Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

741–750 of 1001 posts

Re: CIA malware and hacking tools

#741

Also: OmniGraffle and Sublime Text license keys (registered to "Affinity Computer Technology") https://wikileaks.org/ciav7p1/cms/page_25264141.html https://wikileaks.org/ciav7p1/cms/page_9535650.html

Ooo now I can say my text editor is commissioned by the CIA!

Your tax dollars at work!

Re: CIA malware and hacking tools

#742

Earlier quoted context omitted.

While what they are publishing is true and should not be ignored, they certainly appear to be choosing their targets and not choosing others, for example, they claimed to have information from the RNC , but they did not publish it claiming it was already published in other sources. The timing of the leaks was rather suspect too. In interviews, Assange insinuated months before during the primary that he had the emails…

> While what they are publishing is true and should not be ignored Why does this matter? I feel like the reason people are worried about bias is that it means the source is not trustworthy. If Wikileaks is publishing true information, they should be trustworthy, even if their choice of targets is not unbiased.

Because what isn't printed is often more important than what is. That's what editorial influence does.

In my city, the local Hearst rag often doesn't report on things that the city administration doesn't want published. For example, a city employee was indicted for killing a girl and burying her body on city property (probably while on the clock) and was on "paid suspension" (i.e. On payroll, not working) for two years. Awkward situation for the mayor.

The arrest happened on a Friday night. The story? Page 4, section B on Monday.

In a story like this Wikileaks thing, the context is missing. How are these things used? To what end? Snowden tried to provide that context.

Re: CIA malware and hacking tools

#743

Also: OmniGraffle and Sublime Text license keys (registered to "Affinity Computer Technology") https://wikileaks.org/ciav7p1/cms/page_25264141.html https://wikileaks.org/ciav7p1/cms/page_9535650.html

... along with VMware Fusion and Workstation keys, Microsoft KMS keys, and probably more I missed.

Re: CIA malware and hacking tools

#744

The technology used by the CIA and NSA is all stuff people on HN can totally grok. That's kind of exciting and disappointing at the same time. Some people on this site could probably do better than the CIA and NSA is doing. Some people here probably wrote some of leaked stuff. Hah! I like the way the teams are broken up by device target but I think they should probably have an even more decentralized setup. Or maybe…

> The technology used by the CIA and NSA is all stuff people on HN can totally grok.

Yep, the typical stuff: CentOS, Debian, Ubuntu, Python, Ansible, Packer(.io), vim, Sublime Text, SourceTree, Git, ...

Plenty of references to Stack Overflow, Reddit, and such too.

Re: CIA malware and hacking tools

#745
post #645
post #620

Earlier quoted context omitted.

> You can publish only true facts Can we go back to just calling them "facts"? A statement can be true or false, but a fact is true. You're playing into the idea that there are "false facts" or "alternative facts." There aren't. Those are lies or errors.

It's useful to be able to talk about "facts" - including a fact pattern which is inaccurate - as distinct from opinion or assessment. From WikiPedia: > Alternatively, fact may also indicate an allegation or stipulation of something that may or may not be a true fact, (e.g., "the author's facts are not trustworthy"). This alternate usage, although contested by some, has a long history in standard English.

[deleted]

Re: CIA malware and hacking tools

#746
post #123

Earlier quoted context omitted.

I'm pretty okay with wikileaks not releasing hundreds of zero day exploits into the wild en mass.

I'd like to hear a security expert's opinion on whether releasing even patched 0-days could be considered harmful ? even if the 'sploits dont work out of the box, it seems like they would still advance the state of the art, and allow moderately-skilled hackers to build on very sophisticated designs, adapt and make them effective again - "stand on the shoulders of giants" kind of thing.

In the Equation Group releases, there were 0-days for older versions of Cisco's ASA software.

Others built on that and updated it to also exploit newer versions (9.x, IIRC) of the software.

Re: CIA malware and hacking tools

#747

Earlier quoted context omitted.

> We also know that the US's military spending (known budget) is something like 6x Russia's military spending, and we can imagine that intelligence spending is a similar multiple higher. Payroll for 5,000 hackers is within the reach of many world governments I'd think.

5,000 IT people in a government org is about $1B with base infrastructure. No big deal.

In the U.S. it is.

Re: CIA malware and hacking tools

#748
post #576

Earlier quoted context omitted.

He very clearly explained his motives for not doing so in the AMA, and he gave an alternate POL by reading from the blockchain. This whole narrative of Wikileaks not being neutral is a very weird story, because they've never published anything that wasn't verified to be true. Since that's something they can't be attacked on, it seems that the strategy for discrediting Wikileaks has now become to accuse them of associ…

Let's say hypothetically that the Russian government has a Cyber Defense arm that has nearly the scope and capability as the US (the DNC/Hillary stuff seems to indicate this). Let's say this is true for many world powers (US, UK, China, and Russia for starters). However, it seems like Wikileaks, while claiming to be a neutral source that "just wants to make powerful people accountable", they only seem to be releasing…

The amount of U.S. leaks is likely due to the relatively free environment compared to those other countries such as Russia and especially China, who have similar levels of espionage activity. The most leaks will come from environments with:

1) Relatively high freedom 2) Variety in values/opinions (often due to freedom) 3) Secrets to be leaked

1 ensures the leaker's ability to leak, 2 ensures there is a leaker to leak, and 3 ensures there is something to be leaked.

Assange outlined his goals [1] a while ago in regards to exposing secrets, and I think Wikileaks is staying in line with those rather well. It essentially states that they'll leak whatever they receive, and try to enforce a kind of 'secrecy tax' on governments/parties/organizations that refuse to be transparent via forcing them into less effective means of communication and overall less use of technology.

[1] http://cryptome.org/0002/ja-conspiracies.pdf

Re: CIA malware and hacking tools

#749

WikiLeaks Vault7 Year Zero 2017 https://archive.org/details/WikiLeaksYearZero2017V1.7z Passphrase is SplinterItIntoAThousandPiecesAndScatterItIntoTheWinds

n.b.: The actual file is at https://archive.org/download/WikiLeaksYearZero2017V1.7z/Wiki...

Torrent: https://archive.org/download/WikiLeaksYearZero2017V1.7z/Wiki...

Re: CIA malware and hacking tools

#750

It's interesting to note that Julian Assange didn't demonstrate control of the wikileaks private key during his Reddit AMA 1 month ago: https://www.reddit.com/r/IAmA/comments/5n58sm/i_am_julian_as... Considering the political situation unfolding in the US and who this leak weakens, there is some evidence that wikileaks is not in the hands of a neutral party. There is clear motive right now for undermining the CIA. Th…

There are several elements: 1) what the material exposes 2) how it was obtained 3) why it was released We should condemn (2) and (3) even if we condemn (1). That is, a properly functioning society shouldn't need to rely on leaks for corruption and abuse of power to be exposed. At the same time, we should always respond to abuse of power and trust; to do so because we don't want to help "the bad guys" simply creates a…

I have to disagree - leaks seem to be the only way that this information gets out and the only way that people seem to care much about privacy.
Post reply on HN