Live data from Hacker News

Wikileaks releases CIA's Marble: Malware obfuscation tools

wikileaks.org

191–200 of 284 posts

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#191
post #165

Earlier quoted context omitted.

im sure youre in favor of wikileaks publishing the US nuclear launch codes for isis or russia to use. information should be set free even if it sets off the Apocalypse?

Maybe we shouldn't have systems that are just a password away leak from creating the Apocalypse? Actually, I am pretty sure we don't. Those codes come in pairs and are all subject to two person control. Also, those guys that turn the keys can use their own judgment to veto the launch. In the event a leak was known or an unknown reason to launch came through I suspect they wouldn't. Those codes won't let them re-targe…

pedantry and avoiding the whole logical point. the whole point is there can exist such secrets. how about if they leak seal team 6's location the second they touch down to kill osama? can you honestly not think of such a situation? if you can then why not refute the point instead of dissembling?

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#192

Earlier quoted context omitted.

> The most blatant endgame here for the US is "NK hacked us. They have nukes! It's time to invade!". And then NK becomes a new market for the West to take over for cheap as they did in Communist Yugoslavia and so on But "They have nukes!" would be reasonable enough reason to invade. Why not work with that narrative as opposed to "They're hacking us!"? Some might say the US has a moral obligation to pursue regime chan…

I do think nukes are the primary reason, much like with Iran. But you see a trend with Iran, Russia, China, NK- when the country is too legitimate to invade (compared to little Serbia or Somalia), isolation and sanctions are pursued. Perhaps it is convenient fear-mongering and deepening of arguments. America seems to be pretty good at spreading multi-faceted arguments about why you shouldn't even _think_ about the le…

> I do think nukes are the primary reason, much like with Iran. But you see a trend with Iran, Russia, China, NK- when the country is too legitimate to invade (compared to little Serbia or Somalia), isolation and sanctions are pursued.

Stuxnet was (in a sense) a much more interesting topic than this leak. It showed that the retaliation is pursued not only by isolation and sanctioning, but with (subtle & undercover) direct attacks too.

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#193

How about instead of talking about whether Wikileaks is good or bad or whether you support them or not, let's talk about the content of the post. From what I've read so far, this is pretty freaking cool. It's super interesting to read these docs and see their thought process involved, especially since the product their building is so different from what people are making on a day to day business. It actually looks pr…

Self-modifying the underlying machine code isn't what it used to be. Besides the difficulty in writing it, there's lot's of caveats about how it interacts with the cache and the instruction pipeline. It also requires setup, because with modern memory protection all the machine code is read-only. Changing the memory protection for some machine code to be executable and writable at once will set off some alarms (And is…

Wow, very interesting. Thanks!

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#194
post #24

I've really turned on Wikileaks. Itd be one thing if all the major powers had equivalent leaks publishing, but focusing on the US basically serves Chinese and Russian interests far more than it does the citizens of the US. String obfuscation isn't stemming from some corrupt deal that needs sunlight... this is just doing a disservice to their original mission.

honest question: does wikileaks not have necessary connections in China to collect the intel and stuff?

Honest answer AFAIK: I met Julian back in 1997 in Australia at the security conference that launched his and Suelette Dreyfus' book about the history of the Melbourne hacker scene, Underground. I met him again at HAR2009 in the Netherlands. He was very interested in the fact that I had been living in China for nearly 10 years and confided that he was really surprised after Wikileaks launched not to have received Chinese materials. I hope to meet him again as a free man... or the next time I'm in London. In my opinion he's a fantastic person, an internationalist and a pragmatist who shares knowledge and resources, has truly excelled in multiple fields and genuinely embodies the triple ideals of curiosity, intelligence and social concern. The world needs more Julians, but I think he would agree it would be better if an organization like Wikileaks wasn't required to keep the bastards honest. Shame on those working in defense and surveillance industries.

PS. Everyone here should play the 4 hour game Orwell which does a great job of communicating the social ethics at play in surveillance abuse of technology: https://news.ycombinator.com/item?id=13549725

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#195

Earlier quoted context omitted.

Does any evidence exist that suggests Wikileaks is withholding information on China or Russia? If not, I don't see how you could conclude they're 'focusing on the US'. They publish what they receive.

To what extent are Wikileaks actively soliciting inputs from Russia or China? Why, for example, was the Panama Papers leak (or other major financial disclosure leaks) not handled through Wikileaks? (Edward Snowden's disclosures would be another example, though that did target the US.)

I believe most if not all of thier staff is English-speaking (and not Chinese/Russian-speaking). They'd have to find different staff to work in yhose other languages, or to even inderstand the documents' importance.

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#196

Earlier quoted context omitted.

I totally support Wikileaks. Both China and Russia are oppressive regimes. They don't pretend to be "land of free" while oppressing their people. USA does! Secondly there is element of "outcome". Exposing US government has clear benefit of keeping people informed and hence help them make better voting decisions. Telling Chinese people that their government is systematically harvesting organs of Tibetian people has no…

I'm a young person with other young people friends. One such friend grew up in Shanghai. He had never heard of the Tiananmen Square student protests (and the resulting military intervention) until he came to the US for college and someone asked him about it. Anecdotally, it seems China does a very, very, good job of controlling information through their extensive government controls. Telling Chinese people about some…

Your young friend was uninformed but that doesn't mean that most people in China don't know about the incident. You have to get something much further than that.

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#197

I've really turned on Wikileaks. Itd be one thing if all the major powers had equivalent leaks publishing, but focusing on the US basically serves Chinese and Russian interests far more than it does the citizens of the US. String obfuscation isn't stemming from some corrupt deal that needs sunlight... this is just doing a disservice to their original mission.

Well, if you ask rest of the world, they are quite happy to know what's really going on. It would be great that we can see the bottom of things in China or Russia, but that's not up to them. How do you know that WL got something real but didn't release deliberately?

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#198

How about instead of talking about whether Wikileaks is good or bad or whether you support them or not, let's talk about the content of the post. From what I've read so far, this is pretty freaking cool. It's super interesting to read these docs and see their thought process involved, especially since the product their building is so different from what people are making on a day to day business. It actually looks pr…

Edit: part of my comment is corrected by comment below - Thanks openasocket!

Another comment about the content of this article:

Three quarters down the wiki page there is code for "adding foreign language" to the code. The options are are to add code comments in Arabic/Chinese/Russian/Korean/Farsi. My gut reaction is the purpose of this added language is to obfuscate the true source of the code - i.e. the code has Chinese comments in it so it must be from China. Ahh. I guess this makes sense to do. Only problem now is that the Chinese/Russian/Farsi/etc characters that they included in their code is now public. (Obviously now the CIA will change the foreign language words they insert)

I'd posit if someone had an X-year-old (i.e. x=7) copy of some malware, and the malware had these specific foreign language comments as shown by the article, there's a good possibility the source of the malware would be from the us government.

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#199
post #198

How about instead of talking about whether Wikileaks is good or bad or whether you support them or not, let's talk about the content of the post. From what I've read so far, this is pretty freaking cool. It's super interesting to read these docs and see their thought process involved, especially since the product their building is so different from what people are making on a day to day business. It actually looks pr…

Edit: part of my comment is corrected by comment below - Thanks openasocket! Another comment about the content of this article: Three quarters down the wiki page there is code for "adding foreign language" to the code. The options are are to add code comments in Arabic/Chinese/Russian/Korean/Farsi. My gut reaction is the purpose of this added language is to obfuscate the true source of the code - i.e. the code has Ch…

This is for obfuscating string constants, the foreign languages included is a red herring. The reason for this is that nontrivial code often has string constants in it, and the string contents are stored in the ELF/PE file in a manner that makes it trivial to extract. Since these strings often reveal a lot about the malware (e.g. a string constant "Your computer has been infected with randomware. Please deposit %d bitcoins to address %s") antivirus signatures often use them to detect specific kinds of malware, and reverse engineers find them useful in determining what a binary does. This framework scrambles the string contents (using techniques like XOR-ing every character against a random key), and injects some code into the executable so that the strings are unscrambled on startup. They just have foreign languages in the example to demonstrate this framework correctly handles unicode.

Analysts never use the language of the code comments for attribution, because such things are trivial to forge.

Re: Wikileaks releases CIA's Marble: Malware obfuscation tools

#200

I wonder if Sony really was "hacked by the North Koreans" then.

We have fairly extensive evidence that Sony was hacked by a Russian-based APT group. It is likely they were paid to do so by the North Koreans. Check out https://www.operationblockbuster.com/wp-content/uploads/2016... for more info. TL;DR attribution is based on shared C2 and staging server infrastructure, a shared code base with unique implementations, and even shared public keys.

Disclaimer: I know and have worked with the people on Operation Blockbuster.

Post reply on HN