Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

371–380 of 1001 posts

Re: CIA malware and hacking tools

#371
post #142

Earlier quoted context omitted.

> Command & Control and Listening Post software were classified, then CIA officers could be prosecuted or dismissed for violating rules that prohibit placing classified information onto the Internet. Consequently the CIA has secretly made most of its cyber spying/war code unclassified. This is almost hilarious. Not that being classified would make any difference: cyber-"weapons" have something in common with biologic…

Obviously there's a difference between cyber and conventional weapons, but imagine if the same rationale were extended to physical munitions: "We can't drop this bomb on the enemy, it contains classified technology"

This in fact has happened in real life : e.g. in WWII proximity fuse antiaircraft shells were not used in the European theater for fear unexploded examples would be reverse engineered by the enemy. They were used in the Pacific where it was reasoned they would fall into the ocean where they would be unlikely to reach enemy hands.

Re: CIA malware and hacking tools

#372
post #321
post #66

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation. With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from. Th…

I think it's vitally important, at least in this forum where tech knowledge is fairly high to avoid saying that "Russia hacked the election" without any sort of qualifier. Because the implication is that they hacked voter booths or somehow changed votes. In reality they allegedly hacked computers of people related to a single party and brought to light the illicit activities that party was doing. tl;dr Saying Russia…

Agreed. All this fuss gives Russia more prestige/soft power.

Re: CIA malware and hacking tools

#373
post #66

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation. With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from. Th…

> that "Russians" hacked the election That's not the claim. In fact, multiple people have said that is not the claim. The claim is that the Russians influenced the election in favor of Trump by promoting propaganda against Clinton.

Actually, that was the claim, but once people started undermining the story they had to shift to the word "influence" to save face. This kind of shit is why middle-class rightwing America cheers when Trump calls out fake news. A complete inability to honestly say, ok, we don't know, or ok, we fucked up. Nope, the story always was X... sure it was.

Re: CIA malware and hacking tools

#375
post #92

In what is surely one of the most astounding intelligence own goals in living memory, the CIA structured its classification regime such that for the most market valuable part of "Vault 7" — the CIA's weaponized malware (implants + zero days), Listening Posts (LP), and Command and Control (C2) systems — the agency has little legal recourse. The CIA made these systems unclassified. Why the CIA chose to make its cyberar…

So then there would be no justifiable reason to reject a FOIA request for the source code.

I’m going to assume that the response would be that there are no such thing as Vault 7, a digital capability or even the CIA.

Re: CIA malware and hacking tools

#376
post #92

In what is surely one of the most astounding intelligence own goals in living memory, the CIA structured its classification regime such that for the most market valuable part of "Vault 7" — the CIA's weaponized malware (implants + zero days), Listening Posts (LP), and Command and Control (C2) systems — the agency has little legal recourse. The CIA made these systems unclassified. Why the CIA chose to make its cyberar…

So then there would be no justifiable reason to reject a FOIA request for the source code.

I’m going to assume that the response would be that there are no such thing as Vault 7, a digital capability or even the CIA.

Re: CIA malware and hacking tools

#377

Glad to see CIA hackers are Dr. Who fans! "Weeping Angel" makes it look like a Samsung television is off while it is really on and recording the room. Precisely what the Weeping Angel does during the Dr's first encounter.

Sontarans also make an appearance: https://wikileaks.org/ciav7p1/cms/page_524426.html

Re: CIA malware and hacking tools

#378
post #170

Earlier quoted context omitted.

I didn't flag it, but I'd imagine a lot of people don't trust the source (any more). Edit: Why the downvotes? I didn't indicate my position, I pointed out that some people don't trust WikiLeaks any more, which is obvious - go and look at the responses they get on twitter.

Did I miss a memo? Wikileaks has done tireless work in this field and has largely been correct about its claims and the authenticity of its documents. If not Wikileaks, whom do we trust for this sort of info?

You're missing a strategic consideration. If Wikileaks operates with ulterior motives, it could have an interest in dropping obsolete or even valid information for a variety of other reasons besides wanting people to be informed; to destabilize or distract, for example. Likewise, other parties could exploit Wikileaks to those ends, feeding low-level intelligence to Wikileaks for second-order purposes.

If not Wikileaks, whom do we trust for this sort of info?

Nobody. Open-source espionage means institutional reliability is a chimera. The more credibility you invest something with, the better of an attack vector it becomes.

Re: CIA malware and hacking tools

#379
post #66

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation. With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from. Th…

> that "Russians" hacked the election That's not the claim. In fact, multiple people have said that is not the claim. The claim is that the Russians influenced the election in favor of Trump by promoting propaganda against Clinton.

I think it's a little more nuanced than that.

I think the more likely objective (assuming the Russians were behind this, which for the time being is a fair assumption) is that they wanted to delegitimize a President Clinton. Everyone thought she would win. I think it's a bold claim to make that the Kremlin set out on a campaign to elevate an obtuse philanderer in a field of 16 who ignores any semblance of political norms. Rather, I think they just wanted to further tarnish Clinton's image, as President, as a corrupt establishment figure.

Re: CIA malware and hacking tools

#380

Earlier quoted context omitted.

What conspiracy theory? Assange, the person most likely to actually know what happened, has stated that the source for the Podesta emails was a disgruntled "washington insider" In addition, former British ambassador Craig Murray (a man with a solid reputation and little reason to lie) claims to have personally met the source and insists that the source is definitely a political insider without ties to Russia. https:/…

I thought the Podesta emails (at least the ones in the Wikileaks archive that Wikileaks keep tweeting urls to searches of) were from someone sending Podesta a fake gmail password reset email? I don't think a disgruntled washington insider did that! I could be confused and there's another set of emails that you're referring to. It's impossible to keep up on everything lately.

> I don't think a disgruntled washington insider did that!

Quite the contrary: If I definitely know that my target is too incompetent to check what he clicks on, or that he forgets his password every week, it's waaay easier for me to achieve my goal.

Post reply on HN