Earlier quoted context omitted.
> Compare the security of Android - which we now know to be 'owned' by the US Government To what are you referring to here, precisely? Since AOSP is open source, is there a specific line of code that you can point to that contains (or is emblematic of) this insecurity? Your article doesn't seem to say.
The CIA tools to own it were just leaked. You are commenting on the thread talking about those tools and the leak announcement.
WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
81–90 of 250 posts
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#82Earlier quoted context omitted.
The kernel is owned (or some part of the phone below the application level). The encryption only gets applied at the application level before the messages are sent down the wire. The interception happens prior to the encryption being applied . Think of it as a dongle on the wire between your keyboard and the computer. It doens't matter if the computer is secure - the message is intercepted prior to any encryption. Th…
> Given Google's stance of not encrypting local storage in any way that I am aware of, this is fundamentally unsurprising. I have long been saying that Android is insecure and that storing passwords in Chrome is dangerous. ChromeOS and Android both implement FDE. There are some legitimate criticisms of (especially) the latter, voiced by e.g. Matthew Green, but you're just speaking nonsense here. There's very little v…
> ChromeOS and Android both implement FDE
Which is irrelevant if the runtime is compromised, which appears to be the case.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#83This is why we should not rely on encrypted apps running on top of some other platform. disclosure: working on an open source alternative for messaging
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#84Earlier quoted context omitted.
No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.
If the app and service were not involved the only reason to mention them is to create doubt they are secure.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#85Earlier quoted context omitted.
If the app and service were not involved the only reason to mention them is to create doubt they are secure.
"The strongest chain will break at it's weakest point". If I as a user, believe that a sequence of actions, from my keystrokes to voice input, which I perceive to be a direct interaction with a secure app are in fact insecure, then is the app really secure? I guess that's the question being posed here
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#86Earlier quoted context omitted.
No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.
You are 100 percent correct. Though I think the headline is a bit clickbaity but have to agree, it is accurate.
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#87Earlier quoted context omitted.
Agreed 100% - but methinks NYT (and others) still look to them for technical guidance on some matters - however misguided that might be.
The NYT has a _huge_ list of experts to contact for stories like this. They chose not to, in the interests of getting a salacious lede printed quickly.
They have changed the title. Currently: "WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents"
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#88Earlier quoted context omitted.
"The strongest chain will break at it's weakest point". If I as a user, believe that a sequence of actions, from my keystrokes to voice input, which I perceive to be a direct interaction with a secure app are in fact insecure, then is the app really secure? I guess that's the question being posed here
Also make sure no one is looking over your shoulder or listening nearby. "Signal encryption bypasssed by new look over shoulder attack."
Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#89Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
#90https://wikileaks.org/ciav7p1/cms/page_11629096.html
As you can see they pretty much all reference very old versions of Android (v4) and Chrome.