The CIA Campaign to Steal Apple's Secrets
11–20 of 138 posts
Re: The CIA Campaign to Steal Apple's Secrets
#12If I'm understanding this right, this article is claiming that the CIA served up [edit: could serve up, not proven they did, see comments below about plausibility] poisoned versions of XCode, which would then be used to make App Store apps that eventually phoned home to Langley with either app-specific data or whole-phone data. This raises so many questions, among them: 1) What was [edit: would be] the criteria for s…
They said they created a poisoned version of XCode, not that they were able to serve it up successfully to anyone.
But I edited my comment to include your point: no hard proof that this technique was used...yet.
Re: The CIA Campaign to Steal Apple's Secrets
#13The cynic in me feels that this might be part of a PR campaign coordinated between the US govt and US tech companies to try to give the impression of an adversarial relationship between the two. The article quotes Steven Bellovin: “Their attitude is basically amoral: whatever works is OK.” If you forgot the article, could you tell who this is talking about? The government or the corporations? It seems like it fits bo…
Re: The CIA Campaign to Steal Apple's Secrets
#14The cynic in me feels that this might be part of a PR campaign coordinated between the US govt and US tech companies to try to give the impression of an adversarial relationship between the two. The article quotes Steven Bellovin: “Their attitude is basically amoral: whatever works is OK.” If you forgot the article, could you tell who this is talking about? The government or the corporations? It seems like it fits bo…
Interesting twist when Glenn Greenwald/Snowden is now suspected of doing PR for tech companies.
Re: The CIA Campaign to Steal Apple's Secrets
#15Re: The CIA Campaign to Steal Apple's Secrets
#16Re: The CIA Campaign to Steal Apple's Secrets
#17If I'm understanding this right, this article is claiming that the CIA served up [edit: could serve up, not proven they did, see comments below about plausibility] poisoned versions of XCode, which would then be used to make App Store apps that eventually phoned home to Langley with either app-specific data or whole-phone data. This raises so many questions, among them: 1) What was [edit: would be] the criteria for s…
So I'm not sure why you are referencing Facebook switching from a WebView-based app to a more native approach.
In addition, if the Xcode installation was compromised nothing should be considered safe on that device going forward.
Re: The CIA Campaign to Steal Apple's Secrets
#18Earlier quoted context omitted.
Interesting twist when Glenn Greenwald/Snowden is now suspected of doing PR for tech companies.
I must have missed that release, do you have any links?
Re: The CIA Campaign to Steal Apple's Secrets
#19If I'm understanding this right, this article is claiming that the CIA served up [edit: could serve up, not proven they did, see comments below about plausibility] poisoned versions of XCode, which would then be used to make App Store apps that eventually phoned home to Langley with either app-specific data or whole-phone data. This raises so many questions, among them: 1) What was [edit: would be] the criteria for s…
Theoretically speaking, if you were building an PhoneGap/Cordova app binary using a compromised seed of Xcode it would be no different than building a non-PhoneGap/Cordova based iOS app. So I'm not sure why you are referencing Facebook switching from a WebView-based app to a more native approach. In addition, if the Xcode installation was compromised nothing should be considered safe on that device going forward.
Of course this is all very hypothetical unless someone finds an example in the wild.
Re: The CIA Campaign to Steal Apple's Secrets
#20If I'm understanding this right, this article is claiming that the CIA served up [edit: could serve up, not proven they did, see comments below about plausibility] poisoned versions of XCode, which would then be used to make App Store apps that eventually phoned home to Langley with either app-specific data or whole-phone data. This raises so many questions, among them: 1) What was [edit: would be] the criteria for s…
Theoretically speaking, if you were building an PhoneGap/Cordova app binary using a compromised seed of Xcode it would be no different than building a non-PhoneGap/Cordova based iOS app. So I'm not sure why you are referencing Facebook switching from a WebView-based app to a more native approach. In addition, if the Xcode installation was compromised nothing should be considered safe on that device going forward.