Live data from Hacker News

WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

nytimes.com

111–120 of 250 posts

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#111
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

They've corrected it; HN should do the same.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#112
post #38

Earlier quoted context omitted.

> Given Google's stance of not encrypting local storage in any way that I am aware of, this is fundamentally unsurprising. I have long been saying that Android is insecure and that storing passwords in Chrome is dangerous. ChromeOS and Android both implement FDE. There are some legitimate criticisms of (especially) the latter, voiced by e.g. Matthew Green, but you're just speaking nonsense here. There's very little v…

I am not talking about ChromeOS - I am talking about the Chrome browser. Localstorage, last I checked, which was recently, is plaintext. > ChromeOS and Android both implement FDE Which is irrelevant if the runtime is compromised, which appears to be the case.

Let's be all Socratic here:

Given a desktop OS like Windows that implements FDE like Bitlocker and runs a browser like Chrome, can you describe a hypothetical threat in which Chrome encrypting localstorage would prevent exploitation?

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#113
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

Seems like the headline is perfectly fine. The software on the device you don't own is bypassed, resulting in encryption being ineffective? That seems like a highly critical issue for whoever owns the software . Step the fuck up Google. Android security is an embarrassment.

The headline mentions specific apps; readers will remember that those apps are "insecure". Very dangerous.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#114
post #95

Earlier quoted context omitted.

The kernel is owned (or some part of the phone below the application level). The encryption only gets applied at the application level before the messages are sent down the wire. The interception happens prior to the encryption being applied . Think of it as a dongle on the wire between your keyboard and the computer. It doens't matter if the computer is secure - the message is intercepted prior to any encryption. Th…

> Given Google's stance of not encrypting local storage in any way that I am aware of, this is fundamentally unsurprising How does not encrypting local storage relate to this story? You're just pulling that one out of thin air to somehow prove your point. Besides the fact that there is no correlation between encrypting local storage and intercepting keystrokes or more broadly owning the kernel, it's also false. Thoug…

I agree. Wholeheartedly. The point, however, is that it belies Google's larger approach, including that they turned a browser into an operating system.

Encrypting local storage would not have saved you. Absolutely. Maybe I am reading tea leaves, but it seems to me that this is indicative of the sort of security-lax mindset that allowed android to be owned.

> And your app wouldn't be safe from it either.

Yup. I know. It is a concern.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#115
post #75

Earlier quoted context omitted.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

This is a dangerous headline because it implies that Signal was broken, which could lead to people moving to LESS SECURE SERVICES because they think the more secure one is broken. When in reality is the phone and OS. They have similar end result for the phone in question, but headlines like this can lead to people being less secure on the whole.

I've had friends and family reaching out to me all morning saying "Signal is broken, see the NYT." This headline is incredibly misinformed and misleading and I hope they issue a correction quickly.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#116
post #112

Earlier quoted context omitted.

I am not talking about ChromeOS - I am talking about the Chrome browser. Localstorage, last I checked, which was recently, is plaintext. > ChromeOS and Android both implement FDE Which is irrelevant if the runtime is compromised, which appears to be the case.

Let's be all Socratic here: Given a desktop OS like Windows that implements FDE like Bitlocker and runs a browser like Chrome, can you describe a hypothetical threat in which Chrome encrypting localstorage would prevent exploitation?

Yes - worms or browsers that scan local data files without accessing the runtime of the parent application.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#117

Earlier quoted context omitted.

NYT is pivoting to a model that brings it more clicks.

It is a disturbing trend lately for publishers to seemingly insert deliberate fallacies into their headlines just to get more people engaged, causing them to pop up on more social media timelines.

Well they want to become Drudge before Drudge becomes them.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#118
post #13
post #11

Earlier quoted context omitted.

Unfortunately, this is a line that Wikileaks themselves are running with: https://twitter.com/wikileaks/status/839120909625606152

Running misinformation is part of Wikileaks' job. It's not the NYT's job.

They at least re-clarified on twitter. But not in the article. https://twitter.com/nytimes/status/839160771674255360

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#119
post #19

To me this is much more worrying: > As of October 2014 the CIA was also looking at infecting the vehicle control systems used by modern cars and trucks. The purpose of such control is not specified, but it would permit the CIA to engage in nearly undetectable assassinations. https://wikileaks.org/ciav7p1/ Given the fact that car makers don't even have "PC age" security in their cars, things are looking pretty bad for…

No post body was provided.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#120
post #94

Earlier quoted context omitted.

Well I think they put out the article first and get experts to correct the finer points later. I don't agree this is the best tactic, but reporting first is important. They have changed the title. Currently: "WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents"

See for instance WaPo, where Greg Miller and Ellen Nakashima got Nicholas Weaver from ICIR on the record for analysis for the story. Compare with the NYT's original story, which had no disclosed expert sourcing. Maybe a habit we should all develop is to first scan these things to see who they got on the record to talk about it. It's not hard for them. I'm not making this up: NYT has a huge list of experts to reach ou…

> It's not hard for them. I'm not making this up: NYT has a huge list of experts to reach out to for stories. They just chose not to.

I wasn't disagreeing with you. I was just saying that their tactic is to publish first and update. This is pretty common, especially in bigger stories. They get paid by getting eyeballs on their site. If someone publishes 20 mins before them they lose money, even if they are more accurate.

So just always take a breaking story as a draft. The story isn't finished and I bet will get updated several times.

Post reply on HN