Live data from Hacker News

CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

washingtonpost.com

101–106 of 106 posts

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#101
post #74

Earlier quoted context omitted.

>When intelligence agencies share clear evidence a dictator gassed his own civilian population Funnily enough, there's no clear evidence of this. According to OPCW leaked documents there's a higher probability the gas was manually placed at the site. [1] Which of course, calls into question the Syrian government's involvement, especially given earlier intelligence showing ISIS had possession of such chemical weapons.…

You're asking for clear evidence but then using an op-ed from a known controversial journalist on Syria, sharing a Wikileaks leak after the GRU was caught hacking the OPCW ? Clear evidence you can't fake: a rush of hundreds of people (including children) to the different hospitals near the Khan Sheikhoun site while all showing the same respiratory and neurological symptoms. How can one fool so many doctors? Here's a…

This seems to be some form of strawman, given I never even implied there was no attack. Merely that it was misattributed according to leaked documents written by chemical experts.

Also, Assad was by all accounts winning the war and pushing back on all fronts at the time. Do you think he's such a lunatic and so strategically bankrupt that he'd launch a chemical attack on his own people while he's winning? Or is it more likely that ISIS launched a false flag attack using chemical weapons that we know they have in order to get the West to do their bidding against Assad?

The Syrian war is a mess, and there are no good guys. The US-backed rebels commit war crimes and behead children, for example.

The source of leaked documents really doesn't concern me as long as they are authentic. For argument's sake, if Snowden was a Kremlin double agent I wouldn't care because he revealed genuine government wrongdoing.

Attacking the source generally isn't a valid argument, especially given the authenticity of the information.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#102
post #72

Earlier quoted context omitted.

All of that was based on the opinion of a private organization. No intelligence official ever had possession of the server or was involved at any time.

Russia did not limit it's election interference to hacking one single server. This is actually very straightforward. Here are more details and evidence if you are sincere and want to dig deeper: https://www.intelligence.senate.gov/sites/default/files/docu...

Do you think it's prudent for the intelligence community to allow private organizations to attribute nation state attacks on their behalf without inspecting the evidence?

It's a pretty simple question, and that's what it boils down to.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#103
post #80

Earlier quoted context omitted.

It's more analogous to saying "the defense contractors for a new stealth plane failed to protect the designs and prototypes, so the enemy now has all of the detailed info they need to build countermeasures against this stealth technology". Securing the plans for stealth is a key requirement of the stealth continuing to work. Also, I'm sure those members of "the hacking team" weren't allowed to discuss their work with…

No, that's not what the analogy at hand. The designers of a stealth plane are just that. The right analogy would be if the navy seals designed a secret weapon, someone infiltrated their ranks and exfiltrated the weapons plans. Navy seals are not immune to moles. No org is. Your implication that this was due to lack of proper security hygeine is unfounded. Security hygeine reduces risk it does not eliminate it. Risk i…

I agree that your analogy works better.

> Your implication that this was due to lack of proper security hygeine is unfounded. Security hygeine reduces risk it does not eliminate it.

Nope. No security professional will admit that anything ever eliminates risk, so that's a strawman fallacy.

The point is that sharing admin passwords is a blatant violation of cybersecurity hygiene which every employee of the CIA is capable of understanding and avoiding. If the org can't enforce even just the basic stuff, there's not much hope of raising standards above that.

> from the most persistent and resourceful attackers.

Here's a secret that everyone already knows: the most persistent and resourceful attackers will always get in given enough time.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#104
post #80

Earlier quoted context omitted.

No, that's not what the analogy at hand. The designers of a stealth plane are just that. The right analogy would be if the navy seals designed a secret weapon, someone infiltrated their ranks and exfiltrated the weapons plans. Navy seals are not immune to moles. No org is. Your implication that this was due to lack of proper security hygeine is unfounded. Security hygeine reduces risk it does not eliminate it. Risk i…

I agree that your analogy works better. > Your implication that this was due to lack of proper security hygeine is unfounded. Security hygeine reduces risk it does not eliminate it. Nope. No security professional will admit that anything ever eliminates risk, so that's a strawman fallacy. The point is that sharing admin passwords is a blatant violation of cybersecurity hygiene which every employee of the CIA is capab…

I agree on both of your last two points. Not sure where disagree then.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#105
post #73

Earlier quoted context omitted.

That's completely untrue.

Shawn Henry said "We said that we had a high degree of confidence it was the Russian Government" Sorry, but "high degree of confidence" is not proof, especially not from the organization that told us Iraq had WMDs with high degrees of confidence. Additionally, at no point in time did they have access to the hardware. Are you forgetting that this is the same collection of people responsible for being unable to secure…

Skepticism of the claims of law enforcement and the intelligence community are good, for a multitude of reasons, but the case here is a lot stronger than you're suggesting and is substantiated by much more than mere finger-pointing by the US government or other governments.

It's unfortunate that the political climate in the US is on such a knife's edge right now that basically no one trusts anyone and everyone is running with their own databases of the facts of the world.

I understand the US government is itself very largely to blame for this deep distrust, but posts like yours make me worried for the next few decades. This isn't a criticism of you at all, but just general concern that things are kind of coming apart at the seams societally. I really hope the "two movies on one screen" phenomenon doesn't escalate to the point that the screen shatters into a billion pieces.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#106

How does somebody exfiltrate 34 TERABYTES from a secure facility without getting noticed? To misquote Dr. Strangelove, "ze whole point of ze secret hack is lost if you don't keep it a secret." https://youtu.be/2yfXgu37iyI?t=205 Oh, maybe they have a firewall built on a RaspberryPi somebody ordered online. Seriously, WTF? This is as insecure as having contract sysadmins with root privilege spread all over the globe. A…

What are the tools to help orgs notice exfiltration?

Glossing over 10 years of tens of thousands of people's work, things like Titan Rain (1, 2) led to a lot of thinking about monitoring your production environment with things like the istio sidecar system.

(1) https://en.wikipedia.org/wiki/Netwitness

(2) https://en.wikipedia.org/wiki/Shawn_Carpenter

Post reply on HN