This headline is false and misleading, and does not reflect the headline on the article (WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents)
The headline here was the headline in the article. They've changed it after the submission and I believe mods here are going to do the same.
WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
191–200 of 250 posts
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#192Earlier quoted context omitted.
:) Cheers.
For serious, thank you for taking the time to engage. I do take this seriously.
The whole "why not encrypt local resources" thing is an odd red herring that a lot of (even fairly experienced) people trip over. There was a massive public furor over Chrome's chrome://settings/passwords (i.e. lack of a master password) design choice a couple of years ago that was a specific such case in point.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#193Earlier quoted context omitted.
They bypassed it by compromising Android phones. There is a clear action item here if you want to be secure: switch to an iPhone, which is what tptacek has been saying here all along.
Have you read the announcement? iPhones are wide open for the 3-letter-agencies, too.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#194Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#195Earlier quoted context omitted.
> Next time I won't post in a rush during work hours. I'd suggest taking the same approach with your "secure, end-to-end encrypted communications" app you keep mentioning here[0] A one-way sha256 hash of a message using a password that has to be 8 characters long[1] and can't accept special characters[2] is not a secure communications app It is trivial to find the plaintext in these situations. Your Chrome extension…
Believe it or not, I very much appreciate your feedback.
As for Chrome - that team has some of the smartest infosec and cryptography people in the world working on and contributing to the project. If you want some insight into how some of the security design principals and tradeoffs were rationalized, i'd start with the project wiki:
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#196Earlier quoted context omitted.
Wait, what? If you are running something based off of AOSP, you're running code that was touched by Google employees. Is your fear that Google is installing backdoors to help the CIA? If so, why are you afraid of that?
> you're running code that was touched by Google employees Doesn't matter who touches code when that code is publicly visible and available to the scrutiny of everyone. AOSP can be checked out and audited independently, just like any open source project.
Open vs closed source is a distinction I don't see a lot of folks in the security community take seriously, and for good reason: it's a response to a very specific threat model, where your concern is not primarily accidental 0days but intentional backdoors.
I would posit that the cost of a backdoor is probably higher than the cost of an 0day: the reputational risk to Google or Apple if they were discovered to have planted one is worth potentially billions of dollars in sales, so they will spend a lot of money fighting any such court order (and, as far as we know, such an order has never been successfully made).
The counterargument here is that if the government did win such an order, the backdoor is the gift that keeps on giving, whereas 0days eventually get patched and fixed.
But that's a long digression. For most users, this is simply the wrong threat model.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#197Earlier quoted context omitted.
Believe it or not, I very much appreciate your feedback.
I'd probably take the site down, or mark it clearly as being a hobby project. As for Chrome - that team has some of the smartest infosec and cryptography people in the world working on and contributing to the project. If you want some insight into how some of the security design principals and tradeoffs were rationalized, i'd start with the project wiki: https://www.chromium.org/Home/chromium-security
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#198Earlier quoted context omitted.
> because it implies that Signal was broken It does mean Signal is pointless to use however. Why encrypt if your communications are picked up prior to encryption? Akin to putting your seat belt on after the car has crashed.
Because your opponent might not be the CIA and because your phone might not be compromised. So in that case switching to something less secure will instantly make your problems worse.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#199Earlier quoted context omitted.
This is entirely a non-issue. If group with the massive funding and pervasive reach like the CIA can operate with impunity it does not matter what app or what security you think you have.
Going from easy dragnet surveillance of unencrypted communications to having to use expensive to deploy, develop, maintain targeted attacks that get patched (with, on iOS, ridiculously high penetration rates) does not seem like a moot issue.
The fine distinction of one app being singled out sucks, but it really is small potatoes here. The owner of the app should write the NYT and complain that their app was used inappropriately or perhaps write an editorial to get even more free advertising. The real news is that the CIA lied to Americans and the President so they could continue damaging American businesses, in the name of protecting America.
It sounds like we are not too far off from the CIA being able to write self spreading malware that allows monitoring they just haven't because... maybe it would be too easy to spot. Oh wait groups like the CIA did this already and rigged it to delete itself when not on one of their intended target's machines, stuxnet.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#200Earlier quoted context omitted.
> because it implies that Signal was broken It does mean Signal is pointless to use however. Why encrypt if your communications are picked up prior to encryption? Akin to putting your seat belt on after the car has crashed.
"Akin to putting your seatbelt knowing full well a thermonuclear attack is always possible." Yes, catastrophic compromise is possible, but that does not render all security measures moot. A precious few attackers have the capability for such attacks, they are very costly to develop and therefore very precious and well kept secrets, to be used on high profile targets. Unless you are a spy, a terrorist, a state officia…
Maybe, if one person can do it so can others. It would be foolish to assume you are safe just because the US government doesn't deem you a person of interest. It might be far fetched, but now that the world knows it's possible to bypass encryption you cannot ignore the fact that Signal may not work at all.