Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

341–350 of 1001 posts

Re: CIA malware and hacking tools

#341
post #265
post #92

In what is surely one of the most astounding intelligence own goals in living memory, the CIA structured its classification regime such that for the most market valuable part of "Vault 7" — the CIA's weaponized malware (implants + zero days), Listening Posts (LP), and Command and Control (C2) systems — the agency has little legal recourse. The CIA made these systems unclassified. Why the CIA chose to make its cyberar…

That passage is just dumb. Copyright would not stop hackers from using the tool once it is leaked.

I think what it's trying to convey is that there's absolutely no legal recourse in any capacity for the CIA at this point to try and do any sort of damage control.

Re: CIA malware and hacking tools

#342
post #13

I wonder how many of the exploits/tools released are still usable today. Also, the actual video press release had to be rescheduled due to their video stream being attacked.[0] "NOTICE: As Mr. Assange's Perscipe+Facebook video stream links are under attack his video press conference will be rescheduled." [0]: https://twitter.com/wikileaks/status/839104886625157120

Are they implying that Facebook is being DOS'ed?

Re: CIA malware and hacking tools

#343

Earlier quoted context omitted.

Unfortunately for this we aren't going to get some 1080p video of someone in a mask sneaking into the DNC server room, just the fact that the 17 agencies all agree based on what they've seen believe that to be the case. Unfortunately everyone these days think everything is a conspiracy or has to have HD recordings of something they think happened as public evidence or it is false, but that's not how the world really…

The thing is, "17 agencies agree" doesn't really mean anything, if the evidence that all 17 agencies are relying on is a single report from a private security company hired by the DNC, and not independent investigation. If all of those agencies had looked at the original evidence themselves, the story would be different.

Also, the "17 agencies" statement came from James Clapper, and not individually issued from each of the agencies themselves. It also bears mentioning that the "17 agencies" include groups that I really, really doubt bothered to investigate ANYTHING to do with a politician getting his emails hacked - do people actually believe that the coast guard was tracking down Russian hackers after DNC secrets? What about the department of energy? These are some of the "17 agencies" mentioned.

Re: CIA malware and hacking tools

#344
post #142

Earlier quoted context omitted.

> Command & Control and Listening Post software were classified, then CIA officers could be prosecuted or dismissed for violating rules that prohibit placing classified information onto the Internet. Consequently the CIA has secretly made most of its cyber spying/war code unclassified. This is almost hilarious. Not that being classified would make any difference: cyber-"weapons" have something in common with biologic…

Obviously there's a difference between cyber and conventional weapons, but imagine if the same rationale were extended to physical munitions: "We can't drop this bomb on the enemy, it contains classified technology"

I don't think the difference is so obvious even that far in the future, or even right now. If you targeted an attack correctly, I'm pretty sure you could achieve a statistical range of casualties. Does it matter that you used data instead of bombs?

Re: CIA malware and hacking tools

#345

This had the potential of being a positive development brought by Trump's election: many behaviors by the US three letter agencies that were glossed over for the past 8 years (due to the party in power being "on the right side of history") are again reprehensible and deemed a threat to be fought by the tech community.

I agree but unless every other nation stops doing this there is little value in being the only "clean" country (assuming somehow we stop). And what are the implications of doing so? We used to believe that free and open societies would naturally prosper compared to authoritarian/totalitarian societies but what if that was all a lie? "Five Eyes" dates back to the 1940's, ECHELON at least the 1980's - none of this is new. Maybe we are all just naive to the realities of geopolitics? Is this just the modern version of "We sleep soundly in our beds because rough men stand ready in the night to visit violence on those who would do us harm."?

Personally, I'd rather live in a world dominated by America/Europe than one dominated by Russia or China. All parties have lengthy histories of atrocious behaviour but the US/Europe doesn't have a "Great Firewall" and critics of our leadership are not disappeared (yet?). I just hope "If you want a vision of the future, imagine a boot stamping on a human face - forever." remains fictional....

Re: CIA malware and hacking tools

#346

Earlier quoted context omitted.

> The US chemical weapons program is downright frightening. Was : they committed to destroying those weapons, and have been doing so for 24 years. They were 89.75% complete in 2012. The video you linked was from 1973. https://en.wikipedia.org/wiki/United_States_chemical_weapons...

Just like they committed to revealing exploits to the tech industry instead of hoarding them?

> Just like they committed to revealing exploits to the tech industry instead of hoarding them?

I think you're letting your cynicism get in the way of truth and understanding.

The US has signed and ratified a treaty committing to destroy all chemical weapons and never produce them again [1], and it has built the infrastructure to do so [2] [3].

It's conspiracy-nut territory to think the US is simultaneously stockpiling chemical weapons in some super-secret program without good evidence for it.

[1] https://en.wikipedia.org/wiki/Chemical_Weapons_Convention

[2] https://www.youtube.com/watch?v=7u-ACe1CBfA

[3] https://www.youtube.com/watch?v=wftLydix0Nw

Re: CIA malware and hacking tools

#347
post #309
post #272

Quit with the fucking conspiracy theories. Seriously -- can we get a fucking mod in here to get rid of this shit.

You're commenting on a release that includes CIA guidelines for structuring file metadata specifically to avoid US attribution... And arguing that questioning the integrity of file metadata is a conspiracy theory... https://wikileaks.org/ciav7p1/cms/page_14587109.html

File metadata wasn't my concern. Spreading baseless rumors without concern for grieving family and friends makes Sparkling (and his buddies) grade-A fuckwads in my book.

Re: CIA malware and hacking tools

#348

Earlier quoted context omitted.

Unfortunately for this we aren't going to get some 1080p video of someone in a mask sneaking into the DNC server room, just the fact that the 17 agencies all agree based on what they've seen believe that to be the case. Unfortunately everyone these days think everything is a conspiracy or has to have HD recordings of something they think happened as public evidence or it is false, but that's not how the world really…

>" just the fact that the 17 agencies all agree based on what they've seen believe that to be the case." This simply isn't true. The whole "17 agencies" thing is a talking point that first came up in one of Hillary Clinton's debates and gets repeated without challenge. The "17 agencies" didn't all independently make their own assesments about what happened and decided it was the Russians. Instead, James Clapper (at t…

He wasn't going to out a secret program in a public hearing.

The folks asking the questions had security clearance and could have asked the question during a classified briefing but they chose not to.

Re: CIA malware and hacking tools

#349
post #216
post #195

OS-level backdoors can be easily patched. Unlike hardware based backdoors, curtesy of Intel AMT.

And yet the leaked tools don't seem to have much in the way of hardware-based exploits, which might say something about the feasibility of this kind of thing on actual systems. Obviously it can be done, but it were as pervasive as the tinfoil hatters believe, surely it would have shown up here. No?

The document covers how they put a good amount of effort into ensuring there's not a clear link back to the CIA or relevant parties if one of these things is discovered. I imagine having hardware level vulnerabilities would much more quickly point directly to the only agencies capable of such techniques.
Post reply on HN