Live data from Hacker News

WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

nytimes.com

51–60 of 250 posts

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#51
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

If the app and service were not involved the only reason to mention them is to create doubt they are secure.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#52
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

What's wrong with it? They were able to bypass the encryption. They got the data without it being encrypted. How is that not bypassing encryption?

Furthermore, from the point of view of the end-user, the important point is that WhatsApp and Signal are not necessarily secure to use. The exact nature of the security hole is not as important for the vast majority of users.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#53
post #47

Earlier quoted context omitted.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

You are 100 percent correct. Though I think the headline is a bit clickbaity but have to agree, it is accurate.

I've been thinking a lot about this as it relates to the "fake news" trend. Journalists have been using real information to lead people to wrong conclusions. Now we are very concerned about political sites using false information to lead people to wrong conclusions. Fake facts are bad but using facts to mislead people does damage to people's trust as well.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#54
post #49
post #36

Earlier quoted context omitted.

Wait, what? If you are running something based off of AOSP, you're running code that was touched by Google employees. Is your fear that Google is installing backdoors to help the CIA? If so, why are you afraid of that?

Right, so in the scenario I mentioned, an update to a Google application would give this application more access to the kernel (through some backdoor) and enable it to intercept the communication of other apps. I'm asking whether this is possible or not - assuming the kernel itself cannot be modified. If that's the case then parts of the android kernel or the way android handles access to microphones, etc. might need…

The Android security model doesn't work that way. Non-system applications can't access the kernel, minus a local EOP or something like that.

Is that your concern? And if so, why are you concerned specifically about Google apps? Any malicious app can exploit a local EOP.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#55
You should consider the assumption that your security IS compromised at any given point in time (bypassed or whatever) then you could foresee and prevent some worst case scenarios which usually come from hubris nonetheless ("hey, our app is 100% secure and tested by the top security experts - not like other apps on the market").

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#56
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

NYT is pivoting to a model that brings it more clicks.

It is a disturbing trend lately for publishers to seemingly insert deliberate fallacies into their headlines just to get more people engaged, causing them to pop up on more social media timelines.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#57
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

"sidestep" would probably have been a better word choice than "bypass" only because of the connotation of these words... the average person isn't going to parse these words however, sooo... ?

Completely agree that "sidestep" would have been a much better choice. I think the title is technically correct but that doesn't mean much since context matters a lot. "Sidestep" is a lot more intuitive and, I do disagree with you here, I think the average person would get a better idea of what's happening if they read "sidestep" instead of "bypass"

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#58
post #52
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

What's wrong with it? They were able to bypass the encryption. They got the data without it being encrypted. How is that not bypassing encryption? Furthermore, from the point of view of the end-user, the important point is that WhatsApp and Signal are not necessarily secure to use. The exact nature of the security hole is not as important for the vast majority of users.

The phone itself may not be secure. Maybe they should include gmail, schwab, camera, microphone, amazon and every other thing in their description. Literally this is FUD.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#59

Earlier quoted context omitted.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

If the app and service were not involved the only reason to mention them is to create doubt they are secure.

"The strongest chain will break at it's weakest point".

If I as a user, believe that a sequence of actions, from my keystrokes to voice input, which I perceive to be a direct interaction with a secure app are in fact insecure, then is the app really secure?

I guess that's the question being posed here

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#60
post #4

According to the statement from WikiLeaks, government hackers can penetrate Android phones and collect “audio and message traffic before encryption is applied.” How is that possible? Isn't the data encrypted before it's sent over the wire?

Malware running on a phone can do anything it wants, take screenshots, record messages/typing, etc. Unfortunately, the article is misleading by claiming encryption was bypassed.

Bypass could be appropriate in the sense that it was "sidestepped", not "broken". I think it's a fine word but I don't think the average reader knows / cares about the difference.
Post reply on HN