Live data from Hacker News

WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

nytimes.com

171–180 of 250 posts

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#171
post #46

Earlier quoted context omitted.

> Compare the security of Android - which we now know to be 'owned' by the US Government To what are you referring to here, precisely? Since AOSP is open source, is there a specific line of code that you can point to that contains (or is emblematic of) this insecurity? Your article doesn't seem to say.

> Here is my take as an information lawyer and (slightly-higher than script-kiddy-level) web developer as a "(slightly-higher than script-kiddy-level) web developer" I'm going to guess that he doesn't actually know very much about AOSP, the Linux kernel, or indeed GNU/Linux security in general. So his emphatic statement "Compare the security of Android - which we now know to be 'owned' by the US Government" is pretty…

> I'm going to guess that he doesn't actually know very much about AOSP, the Linux kernel, or indeed GNU/Linux security in general.

I know a fair amount for a 'layperson', which you can (probably rightly) argue means I am unqualified for comment in these circles, and you are right that I am including too much speculation. I absolutely, inarguably overstepped. My bad.

However, with regard to Android being owned - this article is literally about the CIA tools that are used to compromise Android. The trove has been released. It is incontrovertible at this point: https://www.washingtonpost.com/world/national-security/wikil...

The issue is to what extent other fundamental assumptions are now called into question. Is it only android, or is Chrome now suspect as well? What protocols are compromised?

I suspect we will find out more in the coming days, and I should have been more circumspect in my own post. It was unbecoming.

In any event, thanks for your feedback.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#172
And people wonder why I am only lukewarm about encryption and opsec. I use both for myself, but I've given up evangelizing other people years ago because (as I've said here on HN many times):

For regular people, the effort of encrypting things is simply not worth it because they're powerless against a really determined attacker. It's rational to protect against casual attacks from spammers and scammers, but protecting oneself against state-level attackers is futile unless you make a full-time job out of it.

Someone usually pipes up at this point saying 'we need to limit the powers of the state', like some sternly-worded law is going to undo the existence of the technology or take away the vast economic and political incentives to deploy it. Get real folks, technology doesn't get un-invented, and powerful organizations are just like powerful organisms; they're opportunist, they maximize their own chances of survival, and when they do collapse the resulting power vacuum is filled as rapidly as any other vacuum would be. One can certainly seek to govern the behavior of a state or state organ, but attempting to limit its technical ability is naive, for the same reason that you'd be naive to try to fix police brutality by legislating about the design parameters of police batons.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#174
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

[deleted]

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#175
post #165

Earlier quoted context omitted.

> I try to heavily caveat any statement I make about the law. That is appreciated, and you are in the minority. I'm taking this advice, btw, and being more circumspect when I post in the future.

:) Cheers.

For serious, thank you for taking the time to engage. I do take this seriously.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#176
post #81

Earlier quoted context omitted.

The CIA tools to own it were just leaked. You are commenting on the thread talking about those tools and the leak announcement.

As far as I can tell, my question ("which line of code is broken?") is also not answered either in the NYT piece or the wikileaks release. If I'm wrong, do you have a link?

https://www.washingtonpost.com/world/national-security/wikil...

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#177
post #136
post #75

Earlier quoted context omitted.

This is a dangerous headline because it implies that Signal was broken, which could lead to people moving to LESS SECURE SERVICES because they think the more secure one is broken. When in reality is the phone and OS. They have similar end result for the phone in question, but headlines like this can lead to people being less secure on the whole.

> because it implies that Signal was broken It does mean Signal is pointless to use however. Why encrypt if your communications are picked up prior to encryption? Akin to putting your seat belt on after the car has crashed.

No, no, no!

Defense in depth! Do you stop using TLS on your banking website every time a Windows 0day comes out?

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#178
post #164

Earlier quoted context omitted.

And the bonus to the CIA ignoring the deal the Obama administration made with Big Tech to disclose vulnerabilities is that now (apparently) all of the tools the CIA had accumulated are out in the wild, instead of being fixed.

I don't know why Obama allowed this, could he have had the CIA shut this stuff down he was the Chief Executive? I wonder what this administration will do with this knowledge. It will be interesting to see trump respond too, rather than manufacture news.

Frankly, I am not sure if anyone in the White House has been able to truly control the intelligence agencies since the first Bush. And I say that only because he was a former CIA director, so he had a better chance of knowing where the control levers were hidden.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#179

Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.

> Next time I won't post in a rush during work hours.

I'd suggest taking the same approach with your "secure, end-to-end encrypted communications" app you keep mentioning here[0]

A one-way sha256 hash of a message using a password that has to be 8 characters long[1] and can't accept special characters[2] is not a secure communications app

It is trivial to find the plaintext in these situations.

Your Chrome extension has a very elementary RCI bug in it[3], which because of your extensions broad permissions[4] profile means anyone with your extension installed can have any code executed by visiting any page.

To release (excuse me) crap like this on one hand while FUD'ing Google's security practices on HN on the other requires a level of hubris that I don't think i've ever previously encountered.

[0] https://www.gibberit.com/

[1] http://i.imgur.com/CsgOkZ2.png

[2] http://i.imgur.com/uZg0E4l.png

[3] http://i.imgur.com/eq19mET.png

[4] http://i.imgur.com/lOsibBP.png

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#180

Earlier quoted context omitted.

I am not talking about ChromeOS - I am talking about the Chrome browser. Localstorage, last I checked, which was recently, is plaintext. > ChromeOS and Android both implement FDE Which is irrelevant if the runtime is compromised, which appears to be the case.

>Which is irrelevant if the runtime is compromised, which appears to be the case. You're under the false assumption that these exploits are current - they're not. In fact, they're very old.

These ones?

https://www.washingtonpost.com/world/national-security/wikil...

Post reply on HN