Live data from Hacker News

WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

nytimes.com

141–150 of 250 posts

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#141
post #75

Earlier quoted context omitted.

This is a dangerous headline because it implies that Signal was broken, which could lead to people moving to LESS SECURE SERVICES because they think the more secure one is broken. When in reality is the phone and OS. They have similar end result for the phone in question, but headlines like this can lead to people being less secure on the whole.

I'm sure someone savvy enough to use end-to-end encrypted communication channels will switch to less secure methods based off of a headline /s

It's not really that savvy people would be switching away; it's that non-savvy friends/family of savvy people who read this article now will have a slight negative connotation to those product names, so if their savvy friend/relative tries to convince them to switch to either of them, they might say no for stupid reasons.

This is the point of the majority of propaganda, really: it's not to convince the people who know anything about the issue; it's to prejudice the people who don't, so that it'll be harder for the people in the know to communicate the facts to them.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#142
post #96

Earlier quoted context omitted.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

The point is that the title mentions explicitly Signal and WhatsApp, generating the false impression that it was a weakness in these applications. However, it was a weakness in the OS, so a proper title would have been: | WikiLeaks: CIA managed to bypass encryption on popular messaging services on Android phone (nytimes.com)

Or even just "CIA managed to hack into Android phones."

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#143
post #118
post #13

Earlier quoted context omitted.

Running misinformation is part of Wikileaks' job. It's not the NYT's job.

They at least re-clarified on twitter. But not in the article. https://twitter.com/nytimes/status/839160771674255360

I believe they've edited the article:

"Among other disclosures that, if confirmed, would rock the technology world, the WikiLeaks release said that the C.I.A. and allied intelligence services had managed to bypass encryption on popular phone and messaging services such as Signal, WhatsApp and Telegram. According to the statement from WikiLeaks, government hackers can penetrate Android phones and collect 'audio and message traffic before encryption is applied.'"

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#144

Earlier quoted context omitted.

They bypassed it by compromising Android phones. There is a clear action item here if you want to be secure: switch to an iPhone, which is what tptacek has been saying here all along.

Have you read the announcement? iPhones are wide open for the 3-letter-agencies, too.

[deleted]

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#145

You should consider the assumption that your security IS compromised at any given point in time (bypassed or whatever) then you could foresee and prevent some worst case scenarios which usually come from hubris nonetheless ("hey, our app is 100% secure and tested by the top security experts - not like other apps on the market").

This point can't be emphasized enough. Sophisticated operators always assume they're being listened to, and take precautionary steps.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#146

This headline is false and misleading, and does not reflect the headline on the article (WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents)

The headline here was the headline in the article. They've changed it after the submission and I believe mods here are going to do the same.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#147

Earlier quoted context omitted.

You're very much misrepresenting the facts. Android very much encrypts data (or gives users the option to, I'm not certain if it's the default). Chrome, the desktop application, does not. Why? Because that's a false sense of security. Chrome would have to also store the encryption key, and store it in the same place and under the same access controls as the encrypted data. This is not real protection. It is up to the…

> Why? Because that's a false sense of security. Chrome would have to also store the encryption key, and store it in the same place and under the same access controls as the encrypted data. I hear you, but this is not the case with Safari. It offers secure local storage. It's the securesettings API. It uses the OS level encryption, and, based on the current state of play, this does not appear to be compromised. > as…

> It uses the OS level encryption

So all the NSA/CIA needs is a XNU kernel exploit which they need anyway for iPhone root exploits. Then, intercept the securesettings API or just do a raw memory dump of the browser process.

And the NSA has another card they can play, and that way easier on Apple than on the fragmented Windows ecosystem: all the tiny chips on your motherboard (EC, or any chip on the PCI bus which has DMA) can read and parse the RAM. Given that there is a highly limited number of different Mac EC chips and even then Apple likely uses the same firmware across them, it's easier for CIA/NSA to develop an exploit for these and don't care about kernel at all.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#148
post #106
post #75

Earlier quoted context omitted.

This is a dangerous headline because it implies that Signal was broken, which could lead to people moving to LESS SECURE SERVICES because they think the more secure one is broken. When in reality is the phone and OS. They have similar end result for the phone in question, but headlines like this can lead to people being less secure on the whole.

Most users cannot tell the difference between between the Phone, OS, App and the signal (Let alone an app named Signal). Likely the journalists work with tech savvy to make sure their understood this and it was hard for them to make sense of gigabytes of technical jargon and noise. Arguing this point at all is silly when many people, even many IT professionals don't know and don't care about the difference between by…

That hardly matters if people's response is to use other, less secure things, as was the case with the Guardian and Whatsapp.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#149
post #75

Earlier quoted context omitted.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

This is a dangerous headline because it implies that Signal was broken, which could lead to people moving to LESS SECURE SERVICES because they think the more secure one is broken. When in reality is the phone and OS. They have similar end result for the phone in question, but headlines like this can lead to people being less secure on the whole.

I don't think your argument about less secure services is helpful to layman. By arguing that Whatsapp is more secure, you are giving people a false sense of security. A good way to phrase it would be "all messaging services are equally vulnerable to these kind of attacks, regardless of encryption."

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#150
post #86

Earlier quoted context omitted.

Accurate, but dangerously misleading.

How is it misleading if it is accurate? They bypassed it by compromising the phone. No encryption is going to save you in that situation and their targets were WhatsApp, Telegram, etc. So that part is accurate as well. It is a headline, I think what you are expecting is they put all the facts into the headline and there isn't enough space.

It's misleading by omission. Until I read the article I was under the impression that they had found a flaw or something exploitable in the OWS protocol.

If the problem was with Signal or Whatsapp, as the headline suggested to me, switching to another messaging service is the natural reaction. If people understand that the problem is with the platform, and that all platforms are compromised that solution doesn't work, and using signal is still better than SMS because it still protects against other forms of surveillance.

Post reply on HN