WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
61–70 of 250 posts
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#62This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.
edit: apparently NYT had a different headline and changed it... ignore this post The current title [0] is wrong, but NYTimes is relatively clear: > Among other disclosures that, if confirmed, would rock the technology world, the WikiLeaks release said that the C.I.A. and allied intelligence services had managed to bypass encryption on popular phone and messaging services such as Signal, WhatsApp and Telegram. Accordi…
I think a lot of people in this thread are hating on NYTimes today for this headline because of the inaccurate WhatsApp encryption news stories of recent.
I could see myself being bothered if they had written that the encryption was "broken" or "cracked" as if you destroyed the boulder in your path. Bypass seems fine. Hacker News doesn't normally use bypass as a synonym for break, but for some reason today it i to the commentators
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#63Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.
> Compare the security of Android - which we now know to be 'owned' by the US Government To what are you referring to here, precisely? Since AOSP is open source, is there a specific line of code that you can point to that contains (or is emblematic of) this insecurity? Your article doesn't seem to say.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#64Earlier quoted context omitted.
Right, so in the scenario I mentioned, an update to a Google application would give this application more access to the kernel (through some backdoor) and enable it to intercept the communication of other apps. I'm asking whether this is possible or not - assuming the kernel itself cannot be modified. If that's the case then parts of the android kernel or the way android handles access to microphones, etc. might need…
The Android security model doesn't work that way. Non-system applications can't access the kernel, minus a local EOP or something like that. Is that your concern? And if so, why are you concerned specifically about Google apps? Any malicious app can exploit a local EOP.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#65Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#66According to the statement from WikiLeaks, government hackers can penetrate Android phones and collect “audio and message traffic before encryption is applied.” How is that possible? Isn't the data encrypted before it's sent over the wire?
The kernel is owned (or some part of the phone below the application level). The encryption only gets applied at the application level before the messages are sent down the wire. The interception happens prior to the encryption being applied . Think of it as a dongle on the wire between your keyboard and the computer. It doens't matter if the computer is secure - the message is intercepted prior to any encryption. Th…
Of course, this is a bit of a balancing act, because many disabled people legitimately benefit from the accessibility services, but they are like a huge vacuum from which displayed and entered textual data from your application can be sucked out.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#67This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.
Unfortunately, this is a line that Wikileaks themselves are running with: https://twitter.com/wikileaks/status/839120909625606152
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#68Earlier quoted context omitted.
No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.
If the app and service were not involved the only reason to mention them is to create doubt they are secure.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#69Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.
You want to distinguish between:
- remote takeover (like stagefright vuln)
- ability to take control of the device from within an app sandbox
- ability to unlock a device in your physical possession (FBI was able to do this on prev V of ios)
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#70Nice passive voice there, NYT.