Live data from Hacker News

CIA malware and hacking tools

wikileaks.org

451–460 of 1001 posts

Re: CIA malware and hacking tools

#452
post #435
post #412

Earlier quoted context omitted.

Wikileaks has pretty good track record. I believe so far every single one of the leaks have turned out true, or no one has challenged their authenticity.

Which is it? Your phrasing implies those are the same thing. They're not.

They're not the same, but they're pretty well indistinguishable for anyone who isn't omniscient.

Re: CIA malware and hacking tools

#453
post #226

Earlier quoted context omitted.

Obviously there's a difference between cyber and conventional weapons, but imagine if the same rationale were extended to physical munitions: "We can't drop this bomb on the enemy, it contains classified technology"

While the weapon too secret to use sounds very Dr Strangelove, there have been slightly similar things with real weapons. The one I remember is when radar-triggered proximity shells were invented at the end of WW2 they were only issued for use on ships, so that undetonated shells would fall into the sea, so couldn't be recovered and investigated by the enemy.

Another case, also WWII:

"[U]naware of the opposing air force's knowledge of the chaff concept, planners felt that using it was even more dangerous than not, since, as soon as it was used, the enemy could easily duplicate it and use it against them... for over a year the curious situation arose where both sides of the conflict knew how to use chaff to jam the other side's radar, but refrained from doing so fearing that if they did so the other side would 'learn the trick' and use it against themselves."

https://en.wikipedia.org/wiki/Chaff_(countermeasure)#Second_...

Re: CIA malware and hacking tools

#455

Earlier quoted context omitted.

That's why the CIA doesn't operate inside of the United States. It is beholden to the laws of the United States and tasked with protecting and upholding the Constitution. But there are no stipulations against doing bad things in non-US lands.

> That's why the CIA doesn't operate inside of the United States. False [1] [2] [3] [4] [5] [6] [1] https://en.wikipedia.org/wiki/Project_ARTICHOKE [2] https://en.wikipedia.org/wiki/Crusade_for_Freedom [3] https://en.wikipedia.org/wiki/Project_MKUltra [4] https://en.wikipedia.org/wiki/Operation_Mockingbird [5] https://en.wikipedia.org/wiki/Project_SHAMROCK [6] https://en.wikipedia.org/wiki/HTLINGUAL

Why the CIA isn't supposed to operate inside the United States.

Re: CIA malware and hacking tools

#456

Has anyone with a clue actually gone over the code? If so, is there a description of how it works? Unless things like smart TV's are shipped with malware, or unless they reach out and ask for malware and install it themselves, wouldn't having all your devices behind a NAT box make all this stuff benign? Or am I too naive?

It seems to be a dump of a git "wiki" that is shared between a bunch of devs within the agency.

The content mostly centers around typical wiki style documents where developers are chatting between each other and leaving useful snippets of code and discussing different attack vectors and approaches. It's organized into folders relating to different technologies, platforms and tools.

There isn't a "use me to gain root on an iPhone" program anywhere that I can see, although there are some hints that those things actually exist in the main git repo.

In general there seems to be a lot of information on performing pre-cursor work to get devices into a state where they can be compromised via firmware rewrites etc.

There is quite a lot of interesting information that I'm sure will be of use in hardening systems in years to come, so it isn't all bad news.

It reads as kind of a "Book of tips and tricks" mainly as well as the results of various attack attempts.

Linux seems very low on the list in priorities for attack development. I did see something about opening a side channel inside an SSH session, but it doesn't seem to be a focus.

"X capability that injects a pthread into an OpenSSH client process creating a surreptitious sub-channel to the remote computer."

Certainly looks like they are having a lot of fun attacking Windows boxes and Apple phones mainly, plus Android devices and a smattering of common routers and other gear.

They also seem to have a great sense of humor. Some of the comments are hilarious, as are their project code-names. I laughed at the code sample for a Windows keyboard logger using DirectInput. Does that thing really work? :-)

Re: CIA malware and hacking tools

#457
post #404

Earlier quoted context omitted.

The US chemical weapons program is downright frightening. Unlike these exploits which you can just leave in an office and never use (and which con subsequently go stale as people find and patch exploits), chemical weapons were stored in massive US facilities and many of them have started leaking over the years: https://www.youtube.com/watch?v=FjA0EQPeUGM

I did not watch you link, but many modern chemical weapons are binary compounds. Meaning the two compounds has to be mixed to get the final weapon. This makes leaking etc, not as big problem as leaking of actual chemical weapons... https://en.wikipedia.org/wiki/Binary_chemical_weapon

Once things start leaking you're a very small step away from them mixing accidentally.

Unless containment has been set up in such a way that this is a geographical impossibility (for instance, on two sides of the Rocky mountains to stop accidental mixing in groundwater).

Re: CIA malware and hacking tools

#458

Earlier quoted context omitted.

Just like they committed to revealing exploits to the tech industry instead of hoarding them?

> Just like they committed to revealing exploits to the tech industry instead of hoarding them? I think you're letting your cynicism get in the way of truth and understanding. The US has signed and ratified a treaty committing to destroy all chemical weapons and never produce them again [1], and it has built the infrastructure to do so [2] [3]. It's conspiracy-nut territory to think the US is simultaneously stockpili…

> It's conspiracy-nut territory

While I agree, it was also considered conspiracy-nut territory to have believed most of the stuff in this leak. Look at how the wider tech community treats people like McAffee and Stallman.

Re: CIA malware and hacking tools

#459

Taking the chance to vent just a bit. These are the sort of things I have been telling people about but have been derided as paranoid and a conspiracy theorist. The Samsung TV was a great example of this, which I called would be more than just samsung sending voice data. Also, so many people have loved to respond to people talking about this with some variation of, "but you're not important, why would they bug you".…

> The main connection I have eeked out that I don't think most understand though is the relationship between the Wall Street group and The City of London/Vatican/Swiss Banking groups and their many associated secret society groups and orders of knighthood. This is where you started to lose me. If you've eeked this out, surely you have something you can include to convince us? > I think it is telling that the decrypti…

The vast majority of our history was spent with substantial limits on the ability to collect, distribute, and access information on any one individual, let alone cross-compile information from multiple sources or for multiple individuals.

Scale and rates matter.

Re: CIA malware and hacking tools

#460

Earlier quoted context omitted.

Just like they committed to revealing exploits to the tech industry instead of hoarding them?

> Just like they committed to revealing exploits to the tech industry instead of hoarding them? I think you're letting your cynicism get in the way of truth and understanding. The US has signed and ratified a treaty committing to destroy all chemical weapons and never produce them again [1], and it has built the infrastructure to do so [2] [3]. It's conspiracy-nut territory to think the US is simultaneously stockpili…

Mass surveillance was conspiracy nut territory.

Wide spread market fixing, libor, gold, silver was conspiracy nut territory.

The US engaging in blscksites and systematic torture was conspiracy nut territory.

But criticizing your pro Government apologia only results in comments being banned and removed -- perhaps just more conspiracy nut territory?

Post reply on HN