Live data from Hacker News

WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

nytimes.com

21–30 of 250 posts

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#21
post #16
post #13

Earlier quoted context omitted.

Running misinformation is part of Wikileaks' job. It's not the NYT's job.

Agreed 100% - but methinks NYT (and others) still look to them for technical guidance on some matters - however misguided that might be.

The NYT has a _huge_ list of experts to contact for stories like this. They chose not to, in the interests of getting a salacious lede printed quickly.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#22

According to the statement from WikiLeaks, government hackers can penetrate Android phones and collect “audio and message traffic before encryption is applied.” How is that possible? Isn't the data encrypted before it's sent over the wire?

The kernel is owned (or some part of the phone below the application level). The encryption only gets applied at the application level before the messages are sent down the wire. The interception happens prior to the encryption being applied . Think of it as a dongle on the wire between your keyboard and the computer. It doens't matter if the computer is secure - the message is intercepted prior to any encryption. Th…

You're very much misrepresenting the facts. Android very much encrypts data (or gives users the option to, I'm not certain if it's the default). Chrome, the desktop application, does not. Why? Because that's a false sense of security. Chrome would have to also store the encryption key, and store it in the same place and under the same access controls as the encrypted data. This is not real protection. It is up to the user to not run malicious apps under the same security context as Chrome, and to encrypt their hard drive to protect their data at rest. Nothing that chrome can do in its security context is anything more than placebo - as shown by the fact that malware (and legitimate programs!) can read the Firefox local password database.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#23
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

I agree. They should be called out on it. The headline is basically "fake news."

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#24
post #9

Earlier quoted context omitted.

> Please be aware that the Chrome browser does not offer a secure local storage protocol for its developers ... Compare this to Safari, which offers secure local storage at OS level security But this is just as secure as full disk encryption of the device right?

Not for malware running in user space.

The browser runs in user space. Desktop OSes don't offer any sort of partitioning here. So there's very little reason to have any app-level encryption on a desktop OS.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#26

Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.

Don't take this the wrong way, but as a non-lawyer, I try to heavily caveat any statement I make about the law.

Would you consider heavily caveating statements you make about information security? A lot of what you say here is basically wrong.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#27
post #16
post #13

Earlier quoted context omitted.

Running misinformation is part of Wikileaks' job. It's not the NYT's job.

Agreed 100% - but methinks NYT (and others) still look to them for technical guidance on some matters - however misguided that might be.

If I'm not mistaken then the NYT has shown in the past that it can get basic tech/security facts like these straight.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#28
post #13
post #11

Earlier quoted context omitted.

Unfortunately, this is a line that Wikileaks themselves are running with: https://twitter.com/wikileaks/status/839120909625606152

Running misinformation is part of Wikileaks' job. It's not the NYT's job.

>misinformation is part of Wikileaks' job.

YES! Because they are Russian stooges and they helped Trump get elected!

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#29
post #19

To me this is much more worrying: > As of October 2014 the CIA was also looking at infecting the vehicle control systems used by modern cars and trucks. The purpose of such control is not specified, but it would permit the CIA to engage in nearly undetectable assassinations. https://wikileaks.org/ciav7p1/ Given the fact that car makers don't even have "PC age" security in their cars, things are looking pretty bad for…

https://en.wikipedia.org/wiki/Michael_Hastings_(journalist)#...

Potential assassination?

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#30
post #19

To me this is much more worrying: > As of October 2014 the CIA was also looking at infecting the vehicle control systems used by modern cars and trucks. The purpose of such control is not specified, but it would permit the CIA to engage in nearly undetectable assassinations. https://wikileaks.org/ciav7p1/ Given the fact that car makers don't even have "PC age" security in their cars, things are looking pretty bad for…

These are great arguments against super power private institutions (corporations) that operate in secret and are essentially unaccountable to the public.
Post reply on HN