it anywhere.

Unfortunately for this we aren't going to get some 1080p video of someone in a mask sneaking into the DNC server room, just the fact that the 17 agencies all agree based on what they've seen believe that to be the case. Unfortunately everyone these days think everything is a conspiracy or has to have HD recordings of something they think happened as public evidence or it is false, but that's not how the world really…

The thing is, "17 agencies agree" doesn't really mean anything, if the evidence that all 17 agencies are relying on is a single report from a private security company hired by the DNC, and not independent investigation. If all of those agencies had looked at the original evidence themselves, the story would be different.

Re: CIA malware and hacking tools

#328
post #272

Quit with the fucking conspiracy theories. Seriously -- can we get a fucking mod in here to get rid of this shit.

What conspiracy theory? Assange, the person most likely to actually know what happened, has stated that the source for the Podesta emails was a disgruntled "washington insider" In addition, former British ambassador Craig Murray (a man with a solid reputation and little reason to lie) claims to have personally met the source and insists that the source is definitely a political insider without ties to Russia. https:/…

I thought the Podesta emails (at least the ones in the Wikileaks archive that Wikileaks keep tweeting urls to searches of) were from someone sending Podesta a fake gmail password reset email?

I don't think a disgruntled washington insider did that! I could be confused and there's another set of emails that you're referring to. It's impossible to keep up on everything lately.

Re: CIA malware and hacking tools

#329

Earlier quoted context omitted.

While I don't think the CIA is above killing a US citizen on US soil (you know, for "security" or something), I don't think they need to hack a vehicle to do it, nor would they want to draw the unnecessary speculation and attention. I would expect antics like that to be reserved for high-ranking foreign officials or other hard-to-reach people. If there's one thing that agency should be expected to excel in, it's untr…

Given the relatively low amount of public scrutiny/outrage/attention/fear that this death caused, wouldn't you say that the car technique would be effective? (whether or not it was used in this case)

It's effective at taking a life. However I disagree that the fallout was "relatively low", compared to even a badly staged suicide, or "gang violence", "road rage", or a "botched robbery". IIRC a democratic organization employee was recently slain in DC from a "botched robbery" or something and nobody blinked an eye except in the more fringe communities. To me, that's how you snuff someone out, or OD them on insulin and have an official coroner report say "natural causes". I think a fiery single car crash at top speed is a pretty high profile event, almost up there with polonium poisoning.
Post reply on HN