Live data from Hacker News

New Charges in Huge C.I.A. Breach Known as Vault 7

nytimes.com

51–60 of 187 posts

Re: New Charges in Huge C.I.A. Breach Known as Vault 7

#51
post #27

Mr. Schulte had been charged last year in New York with possession of child pornography Very interesting! It almost seems like the pornography charges against him was a way to punish him but without prosecuting him for the actual leakage. Perhaps the government wanted to still point the fingers at someone else or avoid embarrassment?

You should read the indictment. That porn was not planted. https://www.scribd.com/document/379346745/Joshua-Adam-Schult...

I read the indictment, but I don't see how you can be certain it was not planted.

He apparently saved IRC logs of their entire quest to obtain child porn....?

Using his name as a handle?

Impossible? No, but do you really think this is not questionable at all?

Re: New Charges in Huge C.I.A. Breach Known as Vault 7

#52
post #8

Earlier quoted context omitted.

Or option C: a propaganda arm of the Russian Government. EDIT: downvoters aren't offering a response, so I'll just hope or assume that they want evidence: [1] https://foreignpolicy.com/2017/08/17/wikileaks-turned-down-l... [2] https://www.theguardian.com/news/2016/apr/07/putin-dismisses... [3] http://www.haaretz.com/us-news/1.771716 [4] http://edition.cnn.com/2017/10/25/politics/cambridge-analyti... [5] https://sunli…

Calling wikileaks a propaganda arm of the Russian Government is just US propaganda. 1984 double-speak here. Can you point to ANYTHING that wikileaks has reported or released that is untrue?

You can tell the truth and still be deceitful. Claiming to have had evidence on Russian corruption and publicly declaring an intent to release followed by silence and unwillingness to do so indicate two things, to me anyway.

1. The original claim is a lie. There is no evidence of Russian corruption and the claim was made for attention or some other purpose. Remind me, again, how many lies it takes to make someone untrustworthy?

2. The original claim is true, but something or someone prevents information from being released. This is the more insidious reason. It means that the organization will only release "the truth" that jibes with the messages/agenda they want to push, which is propaganda. Regardless of whether or not Russia has a direct influence of the release is unknown, but it becomes propaganda nonetheless.

My personal opinion is that Assange is virtually inseparable from Wikileaks and appears to have a god complex, using the platform as his mouthpiece on his view of the state of things while enjoying the comforts of avoiding consequence.

Re: New Charges in Huge C.I.A. Breach Known as Vault 7

#53
post #9

> Mr. Schulte had been charged last year in New York with possession of child pornography. The fact that they found child porn on his computer is the scariest part. Almost any technical person could frame almost anyone else with CP possession. It's just a matter of putting some files on a computer and/or faking some logs, browser history, etc. It would be incredibly trivial for the CIA to put CP on his computer and t…

If you look at the indictment it details that they found encrypted files on his computer, then used a password obtained from his cell phone to decrypt the files.

If this is a setup, it's beautifully orchestrated.

Re: New Charges in Huge C.I.A. Breach Known as Vault 7

#54

Earlier quoted context omitted.

Calling wikileaks a propaganda arm of the Russian Government is just US propaganda. 1984 double-speak here. Can you point to ANYTHING that wikileaks has reported or released that is untrue?

You can tell the truth and still be deceitful. Claiming to have had evidence on Russian corruption and publicly declaring an intent to release followed by silence and unwillingness to do so indicate two things, to me anyway. 1. The original claim is a lie. There is no evidence of Russian corruption and the claim was made for attention or some other purpose. Remind me, again, how many lies it takes to make someone unt…

By that measure, the New York Times, Fox News, Washington Post, CNN, and Wall Street Journal are all propaganda.

Re: New Charges in Huge C.I.A. Breach Known as Vault 7

#55

Mr. Schulte had been charged last year in New York with possession of child pornography Very interesting! It almost seems like the pornography charges against him was a way to punish him but without prosecuting him for the actual leakage. Perhaps the government wanted to still point the fingers at someone else or avoid embarrassment?

>It almost seems like the pornography charges against him was a way to punish him but without prosecuting him for the actual leakage

It's the new "tax evasion."

Ref: https://en.wikipedia.org/wiki/Al_Capone#Tax_evasion

Re: New Charges in Huge C.I.A. Breach Known as Vault 7

#56
post #9

> Mr. Schulte had been charged last year in New York with possession of child pornography. The fact that they found child porn on his computer is the scariest part. Almost any technical person could frame almost anyone else with CP possession. It's just a matter of putting some files on a computer and/or faking some logs, browser history, etc. It would be incredibly trivial for the CIA to put CP on his computer and t…

Exactly, some bad iframe could load CP files and not display them, later if someone checks the network logs they can "prove" you visited and watched those urls. Combine this with the very specific ad targeting that is possible to pull of(like the guy that managed to make FB to show his ad to his roommate) and you get an easy and remote way to frame people

A hidden iframe was used to install an encrypted VM on the defendants computer, with an encrypted file on it, accessible using a password Only the defendant knew?

There are also extensive file system logs indicating a history of use. That was faked too?

And the IRC logs, those are fake?

Come on man.

Re: New Charges in Huge C.I.A. Breach Known as Vault 7

#57

Earlier quoted context omitted.

Exactly, some bad iframe could load CP files and not display them, later if someone checks the network logs they can "prove" you visited and watched those urls. Combine this with the very specific ad targeting that is possible to pull of(like the guy that managed to make FB to show his ad to his roommate) and you get an easy and remote way to frame people

It's also a strict liability crime, so intent doesn't matter. The evidence can't be viewed except by very few people approved by the justice department, so CP might just be pictures of a 17th year old that the person didn't even know was underage.

you obviously didn't read the indictment. The claims are not some vague image found in his browser cache, but Gigs of graphic and disturbing content with metadata (i.e. titles) that clearly indicate it as CP.

I realize these claims != guilt, rather that a lot of these comments are arguing how easy it would be to get caught up in existing laws. That's not what's claimed here; if true this guy is a collector.

Re: New Charges in Huge C.I.A. Breach Known as Vault 7

#58
post #27

Earlier quoted context omitted.

You should read the indictment. That porn was not planted. https://www.scribd.com/document/379346745/Joshua-Adam-Schult...

I read the indictment, but I don't see how you can be certain it was not planted. He apparently saved IRC logs of their entire quest to obtain child porn....? Using his name as a handle? Impossible? No, but do you really think this is not questionable at all?

Did you read the part about the VM he was (allegedly) hiding?

Re: New Charges in Huge C.I.A. Breach Known as Vault 7

#59
post #26

Earlier quoted context omitted.

Maybe I'm missing something here, but ISTM the question isn't really whether the logs are of a genuine conversation about CP, but rather whether the accused really was a part of that conversation? After all, if he really took part in a conversation about procuring such material, it wouldn't have mattered if he talked like a newb. Likewise, if he wasn't in on it, it doesn't matter that everyone who was in on it got "t…

Read the transcript and decide for yourself, I'm referring strictly to how I've seen people speak on IRC. Warning, there is disturbing text in there. https://dd80b675424c132b90b3-e48385e382d2e5d17821a5e1d8e4c86...

I’ve been on IRC for decades, a few years running a file distribution for audiobooks, which sadly meant I ran across some things I’ll never unsee. I’ve never seen anyone actually say “kiddie porn” who was actually looking for or offering it. It’s all “loli” or filename references, and “#yo” stuff. Those chat logs sound ridiculous, but I have to admit that my experience is limited to channels where cp wasn’t welcome. Maybe when they’re on their own they start talking like a special agent?

To me, it would be like being in a warez channel full of people saying, “I want pirated material.” That at least I have experience with, and someone saying “Where the copyright violations at?” Rather than “any good ftp’s and xdcc’s?” Would raises red flags.

Re: New Charges in Huge C.I.A. Breach Known as Vault 7

#60
post #9

> Mr. Schulte had been charged last year in New York with possession of child pornography. The fact that they found child porn on his computer is the scariest part. Almost any technical person could frame almost anyone else with CP possession. It's just a matter of putting some files on a computer and/or faking some logs, browser history, etc. It would be incredibly trivial for the CIA to put CP on his computer and t…

If you're going to go to all that effort to hide your tracks and frame someone, risking your own conviction for downloading and distributing illegal porn, and the umpteen other crimes you're committing, I feel like you're going to have a good reason ... which reason is going to put you on a list of suspects for framing the person.

You're going to need resources too, if you want access without leaving a trace, TBH I can't see how you can do it remotely (ie at a distance) without cracking the targets upstream ISP. Otherwise their logs of incoming connections from whatever anonymous relays you've used are going to implicate an external attacker, which would tend to corroborate the targets innocence.

In the case of "Josh" other people's links show IRC chats where the other end is confirmed from capture of another perp. Also that his personal phone has the passwords on; that he said the encrypted data was his and that no-one else had access. If the evidence presented is true it seems pretty hard to setup without him being party to the whole thing.

Post reply on HN