Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

721–730 of 1001 posts

Re: CIA malware and hacking tools

#721

Earlier quoted context omitted.

This is a far, far cry from the kinds of quality journalism that Wikileaks does. It appears that the claim the password was 'password' wasn't a story in and of itself but an anecdote relating to the weakness of Podesta's password (which is true). Compare that to Clapper, Director of National Intelligence stating for the record under oath that national intelligence does not have a surveillance operation targeting Amer…

> Compare that to Comey, Director of National Intelligence There is no Comey who has ever been Director of National Intelligence. I suspect you mean Clapper.

Yes. Correction made in the parent comment.

Thank you.

Re: CIA malware and hacking tools

#722
post #576

Earlier quoted context omitted.

He very clearly explained his motives for not doing so in the AMA, and he gave an alternate POL by reading from the blockchain. This whole narrative of Wikileaks not being neutral is a very weird story, because they've never published anything that wasn't verified to be true. Since that's something they can't be attacked on, it seems that the strategy for discrediting Wikileaks has now become to accuse them of associ…

This whole narrative of Wikileaks not being neutral is a very weird story, because they've never published anything that wasn't verified to be true. What does the one thing have to do with the other? Just because you're truthful doesn't mean you're neutral, and nobody is seriously denying the authenticity of these files. What, exactly, have we learned here other than a spy agency knows interesting methods of spying?…

> What, exactly, have we learned here other than a spy agency knows interesting methods of spying?

That the US government pays software companies to keep their products insecure [1]. Why do you believe that they aren't spying on American citizens?

1. https://twitter.com/Snowden/status/839168025517522944

Re: CIA malware and hacking tools

#724

Earlier quoted context omitted.

For the purpose of devil's advocate in this, I think it's possible to state truths and still be misleading and/or distracting from another narrative. Just because something is true doesn't necessarily explain what the motive is for releasing that information. It's certainly healthy to have at least a shadow of a doubt as to what WikiLeaks's motivations are when it's already shown that it can either restrain itself fr…

Strongly concur. Ask any military officer who is a ring knocker; telling a 100% truthful narrative in such a manner as to provide a false narrative is still grounds for breaking the spirit of the honor code, and thus grounds for disenrollment.

Ring knocker?

Re: CIA malware and hacking tools

#725
post #671

Earlier quoted context omitted.

For the purpose of devil's advocate in this, I think it's possible to state truths and still be misleading and/or distracting from another narrative. Just because something is true doesn't necessarily explain what the motive is for releasing that information. It's certainly healthy to have at least a shadow of a doubt as to what WikiLeaks's motivations are when it's already shown that it can either restrain itself fr…

"In fact, the Devil's Advocate may be the biggest innovation killer in America today. "[1] [1] Tom Kelley, co-founder of Ideo as in '10 Faces of Innovation'

Perhaps I'm confused, but this seems like a non-sequitur. We're not discussing innovation.

Re: CIA malware and hacking tools

#726

Earlier quoted context omitted.

I would be careful also if you think you might need to get a clearance in the future. I was in college during the initial Wikileaks Manning dump and I remember getting a email from the DoD forwarded through the Physics department that viewing or sharing classified wikileaks info could prevent us from getting a clearance in the future even of we did not have a clearance at the time.

And that's when you laugh and cite https://www.law.cornell.edu/uscode/text/18/793 subsection (e) wherein you have never transmitted nor believed the documents in question to be harmful to the defense of the United States. Especially in this case as these are all offensive tools.

Then they laugh and deny you clearance because they can.

Re: CIA malware and hacking tools

#727
post #576

Earlier quoted context omitted.

He very clearly explained his motives for not doing so in the AMA, and he gave an alternate POL by reading from the blockchain. This whole narrative of Wikileaks not being neutral is a very weird story, because they've never published anything that wasn't verified to be true. Since that's something they can't be attacked on, it seems that the strategy for discrediting Wikileaks has now become to accuse them of associ…

Let's say hypothetically that the Russian government has a Cyber Defense arm that has nearly the scope and capability as the US (the DNC/Hillary stuff seems to indicate this). Let's say this is true for many world powers (US, UK, China, and Russia for starters). However, it seems like Wikileaks, while claiming to be a neutral source that "just wants to make powerful people accountable", they only seem to be releasing…

> Let's say hypothetically that the Russian government has a Cyber Defense arm that has nearly the scope and capability as the US (the DNC/Hillary stuff seems to indicate this). Let's say this is true for many world powers (US, UK, China, and Russia for starters).

Do we think that, though? We've heard a LOT about Russia's cyber capability lately and the consensus seems to be that they employ groups of criminal kids who are by and large given free reign and occasionally called upon to look at targets of interest. We also know that the US's military spending (known budget) is something like 6x Russia's military spending, and we can imagine that intelligence spending is a similar multiple higher.

I should also make the point that the DNC/Hillary stuff is not a foregone conclusion that it was Russian. These leaks cast new light on the DNI's Grizzly Steppe paper where the NSA gave a 50/50 level of confidence that Russia was involved (but CIA and FBI said that it was greater than 50%). This leak includes information about a project called "UMBRAGE" which is a CIA project to catalog and strategically make use of hacking tools of other countries for certain projects in order to point the finger.

We do know that GCHQ has capabilities that are similar in some ways to CIA/NSA, but is it a foregone conclusion that all world powers have cyber programs this extensive? I don't think that it is.

Re: CIA malware and hacking tools

#728
post #528

Earlier quoted context omitted.

This is certainly a big headache not just for munitions but lots of military equipment. A famous recent example was the Navy Seals blowing up one of their (experimental) Stealth Black Hawks when it was damaged while landing during the Bin Laden raid. Edit: scuttle; (verb): sink (one's own ship) deliberately by holing it or opening its seacocks to let water in

Scuttling isn't just for the sake of classified technology (which usually has been separately rigged to be easily destroyed without destroying its carrier.) The more important role of scuttling—at least during wartime—is to prevent the ship you just abandoned getting hauled into the enemy's shipyard as a "prize" and restored to service with its guns pointed back toward you. This is also more toward what is meant by N…

After WWI the German fleet was scuttled (by the Germans) in Scapa Flow to prevent the Allies from using them. Notable quote from British Admiral Wemyss:

> I look upon the sinking of the German fleet as a real blessing. It disposes, once and for all, the thorny question of the redistribution of these ships.

Also of note - in WWI ships had been deliberately scuttled ('the Blockships') to secure the smaller entry ways into Scapa Flow, by WWII these (and the anti-submarine netting in the larger channels) were shown to be inadequate when U-47 sunk the HMS Royal Oak. This attack led to the building of the Churchill Barriers without which I doubt we would have anywhere near as strong a community as we currently have in the Orkney Isles.

Today the wrecks of both the German Fleet and the Blockships are excellent shallow dive sites in slightly chilly water. If you dive I strongly recommend going to Orkney.

https://en.wikipedia.org/wiki/Scuttling_of_the_German_fleet_...

http://www.scapaflowwrecks.com/wrecks/blockships/

Re: CIA malware and hacking tools

#729

Looks like the CIA is screwing the public by mutual consent. The public is demanding more of the same, just as long as it's directed at whoever is out their favor. Here're the two topmost comments on NYT at the moment[0]: karma2013 New Jersey 3 hours ago If anyone still has doubts that Wikileaks and the Russians are working together to undermine and destabilize our government institutions, erode public confidence in…

If you've spent anytime on twitter or reddit lately, there's an increasingly large amount of political astroturfing from special interest organizations. https://en.wikipedia.org/wiki/50_Cent_Party http://www.sfgate.com/technology/businessinsider/article/US-... https://en.wikipedia.org/wiki/Smith-Mundt_Modernization_Act_... https://www.theguardian.com/technology/2011/mar/17/us-spy-op...

Have you noticed this trend on HN? Because I see essentially the same sentiment in this thread. Little if anything is effected purely by overt or tacit collusion.

Re: CIA malware and hacking tools

#730
Anyone in the know how about whether the CIA subverted the security of software or whether they inserted vulnerabilities into software?

One of the shocking and disgusting things from the NSA leaks was that it actively sought to create new vulnerabilities and to create subverted software industry products in the United States.

So far it looks like the CIA is using discovered vulnerabilities (imo better than sabotaging industry). But given the size of the leaks I'm having difficulty confirming that this is indeed the case.

Post reply on HN