Live data from Hacker News

WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

nytimes.com

71–80 of 250 posts

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#72
post #54
post #49

Earlier quoted context omitted.

Right, so in the scenario I mentioned, an update to a Google application would give this application more access to the kernel (through some backdoor) and enable it to intercept the communication of other apps. I'm asking whether this is possible or not - assuming the kernel itself cannot be modified. If that's the case then parts of the android kernel or the way android handles access to microphones, etc. might need…

The Android security model doesn't work that way. Non-system applications can't access the kernel, minus a local EOP or something like that. Is that your concern? And if so, why are you concerned specifically about Google apps? Any malicious app can exploit a local EOP.

Google Apps are typically installed as system apps. Play Store is obvious, since it needs to be able to install/update applications without prompting. The need for other apps (e.g. Gmail) to need system-level permissions is less obvious, but most of them fail to run if you just sideload it without the permissions.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#73
post #52

Earlier quoted context omitted.

What's wrong with it? They were able to bypass the encryption. They got the data without it being encrypted. How is that not bypassing encryption? Furthermore, from the point of view of the end-user, the important point is that WhatsApp and Signal are not necessarily secure to use. The exact nature of the security hole is not as important for the vast majority of users.

The phone itself may not be secure. Maybe they should include gmail, schwab, camera, microphone, amazon and every other thing in their description. Literally this is FUD.

These are the most relevant apps to use, it indicates that even when using security apps there is a problem. The message is "WhatsApp is not safe", its not relevant to most people why.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#74

Earlier quoted context omitted.

If the app and service were not involved the only reason to mention them is to create doubt they are secure.

"The strongest chain will break at it's weakest point". If I as a user, believe that a sequence of actions, from my keystrokes to voice input, which I perceive to be a direct interaction with a secure app are in fact insecure, then is the app really secure? I guess that's the question being posed here

Also make sure no one is looking over your shoulder or listening nearby. "Signal encryption bypasssed by new look over shoulder attack."

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#75
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

This is a dangerous headline because it implies that Signal was broken, which could lead to people moving to LESS SECURE SERVICES because they think the more secure one is broken. When in reality is the phone and OS.

They have similar end result for the phone in question, but headlines like this can lead to people being less secure on the whole.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#76
post #35
post #19

To me this is much more worrying: > As of October 2014 the CIA was also looking at infecting the vehicle control systems used by modern cars and trucks. The purpose of such control is not specified, but it would permit the CIA to engage in nearly undetectable assassinations. https://wikileaks.org/ciav7p1/ Given the fact that car makers don't even have "PC age" security in their cars, things are looking pretty bad for…

Makes the conspiracy theories regarding journalist Michael Hastings' death in 2013 seem more plausible. [1] Former U.S. National Coordinator for Security, Infrastructure Protection, and Counter-terrorism Richard A. Clarke said that what is known about the crash is "consistent with a car cyber attack". He was quoted as saying "There is reason to believe that intelligence agencies for major powers — including the Unite…

His brother and family don't believe the conspiracy theories. If there was any evidence, I don't think they'd be scared to say so in such an emotional state.

Also in the police report, I believe his brother said he had been using DMT and he tested positive for what was likely Adderall. He was in a unique state to truly be paranoid and throwing psychedelics in the mix could cause one to try to cope in ways that challenge reality.

Of course, this also would be the perfect time to stage a murder and it's not improbable that someone did discuss killing him. Also DMT only last 5-10 minutes, he certainly wasn't driving while doing it and if anything, it can give you a sense of peace and acceptance to the craziness of life.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#77

Mention "Signal" in any article and you'll have @tptacek running here to defend it with any costs.

Signal doesn't even need defending here. The article claims that the CIA has compromised the Android device itself. They are intercepting communications before/after it's decrypted on the device. Signal can help make sure you're transmitting information encrypted over the wire, but it can't really help you if your device is compromised.

Agreed, signal on iOS->iOS still seems unaffected.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#78
post #46

Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.

> Compare the security of Android - which we now know to be 'owned' by the US Government To what are you referring to here, precisely? Since AOSP is open source, is there a specific line of code that you can point to that contains (or is emblematic of) this insecurity? Your article doesn't seem to say.

> Here is my take as an information lawyer and (slightly-higher than script-kiddy-level) web developer

as a "(slightly-higher than script-kiddy-level) web developer" I'm going to guess that he doesn't actually know very much about AOSP, the Linux kernel, or indeed GNU/Linux security in general. So his emphatic statement "Compare the security of Android - which we now know to be 'owned' by the US Government" is pretty much worthless as he's very clearly speculating about things that he doesn't understand.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#79
post #52

Earlier quoted context omitted.

What's wrong with it? They were able to bypass the encryption. They got the data without it being encrypted. How is that not bypassing encryption? Furthermore, from the point of view of the end-user, the important point is that WhatsApp and Signal are not necessarily secure to use. The exact nature of the security hole is not as important for the vast majority of users.

The phone itself may not be secure. Maybe they should include gmail, schwab, camera, microphone, amazon and every other thing in their description. Literally this is FUD.

And it's a rare case where FUD is absolutely applicable:

Fear that using a "secure" messaging app on your rooted phone will expose you to consequences.

Uncertainty that your communications are secure when using your phone with the "secure" messaging app.

Doubt that using the "secure" messaging app is secure.

yes, it's FUD.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#80
post #53
post #47

Earlier quoted context omitted.

You are 100 percent correct. Though I think the headline is a bit clickbaity but have to agree, it is accurate.

I've been thinking a lot about this as it relates to the "fake news" trend. Journalists have been using real information to lead people to wrong conclusions. Now we are very concerned about political sites using false information to lead people to wrong conclusions. Fake facts are bad but using facts to mislead people does damage to people's trust as well.

If they emphasized that no app is secure if the phone itself is compromised I wouldn't hae a problem with it. By calling out specific apps it could cause someone to switch to a less secure alternative not mentioned.
Post reply on HN