Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

111–120 of 1001 posts

Re: CIA malware and hacking tools

#111
post #15

Earlier quoted context omitted.

One cause for concern is that the CIA appears to not only have lost control of the documentation, but of the tools themselves: "Recently, the CIA lost control of the majority of its hacking arsenal...and associated documentation. This extraordinary collection...gives its possessor the entire hacking capacity of the CIA." So, now, you get to worry about anybody else that might have this toolset. (Not withstanding your…

>> So, now, you get to worry about anybody else that might have this toolset. You also have to consider who has the capability to actually use these tools - its not like they come with a user manual. Could Joe Schmo download these and start using them tomorrow? Probably not. Also, I'm pretty sure this isn't "the entire hacking capacity of the CIA". If you consider all the stuff that came out with the Snowden leaks, y…

They have stated this is part 1 of a long series of Vault7 releases, so it might be possible.

Re: CIA malware and hacking tools

#112

So will this zero days be reported to Google,Apple,Microsoft & Co.? Or is this more a "FYI document"? It seems you can be on the safer side if you use a more exotic phone OS which is not widely used or a more dumb feature phone.

An obscure OS would potentially help protect you on that one layer, but it's hardly a panacea. For one thing, an obscure OS means fewer friendly eyes looking for vulnerabilities. For another, you're still going to be vulnerable to things like a baseband attack:

https://dwaterson.com/2013/11/18/vulnerabilities-of-the-seco...

Re: CIA malware and hacking tools

#113
post #60

Earlier quoted context omitted.

That has less to do with how I feel and more to do with how the CIA is setup. Their role in domestic affairs is severely restricted, that is primarily the job of the FBI which has more requirements to conduct "searches". For them to be operating to the fullest extent of their perceived role, I can't find myself to be upset.

"their role in domestic affairs is severely restricted" You're delusional if you still believe this.

It's not delusional to accurately state the law. But there does need to be strong oversight of these organizations to make sure they actually follow the law.

Edit: and yes, there is plenty of evidence that especially during the Vietnam war the CIA was actually breaking the law.

Re: CIA malware and hacking tools

#115

But considering that Wikileaks is essentially a Russian intelligence services front at this point, spreading this kind of disinformation does a great deal to muddy the waters about the hacking.

Have you read anything from experts in the area?

https://medium.com/@jeffreycarr/can-facts-slow-the-dnc-breac...

Re: CIA malware and hacking tools

#116
post #34

This idea that the government should somehow be exempt from proper cybersecurity ethics is disgusting. When the CIA or the NSA find zero day attacks in software, they should report them immediately to be fixed, not build tools specifically to exploit them. It's only a matter of time before these attacks either leak or are rediscovered by other malicious parties. The government is effectively turning their own people…

True, but that's a general indictment of any spy agency for any country. More broadly than just software, their mission is to control information...who gets it / who doesn't.

This might sounds naive, but I am genuinely wondering whether they are failing at this mission in the long run, though? They can hardly believe they're they are the only ones in control of these exploits. Can't the same exploits be used against them?

Re: CIA malware and hacking tools

#117
post #89

Earlier quoted context omitted.

Wikileaks' political alignment doesn't have anything to do with the authenticity of the material they provide.

No, but it does have to do with what authentic material they provide. There's a reason courts require "the whole truth"

What would "the whole truth" mean in this context? An explanation of how we got here, starting with the Big Bang?

Re: CIA malware and hacking tools

#118
post #72

Earlier quoted context omitted.

Why would anyone consider that? (Yes I know the accusations, but they don't appear backed by evidence or reason).

The guy went from "cryptoanarchy" to having a TV show on RT(a propaganda network)and saying Russia has "vibrant" criticism of Putin's regime (beyond absurd). Not to mention him somehow being able to facilitate Snowden's entry into Russia. I'm no fan of imperialist American foreign policy, but Russia is just as grotesque. http://www.repubblica.it/esteri/2016/12/23/news/assange_wiki...

This doesn't prove your original claim in any way.

Re: CIA malware and hacking tools

#119
post #10

Maybe it is just my lack of knowledge but why were all the recently leaked hacking tools made by US and none by Russia or China?

My feeling - based on reading only publicly-available resources - is that China and Russia rely more on more traditional "HUMINT" (Human Intelligence), while the US has come to rely more and more and "SIGINT" (Signals Intelligence).

Re: CIA malware and hacking tools

#120

One of the findings: Notepad++ has a DLL hijack [1] [1] https://wikileaks.org/ciav7p1/cms/page_26968090.html

Any executable is vulnerable to DLL hijacking, they're just looking for easier targets that load known DLLs (with known function signatures) from their own folders (NOT system folders).

I'm assuming the goal is to minimise detection by what they call PSPs (av / security products)

This is not a flaw within notepad++

Post reply on HN