Earlier quoted context omitted.
The truth may not be political, however the curation is. Take the US election, for example. Wikileaks has released information about Clinton and the DNC, and claims they have stuff they never released about Trump and the GOP [1, 2]. Other sources have said the GOP was hacked in the same attack that got Podesta [3]. The only person less likely to criticize Russia than Trump is Assange. Wikileaks lost any proximity to…
Do you hold WaPo, NYT, CNN to those same standards? Because that is mainly what American "MSM" does, selectively publish information which bebefits the agenda of American foreign policy interests. It's fair if you align yourself with American foreign policy interests, I do too, but to single out other publications that don't follow that agenda is just a case of having self interested double standards. All of the crit…
Wikileaks releases CIA's Marble: Malware obfuscation tools
121–130 of 284 posts
Re: Wikileaks releases CIA's Marble: Malware obfuscation tools
#122this comment is a great example of foreign astroturfing try posting from an account with a comment history next time
Re: Wikileaks releases CIA's Marble: Malware obfuscation tools
#123Could be a fun one for game DRM? Or apps where an API key is hidden in the binary?
Re: Wikileaks releases CIA's Marble: Malware obfuscation tools
#124Earlier quoted context omitted.
> They're pretty obviously trying to push the idea that attribution of hacks (such as the DNC hack) can be really easily spoofed, and you shouldn't trust them. OK, and? Is it incorrect that they can spoofed? If not, doesn't that necessarily mean that you can't take "the Russians did this" at face value?
It's entirely irrelevant to this release. The attribution to Russia has nothing to do with the language of strings embedded in the malware. It's based on the re-use of the same exact techniques, including command-and-control server addresses and encryption keys that have been used in many, many other attacks that align extremely closely with Russian interests. Successfully hacking, over the course of about a decade,…
Is there an official source that actually breaks down the similarities to which attacks? I have my doubts about the attribution of the DNC hack to _state_ agents. The only specific I've read was the Gucifer 2.0 windows language being set to Russian.
Every other attribution has been a "trust us, we've seen this before" but I am very skeptical of intelligence and law enforcement agencies unattributed claims and I think they've earned that distrust.
Re: Wikileaks releases CIA's Marble: Malware obfuscation tools
#125Earlier quoted context omitted.
https://wikileaks.org/vault7/#Marble Framework > The source code shows that Marble has test examples not just in English but also in Chinese, Russian, Korean, Arabic and Farsi. This would permit a forensic attribution double game, for example by pretending that the spoken language of the malware creator was not American English, but Chinese, but then showing attempts to conceal the use of Chinese, drawing forensic in…
>There's no evidence the CIA has ever done this. This is pure conjecture based on the fact that there's demo code showing that the library supports Unicode. Where is the conjecture? the exact quote is "this would permit" not "this has happened" > They're pretty obviously trying to push the idea that attribution of hacks (such as the DNC hack) can be really easily spoofed, and you shouldn't trust them. They are ~revea…
Wikileaks is implying -- heavily enough that every news article I've seen mentions it (some, even, without the "might" or "could") -- that the main reason the CIA would support Unicode is so that they can trick people into thinking they're Chinese.
Mentioning (the quite obvious fact) that it's possible to include foreign text in code as an effort to confuse adversaries, while discussing an actual implementation of text obfuscation, will confuse reasonable people who lack the technical understanding of what this is into thinking the software obfuscates text by somehow changing the language it's in.
Here's a more egregious example:
This doc (https://wikileaks.org/ciav7p1/cms/page_13763790.html) contains one line "Vehicle Systems (e.g. VSEP)." It doesn't elaborate what "Vehicle Systems" they mean or define "VSEP," but given the other projects worked on by the same team (all using embedded systems to spy on you), the most reasonable interpretation to me is that they'd be trying to intercept GPS and other sensor data, including voice and video from cameras and microphones.
Wikileaks wrote "As of October 2014 the CIA was also looking at infecting the vehicle control systems used by modern cars and trucks. The purpose of such control is not specified, but it would permit the CIA to engage in nearly undetectable assassinations." In this case, they added the word "control" from nothing, making the completely unsupported claim that the CIA is investigating the possibility of assassinating people by hacking their cars (which, hey, might be true... but there's nothing supporting that idea here).
Sure enough, dozens of article were written about how the CIA is killing people by driving their cars off cliffs.
Re: Wikileaks releases CIA's Marble: Malware obfuscation tools
#126I've really turned on Wikileaks. Itd be one thing if all the major powers had equivalent leaks publishing, but focusing on the US basically serves Chinese and Russian interests far more than it does the citizens of the US. String obfuscation isn't stemming from some corrupt deal that needs sunlight... this is just doing a disservice to their original mission.
Re: Wikileaks releases CIA's Marble: Malware obfuscation tools
#127this comment is a great example of foreign astroturfing try posting from an account with a comment history next time
I hope my comment history works for you and you will not be reporting me to any "authorities"
Re: Wikileaks releases CIA's Marble: Malware obfuscation tools
#128Earlier quoted context omitted.
I totally support Wikileaks. Both China and Russia are oppressive regimes. They don't pretend to be "land of free" while oppressing their people. USA does! Secondly there is element of "outcome". Exposing US government has clear benefit of keeping people informed and hence help them make better voting decisions. Telling Chinese people that their government is systematically harvesting organs of Tibetian people has no…
>Telling Chinese people that their government is systematically harvesting organs of Tibetian people has no new information or benefit. This is hilarious. Whatever you have been smoking, it needs to stop.
Re: Wikileaks releases CIA's Marble: Malware obfuscation tools
#129It's obviously that no matter how big NSA conspiracy is every dollar spent, every meeting occur, every decision made all have to be controlled and documented. And any 3rd party company working for agency must have official contract, must report taxes and sometimes can even sell all the same tools for other governments. So it's thousand people participate at every single step.
In world of paranoid and corrupt ex-KGB mafia nothing like that required. All you need is just few experts and enough of money. Russia have plenty of online criminals: carders, illegal pharmacy and drug dealers, owners of credit card processings used for fraud, money laundering payment systems, botnet owners, spyware developers and most of them are controlled by state or somewhat under special agency protection racket.
Need 0-day exploit? Rootkit? Spyware? Any unique tools? Anything can is there for money! DDoS attack or a lot of proxy servers at any location needed? Plenty of services there and agencies obviously know owners. No documentation or reporting needed since corrupt government agencies are closely tied to those criminals for years.
So the same attacks that would involve at least few hundred of people in usual US three letter agency would likely require to just few dozens in Russia. What's more important no one would ever tell the difference between this activity and usual agency behaviour that related to usual corruption schemes.
So if you seriously think there is Russian government behind some attacks then shouldn't expect any leaks about that. If there is something important for Kremlin they wouldn't mind to dump money on it, but there will be very few people aware of it and of course there will never be any documents or other traces since they would be done as any other attack against commercial company or opposition politician.
Re: Wikileaks releases CIA's Marble: Malware obfuscation tools
#130If anything wikileaks has shown a superior journalistic record in publishing whatever comes across their desk, so I don't see people criticising wikileaks on this the weakest of points as anything but intellectually dishonest at best.