Earlier quoted context omitted.
Makes the conspiracy theories regarding journalist Michael Hastings' death in 2013 seem more plausible. [1] Former U.S. National Coordinator for Security, Infrastructure Protection, and Counter-terrorism Richard A. Clarke said that what is known about the crash is "consistent with a car cyber attack". He was quoted as saying "There is reason to believe that intelligence agencies for major powers — including the Unite…
His brother and family don't believe the conspiracy theories. If there was any evidence, I don't think they'd be scared to say so in such an emotional state. Also in the police report, I believe his brother said he had been using DMT and he tested positive for what was likely Adderall. He was in a unique state to truly be paranoid and throwing psychedelics in the mix could cause one to try to cope in ways that challe…
WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
101–110 of 250 posts
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#102Earlier quoted context omitted.
No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.
This is a dangerous headline because it implies that Signal was broken, which could lead to people moving to LESS SECURE SERVICES because they think the more secure one is broken. When in reality is the phone and OS. They have similar end result for the phone in question, but headlines like this can lead to people being less secure on the whole.
you're all idiots.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#103This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.
Step the fuck up Google. Android security is an embarrassment.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#104Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.
So your comparing the current security of the iPhone with old CIA Android and Chrome exploits from circa 2011-2013?
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#105Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.
The background video on gibber is awful, makes it very hard to read the page. I've just opened it in another browser with all the JS on and again your page totally doesn't work with the google ajax switched on. Worth fixing.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#106Earlier quoted context omitted.
No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.
This is a dangerous headline because it implies that Signal was broken, which could lead to people moving to LESS SECURE SERVICES because they think the more secure one is broken. When in reality is the phone and OS. They have similar end result for the phone in question, but headlines like this can lead to people being less secure on the whole.
Arguing this point at all is silly when many people, even many IT professionals don't know and don't care about the difference between bypassed and broken. This arguing detracts from the important news...
The CIA sees fit to ignore the security of Americans by not alerting the companies that make the software the CIA exploits. They do this to insure they can hack whoever they want, and there is no meaningful oversight and no ethical, economic or constitutional consideration.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#107Earlier quoted context omitted.
The Android security model doesn't work that way. Non-system applications can't access the kernel, minus a local EOP or something like that. Is that your concern? And if so, why are you concerned specifically about Google apps? Any malicious app can exploit a local EOP.
Yes, that is my concern. You mention system applications - I believe this excludes any application which can be installed (with an app store or apk)? What is a local EOP? I couldn't find any info on this abbreviation. I used Google as an example.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#108Earlier quoted context omitted.
The kernel is owned (or some part of the phone below the application level). The encryption only gets applied at the application level before the messages are sent down the wire. The interception happens prior to the encryption being applied . Think of it as a dongle on the wire between your keyboard and the computer. It doens't matter if the computer is secure - the message is intercepted prior to any encryption. Th…
You're very much misrepresenting the facts. Android very much encrypts data (or gives users the option to, I'm not certain if it's the default). Chrome, the desktop application, does not. Why? Because that's a false sense of security. Chrome would have to also store the encryption key, and store it in the same place and under the same access controls as the encrypted data. This is not real protection. It is up to the…
I hear you, but this is not the case with Safari. It offers secure local storage. It's the securesettings API. It uses the OS level encryption, and, based on the current state of play, this does not appear to be compromised.
> as shown by the fact that malware (and legitimate programs!) can read the Firefox local password database.
Is this also the case for Safari? I have not read anything to this effect.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#109This is why we should not rely on encrypted apps running on top of some other platform. disclosure: working on an open source alternative for messaging
Wouldn't you also need an encrypted os for your phone?