Live data from Hacker News

WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

nytimes.com

191–200 of 250 posts

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#191
post #146

This headline is false and misleading, and does not reflect the headline on the article (WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents)

The headline here was the headline in the article. They've changed it after the submission and I believe mods here are going to do the same.

Yes. NYT often changes their headlines and we follow suit, with some lag.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#192
post #165

Earlier quoted context omitted.

:) Cheers.

For serious, thank you for taking the time to engage. I do take this seriously.

Yep. Same. And I would probably have posted a longer and less confrontational explanation of why you're (mostly) wrong if I weren't tired after a long day of work. ;)

The whole "why not encrypt local resources" thing is an odd red herring that a lot of (even fairly experienced) people trip over. There was a massive public furor over Chrome's chrome://settings/passwords (i.e. lack of a master password) design choice a couple of years ago that was a specific such case in point.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#193

Earlier quoted context omitted.

They bypassed it by compromising Android phones. There is a clear action item here if you want to be secure: switch to an iPhone, which is what tptacek has been saying here all along.

Have you read the announcement? iPhones are wide open for the 3-letter-agencies, too.

While the Wikileaks announcement explicitly mentions the iPhone (zero-days to "control, infest, and exfiltrate data"), the NY Times article mentions only Android in the context of bypassing Signal, WhatsApp.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#195
post #179

Earlier quoted context omitted.

> Next time I won't post in a rush during work hours. I'd suggest taking the same approach with your "secure, end-to-end encrypted communications" app you keep mentioning here[0] A one-way sha256 hash of a message using a password that has to be 8 characters long[1] and can't accept special characters[2] is not a secure communications app It is trivial to find the plaintext in these situations. Your Chrome extension…

Believe it or not, I very much appreciate your feedback.

I'd probably take the site down, or mark it clearly as being a hobby project.

As for Chrome - that team has some of the smartest infosec and cryptography people in the world working on and contributing to the project. If you want some insight into how some of the security design principals and tradeoffs were rationalized, i'd start with the project wiki:

https://www.chromium.org/Home/chromium-security

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#196
post #129
post #36

Earlier quoted context omitted.

Wait, what? If you are running something based off of AOSP, you're running code that was touched by Google employees. Is your fear that Google is installing backdoors to help the CIA? If so, why are you afraid of that?

> you're running code that was touched by Google employees Doesn't matter who touches code when that code is publicly visible and available to the scrutiny of everyone. AOSP can be checked out and audited independently, just like any open source project.

Sure, I guess. As I noted elsewhere in this thread, in general your risk is that the cost of exploitation is low (e.g. Android 4.x) or your value of exploitation is high (e.g. San Bernardino shooter).

Open vs closed source is a distinction I don't see a lot of folks in the security community take seriously, and for good reason: it's a response to a very specific threat model, where your concern is not primarily accidental 0days but intentional backdoors.

I would posit that the cost of a backdoor is probably higher than the cost of an 0day: the reputational risk to Google or Apple if they were discovered to have planted one is worth potentially billions of dollars in sales, so they will spend a lot of money fighting any such court order (and, as far as we know, such an order has never been successfully made).

The counterargument here is that if the government did win such an order, the backdoor is the gift that keeps on giving, whereas 0days eventually get patched and fixed.

But that's a long digression. For most users, this is simply the wrong threat model.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#197
post #195

Earlier quoted context omitted.

Believe it or not, I very much appreciate your feedback.

I'd probably take the site down, or mark it clearly as being a hobby project. As for Chrome - that team has some of the smartest infosec and cryptography people in the world working on and contributing to the project. If you want some insight into how some of the security design principals and tradeoffs were rationalized, i'd start with the project wiki: https://www.chromium.org/Home/chromium-security

It's currently marked as beta all over the site, for exactly these reasons.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#198
post #136

Earlier quoted context omitted.

> because it implies that Signal was broken It does mean Signal is pointless to use however. Why encrypt if your communications are picked up prior to encryption? Akin to putting your seat belt on after the car has crashed.

Because your opponent might not be the CIA and because your phone might not be compromised. So in that case switching to something less secure will instantly make your problems worse.

Of course, Im only speaking in the context that you are worried about the CIA or other governments.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#199
post #170
post #161

Earlier quoted context omitted.

This is entirely a non-issue. If group with the massive funding and pervasive reach like the CIA can operate with impunity it does not matter what app or what security you think you have.

Going from easy dragnet surveillance of unencrypted communications to having to use expensive to deploy, develop, maintain targeted attacks that get patched (with, on iOS, ridiculously high penetration rates) does not seem like a moot issue.

I don't see how this goes from one to the other. It seems that just about every Android and iOS device can be part of an "easy dragnet" without any app installed. If the wikileaks article is correct about the CIA having kept multiple 0-day exploits hidden for each OS, then breaking anything even remotely is a work ticket and not a research project for them.

The fine distinction of one app being singled out sucks, but it really is small potatoes here. The owner of the app should write the NYT and complain that their app was used inappropriately or perhaps write an editorial to get even more free advertising. The real news is that the CIA lied to Americans and the President so they could continue damaging American businesses, in the name of protecting America.

It sounds like we are not too far off from the CIA being able to write self spreading malware that allows monitoring they just haven't because... maybe it would be too easy to spot. Oh wait groups like the CIA did this already and rigged it to delete itself when not on one of their intended target's machines, stuxnet.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#200
post #136

Earlier quoted context omitted.

> because it implies that Signal was broken It does mean Signal is pointless to use however. Why encrypt if your communications are picked up prior to encryption? Akin to putting your seat belt on after the car has crashed.

"Akin to putting your seatbelt knowing full well a thermonuclear attack is always possible." Yes, catastrophic compromise is possible, but that does not render all security measures moot. A precious few attackers have the capability for such attacks, they are very costly to develop and therefore very precious and well kept secrets, to be used on high profile targets. Unless you are a spy, a terrorist, a state officia…

> Unless you are a spy, a terrorist, a state official with significant power or a dissident against the likes of Russia or China, end-to-end encryption like Signal will keep your communication private.

Maybe, if one person can do it so can others. It would be foolish to assume you are safe just because the US government doesn't deem you a person of interest. It might be far fetched, but now that the world knows it's possible to bypass encryption you cannot ignore the fact that Signal may not work at all.

Post reply on HN