Live data from Hacker News

WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

nytimes.com

201–210 of 250 posts

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#201
post #118

Earlier quoted context omitted.

They at least re-clarified on twitter. But not in the article. https://twitter.com/nytimes/status/839160771674255360

I believe they've edited the article: "Among other disclosures that, if confirmed, would rock the technology world, the WikiLeaks release said that the C.I.A. and allied intelligence services had managed to bypass encryption on popular phone and messaging services such as Signal, WhatsApp and Telegram. According to the statement from WikiLeaks, government hackers can penetrate Android phones and collect 'audio and me…

If that's an edit, it's still pretty poor. The 'experts' quoted are Wikileaks themselves. The disclosure 'A spy agency had 0-day exploits for mobile devices' would not rock anything.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#202
post #179

Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.

> Next time I won't post in a rush during work hours. I'd suggest taking the same approach with your "secure, end-to-end encrypted communications" app you keep mentioning here[0] A one-way sha256 hash of a message using a password that has to be 8 characters long[1] and can't accept special characters[2] is not a secure communications app It is trivial to find the plaintext in these situations. Your Chrome extension…

Could you explain how [3] is an RCI bug? getNum() returns either 'false' or 'n' with the length of gibberText (ie. n20, n35, etc). I can't imagine any content where .length() would return harmful code; though I'm not well versed in JS.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#203
post #13
post #11

Earlier quoted context omitted.

Unfortunately, this is a line that Wikileaks themselves are running with: https://twitter.com/wikileaks/status/839120909625606152

Running misinformation is part of Wikileaks' job. It's not the NYT's job.

In contrast, running McCarthy type propaganda and smear campaigns against Julian Assange/Wikileaks is part of NYT's job.

https://www.nytimes.com/2017/01/04/us/politics/julian-assang...

https://www.nytimes.com/2017/01/08/business/media/assange-wi...

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#204
post #198

Earlier quoted context omitted.

Because your opponent might not be the CIA and because your phone might not be compromised. So in that case switching to something less secure will instantly make your problems worse.

Of course, Im only speaking in the context that you are worried about the CIA or other governments.

Even if you are worried about them it still does not mean that you have been compromised. And if you do worry about them: don't use your phone (or any computer, for that matter) for sensitive stuff.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#205
post #35
post #19

To me this is much more worrying: > As of October 2014 the CIA was also looking at infecting the vehicle control systems used by modern cars and trucks. The purpose of such control is not specified, but it would permit the CIA to engage in nearly undetectable assassinations. https://wikileaks.org/ciav7p1/ Given the fact that car makers don't even have "PC age" security in their cars, things are looking pretty bad for…

Makes the conspiracy theories regarding journalist Michael Hastings' death in 2013 seem more plausible. [1] Former U.S. National Coordinator for Security, Infrastructure Protection, and Counter-terrorism Richard A. Clarke said that what is known about the crash is "consistent with a car cyber attack". He was quoted as saying "There is reason to believe that intelligence agencies for major powers — including the Unite…

> Makes the conspiracy theories regarding journalist Michael Hastings' death in 2013 seem more plausible.

Not really. The possibility of taking over unmodified cars remotely was not very widely known at the time. An organization that knew about that and had the technology to actually do so would not want to use it except on high value targets that they could not reach by more conventional means, because they would want to keep this capability under the radar of potential targets for as long as possible.

Due to the nature of his work Hastings would have been easy to take out by conventional means. He was an investigative reporter. It would be easy to feed him a lead on some story, like some important political person having a connection to a drug gang, and set up a meeting in a sketchy part of town with someone who says they want to give him confidential information about that. There would be nothing suspicious about that, and it would be easy to arrange for this fake meeting to go bad and end up with Hastings dead.

This would look like a sad but not totally unexpected way for a bold, risk taking, investigative reporter to die, and there would be not even a hint of a connection to any government agency.

If his car did not have remote vulnerabilities, and so any takeover involved modifying the car, then killing him by car takeover is even more absurd. It runs the risk of the modifications being discovered between the time they are installed and the time they are used (what if he takes his car in for service and the mechanic finds them?), and if used in a place where the agency doing the assassination does not have control of the scene afterwards risks the mods being discovered in the wreckage.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#206

We really need Qualcomm and others to document their hardware interfaces for modems, baseboards, and SoCs so that open firmware and drivers can be developed for these devices.

While I completely and I think I understand why, could you expand on this? If I did I would probably not be as accurate as you.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#207
post #202
post #179

Earlier quoted context omitted.

> Next time I won't post in a rush during work hours. I'd suggest taking the same approach with your "secure, end-to-end encrypted communications" app you keep mentioning here[0] A one-way sha256 hash of a message using a password that has to be 8 characters long[1] and can't accept special characters[2] is not a secure communications app It is trivial to find the plaintext in these situations. Your Chrome extension…

Could you explain how [3] is an RCI bug? getNum() returns either 'false' or 'n' with the length of gibberText (ie. n20, n35, etc). I can't imagine any content where .length() would return harmful code; though I'm not well versed in JS.

I'm also interested to know.

Believe it or not, I would love to get Nik as a consultant. I fear my 'hubris' (I won't deny it, this idea is extraordinarily ambitious and I have to be arrogant to even conceive of it) will have pissed him off irrevocably.

That aside, I don't really follow his point on the login PW. I understand 8 char alphanum pw is pretty low entropy... but that isn't used for encryption. And the login attempt rate is pretty strictly rate limited.

And yes, I am getting professionals - not me - to do the heavy lifting. I wrote the proof of concept. I am in no way surprised to find it has issues - I am aware of a few others myself.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#208
Given the other revelations of the last few weeks, I have to wonder if these exploits are getting installed on every phone that the CBP demands people unlock. Seems like the obvious thing to do. Best not to trust your phone or any software on it at least without a factory reset, and preferably a software update, after it's been in CBP custody for any time.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#209
post #199
post #170

Earlier quoted context omitted.

Going from easy dragnet surveillance of unencrypted communications to having to use expensive to deploy, develop, maintain targeted attacks that get patched (with, on iOS, ridiculously high penetration rates) does not seem like a moot issue.

I don't see how this goes from one to the other. It seems that just about every Android and iOS device can be part of an "easy dragnet" without any app installed. If the wikileaks article is correct about the CIA having kept multiple 0-day exploits hidden for each OS, then breaking anything even remotely is a work ticket and not a research project for them. The fine distinction of one app being singled out sucks, but…

You made a specific claim: no app, easy dragnet, work ticket level, because tons of hidden 0days. I'm taking it as read that a publicly patched one doesn't count. Is there evidence for that claim in the actual documents?

Pending that, here is evidence of a counter claim. I'd repeat what tptacek said, but he's whittled it down better than I could: https://news.ycombinator.com/item?id=13811541

To cite Tony Arcieri, the only elite cryptanalysis trick in play here is "Android is a tire fire". Cue surprised gasp from security researchers.

Furthermore, you did not refute my central claim. Popping a Cisco 12k: read a bunch of unencrypted comms until detection. Target a specific person to get bit by a specific iOS exploit: maybe read some of the data until it gets patched. Surely you'll agree that one is drastically more expensive than the other?

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#210
post #9

Earlier quoted context omitted.

> Please be aware that the Chrome browser does not offer a secure local storage protocol for its developers ... Compare this to Safari, which offers secure local storage at OS level security But this is just as secure as full disk encryption of the device right?

Not for malware running in user space.

Running in user space is not enough. It would need root. It is also hard to keep root, when you have dm-verity and selinux in enforcing mode.

Android applications are also sandboxed from each other. You would have hard time getting from one app to another's files, unless the original app published them - or you've got root.

Post reply on HN