Live data from Hacker News

The CIA Campaign to Steal Apple's Secrets

firstlook.org

51–60 of 138 posts

Re: The CIA Campaign to Steal Apple's Secrets

#51
post #38

Earlier quoted context omitted.

I think the point of The Intercept releasing this Apple specific info (mostly, there's a bit about Microsoft being targeted as well) is to try to appeal to the large number of Apple customers. I'd love to see some of the other line items in the leaked CBJ document, as there are probably some other targeted attacks documented. Regarding Apple not capitulating, I'm giving them the benefit of the doubt, and assuming tha…

"No comment" from Cook would be an interesting standoff. If he were prosecuted for it, that would confirm something NSL-like. But would it be worth it to a CEO to go to jail for a few years for a principle?

There is a good chance that Cook, like anyone else is vulnerable to other charges; and in case he is a saint, they would just make something up. It won't be 'brave champion of freedom Tim Cook takes a principled stand and is persecuted by the NSA for it.' It would be either something like what happened to Joseph Naccio, or worse.

Re: The CIA Campaign to Steal Apple's Secrets

#52
post #47

Seriously. This isn't even bad. Go to DEFCON and you'll see a ton of people doing this crap. There is a reason a bunch of paranoid people (includes me) bought faraday cages for our phones. Everyone is trying to break in to the little black boxes we carry around with some of our most personal information. They have ACTUALLY done bad crap. This is normal security research. There is no need to blow normal research and s…

>Seriously. This isn't even bad....There is no need to blow normal research and security work out of proportion.

Is normal security research done with the goal of finding/creating holes with the purpose of keeping them secret in order to use them as attack vectors without letting the owners of the compromised systems know about the vulnerabilities?

What's bad about this is the purpose of the research (not to discover and strengthen security, but instead to destroy it), combined with the weaponization of it (the entire goal of doing the research is to use the exploits), and the actor carrying out the attacks (the state).

It's obvious on its face why this is alarming.

Re: The CIA Campaign to Steal Apple's Secrets

#53

This is a great argument for "Gentoo Android". While much of the iOS is Open Source or Free Software, the end-user can't really inspect the source that went into their particular device. Note that, to the extent that the CIA steals Apple secrets from foreign sources, they may not be violating any US laws. However Apple does the vast majority of its system software development in Cupertino, California. My next phone i…

You might want to lookup the Replicant project.

http://www.replicant.us http://en.wikipedia.org/wiki/Replicant_(operating_system)

It looks like the development team could use some new contributors.

Re: The CIA Campaign to Steal Apple's Secrets

#54
post #45
post #30

What strikes me after this revelation is how unique the United States is, because: (a) it has dozens of companies that create technology the rest of the world uses, and (b) it has a govt. that secretly works to undermine the technology developed by those companies. You're not going to hear about many foreign govt's actively hacking their country's software products, simply because they could easily/secretly armtwist…

Your example isn't a particular good one. Huawei has been accused of backdooring their products for the Chinese government on numerous occasions, including presentations at DEFCON exposing those backdoors. There are also numerous cases of backdoors in Chinese cell phones.

That's exactly what he's saying: "You're not going to hear about many foreign govt's actively hacking their country's software products, simply because they could easily/secretly armtwist cos. into installing backdoors at the beginning"

Re: The CIA Campaign to Steal Apple's Secrets

#55
post #15

How much longer can this continue? We have American agencies attacking American companies "because terrorism". It's been 13 years since our trauma, maybe now's the time to remove the razor blade from our wrists, look ourselves in the mirror and just carry on. Bad stuff is always going to be in our future — stuff that will increasingly appear preventable between the Internet and a lot of hindsight — but our current so…

I'm actually somewhat torn on this.

While I'm against mass surveillance, I think that targeted surveillance can be a good thing. By nature of it being targeted, it is expensive to use on more people than necessary. The kind of spying the CIA would enable through compromising Apple secrets would be restricted to high-value targets if for no other reason than to ensure none of their targets knew they had that capability.

There are bad people out there, and we expect our government to stop them.

Re: The CIA Campaign to Steal Apple's Secrets

#56

Every time I read about a private company being targeted, I remember how simply state-level spies have been compromised. Hanssen[1], for instance, betrayed the CIA over 22 years, for just $1.4M. The info leaked included info on other agents, at least one who was executed. Or [2], Walker gave crypto info to decrypt Navy messages. For a few grand a month. There's plenty more listed even on Wikipedia. The amounts involv…

[deleted]

Re: The CIA Campaign to Steal Apple's Secrets

#57

Every time I read about a private company being targeted, I remember how simply state-level spies have been compromised. Hanssen[1], for instance, betrayed the CIA over 22 years, for just $1.4M. The info leaked included info on other agents, at least one who was executed. Or [2], Walker gave crypto info to decrypt Navy messages. For a few grand a month. There's plenty more listed even on Wikipedia. The amounts involv…

Real spies don't work for money; they work for/against an ideology. Money would actually be a tip-off that they're a spy; if you have high level security clearance, your bank accounts are monitored.

The NSA/CIA/FBI almost certainly do have moles working within the major tech companies. As do the intelligence agencies of China, Russia, the UK, France, Germany and Israel.

Re: The CIA Campaign to Steal Apple's Secrets

#58

If I'm understanding this right, this article is claiming that the CIA served up [edit: could serve up, not proven they did, see comments below about plausibility] poisoned versions of XCode, which would then be used to make App Store apps that eventually phoned home to Langley with either app-specific data or whole-phone data. This raises so many questions, among them: 1) What was [edit: would be] the criteria for s…

Okay, can't sleep, so: 5) The whole point of this proof-of-concept seems to be to have unsuspecting, innocent devs who build regular boring apps, like Tinder For Dogs or whatever, unknowingly build the app using poisoned XCode. That way, when Mr. Bad Guy eventually installs Tinder For Dogs on his iPhone, the CIA gets a secret backdoor to his entire phone. But this seems so overly complicated! If the CIA already has a…

They'll probably attempt to install the bugged XCode at TextSecure, WhatsApp, etc. That way, people are happily using an app from a well known vendor (not CIA Games Company, Inc.) while still being surveilled.

Re: The CIA Campaign to Steal Apple's Secrets

#59
post #57

Every time I read about a private company being targeted, I remember how simply state-level spies have been compromised. Hanssen[1], for instance, betrayed the CIA over 22 years, for just $1.4M. The info leaked included info on other agents, at least one who was executed. Or [2], Walker gave crypto info to decrypt Navy messages. For a few grand a month. There's plenty more listed even on Wikipedia. The amounts involv…

Real spies don't work for money; they work for/against an ideology. Money would actually be a tip-off that they're a spy; if you have high level security clearance, your bank accounts are monitored. The NSA/CIA/FBI almost certainly do have moles working within the major tech companies. As do the intelligence agencies of China, Russia, the UK, France, Germany and Israel.

Alrich Ames was eventually busted for spending money that the soviets were paying him.

http://en.wikipedia.org/wiki/Aldrich_Ames

Re: The CIA Campaign to Steal Apple's Secrets

#60
post #57

Every time I read about a private company being targeted, I remember how simply state-level spies have been compromised. Hanssen[1], for instance, betrayed the CIA over 22 years, for just $1.4M. The info leaked included info on other agents, at least one who was executed. Or [2], Walker gave crypto info to decrypt Navy messages. For a few grand a month. There's plenty more listed even on Wikipedia. The amounts involv…

Real spies don't work for money; they work for/against an ideology. Money would actually be a tip-off that they're a spy; if you have high level security clearance, your bank accounts are monitored. The NSA/CIA/FBI almost certainly do have moles working within the major tech companies. As do the intelligence agencies of China, Russia, the UK, France, Germany and Israel.

Aldrich Ames worked for money - he got over $4 million from the Soviets and betrayed a huge number of Western spies:

http://en.wikipedia.org/wiki/Aldrich_Ames

Post reply on HN