This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.
WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
111–120 of 250 posts
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#112Earlier quoted context omitted.
> Given Google's stance of not encrypting local storage in any way that I am aware of, this is fundamentally unsurprising. I have long been saying that Android is insecure and that storing passwords in Chrome is dangerous. ChromeOS and Android both implement FDE. There are some legitimate criticisms of (especially) the latter, voiced by e.g. Matthew Green, but you're just speaking nonsense here. There's very little v…
I am not talking about ChromeOS - I am talking about the Chrome browser. Localstorage, last I checked, which was recently, is plaintext. > ChromeOS and Android both implement FDE Which is irrelevant if the runtime is compromised, which appears to be the case.
Given a desktop OS like Windows that implements FDE like Bitlocker and runs a browser like Chrome, can you describe a hypothetical threat in which Chrome encrypting localstorage would prevent exploitation?
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#113This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.
Seems like the headline is perfectly fine. The software on the device you don't own is bypassed, resulting in encryption being ineffective? That seems like a highly critical issue for whoever owns the software . Step the fuck up Google. Android security is an embarrassment.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#114Earlier quoted context omitted.
The kernel is owned (or some part of the phone below the application level). The encryption only gets applied at the application level before the messages are sent down the wire. The interception happens prior to the encryption being applied . Think of it as a dongle on the wire between your keyboard and the computer. It doens't matter if the computer is secure - the message is intercepted prior to any encryption. Th…
> Given Google's stance of not encrypting local storage in any way that I am aware of, this is fundamentally unsurprising How does not encrypting local storage relate to this story? You're just pulling that one out of thin air to somehow prove your point. Besides the fact that there is no correlation between encrypting local storage and intercepting keystrokes or more broadly owning the kernel, it's also false. Thoug…
Encrypting local storage would not have saved you. Absolutely. Maybe I am reading tea leaves, but it seems to me that this is indicative of the sort of security-lax mindset that allowed android to be owned.
> And your app wouldn't be safe from it either.
Yup. I know. It is a concern.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#115Earlier quoted context omitted.
No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.
This is a dangerous headline because it implies that Signal was broken, which could lead to people moving to LESS SECURE SERVICES because they think the more secure one is broken. When in reality is the phone and OS. They have similar end result for the phone in question, but headlines like this can lead to people being less secure on the whole.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#116Earlier quoted context omitted.
I am not talking about ChromeOS - I am talking about the Chrome browser. Localstorage, last I checked, which was recently, is plaintext. > ChromeOS and Android both implement FDE Which is irrelevant if the runtime is compromised, which appears to be the case.
Let's be all Socratic here: Given a desktop OS like Windows that implements FDE like Bitlocker and runs a browser like Chrome, can you describe a hypothetical threat in which Chrome encrypting localstorage would prevent exploitation?
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#117Earlier quoted context omitted.
NYT is pivoting to a model that brings it more clicks.
It is a disturbing trend lately for publishers to seemingly insert deliberate fallacies into their headlines just to get more people engaged, causing them to pop up on more social media timelines.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#118Earlier quoted context omitted.
Unfortunately, this is a line that Wikileaks themselves are running with: https://twitter.com/wikileaks/status/839120909625606152
Running misinformation is part of Wikileaks' job. It's not the NYT's job.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#119To me this is much more worrying: > As of October 2014 the CIA was also looking at infecting the vehicle control systems used by modern cars and trucks. The purpose of such control is not specified, but it would permit the CIA to engage in nearly undetectable assassinations. https://wikileaks.org/ciav7p1/ Given the fact that car makers don't even have "PC age" security in their cars, things are looking pretty bad for…
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#120Earlier quoted context omitted.
Well I think they put out the article first and get experts to correct the finer points later. I don't agree this is the best tactic, but reporting first is important. They have changed the title. Currently: "WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents"
See for instance WaPo, where Greg Miller and Ellen Nakashima got Nicholas Weaver from ICIR on the record for analysis for the story. Compare with the NYT's original story, which had no disclosed expert sourcing. Maybe a habit we should all develop is to first scan these things to see who they got on the record to talk about it. It's not hard for them. I'm not making this up: NYT has a huge list of experts to reach ou…
I wasn't disagreeing with you. I was just saying that their tactic is to publish first and update. This is pretty common, especially in bigger stories. They get paid by getting eyeballs on their site. If someone publishes 20 mins before them they lose money, even if they are more accurate.
So just always take a breaking story as a draft. The story isn't finished and I bet will get updated several times.