Live data from Hacker News

WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

nytimes.com

121–130 of 250 posts

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#121
post #86
post #47

Earlier quoted context omitted.

You are 100 percent correct. Though I think the headline is a bit clickbaity but have to agree, it is accurate.

Accurate, but dangerously misleading.

How is it misleading if it is accurate? They bypassed it by compromising the phone. No encryption is going to save you in that situation and their targets were WhatsApp, Telegram, etc. So that part is accurate as well. It is a headline, I think what you are expecting is they put all the facts into the headline and there isn't enough space.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#122
post #75

Earlier quoted context omitted.

This is a dangerous headline because it implies that Signal was broken, which could lead to people moving to LESS SECURE SERVICES because they think the more secure one is broken. When in reality is the phone and OS. They have similar end result for the phone in question, but headlines like this can lead to people being less secure on the whole.

I'm sure someone savvy enough to use end-to-end encrypted communication channels will switch to less secure methods based off of a headline /s

It already happened with Whatsapp and the Guardian's irresponsible reporting. Organizers and protesters switching to unencrypted messaging or even SMS, because of the perception that Whatsapp was hacked. Someone savvy enough to use end to end encryption may be someone who values privacy, but there's not reason to assume they are also someone who is themselves a security expert. The point of apps like Whatsapp and Signal working to make end to end encryption easy for the average person is to increase encrypted messaging use, not make everyone a security expert.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#123
post #26

Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.

Don't take this the wrong way, but as a non-lawyer, I try to heavily caveat any statement I make about the law. Would you consider heavily caveating statements you make about information security? A lot of what you say here is basically wrong.

Indeed, this is technical expertise domain of an information security researcher, not a lawyer.

A national security lawyer could provide interesting insight into how the CIA is allowed to use these tools vs NSA.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#124
post #106
post #75

Earlier quoted context omitted.

This is a dangerous headline because it implies that Signal was broken, which could lead to people moving to LESS SECURE SERVICES because they think the more secure one is broken. When in reality is the phone and OS. They have similar end result for the phone in question, but headlines like this can lead to people being less secure on the whole.

Most users cannot tell the difference between between the Phone, OS, App and the signal (Let alone an app named Signal). Likely the journalists work with tech savvy to make sure their understood this and it was hard for them to make sense of gigabytes of technical jargon and noise. Arguing this point at all is silly when many people, even many IT professionals don't know and don't care about the difference between by…

And the bonus to the CIA ignoring the deal the Obama administration made with Big Tech to disclose vulnerabilities is that now (apparently) all of the tools the CIA had accumulated are out in the wild, instead of being fixed.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#125
post #35

Earlier quoted context omitted.

Makes the conspiracy theories regarding journalist Michael Hastings' death in 2013 seem more plausible. [1] Former U.S. National Coordinator for Security, Infrastructure Protection, and Counter-terrorism Richard A. Clarke said that what is known about the crash is "consistent with a car cyber attack". He was quoted as saying "There is reason to believe that intelligence agencies for major powers — including the Unite…

His brother and family don't believe the conspiracy theories. If there was any evidence, I don't think they'd be scared to say so in such an emotional state. Also in the police report, I believe his brother said he had been using DMT and he tested positive for what was likely Adderall. He was in a unique state to truly be paranoid and throwing psychedelics in the mix could cause one to try to cope in ways that challe…

[deleted]

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#126
post #13
post #11

Earlier quoted context omitted.

Unfortunately, this is a line that Wikileaks themselves are running with: https://twitter.com/wikileaks/status/839120909625606152

Running misinformation is part of Wikileaks' job. It's not the NYT's job.

Could you explain more about "misinformation is part of wikileaks' job"

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#127

Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.

Eh, they couldn't hack (1) the device in standby/locked with keys flushed and (2) the encrypted physical data on the flash. But that is a much more difficult proposition.

Just hacking the device while it is being used is what every iOS jailbreak does. And there seem to be quite a number of them.

Not sure why you mention "secure local storage"; none of that local storage is secure if the device is compromised! That can then be bypassed in the same way that you bypass WhatsApp or manipulate any other app on the device.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#128
post #40
post #31

Earlier quoted context omitted.

I would like your take on a more specific question: Do you think that Google applications (GMail, Search, Translate, Maps, etc) themselves can get access to the necessary kernel subroutines to catch information which is intended for encryption? Or would running a custom rom (ie. cyanogenmod) while still using Google applications suffice to mitigate these attacks?

Well, the Play store can seemingly update my system apps with no prompting. So I would guess that it's possible even on Cyanogenmod.

The open source side of that spun off as LineageOS: http://lineageos.org/

There was some huge political problem and the Cyanogen company did something the open source guys didn't like, so they left.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#129
post #36
post #31

Earlier quoted context omitted.

I would like your take on a more specific question: Do you think that Google applications (GMail, Search, Translate, Maps, etc) themselves can get access to the necessary kernel subroutines to catch information which is intended for encryption? Or would running a custom rom (ie. cyanogenmod) while still using Google applications suffice to mitigate these attacks?

Wait, what? If you are running something based off of AOSP, you're running code that was touched by Google employees. Is your fear that Google is installing backdoors to help the CIA? If so, why are you afraid of that?

> you're running code that was touched by Google employees

Doesn't matter who touches code when that code is publicly visible and available to the scrutiny of everyone. AOSP can be checked out and audited independently, just like any open source project.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#130
post #112

Earlier quoted context omitted.

Let's be all Socratic here: Given a desktop OS like Windows that implements FDE like Bitlocker and runs a browser like Chrome, can you describe a hypothetical threat in which Chrome encrypting localstorage would prevent exploitation?

Yes - worms or browsers that scan local data files without accessing the runtime of the parent application.

So your threat model is "malware which has access to memory containing plaintext but is written by idiots"?

0_o

Post reply on HN