This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.
No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.
WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
51–60 of 250 posts
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#52This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.
Furthermore, from the point of view of the end-user, the important point is that WhatsApp and Signal are not necessarily secure to use. The exact nature of the security hole is not as important for the vast majority of users.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#53Earlier quoted context omitted.
No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.
You are 100 percent correct. Though I think the headline is a bit clickbaity but have to agree, it is accurate.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#54Earlier quoted context omitted.
Wait, what? If you are running something based off of AOSP, you're running code that was touched by Google employees. Is your fear that Google is installing backdoors to help the CIA? If so, why are you afraid of that?
Right, so in the scenario I mentioned, an update to a Google application would give this application more access to the kernel (through some backdoor) and enable it to intercept the communication of other apps. I'm asking whether this is possible or not - assuming the kernel itself cannot be modified. If that's the case then parts of the android kernel or the way android handles access to microphones, etc. might need…
Is that your concern? And if so, why are you concerned specifically about Google apps? Any malicious app can exploit a local EOP.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#55Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#56This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.
NYT is pivoting to a model that brings it more clicks.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#57This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.
"sidestep" would probably have been a better word choice than "bypass" only because of the connotation of these words... the average person isn't going to parse these words however, sooo... ?
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#58This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.
What's wrong with it? They were able to bypass the encryption. They got the data without it being encrypted. How is that not bypassing encryption? Furthermore, from the point of view of the end-user, the important point is that WhatsApp and Signal are not necessarily secure to use. The exact nature of the security hole is not as important for the vast majority of users.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#59Earlier quoted context omitted.
No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.
If the app and service were not involved the only reason to mention them is to create doubt they are secure.
If I as a user, believe that a sequence of actions, from my keystrokes to voice input, which I perceive to be a direct interaction with a secure app are in fact insecure, then is the app really secure?
I guess that's the question being posed here
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#60According to the statement from WikiLeaks, government hackers can penetrate Android phones and collect “audio and message traffic before encryption is applied.” How is that possible? Isn't the data encrypted before it's sent over the wire?
Malware running on a phone can do anything it wants, take screenshots, record messages/typing, etc. Unfortunately, the article is misleading by claiming encryption was bypassed.