Live data from Hacker News

WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

nytimes.com

131–140 of 250 posts

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#131
post #86

Earlier quoted context omitted.

Accurate, but dangerously misleading.

How is it misleading if it is accurate? They bypassed it by compromising the phone. No encryption is going to save you in that situation and their targets were WhatsApp, Telegram, etc. So that part is accurate as well. It is a headline, I think what you are expecting is they put all the facts into the headline and there isn't enough space.

They bypassed it by compromising Android phones. There is a clear action item here if you want to be secure: switch to an iPhone, which is what tptacek has been saying here all along.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#132
post #96

Earlier quoted context omitted.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

The point is that the title mentions explicitly Signal and WhatsApp, generating the false impression that it was a weakness in these applications. However, it was a weakness in the OS, so a proper title would have been: | WikiLeaks: CIA managed to bypass encryption on popular messaging services on Android phone (nytimes.com)

They pwned iPhones too. And servers. And desktops, tablets, and your TV.

While Signal and WhatsApp have not been broken (apparently), pretty much every platform they are hosted on has been.

The main point is that the CIA can read your encrypted messages before they become encrypted, if they really want to. So while your encryption works, you can still be pwned.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#133
post #99

Earlier quoted context omitted.

Google Apps are typically installed as system apps. Play Store is obvious, since it needs to be able to install/update applications without prompting. The need for other apps (e.g. Gmail) to need system-level permissions is less obvious, but most of them fail to run if you just sideload it without the permissions.

Huh? What permissions are you referring to that the Gmail app has? Also, if I remember right (and I'm not an Android expert, so grain of salt here), Android OS itself enforces sandboxing based on app signing keys; even the Play app can't overwrite the Signal binary without a binary signed by the same key (though conceivably it could install some other fake-Signal app that looks just like Signal and has a similar icon…

While you are correct about the enforcement applying to Google Apps the Google Play Services has all possible permissions. I don't know if they could do something with the kernel from that alone though.

Personally I trust Android as much as I'd trust iOS... Which is to say I expect the government can get at either with physical access but only at the highest levels of government (CIA/NSA/FBI).

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#134
post #26

Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.

Don't take this the wrong way, but as a non-lawyer, I try to heavily caveat any statement I make about the law. Would you consider heavily caveating statements you make about information security? A lot of what you say here is basically wrong.

[deleted]

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#135

Earlier quoted context omitted.

How is it misleading if it is accurate? They bypassed it by compromising the phone. No encryption is going to save you in that situation and their targets were WhatsApp, Telegram, etc. So that part is accurate as well. It is a headline, I think what you are expecting is they put all the facts into the headline and there isn't enough space.

They bypassed it by compromising Android phones. There is a clear action item here if you want to be secure: switch to an iPhone, which is what tptacek has been saying here all along.

Have you read the announcement? iPhones are wide open for the 3-letter-agencies, too.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#136
post #75

Earlier quoted context omitted.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

This is a dangerous headline because it implies that Signal was broken, which could lead to people moving to LESS SECURE SERVICES because they think the more secure one is broken. When in reality is the phone and OS. They have similar end result for the phone in question, but headlines like this can lead to people being less secure on the whole.

> because it implies that Signal was broken

It does mean Signal is pointless to use however. Why encrypt if your communications are picked up prior to encryption? Akin to putting your seat belt on after the car has crashed.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#137
post #86

Earlier quoted context omitted.

Accurate, but dangerously misleading.

How is it misleading if it is accurate? They bypassed it by compromising the phone. No encryption is going to save you in that situation and their targets were WhatsApp, Telegram, etc. So that part is accurate as well. It is a headline, I think what you are expecting is they put all the facts into the headline and there isn't enough space.

Well, why singling out the two services in the headline when this applies to basically every application ever?

Luckily, they've realized the mistake and apparently changed the headline.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#138
post #99

Earlier quoted context omitted.

Google Apps are typically installed as system apps. Play Store is obvious, since it needs to be able to install/update applications without prompting. The need for other apps (e.g. Gmail) to need system-level permissions is less obvious, but most of them fail to run if you just sideload it without the permissions.

Huh? What permissions are you referring to that the Gmail app has? Also, if I remember right (and I'm not an Android expert, so grain of salt here), Android OS itself enforces sandboxing based on app signing keys; even the Play app can't overwrite the Signal binary without a binary signed by the same key (though conceivably it could install some other fake-Signal app that looks just like Signal and has a similar icon…

> Huh? What permissions are you referring to that the Gmail app has?

Maybe he was referring to these privileged permissions: http://android.stackexchange.com/a/17874/104563

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#139
post #106
post #75

Earlier quoted context omitted.

This is a dangerous headline because it implies that Signal was broken, which could lead to people moving to LESS SECURE SERVICES because they think the more secure one is broken. When in reality is the phone and OS. They have similar end result for the phone in question, but headlines like this can lead to people being less secure on the whole.

Most users cannot tell the difference between between the Phone, OS, App and the signal (Let alone an app named Signal). Likely the journalists work with tech savvy to make sure their understood this and it was hard for them to make sense of gigabytes of technical jargon and noise. Arguing this point at all is silly when many people, even many IT professionals don't know and don't care about the difference between by…

[deleted]

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#140
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

I think the part that's misleading is that with a loose/typical/casual reading it sounds like the bypass is at the application level as opposed to the OS/host level. By suggesting specific apps/services may be "bypassed" they fail to make it crystal clear to all readers that any breakage is likely app/service agnostic.

Of course this source is part of the same media that continually calls the election "hacked" despite there being no known technical irregularities with voting machines or vote recording or the actual election itself [^1] (that I'm aware of, at least). (Yes, computer systems were compromised, and data was exfiltrated from the DNC/related parties and released by foreign state actors. Unfortunately that is not "hacking an election." It's just plain and traditional information ops.)

So it's pretty par.

Mainstream news sources seem to continually get worse at reporting tech related stories, and I think there must be an even greater level of confusion when it comes to typical non-techinical individual citizens.

[^1]: Whether anybody is actually interested in actual elections running in auditable, effective, and functional way is apparently another question entirely, and the answer from most seems to be "nope."

Post reply on HN