Live data from Hacker News

The CIA Campaign to Steal Apple's Secrets

firstlook.org

1–10 of 138 posts

Re: The CIA Campaign to Steal Apple's Secrets

#3
The implication of the article is that this is some sort of specific attack against Apple. Surely the reality is that the CIA, and pretty much all 3-letter agencies globally, in a concerted and organised way try to break the security of all secure devices. That's a big part of their job - you can't gather intelligence if you can't read it.

The good things in the article are two-fold: firstly, Apple haven't just capitulated and handed over whatever is asked of them, and secondly the documents about the effort don't specifically mention any sort of success which could be interpreted as the agency failing. Of course, if they had been successful I imagine they'd keep as quiet as possible about it.

Re: The CIA Campaign to Steal Apple's Secrets

#5
The cynic in me feels that this might be part of a PR campaign coordinated between the US govt and US tech companies to try to give the impression of an adversarial relationship between the two.

The article quotes Steven Bellovin: “Their attitude is basically amoral: whatever works is OK.” If you forgot the article, could you tell who this is talking about? The government or the corporations? It seems like it fits both pretty well. The two entities both have a lot to gain from cooperating. Why wouldn't they? Whatever works.

Re: The CIA Campaign to Steal Apple's Secrets

#6
post #2

A great ad for Apple's security.

I agree. When the intelligence community has to resort to this, I think the everyman is ok:

>At the 2011 Jamboree conference, there were two separate presentations on hacking the GID key on Apple’s processors. One was focused on non-invasively obtaining it by studying the electromagnetic emissions of — and the amount of power used by — the iPhone’s processor while encryption is being performed. Careful analysis of that information could be used to extract the encryption key. Such a tactic is known as a “side channel” attack. The second focused on a “method to physically extract the GID key.”

Re: The CIA Campaign to Steal Apple's Secrets

#7
post #5

The cynic in me feels that this might be part of a PR campaign coordinated between the US govt and US tech companies to try to give the impression of an adversarial relationship between the two. The article quotes Steven Bellovin: “Their attitude is basically amoral: whatever works is OK.” If you forgot the article, could you tell who this is talking about? The government or the corporations? It seems like it fits bo…

Interesting twist when Glenn Greenwald/Snowden is now suspected of doing PR for tech companies.

Re: The CIA Campaign to Steal Apple's Secrets

#8
post #4

The CIA? Thought the NSA did this.

Here's their mission statement:

"Preempt threats and further US national security objectives by collecting intelligence that matters, producing objective all-source analysis, conducting effective covert action as directed by the President, and safeguarding the secrets that help keep our Nation safe."

Historically the CIA and NSA have a competitive relationship, they vie for the same funding. I would think pursuing iPhone security would cross into the NSA's domain and that they wouldn't appreciate it, however the CIA has a budget 50% larger than the NSA and I'm sure they'd like to keep it that way by staying relevant.

Re: The CIA Campaign to Steal Apple's Secrets

#9
If I'm understanding this right, this article is claiming that the CIA served up [edit: could serve up, not proven they did, see comments below about plausibility] poisoned versions of XCode, which would then be used to make App Store apps that eventually phoned home to Langley with either app-specific data or whole-phone data.

This raises so many questions, among them:

1) What was [edit: would be] the criteria for serving up a poisoned version instead of a real version of XCode to a dev? Was it [would it be] limited to downloadable versions or were DVD software copies affected too? One possibility came to mind: Does XCode come in different flavors based on county of sale/download, language, or a combo of the two? If so, would that be that criteria for their attempt to not target US citizens, by crudely targeting non-US and/or non-English app developer accounts? Because that would be the fakiest attempt yet at trying to claim plausible deniability, since so many apps with mainly American userbases are developed by overseas devs.

2) If a dev had a poisoned version of XCode, how could they not see a mysterious server being pinged during their development of the app? How could Apple not see something amiss during their QA of the app before they pushed it to the store?

3) If I were an evil genius Big Brother no holds barred government, I'd want data from messaging apps, social networks, and geolocation apps most of all, less so from things like single-player games. Thoughts on which apps are likely to be in the top 5 of their wishlist?

4) Does this mean that PhoneGap / Cordova / non-native HTML5 apps really are better? :-)

Say, why did Facebook change to a native app again?

Re: The CIA Campaign to Steal Apple's Secrets

#10

If I'm understanding this right, this article is claiming that the CIA served up [edit: could serve up, not proven they did, see comments below about plausibility] poisoned versions of XCode, which would then be used to make App Store apps that eventually phoned home to Langley with either app-specific data or whole-phone data. This raises so many questions, among them: 1) What was [edit: would be] the criteria for s…

They said they created a poisoned version of XCode, not that they were able to serve it up successfully to anyone.
Post reply on HN