Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.
WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
31–40 of 250 posts
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#32According to the statement from WikiLeaks, government hackers can penetrate Android phones and collect “audio and message traffic before encryption is applied.” How is that possible? Isn't the data encrypted before it's sent over the wire?
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#33Mention "Signal" in any article and you'll have @tptacek running here to defend it with any costs.
You made a new account today just for that?
You would enjoy Yasha Levine https://twitter.com/search?q=%40yashalevine%20signal&src=typ...
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#34To me this is much more worrying: > As of October 2014 the CIA was also looking at infecting the vehicle control systems used by modern cars and trucks. The purpose of such control is not specified, but it would permit the CIA to engage in nearly undetectable assassinations. https://wikileaks.org/ciav7p1/ Given the fact that car makers don't even have "PC age" security in their cars, things are looking pretty bad for…
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#35To me this is much more worrying: > As of October 2014 the CIA was also looking at infecting the vehicle control systems used by modern cars and trucks. The purpose of such control is not specified, but it would permit the CIA to engage in nearly undetectable assassinations. https://wikileaks.org/ciav7p1/ Given the fact that car makers don't even have "PC age" security in their cars, things are looking pretty bad for…
Former U.S. National Coordinator for Security, Infrastructure Protection, and Counter-terrorism Richard A. Clarke said that what is known about the crash is "consistent with a car cyber attack". He was quoted as saying "There is reason to believe that intelligence agencies for major powers — including the United States — know how to remotely seize control of a car. So if there were a cyber attack on [Hastings'] car — and I'm not saying there was, I think whoever did it would probably get away with it."[68]
Cenk Uygur, friend of Hastings' and host of The Young Turks, told KTLA that many of Michael's friends were concerned that he was "in a very agitated state", saying he was "incredibly tense" and worried that his material was being surveilled by the government. Friends believed that Michael's line of work led to a "paranoid state".[80] USA Today reported that in the days before his death, Hastings believed his car was being "tampered with" and that he was scared and wanted to leave town.[81]
[1] https://en.wikipedia.org/wiki/Michael_Hastings_(journalist)
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#36Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.
I would like your take on a more specific question: Do you think that Google applications (GMail, Search, Translate, Maps, etc) themselves can get access to the necessary kernel subroutines to catch information which is intended for encryption? Or would running a custom rom (ie. cyanogenmod) while still using Google applications suffice to mitigate these attacks?
If you are running something based off of AOSP, you're running code that was touched by Google employees. Is your fear that Google is installing backdoors to help the CIA? If so, why are you afraid of that?
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#37This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#38According to the statement from WikiLeaks, government hackers can penetrate Android phones and collect “audio and message traffic before encryption is applied.” How is that possible? Isn't the data encrypted before it's sent over the wire?
The kernel is owned (or some part of the phone below the application level). The encryption only gets applied at the application level before the messages are sent down the wire. The interception happens prior to the encryption being applied . Think of it as a dongle on the wire between your keyboard and the computer. It doens't matter if the computer is secure - the message is intercepted prior to any encryption. Th…
ChromeOS and Android both implement FDE. There are some legitimate criticisms of (especially) the latter, voiced by e.g. Matthew Green, but you're just speaking nonsense here.
There's very little value in per-app encryption on desktop OSes; it's security theater.
I shudder to think of what your "secure communications" app does. I hope you're a good lawyer. ;)
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#39This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.
The encryption is not broken, it's bypassed. The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless.
So the word "bypass" is correct.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#40Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.
I would like your take on a more specific question: Do you think that Google applications (GMail, Search, Translate, Maps, etc) themselves can get access to the necessary kernel subroutines to catch information which is intended for encryption? Or would running a custom rom (ie. cyanogenmod) while still using Google applications suffice to mitigate these attacks?