Live data from Hacker News

WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

nytimes.com

181–190 of 250 posts

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#181
post #136
post #75

Earlier quoted context omitted.

This is a dangerous headline because it implies that Signal was broken, which could lead to people moving to LESS SECURE SERVICES because they think the more secure one is broken. When in reality is the phone and OS. They have similar end result for the phone in question, but headlines like this can lead to people being less secure on the whole.

> because it implies that Signal was broken It does mean Signal is pointless to use however. Why encrypt if your communications are picked up prior to encryption? Akin to putting your seat belt on after the car has crashed.

Because your opponent might not be the CIA and because your phone might not be compromised.

So in that case switching to something less secure will instantly make your problems worse.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#182
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

You're both right: encryption was bypassed, but mentioning specific apps implies those apps were specifically affected and is misleading.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#184
post #136
post #75

Earlier quoted context omitted.

This is a dangerous headline because it implies that Signal was broken, which could lead to people moving to LESS SECURE SERVICES because they think the more secure one is broken. When in reality is the phone and OS. They have similar end result for the phone in question, but headlines like this can lead to people being less secure on the whole.

> because it implies that Signal was broken It does mean Signal is pointless to use however. Why encrypt if your communications are picked up prior to encryption? Akin to putting your seat belt on after the car has crashed.

"Akin to putting your seatbelt knowing full well a thermonuclear attack is always possible."

Yes, catastrophic compromise is possible, but that does not render all security measures moot. A precious few attackers have the capability for such attacks, they are very costly to develop and therefore very precious and well kept secrets, to be used on high profile targets.

Unless you are a spy, a terrorist, a state official with significant power or a dissident against the likes of Russia or China, end-to-end encryption like Signal will keep your communication private.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#185

Earlier quoted context omitted.

You're very much misrepresenting the facts. Android very much encrypts data (or gives users the option to, I'm not certain if it's the default). Chrome, the desktop application, does not. Why? Because that's a false sense of security. Chrome would have to also store the encryption key, and store it in the same place and under the same access controls as the encrypted data. This is not real protection. It is up to the…

> Why? Because that's a false sense of security. Chrome would have to also store the encryption key, and store it in the same place and under the same access controls as the encrypted data. I hear you, but this is not the case with Safari. It offers secure local storage. It's the securesettings API. It uses the OS level encryption, and, based on the current state of play, this does not appear to be compromised. > as…

I'll admit that the OSX Keychain has advantages - Offering OS-managed secure storage, with the possibility of the OS authenticating requests for credentials with the user is pretty cool. But as Chrome is cross-platform, and there's not standardized and similar APIs on Linux and Windows, I don't think it's the right move to have an OSX exclusive implementation that uses that api.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#186
post #141

Earlier quoted context omitted.

I'm sure someone savvy enough to use end-to-end encrypted communication channels will switch to less secure methods based off of a headline /s

It's not really that savvy people would be switching away; it's that non-savvy friends/family of savvy people who read this article now will have a slight negative connotation to those product names, so if their savvy friend/relative tries to convince them to switch to either of them, they might say no for stupid reasons. This is the point of the majority of propaganda, really: it's not to convince the people who kno…

In particular because the App Store features not only the usual suspects (Skype, Allo, ...), but many other somewhat random apps (Gonzo, BabelNet, Kissapp, 5s, ...) promising encrypted chat, and people might think, "hmm, WhatsApp and Signal are insecure, it says so in the NY Times, so let's try one of these"

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#187

Earlier quoted context omitted.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

If the app and service were not involved the only reason to mention them is to create doubt they are secure.

Exactly. If they can read your messages, it's not secure.

You're being really picky in focusing on how Signal itself wasn't hacked.

What's the difference if they can crack the OS or some other app itself and have access?

A very small technical argument is the difference. When the outcome is still "Oh hey, guess what though, they can still read those messages."

It's like a thief breaks into your house, reads your mail, and you're arguing the Post Office wasn't hacked, no big deal!

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#188
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

We've updated the headline to what the NYT currently says. Previously it said "WikiLeaks: CIA managed to bypass encryption on popular services Signal, WhatsApp".

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#189
post #179

Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.

> Next time I won't post in a rush during work hours. I'd suggest taking the same approach with your "secure, end-to-end encrypted communications" app you keep mentioning here[0] A one-way sha256 hash of a message using a password that has to be 8 characters long[1] and can't accept special characters[2] is not a secure communications app It is trivial to find the plaintext in these situations. Your Chrome extension…

Believe it or not, I very much appreciate your feedback.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#190
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

But the rest of the headline is misleading. It's Android that was broken into, not Whatsapp or Signal. The headline encourages a false idea that those apps have a systemic flaw that allows the CIA to read any messages sent over them, which is incorrect. "Bypass" is the right word, but the sentence as a whole misses the point and spreads a misleading message.
Post reply on HN