Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows
1–10 of 45 posts
Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows
#2Because it seems to be a lightweight blog post based on an already old leak, without much analysis.
Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows
#3Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows
#4Is this just an article based on the (already posted) vault7 trove of documents? Because it seems to be a lightweight blog post based on an already old leak, without much analysis.
Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows
#5The SSID is the name of a Mexican restaurant in western Washington DC...
Unfortunately the document doesn't include API documentation for the geolocation services of Google and Microsoft. Would be interesting to know if CIA is aware of a way around api-key restrictions :)
Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows
#6I think there is definitely something to be said for the fact that if the CIA is doing this, then criminals are too - since the fine line between what the CIA does and what a criminal does is simply, a sheet of paper with someones signature on it.
Most of all, however, I think its very important that we continue to reveal these secrets. For those of us not living under the CIA's nefarious shadow, it is good to see them get their secrets revealed.
Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows
#7Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows
#8Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows
#9If one was to purchase a Mac and it was to be intercepted and infected, what does that resealing process look like?
Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows
#10Many will quietly connect to open APs when they're discovered and use DNS requests to tunnel this information back, thus attempting to work around captive portals. They might, for example, send an A-record query like this:
chrissnell-laptop-DEADBEEFC0W.security.bigcorp.com
where DEADBEEFC0W is the ESSID of a discovered nearby AP and security.bigcorp.com is a specialized DNS server configured to record this data.