Live data from Hacker News

WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

nytimes.com

41–50 of 250 posts

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#41

Mention "Signal" in any article and you'll have @tptacek running here to defend it with any costs.

Signal doesn't even need defending here.

The article claims that the CIA has compromised the Android device itself. They are intercepting communications before/after it's decrypted on the device.

Signal can help make sure you're transmitting information encrypted over the wire, but it can't really help you if your device is compromised.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#42
post #35
post #19

To me this is much more worrying: > As of October 2014 the CIA was also looking at infecting the vehicle control systems used by modern cars and trucks. The purpose of such control is not specified, but it would permit the CIA to engage in nearly undetectable assassinations. https://wikileaks.org/ciav7p1/ Given the fact that car makers don't even have "PC age" security in their cars, things are looking pretty bad for…

Makes the conspiracy theories regarding journalist Michael Hastings' death in 2013 seem more plausible. [1] Former U.S. National Coordinator for Security, Infrastructure Protection, and Counter-terrorism Richard A. Clarke said that what is known about the crash is "consistent with a car cyber attack". He was quoted as saying "There is reason to believe that intelligence agencies for major powers — including the Unite…

> Makes the conspiracy theories regarding journalist Michael Hastings' death in 2013 seem more plausible.

I never thought they seemed implausible.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#46

Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.

> Compare the security of Android - which we now know to be 'owned' by the US Government

To what are you referring to here, precisely?

Since AOSP is open source, is there a specific line of code that you can point to that contains (or is emblematic of) this insecurity?

Your article doesn't seem to say.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#47
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

You are 100 percent correct. Though I think the headline is a bit clickbaity but have to agree, it is accurate.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#48

Mention "Signal" in any article and you'll have @tptacek running here to defend it with any costs.

That's because so far he's been right. Every news outlet seems to want to report on a "signal hack" and will go to great lengths to twist words to make it sound like that happened.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#49
post #36
post #31

Earlier quoted context omitted.

I would like your take on a more specific question: Do you think that Google applications (GMail, Search, Translate, Maps, etc) themselves can get access to the necessary kernel subroutines to catch information which is intended for encryption? Or would running a custom rom (ie. cyanogenmod) while still using Google applications suffice to mitigate these attacks?

Wait, what? If you are running something based off of AOSP, you're running code that was touched by Google employees. Is your fear that Google is installing backdoors to help the CIA? If so, why are you afraid of that?

Right, so in the scenario I mentioned, an update to a Google application would give this application more access to the kernel (through some backdoor) and enable it to intercept the communication of other apps. I'm asking whether this is possible or not - assuming the kernel itself cannot be modified. If that's the case then parts of the android kernel or the way android handles access to microphones, etc. might need to be hardened in the future.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#50
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

The article should be emphasizing that they actively attack devices of targeted individuals, not leading with the particular consequence of this that Wikileaks mentioned in a tweet.
Post reply on HN