Live data from Hacker News

The CIA Campaign to Steal Apple's Secrets

firstlook.org

11–20 of 138 posts

Re: The CIA Campaign to Steal Apple's Secrets

#12
post #10

If I'm understanding this right, this article is claiming that the CIA served up [edit: could serve up, not proven they did, see comments below about plausibility] poisoned versions of XCode, which would then be used to make App Store apps that eventually phoned home to Langley with either app-specific data or whole-phone data. This raises so many questions, among them: 1) What was [edit: would be] the criteria for s…

They said they created a poisoned version of XCode, not that they were able to serve it up successfully to anyone.

True, but Snowden's data haul is at least a year and a half old by now, and some of the files cited in this article date back longer than that.

But I edited my comment to include your point: no hard proof that this technique was used...yet.

Re: The CIA Campaign to Steal Apple's Secrets

#13
post #5

The cynic in me feels that this might be part of a PR campaign coordinated between the US govt and US tech companies to try to give the impression of an adversarial relationship between the two. The article quotes Steven Bellovin: “Their attitude is basically amoral: whatever works is OK.” If you forgot the article, could you tell who this is talking about? The government or the corporations? It seems like it fits bo…

It is certainly in the interests of the government and its spying agencies for the big monopolies to be successful. It must be a comforting thought to them to know that if they bug just Apple and Microsoft, at a stroke they have over 90% of the population under effective surveillance.

Re: The CIA Campaign to Steal Apple's Secrets

#14
post #7
post #5

The cynic in me feels that this might be part of a PR campaign coordinated between the US govt and US tech companies to try to give the impression of an adversarial relationship between the two. The article quotes Steven Bellovin: “Their attitude is basically amoral: whatever works is OK.” If you forgot the article, could you tell who this is talking about? The government or the corporations? It seems like it fits bo…

Interesting twist when Glenn Greenwald/Snowden is now suspected of doing PR for tech companies.

I must have missed that release, do you have any links?

Re: The CIA Campaign to Steal Apple's Secrets

#15
How much longer can this continue? We have American agencies attacking American companies "because terrorism". It's been 13 years since our trauma, maybe now's the time to remove the razor blade from our wrists, look ourselves in the mirror and just carry on. Bad stuff is always going to be in our future — stuff that will increasingly appear preventable between the Internet and a lot of hindsight — but our current solution is only making things worse. The war on terror, like all the metaphorical wars, is really a civil war. It needs to stop now.

Re: The CIA Campaign to Steal Apple's Secrets

#17

If I'm understanding this right, this article is claiming that the CIA served up [edit: could serve up, not proven they did, see comments below about plausibility] poisoned versions of XCode, which would then be used to make App Store apps that eventually phoned home to Langley with either app-specific data or whole-phone data. This raises so many questions, among them: 1) What was [edit: would be] the criteria for s…

Theoretically speaking, if you were building an PhoneGap/Cordova app binary using a compromised seed of Xcode it would be no different than building a non-PhoneGap/Cordova based iOS app.

So I'm not sure why you are referencing Facebook switching from a WebView-based app to a more native approach.

In addition, if the Xcode installation was compromised nothing should be considered safe on that device going forward.

Re: The CIA Campaign to Steal Apple's Secrets

#19
post #17

If I'm understanding this right, this article is claiming that the CIA served up [edit: could serve up, not proven they did, see comments below about plausibility] poisoned versions of XCode, which would then be used to make App Store apps that eventually phoned home to Langley with either app-specific data or whole-phone data. This raises so many questions, among them: 1) What was [edit: would be] the criteria for s…

Theoretically speaking, if you were building an PhoneGap/Cordova app binary using a compromised seed of Xcode it would be no different than building a non-PhoneGap/Cordova based iOS app. So I'm not sure why you are referencing Facebook switching from a WebView-based app to a more native approach. In addition, if the Xcode installation was compromised nothing should be considered safe on that device going forward.

I was joking about the longstanding native app versus non-native app debate, but thank you for the info. But perhaps if the crucial part of XCode that "phoned home" was not the WebView component but some other component, might that make a difference?

Of course this is all very hypothetical unless someone finds an example in the wild.

Re: The CIA Campaign to Steal Apple's Secrets

#20
post #17

If I'm understanding this right, this article is claiming that the CIA served up [edit: could serve up, not proven they did, see comments below about plausibility] poisoned versions of XCode, which would then be used to make App Store apps that eventually phoned home to Langley with either app-specific data or whole-phone data. This raises so many questions, among them: 1) What was [edit: would be] the criteria for s…

Theoretically speaking, if you were building an PhoneGap/Cordova app binary using a compromised seed of Xcode it would be no different than building a non-PhoneGap/Cordova based iOS app. So I'm not sure why you are referencing Facebook switching from a WebView-based app to a more native approach. In addition, if the Xcode installation was compromised nothing should be considered safe on that device going forward.

[deleted]
Post reply on HN