Live data from Hacker News

WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

nytimes.com

101–110 of 250 posts

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#101
post #35

Earlier quoted context omitted.

Makes the conspiracy theories regarding journalist Michael Hastings' death in 2013 seem more plausible. [1] Former U.S. National Coordinator for Security, Infrastructure Protection, and Counter-terrorism Richard A. Clarke said that what is known about the crash is "consistent with a car cyber attack". He was quoted as saying "There is reason to believe that intelligence agencies for major powers — including the Unite…

His brother and family don't believe the conspiracy theories. If there was any evidence, I don't think they'd be scared to say so in such an emotional state. Also in the police report, I believe his brother said he had been using DMT and he tested positive for what was likely Adderall. He was in a unique state to truly be paranoid and throwing psychedelics in the mix could cause one to try to cope in ways that challe…

I think given what we knew until today, it was prudent for his family to deny the theories. Now that we have evidence showing car hacking isn't just some theoretical exploit, but something they were actively looking into around that time, it merits reexamination.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#102
post #75

Earlier quoted context omitted.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

This is a dangerous headline because it implies that Signal was broken, which could lead to people moving to LESS SECURE SERVICES because they think the more secure one is broken. When in reality is the phone and OS. They have similar end result for the phone in question, but headlines like this can lead to people being less secure on the whole.

you are implying that you are an idiot.

you're all idiots.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#103
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

Seems like the headline is perfectly fine. The software on the device you don't own is bypassed, resulting in encryption being ineffective? That seems like a highly critical issue for whoever owns the software.

Step the fuck up Google. Android security is an embarrassment.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#104

Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.

>Compare the security of Android - which we now know to be 'owned' by the US Government - with the security of iOS, which was the subject of a public and gruesome lawsuit about a year ago because the Fed could not hack iOS.

So your comparing the current security of the iPhone with old CIA Android and Chrome exploits from circa 2011-2013?

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#105

Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.

Was going to email you but I couldn't find a way of getting your contact information without enabling google JS (something you might want to consider as a privacy advocate)

The background video on gibber is awful, makes it very hard to read the page. I've just opened it in another browser with all the JS on and again your page totally doesn't work with the google ajax switched on. Worth fixing.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#106
post #75

Earlier quoted context omitted.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

This is a dangerous headline because it implies that Signal was broken, which could lead to people moving to LESS SECURE SERVICES because they think the more secure one is broken. When in reality is the phone and OS. They have similar end result for the phone in question, but headlines like this can lead to people being less secure on the whole.

Most users cannot tell the difference between between the Phone, OS, App and the signal (Let alone an app named Signal). Likely the journalists work with tech savvy to make sure their understood this and it was hard for them to make sense of gigabytes of technical jargon and noise.

Arguing this point at all is silly when many people, even many IT professionals don't know and don't care about the difference between bypassed and broken. This arguing detracts from the important news...

The CIA sees fit to ignore the security of Americans by not alerting the companies that make the software the CIA exploits. They do this to insure they can hack whoever they want, and there is no meaningful oversight and no ethical, economic or constitutional consideration.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#107
post #64
post #54

Earlier quoted context omitted.

The Android security model doesn't work that way. Non-system applications can't access the kernel, minus a local EOP or something like that. Is that your concern? And if so, why are you concerned specifically about Google apps? Any malicious app can exploit a local EOP.

Yes, that is my concern. You mention system applications - I believe this excludes any application which can be installed (with an app store or apk)? What is a local EOP? I couldn't find any info on this abbreviation. I used Google as an example.

[deleted]

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#108

Earlier quoted context omitted.

The kernel is owned (or some part of the phone below the application level). The encryption only gets applied at the application level before the messages are sent down the wire. The interception happens prior to the encryption being applied . Think of it as a dongle on the wire between your keyboard and the computer. It doens't matter if the computer is secure - the message is intercepted prior to any encryption. Th…

You're very much misrepresenting the facts. Android very much encrypts data (or gives users the option to, I'm not certain if it's the default). Chrome, the desktop application, does not. Why? Because that's a false sense of security. Chrome would have to also store the encryption key, and store it in the same place and under the same access controls as the encrypted data. This is not real protection. It is up to the…

> Why? Because that's a false sense of security. Chrome would have to also store the encryption key, and store it in the same place and under the same access controls as the encrypted data.

I hear you, but this is not the case with Safari. It offers secure local storage. It's the securesettings API. It uses the OS level encryption, and, based on the current state of play, this does not appear to be compromised.

> as shown by the fact that malware (and legitimate programs!) can read the Firefox local password database.

Is this also the case for Safari? I have not read anything to this effect.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#109
post #71

This is why we should not rely on encrypted apps running on top of some other platform. disclosure: working on an open source alternative for messaging

Wouldn't you also need an encrypted os for your phone?

A fully open source RTOS that is trusted and only running this single application. The only external communication is the encrypted messages.
Post reply on HN