How is pen testing of iPhones stealing Apple's secrets? Does Apple know these holes are there and they're keeping them secret? I'll grant you that if the CIA broke into Apple and stole keys, that would stealing along with breaking and entering or the cybercrime equivalent. But that's not what the article says.
The CIA Campaign to Steal Apple's Secrets (2015)
71–80 of 118 posts
Re: The CIA Campaign to Steal Apple's Secrets (2015)
#72How is pen testing of iPhones stealing Apple's secrets? Does Apple know these holes are there and they're keeping them secret? I'll grant you that if the CIA broke into Apple and stole keys, that would stealing along with breaking and entering or the cybercrime equivalent. But that's not what the article says.
Yeah this article is a bit ridiculous. Pen testing is what security researchers do. It's a proverbial mountain out of a molehill. The Intercept longs for its Snowden glory days.
Re: The CIA Campaign to Steal Apple's Secrets (2015)
#73How is pen testing of iPhones stealing Apple's secrets? Does Apple know these holes are there and they're keeping them secret? I'll grant you that if the CIA broke into Apple and stole keys, that would stealing along with breaking and entering or the cybercrime equivalent. But that's not what the article says.
What about moles? Could the CIA hire someone, or many people, to attempt to get hired by Apple and spend years working their way into the higher echelons of the company?
Re: The CIA Campaign to Steal Apple's Secrets (2015)
#74Earlier quoted context omitted.
> WTF do you think they do all day? One would hope that they were trying to gain access to someone else's devices, as opposed to turning the guns towards their own citizens and economy. If a soldier showed up at my door and pointed their gun at me, my reaction wouldn't be "of course you're doing that, your job is to point guns."
> One would hope that they were trying to gain access to someone else's devices, as opposed to turning the guns towards their own citizens and economy. Apple devices are sold all over the world, so there's no way of gaining access to the enemy's devices without that method also being applicable to everyone else. Actually using them on everyone else is a different matter.
Which enemy?
Re: The CIA Campaign to Steal Apple's Secrets (2015)
#75Nothing in this article is surprising. I mean, honestly, if you don't think the CIA is actively trying to gain access to your devices, WTF do you think they do all day? I'd be more concerned if the intelligence agencies of the world WEREN'T doing this. It's their purpose. It's what we pay them for with our taxes. Of course we should also always root for tech companies to stay one step ahead. But infosec is an arms ra…
Considering that Apple is a US company, and that millions of US citizens use Apple products, US intelligence agencies should be securing these devices. Not compromising them. The US has such an overwhelming military advantage over North Korea or Russia that it doesn't have to gain a leg up in infosec. All it has to do is level the playing field by making sure that everyone's running as securely as possible. I'll rely…
>I'll rely on the one dozen Naval Carrier Strike Groups to keep me safe. Really doubt that reading Kim Jong Un's email is going to make a difference.
That's a weak strawman argument.
The fact that spying on foreign enemies now requires the capability to spy domestically is definitely a red flag. But saying we don't need infosec when that Naval Carrier Strike Group can be owned, rendered useless by a cyber attack is naive.
Moreover, rogue hacker groups from all across the world posess the power to covertly & remotely target critical infrastructure of virtually any nation. What good is a Naval Carrier Strike Group going to do against that?
Re: The CIA Campaign to Steal Apple's Secrets (2015)
#76Earlier quoted context omitted.
https://en.wikipedia.org/wiki/COINTELPRO > COINTELPRO (1956–1971) was a series of covert, and at times illegal,[1][2] projects conducted by the United States Federal Bureau of Investigation (FBI) aimed at surveilling, infiltrating, discrediting, and disrupting domestic political organizations. https://en.wikipedia.org/wiki/FBI%E2%80%93King_suicide_lette... > The letter does not specify precisely what action it is urg…
How about in the last 50 years
1. https://monthlyreview.org/2014/09/01/how-we-found-out-about-...
Re: The CIA Campaign to Steal Apple's Secrets (2015)
#77Nothing in this article is surprising. I mean, honestly, if you don't think the CIA is actively trying to gain access to your devices, WTF do you think they do all day? I'd be more concerned if the intelligence agencies of the world WEREN'T doing this. It's their purpose. It's what we pay them for with our taxes. Of course we should also always root for tech companies to stay one step ahead. But infosec is an arms ra…
The thing I'm 100% not okay with is when TLAs use social pressure, legal pressure or traditional espionage to insure there are exploits they can exploit - this has never ended well and is always a concession in security that increases our vulnerability to bad actors. I have a modicum of trust for TLAs in the traditional espionage realms, but they have entirely burned my opinion of them when it comes to tech at this point... The NSA compromising ECC `Dual_EC_DRBG` is just a level of stupidity that demonstrates a clear lack of responsibility to civilians.
Re: The CIA Campaign to Steal Apple's Secrets (2015)
#78Earlier quoted context omitted.
Considering that Apple is a US company, and that millions of US citizens use Apple products, US intelligence agencies should be securing these devices. Not compromising them. The US has such an overwhelming military advantage over North Korea or Russia that it doesn't have to gain a leg up in infosec. All it has to do is level the playing field by making sure that everyone's running as securely as possible. I'll rely…
> Considering that Apple is a US company, and that millions of US citizens use Apple products, US intelligence agencies should be securing these devices. Not compromising them. You're absolutely right! It's unquestionably the job of the US intelligence apparatus to help secure American interests. With that said, Apple is a multi-national company, with millions of units used by people of all nationalities. And a vast…
1: https://www.vadesecure.com/en/nsa-malware-malware-protection...
Re: The CIA Campaign to Steal Apple's Secrets (2015)
#79Earlier quoted context omitted.
> One would hope that they were trying to gain access to someone else's devices, as opposed to turning the guns towards their own citizens and economy. Apple devices are sold all over the world, so there's no way of gaining access to the enemy's devices without that method also being applicable to everyone else. Actually using them on everyone else is a different matter.
"the enemy's devices" Which enemy?
Regional rivals: North Korea and Iran
Authoritarian partners/allies: Turkey, Saudi Arabia, a bunch of other Middle Eastern countries
A bunch of countries flirting with authoritarianism: Brazil, Hungary, Poland, Israel
Re: The CIA Campaign to Steal Apple's Secrets (2015)
#80Earlier quoted context omitted.
> Considering that Apple is a US company, and that millions of US citizens use Apple products, US intelligence agencies should be securing these devices. Not compromising them. You're absolutely right! It's unquestionably the job of the US intelligence apparatus to help secure American interests. With that said, Apple is a multi-national company, with millions of units used by people of all nationalities. And a vast…
So for the sake of possibly needing to break into a non-US citizen's iPhone, they do research to create exploits that put EVERY US citizen who uses an iPhone at risk? And they really don't have a great track record of keeping these exploits safe [1] 1: https://www.vadesecure.com/en/nsa-malware-malware-protection...
With that in mind, do you think it would be wise for an intelligence agency to refuse to consider searching for exploitable holes in a platform that is known for a fact to occasionally used by adversaries? Bear in mind that, of course, there are plenty of other groups and agencies doing the same thing.
Do you think this choice would better serve to advance American interests? If so, why? Would the weaknesses the CIA could find cease to be if the CIA was not looking for them? Perhaps you imagine a scenario in which the CIA finds every exploit first, and in doing so causes them to get fixed rapidly. Would you be comfortable with an intelligence agency working hand-in-glove with a major American company selling supposedly-secure consumer goods? Would you trust such an arrangement to protect you?