Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

491–500 of 1001 posts

Re: CIA malware and hacking tools

#491

Taking the chance to vent just a bit. These are the sort of things I have been telling people about but have been derided as paranoid and a conspiracy theorist. The Samsung TV was a great example of this, which I called would be more than just samsung sending voice data. Also, so many people have loved to respond to people talking about this with some variation of, "but you're not important, why would they bug you".…

> The main connection I have eeked out that I don't think most understand though is the relationship between the Wall Street group and The City of London/Vatican/Swiss Banking groups and their many associated secret society groups and orders of knighthood. This is where you started to lose me. If you've eeked this out, surely you have something you can include to convince us? > I think it is telling that the decrypti…

"surely you have something you can include to convince us?"

Perhaps, but it's not an easy subject to breach at all, but I appreciate your honest question and will attempt a terse summary. During both my time in the military as a pawn, and during my time as a civilian trying to understand the deep state, I have continually come across two fundamental issues regardless of particular area of research:

Bankers touch everything. At first I was just trying to chase the terrorist finance networks up the chain. Thinking it probably mostly ended at some Saudi, Jordanian, UAE banks. Not true, but the problem is that post 9/11 so much of the finance network stuff was taken out of the public view, scrubbed and redacted, or otherwise hushed up. I thought this was for operational reasons, to not give up the game to the ones we were after, but after 3,5,10+ years of no real attacks on the finance network, I'm increasingly convinced they are being protected, not investigated. Now, at this level of course the main argument tends to be similar to the reasonsing used in the 2008 bailout, some variation of "but if we start prosecuting bankers, the banking system might collapse and the economy would tank and..." you get the idea. I don't buy that excuse. Anyway, the real point is that most of the reading I have done on the upper-level banking system indicates they have become supranational, interconnected systems in ways most people can barely understand. This paper is a key reading on this point: https://arxiv.org/pdf/1107.5728.pdf As for citing sources on the relationship between Wall Street and City of London/Vatican, it gets much more tricky. This is the sort of stuff that I imagine would take a palantir type 6 degrees social graph to really unconver in a concrete way, so for now I have to admit it's mostly inductive instead of deductive reasoning. Many context clues from many books in aggregate have helped me form this opinion.

Now, on to the even more slippery subject of secret societies and orders of knighthood. The bottom line is that I don't think anyone can claim to have a holistic grasp on geopolitics/economics/strategy and at the same time ignore the many secret societies associated, for reasons that seem obvious with a little thought. I mean, if you wanted to run a subversive intelligence network, isn't the compartmentalized nature of a secret society simply a mirror of the kind of compartmentalization an intelligence agency would use? (perhaps the agency is the mirror of the society, but I digress). It's just structually set up to allow for infiltration and subversion. Now, that's not to say that is what every society is used for, or that every member is used for. On the contrary, with the rings within rings structure, the vast majority of secret society members tend to have no clue whatsoever of what is happening at the upper level. (Very much like I claim of the CIA). They are useful bodies for cover. One very particular example of this would be P2 or Propaganda Due lodge. https://en.wikipedia.org/wiki/Propaganda_Due

For more a more scholarly type of look into this type of thing, the best author I could recommend would be Carroll Quigley. A professor of history at Georgetown, and cited by Bill Clinton as his mentor, he wrote extensively about the British round table groups influence being used as a rings within rings structure for the purposes of the British empire (later renamed the commonwealth for pr purposes). In large part, the origins of this structure was put in place by Cecil Rhodes, who got the inspiration from reading the documents of the actual Bavarian Illuminati of the late 1700's. It was always one point of contention between Quigley and what he called the plagarists (such as the John Birch society), that Rhodes was simply inspired by the rings within rings structure that Adam Weishaupt wrote about, and that there was no evidence for a connection between the ancient secret societies, and "the illuminati" and the Rhodes society group(s). (A common misconception among the lazy conspiracy theorist, even though I have found plenty of evidence that (free)masonry does get it's roots from Egyptian societies of builders, it's is often publicly disputed as otherwise.)

As for the orders of knighthood, there are some very interesting connections between certain orders and certain types of military and clandenstine operations. For example, I have found an inordinate amount of (military) operator types and those associated have membership in the Knights of Malta, and other similar groups. Associations vary though, from more than just The Vatican, they include factions in the UK/EU royal houses and aristocracies. They are often at odds as well, the other common misconception of lazy conspiracy theorists is that there is a single monolithic group. Many factions exist whose interests sometimes align, and sometimes don't. There are power plays in this region most of the world never hears about. For example, recently: https://cruxnow.com/analysis/2017/01/29/popes-takeover-knigh...

Anyway, to summarize, these are difficult subjects that are complex, full of nuance, and often lengthy, and as such don't lend themselves well to such short-term outlets like a hn comment, but that's an introduction that might help steer your own research if you are genuinely curious.

"I'm not sure what this is referring to. Can you elaborate?"

This reffering to some things JFK said after the bay of pigs fiasco, talking about making a mistake by keeping Allen Dulles (who was conviently put in charge of the commision to investigate the assassination!), and talking about how he wanted to "splinter the CIA into a thousand pieces and scatter it into the winds."

"Truman’s Secretary of State Dean Acheson wrote in his 1969 memoirs that upon the CIA’s creation he “had the gravest forebodings about this organization and warned the president that as set up neither he, the National Security Council, nor anyone else would be in a position to know what it was doing or to control it.”" https://theintercept.com/2016/02/22/in-1974-call-to-abolish-...

"That will protect you in your home and on your personal devices (to a degree), but it doesn't protect you in public."

I think that's a start. I'm aware that with technological progress public privacy is waning and will continue to do so, but we should at least remember the rights of privacy (including right to not be subject to search without warrant or probable cause) on our property, even if that property is digital. Capitulations about how privacy is already dead lack the nuance needed to really address the problems. We could just as easily setup attack resistent OS's and platforms as allow MS to monopolize the market.

"the vast majority of our history was spent with no anonymity and little to no privacy"

I would like to see what makes you think this is true. As far as I can tell, the vast majority of history was rife full of anonymity and privacy. Now, perhaps in a small village everyone in the village, or everyone in the family, knew what you were doing, but there is a big difference between immediate friends and family having first-hand knowledge of your goings and doings and them having knowledge of your goings and doings and storing them on insecure devices which the government can search surreptetiously at will and at a mass scale heretofore unimagined by all but the most forward looking thinkers such as Orwell and Huxley.

Re: CIA malware and hacking tools

#492

If I was CIA and I wanted to waste time by arguing and distracting forum readers, what would I be posting in this thread?

If I were the CIA I'd be quite pleased for people to know how clever and powerful I am so they don't mess with me. Human assets are rare and precious, but I have no problem flinging a few technological ducats in the general direction of the peasants.

This may or may not be an accurate read of events, but in my view many major 'leaks' of recent years are backdoor propaganda; the State Department Cable archive was embarrassing only if you consider it as a leak, but a really great way to express our government's outlook on a wide variety of topics that would result in conflict if done through formal channels. One can't really know what teh motivations of the people revealing teh information is, and one can imagine many benefits as well as headaches from its release, so it's best not to get too invested in any one one model.

Re: CIA malware and hacking tools

#493

Taking the chance to vent just a bit. These are the sort of things I have been telling people about but have been derided as paranoid and a conspiracy theorist. The Samsung TV was a great example of this, which I called would be more than just samsung sending voice data. Also, so many people have loved to respond to people talking about this with some variation of, "but you're not important, why would they bug you".…

deep state This phrase is currently being spread by right-wing conspiracy sites and was under the radar of most people until very recently. In other words, it seems very much that you, as an otherwise reasonable person, are being manipulated by people whose main interest is clickbait (for money) and/or some political agenda that has nothing to do with news. I've seen this detachment from reality increase more and mor…

I have been aware of and researching the deep state long before Trump was even dipping his hand in the political arena, so please don't try to associate the very useful term with right-wing conspiracy sites, clickbait, or political agenda. I resent your condesending and patronising attitude and your misappropriation and misattribution of my sources of knowledge, of which you know nothing.

As a matter of fact the term, as far as I know, originates with one of the best authors on the subject, Peter Dale Scott.

https://www.amazon.com/s/?url=search-alias%3Daps&field-keywo...

Re: CIA malware and hacking tools

#494
post #204

Earlier quoted context omitted.

There also still hasn't been any public evidence that Wikileaks got their Podesta email data from Russians yet. So far we only know the DNC leaks were very likely Russian. That means until today only about ~50% of the 'election hacks' have been attributed to Russia with public evidence. Now this leak calls into question some of the evidence about the DNC hack [1]. This evidence being the malware was Russian. But ther…

What public evidence is there that the DNC leaks were related to Russia?

Mostly this intelligence report from the Office of the Director of National Intelligence: https://www.nytimes.com/interactive/2017/01/06/us/politics/d...

Re: CIA malware and hacking tools

#495

The Samsung TV attack seems rather lame. The attack apparently has to be installed via a USB device, which means somebody has to physically reach the TV. If you can get that far, there are other ways to plant a bug. The documents don't indicate they've been able to install it remotely. Looking into remote update was on the to-do list. There's little interesting technical detail in any of this. It looks like stuff tha…

Yeah, but if you plant a bug that might be detected during a sweep by a security-conscious person. The firmware on the TV, probably not.

Re: CIA malware and hacking tools

#496

The Samsung TV attack seems rather lame. The attack apparently has to be installed via a USB device, which means somebody has to physically reach the TV. If you can get that far, there are other ways to plant a bug. The documents don't indicate they've been able to install it remotely. Looking into remote update was on the to-do list. There's little interesting technical detail in any of this. It looks like stuff tha…

Not hard to use USB exploit at the shipyard or warehouse (Amazon).

Re: CIA malware and hacking tools

#497
post #66

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation. With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from. Th…

IMO it just doesn't make much sense, though, as soon as you picture actual groups of people running these schemes. It's super secret and all, but behind the iris-scanner doors and extreme vetting, people are sitting in offices, drink coffee, have meetings, etc. There's oversight, reports to file and activity logs. Now how should a group of employees, in this environment, sit together and decide to manipulate an election in their own country? That just doesn't seem feasible.

I honestly imagine the day-to-day activity there to be way more mundane than we imagine. It's probably just sifting through thousands of pages worth of intelligence (transcribed phone calls from terrorism suspects, reports from people at foreign embassies, etc) for things that are usable. Probably often with few results. I don't even think the amount of information is the real limitation. It's probably the quality.

Re: CIA malware and hacking tools

#498
post #9

- Smart TV turned into listening devices with fake off mode? - Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc. - Dozens of O-day attacks again Andriod and iPhone. Pretty powerful stuff.

The iOS attack breakdown lists a combination of vulnerabilities in very old versions of iOS, vulnerabilities first published by jailbreak teams, and a couple purchased vulnerabilities. The breakdown ends with a publicly jailbroken iOS version. The Smart TV implant appears to just be a modified version of an open source firmware replacement project.

> vulnerabilities first published by jailbreak teams,

I guess we now know who is sponsoring these jailbreak guys and why.

Re: CIA malware and hacking tools

#499
post #82

I don't really get into political commentary, and I'm not a US citizen, but there's some great RE tips in there. I genuinely lol'ed at their assessment about Comodo's whitelist-only firewall/av. Also, this: https://wikileaks.org/ciav7p1/cms/page_17760284.html (゚ヮ゚)

Thats how you know the leak is real, because this is classic internal Wiki shenanigans, you can't make this up. Also, though there are some talented people working here (you can identify some of their github accounts, thanks to wikileaks tying users to their posts by ID) but I think a LOT of these tools are made/stolen/purchased from elsewhere..

Re: CIA malware and hacking tools

#500
post #92

In what is surely one of the most astounding intelligence own goals in living memory, the CIA structured its classification regime such that for the most market valuable part of "Vault 7" — the CIA's weaponized malware (implants + zero days), Listening Posts (LP), and Command and Control (C2) systems — the agency has little legal recourse. The CIA made these systems unclassified. Why the CIA chose to make its cyberar…

Why do they make such monumentally short-sighted, clearly bad decisions? Is it weak technical leadership (weak political or just old fashioned weak)? What is the internal logic these people use to justify pure folly that's probably done more harm than good even to their own interests and goals? Baffling.
Post reply on HN