Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

331–340 of 1001 posts

Re: CIA malware and hacking tools

#331

Earlier quoted context omitted.

> The US chemical weapons program is downright frightening. Was : they committed to destroying those weapons, and have been doing so for 24 years. They were 89.75% complete in 2012. The video you linked was from 1973. https://en.wikipedia.org/wiki/United_States_chemical_weapons...

Just like they committed to revealing exploits to the tech industry instead of hoarding them?

It sounds like you're just saying this without doing any kind of real comparison between the probably very different scenarios.

Re: CIA malware and hacking tools

#332
post #71
post #9

- Smart TV turned into listening devices with fake off mode? - Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc. - Dozens of O-day attacks again Andriod and iPhone. Pretty powerful stuff.

> Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc I wish I could say that I'm surprised but no... not surprised at all. Same for the IoT stuff.

Yep. We all knew it was happening but turn a blind eye.

And then one of these revelations are exposed and we all start wearing tin foil hats for a month or two.

Re: CIA malware and hacking tools

#333
post #226

Earlier quoted context omitted.

Obviously there's a difference between cyber and conventional weapons, but imagine if the same rationale were extended to physical munitions: "We can't drop this bomb on the enemy, it contains classified technology"

While the weapon too secret to use sounds very Dr Strangelove, there have been slightly similar things with real weapons. The one I remember is when radar-triggered proximity shells were invented at the end of WW2 they were only issued for use on ships, so that undetonated shells would fall into the sea, so couldn't be recovered and investigated by the enemy.

IIRC there was a claim that the shells with the proximity fuses were also used, likely by Patton's forces, in the Battle of the Bulge. Supposedly having the shells explode at a carefully determined distance above the ground made the shells especially effective against German ground troops.

IIRC the proximity fuses were developed at the Johns Hopkins University Applied Physics Laboratory (JHU/APL); that is the story I got when I worked there.

IIRC, the shells were also especially effective as anti-aircraft artillery.

Re: CIA malware and hacking tools

#334
Taking the chance to vent just a bit. These are the sort of things I have been telling people about but have been derided as paranoid and a conspiracy theorist. The Samsung TV was a great example of this, which I called would be more than just samsung sending voice data. Also, so many people have loved to respond to people talking about this with some variation of, "but you're not important, why would they bug you". It really makes me wonder how often those responses were sock puppets attempting to control and derail the narrative, but criticisms like that are so trite eand easily debated.

I have spent a lot of time since the Iraq war (USMC), trying to understand how we got entangled in such a fucking mess, and have continually come to the conclusion that the deep state, of which the CIA is a major part, has actively been working against what I consider the true interests of the United States.

While I agree we need an international intelligence collection unit, let's not forget that originally the CIA's mandate was just to almagamate intelligence from military intelligence units, not to go do shadow operations all over the globe. Truman even wrote an article about how that was not his intention after the JFK assassination, but the article only ran once and Dulles personally flew out to talk to him about a retraction. Ok, though, perhaps that ship has sailed, and ops are a permanent part of collection.

My issue then, is with the disparity between operational intention and what I consider true national interests. I understand a certain amount of realpolitik pragmatism is necessary in the function of nation states and diplomatic international affairs, but I think it has become realpolitik run amok with no anchor on core principles, creating blowback after blowback, to the point that such blowback no longer just seems like incompetence and seems like intentional malice.

Never forget where the CIA came from. It was formed as the OSS by Wall Street Bankers/Lawyers with help from the much older MI6! Those foundations have largely been maintained through their selection process (Yale skull and bones/wolf/scroll and key heavy) The main connection I have eeked out that I don't think most understand though is the relationship between the Wall Street group and The City of London/Vatican/Swiss Banking groups and their many associated secret society groups and orders of knighthood.

In the end, I have postulated that the corruption of the country has been top down, and deliberate. The CIA is a key node point in this corruption, and I question their loyalty to the constitution. Compartmentalization has been used and abused to the point that the mostly good worker bees doing the intel work don't understand the bigger picture plays at work here, and I think it is telling that the decryption passphrase was JFK talking about scattering them to a thousand winds.

There is plenty of evidence that The Company has been operating domestically, unconstitutionally, and against their mandate, for quite some time. I promise you these tools have been used domestically on American whistleblowers, dissidents, and general rabbelrousers considered enemies of the the company. This has been the danger I have been speaking about with the total surveillance state, because now between the company and the agency, all will take is a few turns of some keys and the totalitarian dystopia is fulling engaged, and if you think this was ever about national security I have a bridge to sell you in the pacific. Of course there will be those who claim releases like this are a detriment to national security, and what I claim is the fact that these tools have been used domestically for the purposes of the deep state is the real threat to national security. The agency and the company should be working to help us secure our systems, not NSL gagging tech companies to insert backdoors or give the source so they can do their own 0days, so don't fall for the inevitable cries of but this hurts us and is legitimate. I mean there is evidence they were even corrupting NIST committees! This kind of bullshit is not about national security. I can't believe how easily people accept unconstitutional moves as long as some offical or other claims national security (usually with no evidence). This is about the deep state maintaining power.

For us, the hackers and geeks of the world, they left us alone for a bit, after they lost the 90's cryptowars. It's back on though. This is the danger of tivoization, of proprietary licenses, of closed source code (including BSD licenses that allow such actions). We need to open source everything, start encrypting everything, and making it easier for the layman to use the tools.

Stop using windows and osx, even for gaming. Stop installing windows at your business. Start using HIDS like OSSEC. Start checking your logs. Start checking your checksums. Start hardening your systems and your kernel (grsec). Stop using stock android, and don't use IOS. Desoder microphones on systems. Build faraday cages. Get an SDR and do bug sweeps.

When the surveillance engine is turned on, FOSS hackers will be the only ones free.

Re: CIA malware and hacking tools

#335
post #109
post #5

Based on the overview alone (of course I can't read the entire report that fast!), this is exactly what I expect a spy agency would be doing -- if they were not then I would be disappointed. What exactly in the admittedly shortened list am I supposed to be upset about? It makes no distinction between US citizens and overseas parties. If these actions are being done domestically against US citizens, with no just cause…

I'm sorry but I didn't realize it was a requirement for spies to exist to have a free society.

Didn't you know, the best way to ensure the citizenry is informed, is to keep lots of secrets?!?

Re: CIA malware and hacking tools

#336

Is anyone actually surprised? Even military has USCYBERCOM. What do you think their type of 'weapons' are? My only surprise it that this has leaked.

I'm surprised so much of this work done by NSA is being duplicated by the CIA. Not just a waste of tax payer money but also an even larger risk of lacking oversight than NSA. We all knew NSA was doing this stuff and dug into their oversight mechanisms. But the CIA is a larger and better funded organization than the NSA, so the implications of this are as large as the Snowden stuff.

Not to mention that before Obama left office he made intel sharing between these agencies and domestic agencies even easier. So this can't easily be dismissed as 'not surprising that spy agencies are hacking foreign entities'.

This just provides further insight into how widespread these powerful tools are within the US government.

Whether it's surprising or not is not really the only relevant question.

Re: CIA malware and hacking tools

#337
post #66

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation. With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from. Th…

> that "Russians" hacked the election That's not the claim. In fact, multiple people have said that is not the claim. The claim is that the Russians influenced the election in favor of Trump by promoting propaganda against Clinton.

There's also an argument to be made that Hillary would not have been the nominee had the DNC played fair. The leaked emails show that they actively worked to suppress Bernie, who had huge rallies, similar to Trump.

Re: CIA malware and hacking tools

#338

Earlier quoted context omitted.

Unfortunately for this we aren't going to get some 1080p video of someone in a mask sneaking into the DNC server room, just the fact that the 17 agencies all agree based on what they've seen believe that to be the case. Unfortunately everyone these days think everything is a conspiracy or has to have HD recordings of something they think happened as public evidence or it is false, but that's not how the world really…

The thing is, "17 agencies agree" doesn't really mean anything, if the evidence that all 17 agencies are relying on is a single report from a private security company hired by the DNC, and not independent investigation. If all of those agencies had looked at the original evidence themselves, the story would be different.

But they aren't just relying on a single report from a private security company, where did you assume that?

Re: CIA malware and hacking tools

#339

Earlier quoted context omitted.

> So far we only know the DNC leaks were very likely Russian. We don't know that at all. There isn't a single piece of evidence for it anywhere.

Unfortunately for this we aren't going to get some 1080p video of someone in a mask sneaking into the DNC server room, just the fact that the 17 agencies all agree based on what they've seen believe that to be the case. Unfortunately everyone these days think everything is a conspiracy or has to have HD recordings of something they think happened as public evidence or it is false, but that's not how the world really…

>" just the fact that the 17 agencies all agree based on what they've seen believe that to be the case."

This simply isn't true. The whole "17 agencies" thing is a talking point that first came up in one of Hillary Clinton's debates and gets repeated without challenge.

The "17 agencies" didn't all independently make their own assesments about what happened and decided it was the Russians. Instead, James Clapper (at the time, the Director of National Intelligence) made the claim that the Russians were behind certain hacks. Clapper is the ultimate head of sixteen out of seventeen of the agencies.

The actual agencies involved include parts of the coast guard and the department of energy and other groups that seem REALLY unlikely to have conducted an in-depth, independent investigation into the hacking of a politician's emails.

Also, this is the same James Clapper who lied under oath to congress. Specifically, when asked “Does the NSA collect any type of data at all on millions or hundreds of millions of Americans?” He responded, “No, sir.” Wyden asked “It does not?” and Clapper said, “Not wittingly."

This is perjury and he should have been prosecuted for it. At a minimum, lying under oath makes it less likely that anything else he claims should be taken at face value.

Post reply on HN