Earlier quoted context omitted.
You are 100 percent correct. Though I think the headline is a bit clickbaity but have to agree, it is accurate.
Accurate, but dangerously misleading.
WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
121–130 of 250 posts
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#122Earlier quoted context omitted.
This is a dangerous headline because it implies that Signal was broken, which could lead to people moving to LESS SECURE SERVICES because they think the more secure one is broken. When in reality is the phone and OS. They have similar end result for the phone in question, but headlines like this can lead to people being less secure on the whole.
I'm sure someone savvy enough to use end-to-end encrypted communication channels will switch to less secure methods based off of a headline /s
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#123Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.
Don't take this the wrong way, but as a non-lawyer, I try to heavily caveat any statement I make about the law. Would you consider heavily caveating statements you make about information security? A lot of what you say here is basically wrong.
A national security lawyer could provide interesting insight into how the CIA is allowed to use these tools vs NSA.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#124Earlier quoted context omitted.
This is a dangerous headline because it implies that Signal was broken, which could lead to people moving to LESS SECURE SERVICES because they think the more secure one is broken. When in reality is the phone and OS. They have similar end result for the phone in question, but headlines like this can lead to people being less secure on the whole.
Most users cannot tell the difference between between the Phone, OS, App and the signal (Let alone an app named Signal). Likely the journalists work with tech savvy to make sure their understood this and it was hard for them to make sense of gigabytes of technical jargon and noise. Arguing this point at all is silly when many people, even many IT professionals don't know and don't care about the difference between by…
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#125Earlier quoted context omitted.
Makes the conspiracy theories regarding journalist Michael Hastings' death in 2013 seem more plausible. [1] Former U.S. National Coordinator for Security, Infrastructure Protection, and Counter-terrorism Richard A. Clarke said that what is known about the crash is "consistent with a car cyber attack". He was quoted as saying "There is reason to believe that intelligence agencies for major powers — including the Unite…
His brother and family don't believe the conspiracy theories. If there was any evidence, I don't think they'd be scared to say so in such an emotional state. Also in the police report, I believe his brother said he had been using DMT and he tested positive for what was likely Adderall. He was in a unique state to truly be paranoid and throwing psychedelics in the mix could cause one to try to cope in ways that challe…
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#126Earlier quoted context omitted.
Unfortunately, this is a line that Wikileaks themselves are running with: https://twitter.com/wikileaks/status/839120909625606152
Running misinformation is part of Wikileaks' job. It's not the NYT's job.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#127Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.
Just hacking the device while it is being used is what every iOS jailbreak does. And there seem to be quite a number of them.
Not sure why you mention "secure local storage"; none of that local storage is secure if the device is compromised! That can then be bypassed in the same way that you bypass WhatsApp or manipulate any other app on the device.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#128Earlier quoted context omitted.
I would like your take on a more specific question: Do you think that Google applications (GMail, Search, Translate, Maps, etc) themselves can get access to the necessary kernel subroutines to catch information which is intended for encryption? Or would running a custom rom (ie. cyanogenmod) while still using Google applications suffice to mitigate these attacks?
Well, the Play store can seemingly update my system apps with no prompting. So I would guess that it's possible even on Cyanogenmod.
There was some huge political problem and the Cyanogen company did something the open source guys didn't like, so they left.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#129Earlier quoted context omitted.
I would like your take on a more specific question: Do you think that Google applications (GMail, Search, Translate, Maps, etc) themselves can get access to the necessary kernel subroutines to catch information which is intended for encryption? Or would running a custom rom (ie. cyanogenmod) while still using Google applications suffice to mitigate these attacks?
Wait, what? If you are running something based off of AOSP, you're running code that was touched by Google employees. Is your fear that Google is installing backdoors to help the CIA? If so, why are you afraid of that?
Doesn't matter who touches code when that code is publicly visible and available to the scrutiny of everyone. AOSP can be checked out and audited independently, just like any open source project.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#130Earlier quoted context omitted.
Let's be all Socratic here: Given a desktop OS like Windows that implements FDE like Bitlocker and runs a browser like Chrome, can you describe a hypothetical threat in which Chrome encrypting localstorage would prevent exploitation?
Yes - worms or browsers that scan local data files without accessing the runtime of the parent application.
0_o