This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.
WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
151–160 of 250 posts
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#152Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.
Don't take this the wrong way, but as a non-lawyer, I try to heavily caveat any statement I make about the law. Would you consider heavily caveating statements you make about information security? A lot of what you say here is basically wrong.
That is appreciated, and you are in the minority.
I'm taking this advice, btw, and being more circumspect when I post in the future.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#153Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.
Was going to email you but I couldn't find a way of getting your contact information without enabling google JS (something you might want to consider as a privacy advocate) The background video on gibber is awful, makes it very hard to read the page. I've just opened it in another browser with all the JS on and again your page totally doesn't work with the google ajax switched on. Worth fixing.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#154Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#155Earlier quoted context omitted.
Accurate, but dangerously misleading.
How is it misleading if it is accurate? They bypassed it by compromising the phone. No encryption is going to save you in that situation and their targets were WhatsApp, Telegram, etc. So that part is accurate as well. It is a headline, I think what you are expecting is they put all the facts into the headline and there isn't enough space.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#156Earlier quoted context omitted.
They bypassed it by compromising Android phones. There is a clear action item here if you want to be secure: switch to an iPhone, which is what tptacek has been saying here all along.
Have you read the announcement? iPhones are wide open for the 3-letter-agencies, too.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#157I thought they were already compromised since both these services use SMS authentication; since the defaults AFAIK aren't particularly concerned about a change in the public key, it's broken for anything secure anyway. Tox on the other hand seems much more secure... though I guess if you're phone is compromised you're pretty much screwed to start with (which is not too hard with all the bloatware one needs these days…
Long story short: if someone obtains your Tox private key, they are able to impersonate you in the conversations with other people without you realizing it.
Tox developers admitted this was an issue. Fixing this means changing the protocol itself (which will affect everyone).
Tox is still experimental (which they admit here: https://github.com/TokTok/c-toxcore/issues/426) and it is not advisable to use it.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#158Earlier quoted context omitted.
Huh? What permissions are you referring to that the Gmail app has? Also, if I remember right (and I'm not an Android expert, so grain of salt here), Android OS itself enforces sandboxing based on app signing keys; even the Play app can't overwrite the Signal binary without a binary signed by the same key (though conceivably it could install some other fake-Signal app that looks just like Signal and has a similar icon…
While you are correct about the enforcement applying to Google Apps the Google Play Services has all possible permissions. I don't know if they could do something with the kernel from that alone though. Personally I trust Android as much as I'd trust iOS... Which is to say I expect the government can get at either with physical access but only at the highest levels of government (CIA/NSA/FBI).
As you say, in both cases (iOS and Play Services) it's a commercial closed-source bundle. shrug
I don't personally spend time worrying about that, given that Google and Apple's code is probably better reviewed than some random open source app, but some people like to nerd out about such things.
As you say, the FBI was eventually able to get access to the San Bernardino shooter's phone. But this isn't exclusive to the highest levels of government; it just depends on your budget: http://www.reuters.com/article/us-apple-encryption-fbi-idUSK.... It's not surprising the CIA would have a stockpile of unpatched 0days, found or bought.
I don't believe I'm worth $1m to anyone, so I feel pretty safe using both iOS and a recent, patched Android.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#159This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.
Exactly, and some people including me thought about this possibility years ago. The most secure system in the universe can still be hacked very easily by a malicious closed driver because device drivers have the highest access level to the underlying hardware. Every information being produced: (virtual) keyboard writings, data, contacts, sensors data, GPS, audio, files, etc. I mean everything can be accessed a lot before it reaches the encryption code and be relayed to a 3rd party without the user even noticing.
This plague won't go away, not until enough people with enough influence will require hardware manufacturers to document their hardware in order to create OSS and trustworthy device drivers.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#160This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.
NYT is pivoting to a model that brings it more clicks.