Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

401–410 of 1001 posts

Re: CIA malware and hacking tools

#401

Taking the chance to vent just a bit. These are the sort of things I have been telling people about but have been derided as paranoid and a conspiracy theorist. The Samsung TV was a great example of this, which I called would be more than just samsung sending voice data. Also, so many people have loved to respond to people talking about this with some variation of, "but you're not important, why would they bug you".…

> The main connection I have eeked out that I don't think most understand though is the relationship between the Wall Street group and The City of London/Vatican/Swiss Banking groups and their many associated secret society groups and orders of knighthood.

This is where you started to lose me. If you've eeked this out, surely you have something you can include to convince us?

> I think it is telling that the decryption passphrase was JFK talking about scattering them to a thousand winds.

I'm not sure what this is referring to. Can you elaborate?

> Stop using windows and osx, even for gaming. Stop installing windows at your business. Start using HIDS like OSSEC. Start checking your logs. Start checking your checksums. Start hardening your systems and your kernel (grsec). Stop using stock android, and don't use IOS. Desoder microphones on systems. Build faraday cages.

That will protect you in your home and on your personal devices (to a degree), but it doesn't protect you in public. Anonymity and privacy are an artifact of our congregating in large enough groups that it's not possible to know all those you see in a day, but the vast majority of our history was spent with no anonymity and little to no privacy. I'm convinced our return to a lack of anonymity and privacy is a return to the norm. That doesn't mean I support it or think it's necessarily better, but information wants to be free and humans like to know things, even if that happens to be what you had for breakfast today. Fighting naturally incentivized systems rarely ends well.

Re: CIA malware and hacking tools

#402
post #370
post #353

Earlier quoted context omitted.

> We used to believe that free and open societies would naturally prosper compared to authoritarian/totalitarian societies but what if that was all a lie? Then give up your freedom and start advocating for monarchy in America.

Wouldn't it be easier to try and push for a return to a more open/free society? I don't see how a monarchy solves anything in the US.

How do you justify that with

> unless every other nation stops doing this there is little value in being the only "clean" country (assuming somehow we stop)

If there is little value in being "clean", intelligence agencies have minimal to 0 oversight and accountability, and a non-trivial percentage of the population wants them to dominate geopolitics through any means necessary, how will we ever have an open/free society again?

Re: CIA malware and hacking tools

#403

Earlier quoted context omitted.

This is a great question. Surely they look for vulnerabilities also in their own systems but then what do they do when they find them? Is there some special set of software that always gets patched because the CIA uses it?

Presumably the same thing others do when they know about 0-days? Signatures.

Could you explain a bit more? I'm not sure what you mean.

Re: CIA malware and hacking tools

#404
post #142

Earlier quoted context omitted.

> Command & Control and Listening Post software were classified, then CIA officers could be prosecuted or dismissed for violating rules that prohibit placing classified information onto the Internet. Consequently the CIA has secretly made most of its cyber spying/war code unclassified. This is almost hilarious. Not that being classified would make any difference: cyber-"weapons" have something in common with biologic…

The US chemical weapons program is downright frightening. Unlike these exploits which you can just leave in an office and never use (and which con subsequently go stale as people find and patch exploits), chemical weapons were stored in massive US facilities and many of them have started leaking over the years: https://www.youtube.com/watch?v=FjA0EQPeUGM

I did not watch you link, but many modern chemical weapons are binary compounds. Meaning the two compounds has to be mixed to get the final weapon. This makes leaking etc, not as big problem as leaking of actual chemical weapons...

https://en.wikipedia.org/wiki/Binary_chemical_weapon

Re: CIA malware and hacking tools

#405
Has anyone with a clue actually gone over the code? If so, is there a description of how it works?

Unless things like smart TV's are shipped with malware, or unless they reach out and ask for malware and install it themselves, wouldn't having all your devices behind a NAT box make all this stuff benign?

Or am I too naive?

Re: CIA malware and hacking tools

#407

Earlier quoted context omitted.

> Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc. This basically means if your device is compromised, expect malware to be able to read all content (including Signal, WhatsApp messages). Nothing new. The way it's phrased makes it sound like Signal, WhatsApp have vulnerabilities, but no, the intention is sensationalism over sound analysis.

No mention of Windows Phone. I guess I'm safe =)

Try nokia 3310. They made new ones recently.

Re: CIA malware and hacking tools

#408
post #9

- Smart TV turned into listening devices with fake off mode? - Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc. - Dozens of O-day attacks again Andriod and iPhone. Pretty powerful stuff.

> Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc. This basically means if your device is compromised, expect malware to be able to read all content (including Signal, WhatsApp messages). Nothing new. The way it's phrased makes it sound like Signal, WhatsApp have vulnerabilities, but no, the intention is sensationalism over sound analysis.

Yes, that's nothing new, and it's obvious to us here on HN.

However, I disagree that the intention can only be sensationalism. The average computer/smartphone user (or journalist!) absolutely does not understand that if their device's operating system is compromised, that so are all the apps they run. Saying that messages can be intercepted before they are encrypted is worth pointing out as a realistic consequence of someone's device being compromised; a consequence that J. Random Journalist would not realize if it were not specifically pointed out.

Re: CIA malware and hacking tools

#410
post #71

Earlier quoted context omitted.

> Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc I wish I could say that I'm surprised but no... not surprised at all. Same for the IoT stuff.

Why would you be surprised by the fact that if your phone is compromised, even the best encryption software in the world isn't going to help?

Another victim of sensationalism.
Post reply on HN