Live data from Hacker News

WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

nytimes.com

11–20 of 250 posts

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#11
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

Unfortunately, this is a line that Wikileaks themselves are running with: https://twitter.com/wikileaks/status/839120909625606152

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#12
post #10
post #8

Earlier quoted context omitted.

edit: apparently NYT had a different headline and changed it... ignore this post The current title [0] is wrong, but NYTimes is relatively clear: > Among other disclosures that, if confirmed, would rock the technology world, the WikiLeaks release said that the C.I.A. and allied intelligence services had managed to bypass encryption on popular phone and messaging services such as Signal, WhatsApp and Telegram. Accordi…

They changed the headline: https://twitter.com/nytimes/status/839161021369573378 edit: A new tweet referencing the article: "WikiLeaks release said CIA managed to bypass encryption in mobile apps by compromising the entire phone"

They changed the tweet which I guess is factually correct but still misleading.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#13
post #11
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

Unfortunately, this is a line that Wikileaks themselves are running with: https://twitter.com/wikileaks/status/839120909625606152

Running misinformation is part of Wikileaks' job. It's not the NYT's job.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#14

According to the statement from WikiLeaks, government hackers can penetrate Android phones and collect “audio and message traffic before encryption is applied.” How is that possible? Isn't the data encrypted before it's sent over the wire?

The kernel is owned (or some part of the phone below the application level). The encryption only gets applied at the application level before the messages are sent down the wire. The interception happens prior to the encryption being applied . Think of it as a dongle on the wire between your keyboard and the computer. It doens't matter if the computer is secure - the message is intercepted prior to any encryption. Th…

I don't trust Google, Facebook, or anyone else who provides freemium services and has ties to the American Government. I don't understand why anyone does.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#15
post #9

Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.

> Please be aware that the Chrome browser does not offer a secure local storage protocol for its developers ... Compare this to Safari, which offers secure local storage at OS level security But this is just as secure as full disk encryption of the device right?

Not for malware running in user space.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#16
post #13
post #11

Earlier quoted context omitted.

Unfortunately, this is a line that Wikileaks themselves are running with: https://twitter.com/wikileaks/status/839120909625606152

Running misinformation is part of Wikileaks' job. It's not the NYT's job.

Agreed 100% - but methinks NYT (and others) still look to them for technical guidance on some matters - however misguided that might be.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#18
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

"sidestep" would probably have been a better word choice than "bypass" only because of the connotation of these words... the average person isn't going to parse these words however, sooo... ?

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#19
To me this is much more worrying:

> As of October 2014 the CIA was also looking at infecting the vehicle control systems used by modern cars and trucks. The purpose of such control is not specified, but it would permit the CIA to engage in nearly undetectable assassinations.

https://wikileaks.org/ciav7p1/

Given the fact that car makers don't even have "PC age" security in their cars, things are looking pretty bad for self-driving cars in general.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#20
post #14

Earlier quoted context omitted.

The kernel is owned (or some part of the phone below the application level). The encryption only gets applied at the application level before the messages are sent down the wire. The interception happens prior to the encryption being applied . Think of it as a dongle on the wire between your keyboard and the computer. It doens't matter if the computer is secure - the message is intercepted prior to any encryption. Th…

I don't trust Google, Facebook, or anyone else who provides freemium services and has ties to the American Government. I don't understand why anyone does.

It's funny, I trust Apple because they're not "freemium" as in, they make their profit elsewhere. But I'm not sure I should really! After all they did participate in PRISM AFAIK
Post reply on HN