Live data from Hacker News

Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows

wikileaks.org

1–10 of 45 posts

Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows

#4

Is this just an article based on the (already posted) vault7 trove of documents? Because it seems to be a lightweight blog post based on an already old leak, without much analysis.

vault7 has been announced and partially released, but wikileaks has been releasing a trickle of new documents over time (it seems they learned from the strategic timing of snowden release documents); these documents are new to the public. they seem to release new documents from the vault7 trove every week or two.

Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows

#5
On page 22: " TIPICOS GLORIA 68:7F:74:74:34:2B -75 "

The SSID is the name of a Mexican restaurant in western Washington DC...

Unfortunately the document doesn't include API documentation for the geolocation services of Google and Microsoft. Would be interesting to know if CIA is aware of a way around api-key restrictions :)

Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows

#6
To me, these stories are a) vital, and b) dis-heartening, and c) demonstrative of the fact that we need to continue to build better, open and secure, operating systems and tools for end users.

I think there is definitely something to be said for the fact that if the CIA is doing this, then criminals are too - since the fine line between what the CIA does and what a criminal does is simply, a sheet of paper with someones signature on it.

Most of all, however, I think its very important that we continue to reveal these secrets. For those of us not living under the CIA's nefarious shadow, it is good to see them get their secrets revealed.

Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows

#9
I'm curious what an intercept of Mac Product looks like in the Dark Matter scenario. It's not the first mention I've seen of the CIA intercepting the supply chain of an organization.

If one was to purchase a Mac and it was to be intercepted and infected, what does that resealing process look like?

Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows

#10
This is nothing new. Many IT departments at security-sensitive companies have been doing this for a while with their own gear. It's quite common for enterprised-managed laptops to scan for SSIDs and report this information back to HQ. This is primarily done to assist in the tracking of stolen laptops.

Many will quietly connect to open APs when they're discovered and use DNS requests to tunnel this information back, thus attempting to work around captive portals. They might, for example, send an A-record query like this:

chrissnell-laptop-DEADBEEFC0W.security.bigcorp.com

where DEADBEEFC0W is the ESSID of a discovered nearby AP and security.bigcorp.com is a specialized DNS server configured to record this data.

Post reply on HN