Live data from Hacker News

Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows

wikileaks.org

11–20 of 45 posts

Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows

#11
After reading through the user guide, this appears to contain no vulnerabilities/exploits, just a payload to fulfill a need to track the location pattern of a target.

This is very basic stuff which could be easily replicated with kismet and some scripts. I am guessing this is some sort of intern project.

Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows

#13
post #6

To me, these stories are a) vital, and b) dis-heartening, and c) demonstrative of the fact that we need to continue to build better, open and secure, operating systems and tools for end users. I think there is definitely something to be said for the fact that if the CIA is doing this, then criminals are too - since the fine line between what the CIA does and what a criminal does is simply, a sheet of paper with someo…

I am curious as to what you believe the CIA is supposed to be doing?

Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows

#14
post #4

Is this just an article based on the (already posted) vault7 trove of documents? Because it seems to be a lightweight blog post based on an already old leak, without much analysis.

vault7 has been announced and partially released, but wikileaks has been releasing a trickle of new documents over time (it seems they learned from the strategic timing of snowden release documents); these documents are new to the public. they seem to release new documents from the vault7 trove every week or two.

So Wikileaks is now in the policy of filtering documents and release timings to shape a narrative?

I seem to recall that their claim to fame was that they were above trying to manipulate the narrative and simply dumped documents when they got them.

Why should we trust a cabal of people who are not telling us the full scope of the situation, and instead filtering what we know based on their desire to shape our opinion over any of the other cabals doing the same thing?

Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows

#15

After reading through the user guide, this appears to contain no vulnerabilities/exploits, just a payload to fulfill a need to track the location pattern of a target. This is very basic stuff which could be easily replicated with kismet and some scripts. I am guessing this is some sort of intern project.

Well, it depends on the target: using a sledgehammer to crack a nut can leave you with more damage than results.

Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows

#16

After reading through the user guide, this appears to contain no vulnerabilities/exploits, just a payload to fulfill a need to track the location pattern of a target. This is very basic stuff which could be easily replicated with kismet and some scripts. I am guessing this is some sort of intern project.

Well, it depends on the target: using a sledgehammer to crack a nut can leave you with more damage than results.

Sorry, I am not sure I understand the analogy?

Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows

#17
post #4

Earlier quoted context omitted.

vault7 has been announced and partially released, but wikileaks has been releasing a trickle of new documents over time (it seems they learned from the strategic timing of snowden release documents); these documents are new to the public. they seem to release new documents from the vault7 trove every week or two.

So Wikileaks is now in the policy of filtering documents and release timings to shape a narrative? I seem to recall that their claim to fame was that they were above trying to manipulate the narrative and simply dumped documents when they got them. Why should we trust a cabal of people who are not telling us the full scope of the situation, and instead filtering what we know based on their desire to shape our opinion…

If they are trying to filter something, they are doing a pretty awful job. Everything released so far in Vault 7 appears to simply be a dump of intelligence collection tradecraft/methods.

Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows

#19

This is nothing new. Many IT departments at security-sensitive companies have been doing this for a while with their own gear. It's quite common for enterprised-managed laptops to scan for SSIDs and report this information back to HQ. This is primarily done to assist in the tracking of stolen laptops. Many will quietly connect to open APs when they're discovered and use DNS requests to tunnel this information back, t…

This is a big issue with the CIA tool leaks. The really interesting part is who they're using the tools against and how often; the tools themselves, devoid of context, aren't really very interesting.

If they're using this to track a dozen intelligence officials in Saudi Arabia, it's very different optics from if they're using this to track, say, tens of thousands of "red-flagged" families in the US. (Especially since the CIA technically shouldn't be performing any sort of surveillance within the US.)

The NSA leaks, or at least part of them, were a much bigger deal because they revealed warrantless, widespread, persistent drag-net surveillance of US citizens. So far, the CIA leaks have not revealed anything relating to surveillance of US citizens or even any civilians living anywhere.

The CIA may very well (still) be evil, but these leaks do not even begin to prove it, so far.

Re: Wikileaks reveals CIA's Elsa: a geo-location malware for WiFi / Windows

#20

Earlier quoted context omitted.

Well, it depends on the target: using a sledgehammer to crack a nut can leave you with more damage than results.

Sorry, I am not sure I understand the analogy?

He's saying for some simple jobs you don't want to use a more complex too because there could be consequences. In this context, you don't need to use a fancy exploit that could get into the wild, lead to discovery and be blocked from other targets, or whatever else, when you can use something as simple as this exploit.
Post reply on HN