Live data from Hacker News

The CIA Campaign to Steal Apple's Secrets

firstlook.org

41–50 of 138 posts

Re: The CIA Campaign to Steal Apple's Secrets

#41
Every time I read about a private company being targeted, I remember how simply state-level spies have been compromised. Hanssen[1], for instance, betrayed the CIA over 22 years, for just $1.4M. The info leaked included info on other agents, at least one who was executed.

Or [2], Walker gave crypto info to decrypt Navy messages. For a few grand a month. There's plenty more listed even on Wikipedia. The amounts involved seem... not that high.

Now, sure, Apple almost certainly has higher security. (Quote from the above spy: "KMart has better security than the Navy.")

But with state level resources, do we think employees can be flipped? Or, why is the NSA not getting to grads early on, helping their career, while having them really be agents all along?

I'm on my phone and can't find the reference now, but there was a young physicist that leaked into on atomic weapons purely because he felt the US shouldn't have a monopoly on the capability. The chance that some bright, highly-sought, employee feeling that the US should have spy capabilities is approximately 1.

Is every remotely sensitive employee routinely monitored? Their families? They never get into " life threatening " scenarios? Or embarrassing scenarios that they might feel is the end? (For some, that's as simple as getting a mistress pregnant, and not being able to bear others knowing.)

Just seems like the human employees have got to be compromisable in one form or another, given the resources of the NSA and CIA.

1: http://en.m.wikipedia.org/wiki/Robert_Hanssen 2: http://en.wikipedia.org/wiki/John_Anthony_Walker

Re: The CIA Campaign to Steal Apple's Secrets

#42
post #29
post #15

How much longer can this continue? We have American agencies attacking American companies "because terrorism". It's been 13 years since our trauma, maybe now's the time to remove the razor blade from our wrists, look ourselves in the mirror and just carry on. Bad stuff is always going to be in our future — stuff that will increasingly appear preventable between the Internet and a lot of hindsight — but our current so…

Unofficially, politicians has surrendered the "because terrorism" excuse for a while now, as they simply want access to everyones private information in order to see where the problem are going to be. Having the data helps plan and run successful elections, makes it easier to plan ahead, and gives them power over any department which doesn't has similar access. Imagine being in a political party while private intelli…

I don't think they want that. They take this course because "this was preventable!" is very politically disruptive. None of them want to be the guy who voted against mandatory data retention only to play host to an attack on home soil months later. It's sad, but that's the reality.

Re: The CIA Campaign to Steal Apple's Secrets

#43
post #29
post #15

How much longer can this continue? We have American agencies attacking American companies "because terrorism". It's been 13 years since our trauma, maybe now's the time to remove the razor blade from our wrists, look ourselves in the mirror and just carry on. Bad stuff is always going to be in our future — stuff that will increasingly appear preventable between the Internet and a lot of hindsight — but our current so…

Unofficially, politicians has surrendered the "because terrorism" excuse for a while now, as they simply want access to everyones private information in order to see where the problem are going to be. Having the data helps plan and run successful elections, makes it easier to plan ahead, and gives them power over any department which doesn't has similar access. Imagine being in a political party while private intelli…

You effectively had that during the latter Hoover years with the FBI. That the headquarters is still named after him is an indictment of the US approach to political corruption.

Re: The CIA Campaign to Steal Apple's Secrets

#44
post #38

Earlier quoted context omitted.

I think the point of The Intercept releasing this Apple specific info (mostly, there's a bit about Microsoft being targeted as well) is to try to appeal to the large number of Apple customers. I'd love to see some of the other line items in the leaked CBJ document, as there are probably some other targeted attacks documented. Regarding Apple not capitulating, I'm giving them the benefit of the doubt, and assuming tha…

"No comment" from Cook would be an interesting standoff. If he were prosecuted for it, that would confirm something NSL-like. But would it be worth it to a CEO to go to jail for a few years for a principle?

That of course, depends on the strength of said CEO's principles.

This would be, of course, one of the hardest tests of professional principles you could imagine a CEO going through. I personally think Mr Cook would be a good candidate for passing this test, as he seems to have a track record for standing up for what he believes in.

I also have a feeling that the US government would think twice before taking on the Apple PR juggernaut head to head. It would be too closely matched for comfort. Apple probably have greater mind-share than any of the political parties.

As you say, it would be an interesting standoff!

Re: The CIA Campaign to Steal Apple's Secrets

#45
post #30

What strikes me after this revelation is how unique the United States is, because: (a) it has dozens of companies that create technology the rest of the world uses, and (b) it has a govt. that secretly works to undermine the technology developed by those companies. You're not going to hear about many foreign govt's actively hacking their country's software products, simply because they could easily/secretly armtwist…

Your example isn't a particular good one. Huawei has been accused of backdooring their products for the Chinese government on numerous occasions, including presentations at DEFCON exposing those backdoors. There are also numerous cases of backdoors in Chinese cell phones.

Re: The CIA Campaign to Steal Apple's Secrets

#46
post #45
post #30

What strikes me after this revelation is how unique the United States is, because: (a) it has dozens of companies that create technology the rest of the world uses, and (b) it has a govt. that secretly works to undermine the technology developed by those companies. You're not going to hear about many foreign govt's actively hacking their country's software products, simply because they could easily/secretly armtwist…

Your example isn't a particular good one. Huawei has been accused of backdooring their products for the Chinese government on numerous occasions, including presentations at DEFCON exposing those backdoors. There are also numerous cases of backdoors in Chinese cell phones.

But his point was that China's government doesn't attack the company to get those.

Re: The CIA Campaign to Steal Apple's Secrets

#47
Seriously. This isn't even bad. Go to DEFCON and you'll see a ton of people doing this crap. There is a reason a bunch of paranoid people (includes me) bought faraday cages for our phones. Everyone is trying to break in to the little black boxes we carry around with some of our most personal information.

They have ACTUALLY done bad crap. This is normal security research. There is no need to blow normal research and security work out of proportion. Xcode is signed, they can't just modify it and let it go. The OS X updater is also likely secure and maybe they just figured out how to trick their own computers to install a keylogger. Good, but it probably doesn't work that well. And it's fine! It's research!

Lets focus on the actual violations, not the tools. Exploits and social engineering doesn't compromise: people do. Focus on the people who broke the rules which make sure our country isn't manipulated in to an oligarchy.

Re: The CIA Campaign to Steal Apple's Secrets

#48
post #45

Earlier quoted context omitted.

Your example isn't a particular good one. Huawei has been accused of backdooring their products for the Chinese government on numerous occasions, including presentations at DEFCON exposing those backdoors. There are also numerous cases of backdoors in Chinese cell phones.

But his point was that China's government doesn't attack the company to get those.

How do we know how any putative arrangement of this type has come to be?

Re: The CIA Campaign to Steal Apple's Secrets

#49
post #47

Seriously. This isn't even bad. Go to DEFCON and you'll see a ton of people doing this crap. There is a reason a bunch of paranoid people (includes me) bought faraday cages for our phones. Everyone is trying to break in to the little black boxes we carry around with some of our most personal information. They have ACTUALLY done bad crap. This is normal security research. There is no need to blow normal research and s…

The difference is that when the intelligence community discovers a hole in US-produced software, they will keep it to themselves to exploit the computers of individuals around the world in various operations of dubious value and/or legality.

At DEFCON, exploits are publicized so that software vendors and algorithm developers are motivated to strengthen the security of what they produce so that the software that all of use is more effective against attackers.

Re: The CIA Campaign to Steal Apple's Secrets

#50

Every time I read about a private company being targeted, I remember how simply state-level spies have been compromised. Hanssen[1], for instance, betrayed the CIA over 22 years, for just $1.4M. The info leaked included info on other agents, at least one who was executed. Or [2], Walker gave crypto info to decrypt Navy messages. For a few grand a month. There's plenty more listed even on Wikipedia. The amounts involv…

> Or, why is the NSA not getting to grads early on, helping their career, while having them really be agents all along?

It would be naive to think that they (and other agencies around the world) aren't already doing this.

Post reply on HN