Live data from Hacker News

Wikileaks releases CIA's Marble: Malware obfuscation tools

wikileaks.org

81–90 of 284 posts

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#81
post #73
post #65

Earlier quoted context omitted.

I'm not sure i follow your reasoning. I follow all of their leaks, but i'm not aware of these "summaries" you are referring to. It sounds like perhaps your interaction with wikileaks is mediated by the media, and your problem is with the media. For instance, this link we are commenting on is directly to a primary document, with no summary provided. The only "summaries" i am aware of, would be their tweets, which are…

https://wikileaks.org/vault7/#Marble Framework > The source code shows that Marble has test examples not just in English but also in Chinese, Russian, Korean, Arabic and Farsi. This would permit a forensic attribution double game, for example by pretending that the spoken language of the malware creator was not American English, but Chinese, but then showing attempts to conceal the use of Chinese, drawing forensic in…

>There's no evidence the CIA has ever done this. This is pure conjecture based on the fact that there's demo code showing that the library supports Unicode.

Where is the conjecture? the exact quote is "this would permit" not "this has happened"

> They're pretty obviously trying to push the idea that attribution of hacks (such as the DNC hack) can be really easily spoofed, and you shouldn't trust them.

They are ~revealing~ the capability and intent of attribution obfuscation. I disagree with your assessment that they are ~pushing~ something, implying that there is something which is not self-evident which requires some kind of coercion for belief.

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#82
post #31

I've really turned on Wikileaks. Itd be one thing if all the major powers had equivalent leaks publishing, but focusing on the US basically serves Chinese and Russian interests far more than it does the citizens of the US. String obfuscation isn't stemming from some corrupt deal that needs sunlight... this is just doing a disservice to their original mission.

The truth isn't responsible for serving anyone's interests, and especially not the interests of the biggest secret keeper. The truth is not political, except that it is the natural enemy of politics which rely upon secrecy. If your perspective is that more secrets are being kept by more egregious actors than the US, the truth welcomes your contribution...

> The truth is not political

Nonsense.

Discovering and revealing the truth, and the timing of those actions, can absolutely be political.

If one out of 4 PARTY-X Congressmen are cheating on their wives, and one out of 5 PARTY-Y Congressmen are cheating on their wives...

But somehow wikileaks publishes a list of Congressmen cheating on their wives a week before the election, and they're all PARTY-X on the list, and no PARTY-Y, you get to wonder if it was political.

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#83
post #52
post #22

Earlier quoted context omitted.

It's much harder to leak Russian stuff because a lot of it is in paper form. After Snowden revelations, Russians returned to typewriters for all their top secret stuff [0]: > A source at Russia's Federal Guard Service (FSO), which is in charge of safeguarding Kremlin communications and protecting President Vladimir Putin, claimed that the return to typewriters has been prompted by the publication of secret documents…

Interesting. > Russians returned to typewriters for all their top secret stuff That's what they're telling people, I wonder how much truth there is to it. At the very least it provides a plausible cover story for when people ask why there aren't big leaks.

Not sure why they'd need a cover story for not having big leaks. It's not like US intentionally leaks things either. Anybody is free to try and hack their systems just the same way people hack US ones.

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#85
post #31

I've really turned on Wikileaks. Itd be one thing if all the major powers had equivalent leaks publishing, but focusing on the US basically serves Chinese and Russian interests far more than it does the citizens of the US. String obfuscation isn't stemming from some corrupt deal that needs sunlight... this is just doing a disservice to their original mission.

The truth isn't responsible for serving anyone's interests, and especially not the interests of the biggest secret keeper. The truth is not political, except that it is the natural enemy of politics which rely upon secrecy. If your perspective is that more secrets are being kept by more egregious actors than the US, the truth welcomes your contribution...

The truth may not be political, however the curation is. Take the US election, for example. Wikileaks has released information about Clinton and the DNC, and claims they have stuff they never released about Trump and the GOP [1, 2]. Other sources have said the GOP was hacked in the same attack that got Podesta [3].

The only person less likely to criticize Russia than Trump is Assange.

Wikileaks lost any proximity to an alleged moral high ground when they stopped leaking everything they got, and started editorializing their release schedule for political impact, started talking about US politics, and held back bad things about people they like.

(I say this as someone who is very pro-Snowden.)

1/ http://thehill.com/blogs/ballot-box/presidential-races/29345...

2/ http://theweek.com/speedreads/645239/julian-assange-tells-me...

3/ http://www.nbcnews.com/news/us-news/russia-hack-u-s-politics...

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#86

I've really turned on Wikileaks. Itd be one thing if all the major powers had equivalent leaks publishing, but focusing on the US basically serves Chinese and Russian interests far more than it does the citizens of the US. String obfuscation isn't stemming from some corrupt deal that needs sunlight... this is just doing a disservice to their original mission.

Focusing on the US, serves the US.. But i guess it depends what kind of country you want to live in.

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#87

I've really turned on Wikileaks. Itd be one thing if all the major powers had equivalent leaks publishing, but focusing on the US basically serves Chinese and Russian interests far more than it does the citizens of the US. String obfuscation isn't stemming from some corrupt deal that needs sunlight... this is just doing a disservice to their original mission.

I don't think Australian citizens need to care that much. Also, Chinese and Russian are much higher-hanging fruit if your group primarily speaks English.

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#88
post #66

Earlier quoted context omitted.

So "egregious" behavior extends only to digital surveillance? OK, fine. Surely the US is the worst at that, I think that's a fair assessment. I thought you were talking about seemingly-Wikileak relevant things like secret police stuff, control over national media, poisoning of political enemies, assassinations... Y'know. Boring stuff. Not "egregious" I guess.

>like secret police stuff, control over national media, poisoning of political enemies, assassinations How about "secret police stuff" like the illegal abductions of people to put them into torture "black sites" all over the world? [0] Massive control over global media trough lobbying and propaganda instruments? [1] A long history of successful, and not so successful assassination attempts aimed at the "ideological o…

Sorry, what does any of that have to do with the seeming lack of objectivity in Wikileaks decisions as to what to seek and publish?

You bury it in there ("The point here not being..."), but I think you agree with me. No?

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#89
post #55
post #46

Earlier quoted context omitted.

> If your perspective is that more secrets are being kept by more egregious actors than the US, the truth welcomes your contribution... If your perspective is that the US is truly the most secretive and "egregious" actor on the modern stage, then you are shockingly naive. Or, more likely, misled by the skewed "truth" you are reading.

please provide something to educate me. Who has more spy bases around the world? Who has disseminated their spy tools so widely that they have become available to 3rd parties? Who else is tapping undersea fiber? Who else is behind the SSL layer at google? I like primary documents obviously, but publications are fine too.

That is one of those "known unknowns". That is something you know you do not know that answer to and can never know. If I pick a random poor third world country and tell you they are you can never be sure I'm wrong - "all those villagers going to the river for dirty drinking have a phd equivalent in spying: they only go to the river when people are looking, the rest of the time they use the running water in the basement of the hut - I'll bet you didn't know those grass huts have mansion sized basement underneath with full electric: see how good they are". This of course completely bogus but you can't actually know that for sure.

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#90
post #76
post #73

Earlier quoted context omitted.

https://wikileaks.org/vault7/#Marble Framework > The source code shows that Marble has test examples not just in English but also in Chinese, Russian, Korean, Arabic and Farsi. This would permit a forensic attribution double game, for example by pretending that the spoken language of the malware creator was not American English, but Chinese, but then showing attempts to conceal the use of Chinese, drawing forensic in…

> They're pretty obviously trying to push the idea that attribution of hacks (such as the DNC hack) can be really easily spoofed, and you shouldn't trust them. OK, and? Is it incorrect that they can spoofed? If not, doesn't that necessarily mean that you can't take "the Russians did this" at face value?

It's entirely irrelevant to this release. The attribution to Russia has nothing to do with the language of strings embedded in the malware.

It's based on the re-use of the same exact techniques, including command-and-control server addresses and encryption keys that have been used in many, many other attacks that align extremely closely with Russian interests.

Successfully hacking, over the course of about a decade, American government interests, Eastern Ukrainian militias, Russian dissidents, the Olympic anti-doping committee investigating Russia's wide-spread doping scandal, journalists investigating the downing of MH17, etc. would be a very convoluted and expensive way to spoof attribution of this one attack.

Post reply on HN