Live data from Hacker News

WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

nytimes.com

161–170 of 250 posts

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#161
post #148
post #106

Earlier quoted context omitted.

Most users cannot tell the difference between between the Phone, OS, App and the signal (Let alone an app named Signal). Likely the journalists work with tech savvy to make sure their understood this and it was hard for them to make sense of gigabytes of technical jargon and noise. Arguing this point at all is silly when many people, even many IT professionals don't know and don't care about the difference between by…

That hardly matters if people's response is to use other, less secure things, as was the case with the Guardian and Whatsapp.

This is entirely a non-issue.

If group with the massive funding and pervasive reach like the CIA can operate with impunity it does not matter what app or what security you think you have.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#162

According to the statement from WikiLeaks, government hackers can penetrate Android phones and collect “audio and message traffic before encryption is applied.” How is that possible? Isn't the data encrypted before it's sent over the wire?

If the device isn't secure, all bets are off.

And in my opinion, if you require security that the CIA can't bypass, you won't find it in any mainstream consumer hardware or software.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#163
post #138
post #99

Earlier quoted context omitted.

Huh? What permissions are you referring to that the Gmail app has? Also, if I remember right (and I'm not an Android expert, so grain of salt here), Android OS itself enforces sandboxing based on app signing keys; even the Play app can't overwrite the Signal binary without a binary signed by the same key (though conceivably it could install some other fake-Signal app that looks just like Signal and has a similar icon…

> Huh? What permissions are you referring to that the Gmail app has? Maybe he was referring to these privileged permissions: http://android.stackexchange.com/a/17874/104563

I don't think that confers any ability to bypass the sandbox. Again, not an Android expert, so happy to be shown I'm wrong.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#164
post #106

Earlier quoted context omitted.

Most users cannot tell the difference between between the Phone, OS, App and the signal (Let alone an app named Signal). Likely the journalists work with tech savvy to make sure their understood this and it was hard for them to make sense of gigabytes of technical jargon and noise. Arguing this point at all is silly when many people, even many IT professionals don't know and don't care about the difference between by…

And the bonus to the CIA ignoring the deal the Obama administration made with Big Tech to disclose vulnerabilities is that now (apparently) all of the tools the CIA had accumulated are out in the wild, instead of being fixed.

I don't know why Obama allowed this, could he have had the CIA shut this stuff down he was the Chief Executive?

I wonder what this administration will do with this knowledge. It will be interesting to see trump respond too, rather than manufacture news.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#165
post #26

Earlier quoted context omitted.

Don't take this the wrong way, but as a non-lawyer, I try to heavily caveat any statement I make about the law. Would you consider heavily caveating statements you make about information security? A lot of what you say here is basically wrong.

> I try to heavily caveat any statement I make about the law. That is appreciated, and you are in the minority. I'm taking this advice, btw, and being more circumspect when I post in the future.

:)

Cheers.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#166
> According to the statement from WikiLeaks, government hackers can penetrate Android phones and collect “audio and message traffic before encryption is applied.”

This a perfectly useless bit of information in that it says nothing about how this penetration could occur. Pretty much anything can be cracked with a trojan. Something like a currently valid remove exploit would be a much bigger deal.

I could say that all the secure apps are broken because I can stand behind you and look over your shoulder while listening to anything you might say.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#167
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

Headline does imply the issue was with the messaging services and not the phones.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#168
post #38

Earlier quoted context omitted.

> Given Google's stance of not encrypting local storage in any way that I am aware of, this is fundamentally unsurprising. I have long been saying that Android is insecure and that storing passwords in Chrome is dangerous. ChromeOS and Android both implement FDE. There are some legitimate criticisms of (especially) the latter, voiced by e.g. Matthew Green, but you're just speaking nonsense here. There's very little v…

I am not talking about ChromeOS - I am talking about the Chrome browser. Localstorage, last I checked, which was recently, is plaintext. > ChromeOS and Android both implement FDE Which is irrelevant if the runtime is compromised, which appears to be the case.

>Which is irrelevant if the runtime is compromised, which appears to be the case.

You're under the false assumption that these exploits are current - they're not. In fact, they're very old.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#169
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

Eve operates in meat-space not a mathematical Flatland. Operationally, it does not matter how the message was read. The encryption system is compromised and users do not have practical alternatives.

The reality is that no matter how good the software engineers are; no matter how sound the algorithms; no matter how well funded the startup or open source project; it's completely outnumbered and completely out gunned. Nation states operate at a different scale and easily deployable encryption systems for novice users are white horse led brightly dressed musketeers drum marching to their general's firing line in the midst of a modern free fire zone.

To me, any secure communications systems that provides the convenience of app store downloads and over the air updates should be considered compromised. On the other hand, if someone thinks that a three letter agency might be interested in their communications and that person does not work for another three letter agency, they should probably assume that their signals are compromised if they are detected.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#170
post #161
post #148

Earlier quoted context omitted.

That hardly matters if people's response is to use other, less secure things, as was the case with the Guardian and Whatsapp.

This is entirely a non-issue. If group with the massive funding and pervasive reach like the CIA can operate with impunity it does not matter what app or what security you think you have.

Going from easy dragnet surveillance of unencrypted communications to having to use expensive to deploy, develop, maintain targeted attacks that get patched (with, on iOS, ridiculously high penetration rates) does not seem like a moot issue.
Post reply on HN