Live data from Hacker News

CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

washingtonpost.com

71–80 of 106 posts

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#71

How does somebody exfiltrate 34 TERABYTES from a secure facility without getting noticed? To misquote Dr. Strangelove, "ze whole point of ze secret hack is lost if you don't keep it a secret." https://youtu.be/2yfXgu37iyI?t=205 Oh, maybe they have a firewall built on a RaspberryPi somebody ordered online. Seriously, WTF? This is as insecure as having contract sysadmins with root privilege spread all over the globe. A…

What are the tools to help orgs notice exfiltration?

Preventing any unauthorized USB devices or as cards is a basic one. Many defense contractors have USB disabled and/or the ports filled with glue.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#72

Earlier quoted context omitted.

It's my understanding that nothing truly concrete has been shown to the public?

There has been direct testimony from intelligence officials and thousands of pages of reports including very technical details. Do you want server logs, intercepts, confessions? All these provide nothing of value to the general public. When intelligence agencies share clear evidence a dictator gassed his own civilian population, no one cares or trolls ask for more evidence.

All of that was based on the opinion of a private organization. No intelligence official ever had possession of the server or was involved at any time.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#73
post #55

Earlier quoted context omitted.

The intelligence community's opinion that the DNC hack was done by Russia was based upon the single source of a private organization CrowdStrike. But given all the heavy hitting nation states regularly frame others, "Russia's fingerprints" can mean either they did it or they didn't, so it's functionally worthless.

That's completely untrue.

Shawn Henry said "We said that we had a high degree of confidence it was the Russian Government"

Sorry, but "high degree of confidence" is not proof, especially not from the organization that told us Iraq had WMDs with high degrees of confidence.

Additionally, at no point in time did they have access to the hardware.

Are you forgetting that this is the same collection of people responsible for being unable to secure their own hacking tools?

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#74

Earlier quoted context omitted.

It's my understanding that nothing truly concrete has been shown to the public?

There has been direct testimony from intelligence officials and thousands of pages of reports including very technical details. Do you want server logs, intercepts, confessions? All these provide nothing of value to the general public. When intelligence agencies share clear evidence a dictator gassed his own civilian population, no one cares or trolls ask for more evidence.

>When intelligence agencies share clear evidence a dictator gassed his own civilian population

Funnily enough, there's no clear evidence of this. According to OPCW leaked documents there's a higher probability the gas was manually placed at the site. [1] Which of course, calls into question the Syrian government's involvement, especially given earlier intelligence showing ISIS had possession of such chemical weapons.

[1] https://www.independent.co.uk/voices/douma-syria-opcw-chemic...

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#75

I find it ironic that the CIA didn't bother to have it's systems secured/verified by the NSA. I'm sure the CIA thought that they were good enough, coming from an organization that was infiltrated from its inception, their hubris isn't surprising.

My limited understanding is that these orgs compete with each other for budget allocation and would never allow access into each others systems, but I could be wrong.

This is true to an extent. The other half of the equation is just a cultural thing with the CIA. There’s a lot of intelligence groups in the US, but the CIA considers themselves the top tier. They’ve been around the longest and even other agencies recognize them as kind of the eldest when it comes to intel.

The NSA does some seriously insane stuff, but I don’t think even they take themselves as seriously as the CIA does.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#76

How does somebody exfiltrate 34 TERABYTES from a secure facility without getting noticed? To misquote Dr. Strangelove, "ze whole point of ze secret hack is lost if you don't keep it a secret." https://youtu.be/2yfXgu37iyI?t=205 Oh, maybe they have a firewall built on a RaspberryPi somebody ordered online. Seriously, WTF? This is as insecure as having contract sysadmins with root privilege spread all over the globe. A…

Absolutely. So now let's consider the source, the role that three letter acronym fulfills, and the strategies and tactics it's know to use. Put another way: perhaps it's not an accident? And perhaps some of what was leaked was a decoy? Yes, keeping secrets is difficult. All the more reason to take advantage of that.

>So now let's consider the source, the role that three letter acronym fulfills, and the strategies and tactics it's know to use.

Like leaving data of their secret assets available on Google searches, leading to hundreds of deaths? And firing the employee who warned then of the problem seven years before it was exploited?

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#77
post #65
post #56

Earlier quoted context omitted.

I've been in infosec since the 90's. A lot of times I think this is on us. As much as I respect the technical acumen and creativity of my colleagues in the industry, I don't think we broadly understand risk that well and as a consequence we do a pretty bad job of communicating it. We tend to peg the panic meter with multiplied likelihoods and catastrophized impacts of possible scenarios while directly causing revenue…

Agreed, It doesn’t seem appropriate for info-sec people to be making decisions about what which risks to mitigate, ignore, etc. They should provide input into that process though. We struggled to even get the CIO and CEO to acknowledge and discuss info-sec risk and make decisions regarding what to do about that risk.

Oh yeah, if they aren’t going to even show up to the conversation then it’s time to yank the ripcord.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#78
post #36

A hacking unit is offensive. It's like saying, "america's elite nuclear force failed to stop an ICBM". Blowing up things (attack) is a different ballgame than defenfing things. Think of it this way if you are a hacker devoting 40hrs a week carefully studying and planning to infiltrate a network, you will succeed. APT actors have entire groups of teams dedicated to infiltrating one target at a time. Getting in is feas…

You screw up at offense if your weapons are destroyed or disabled. In case of exploits, this is exactly what happens when they leak out. Your ability to attack in this case is equivalent to keep your arms useful.

This isn't what happened, their weapons were exposed and adversaries now know about them. Their effectiveness is still greater than 0. Digital weapons are copied not stolen, this is the equivalent of russians sendig spies to the US to steal nuke secrerts and the they developed their own nuke. The fact that the US has nukes has nothing to do with their ability to keep secrets and keep out spies. Furthetmore, russians having nukes did not make american nukes ineffective, they simply lost an advantage and to be frank it was only a mattet of time. Just like with the cia hack. And it will happen again!

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#79
post #50

The article tries to make it sound like the failure is a lack of prioritization and if they just focused correctly the problem could have been avoided, but I do not see why anybody would assume they would be able to protect their systems even if they tried. How well protected do you think cyber-weapons designed to surveil countries, disable infrastructure, and destabilize governments should be? How capable and well-f…

Yeah I guess some people really misunderstood how hard making secure system is. Of course you can't claim to kill economy or too many people with it, but really you don't even need that kind of funding to break into most networks.

I guess it's safe to say that even with $1M of funding and small team of dedicated security researchers coupled with right people for social engineering you can break into any network. Everyone can be fooled and humans are always the weakest spot. Especially now when information about everyone is publicly available on social networks so you can gather all information you need remotely.

And when it's come to hacking into networks of company with no dedicated budget for cybersecurity cost of attack would be one or two orders of magnitude lower. Some self-organized groups of hobbyists prove you can even do it with no funding at all.

Re: CIA hacking unit failed to protect its systems, allowing Vault 7 disclosure

#80
post #36

A hacking unit is offensive. It's like saying, "america's elite nuclear force failed to stop an ICBM". Blowing up things (attack) is a different ballgame than defenfing things. Think of it this way if you are a hacker devoting 40hrs a week carefully studying and planning to infiltrate a network, you will succeed. APT actors have entire groups of teams dedicated to infiltrating one target at a time. Getting in is feas…

It's more analogous to saying "the defense contractors for a new stealth plane failed to protect the designs and prototypes, so the enemy now has all of the detailed info they need to build countermeasures against this stealth technology". Securing the plans for stealth is a key requirement of the stealth continuing to work. Also, I'm sure those members of "the hacking team" weren't allowed to discuss their work with…

No, that's not what the analogy at hand. The designers of a stealth plane are just that. The right analogy would be if the navy seals designed a secret weapon, someone infiltrated their ranks and exfiltrated the weapons plans. Navy seals are not immune to moles. No org is.

Your implication that this was due to lack of proper security hygeine is unfounded. Security hygeine reduces risk it does not eliminate it. Risk is proportional to threat and attack surface, for an org like the CIA they have not-so-small attack surface and the whole world as their threat, so reduction in risk by means of common security controls and hygeine will not reduce risk from the most persistent and resourceful attackers.analogy to your reasoning would be "Google has an army of devs and security pros, so Chrome should never have a remote code execution vuln" ,no, as much as they may have money and talent, modern software is too complex for those resources to eliminate all bugs. Perspective is important.

Post reply on HN