Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

521–530 of 1001 posts

Re: CIA malware and hacking tools

#521
post #391

Earlier quoted context omitted.

The problem is that there are very few IT systems that are purely foreign. For example, if the CIA finds an exploit in a wireless router made in China and sold all over the world, that hole can also be found by others and used against targets in the United States. Is being able to hack others worth letting ourselves get hacked?

> Is being able to hack others worth letting ourselves get hacked? The answer to this for me is a clear no. What I was more questioning is given the CIA's role and job, I don't think it's necessarily their responsibility to do it. We're talking about a government agency who's purpose is to collect information about potential threats against the US, they have no reason to want to make that harder on themselves. If you…

If while performing counter-intelligence the CIA discovers that a foreign government/company can/is exploiting computer systems within the US, should the CIA have a responsibility to do anything?

Re: CIA malware and hacking tools

#522
post #428

Earlier quoted context omitted.

I think what it's trying to convey is that there's absolutely no legal recourse in any capacity for the CIA at this point to try and do any sort of damage control.

I am bemused by the naivete that they would care about legal recourse and not just blackbag you and Gitmo2.0 your posteriors if they felt like it.

That's difficult when a large company like Google or Microsoft use the tools as part of their development process to make their software more secure. These are organizations with a very large megaphone if the CIA did that to their employees.

Re: CIA malware and hacking tools

#523

Any guesses on why CNN and MSNBC are completely avoiding reporting this news?

http://money.cnn.com/2017/03/07/technology/wikileaks-cia-hac... http://www.msnbc.com/andrea-mitchell-reports/watch/former-ci... "Completely avoiding"?

It's like 80% of the first page real estate on MSNBC right now:

https://i.imgur.com/KDLbXOx.png

Re: CIA malware and hacking tools

#524
post #464

Earlier quoted context omitted.

Not really; copyright is mostly implicit. If US law made all code developed for the purposes of the CIA automatically copyrighted, the code would be copyrighted. Right now the law says it isn't, so it isn't. Having code be copyrighted does not require any explicit registration.

This is TOTALLY wrong.... All code developed by US Governement is PUBLIC DOMAIN.

The correct part is a work does not have to be registered to have copyright protection. You are also correct that works created by the U.S. federal government do not have copyright protection, they're in the public domain. However, and I think the post you're responding implies this, copyright protected work may be licensed by the federal government without losing its copyright and I think in at least some circumstances works can by created by contract for the federal government and retain copyright protection.

I don't think I've followed the larger point, I don't see how copyright is relevant to the production or dissemination of malware.

Re: CIA malware and hacking tools

#525

Earlier quoted context omitted.

You misunderstand the point of the form. The point is that if later you are suspected of one of those activities, you can be deported because you lied on the form, even though it might be impossible to convict you for the activity itself.

This is absolutely correct. Plus, what they did may not be illegal per se, but we might not want them in the country. For example, I'm not aware of any U.S. law that specifically makes it illegal to have been Nazi concentration camp guard. But we don't want people like that in the country and want to deport them if they are ever found here. Hence the purpose of the immigration form.

Unless they are really good rocket scientists...

Re: CIA malware and hacking tools

#526

Earlier quoted context omitted.

Another victim of sensationalism.

The conclusions are correct. Talking about them isn't sensationalist just because you think they're foreseeable.

I refered to "being not surprised that encryption is broken". There was nothing relevant to encr in the document. The title is wrong.

Re: CIA malware and hacking tools

#527
post #375

Earlier quoted context omitted.

So then there would be no justifiable reason to reject a FOIA request for the source code.

I’m going to assume that the response would be that there are no such thing as Vault 7, a digital capability or even the CIA.

No, it will be the Glomar defense or nothing at all.

Re: CIA malware and hacking tools

#528

Earlier quoted context omitted.

Obviously there's a difference between cyber and conventional weapons, but imagine if the same rationale were extended to physical munitions: "We can't drop this bomb on the enemy, it contains classified technology"

This is certainly a big headache not just for munitions but lots of military equipment. A famous recent example was the Navy Seals blowing up one of their (experimental) Stealth Black Hawks when it was damaged while landing during the Bin Laden raid. Edit: scuttle; (verb): sink (one's own ship) deliberately by holing it or opening its seacocks to let water in

Scuttling isn't just for the sake of classified technology (which usually has been separately rigged to be easily destroyed without destroying its carrier.)

The more important role of scuttling—at least during wartime—is to prevent the ship you just abandoned getting hauled into the enemy's shipyard as a "prize" and restored to service with its guns pointed back toward you.

This is also more toward what is meant by Naval captains "going down with the ship" during battle: they stick around to act as a guard (and proximity fuse) for the scuttling charges, so that whoever just disabled the vessel can't just hop on-board and drive her home. (And, just maybe, catch a large enemy marine contingent in a grand old explosion if they try.)

Re: CIA malware and hacking tools

#529
post #475

Also: OmniGraffle and Sublime Text license keys (registered to "Affinity Computer Technology") https://wikileaks.org/ciav7p1/cms/page_25264141.html https://wikileaks.org/ciav7p1/cms/page_9535650.html

I tried Sublime Text license key and it worked!

Aren't they verified server-side somehow? … I assumed the 10 seats would have been gone almost immediately.

Re: CIA malware and hacking tools

#530
post #488
post #5

Based on the overview alone (of course I can't read the entire report that fast!), this is exactly what I expect a spy agency would be doing -- if they were not then I would be disappointed. What exactly in the admittedly shortened list am I supposed to be upset about? It makes no distinction between US citizens and overseas parties. If these actions are being done domestically against US citizens, with no just cause…

> What exactly in the admittedly shortened list am I supposed to be upset about? That, with taxpayer dollars, the government of the United States is undermining the security of consumer devices around the world. Part of the difference between your worldview and the view of those of us who find this behavior childish and unacceptable is that you "expect a spy agency would be doing [this;] if they were not then [you] w…

It sounds like you believe that what you do on the internet is private and that everyone will just agree to leave it at that. Global diplomacy is a competition, and if you aren't doing everything you can, and keeping pace with technology, you will get left behind. It might not be pleasant, but I would rather, have my country gathering intelligence about me in this manner than other countries. Plus warfare has always been one of the biggest drivers of innovation, this war will and is stimulating innovation in cyber security.
Post reply on HN