Live data from Hacker News

WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

nytimes.com

81–90 of 250 posts

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#81
post #46

Earlier quoted context omitted.

> Compare the security of Android - which we now know to be 'owned' by the US Government To what are you referring to here, precisely? Since AOSP is open source, is there a specific line of code that you can point to that contains (or is emblematic of) this insecurity? Your article doesn't seem to say.

The CIA tools to own it were just leaked. You are commenting on the thread talking about those tools and the leak announcement.

As far as I can tell, my question ("which line of code is broken?") is also not answered either in the NYT piece or the wikileaks release. If I'm wrong, do you have a link?

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#82
post #38

Earlier quoted context omitted.

The kernel is owned (or some part of the phone below the application level). The encryption only gets applied at the application level before the messages are sent down the wire. The interception happens prior to the encryption being applied . Think of it as a dongle on the wire between your keyboard and the computer. It doens't matter if the computer is secure - the message is intercepted prior to any encryption. Th…

> Given Google's stance of not encrypting local storage in any way that I am aware of, this is fundamentally unsurprising. I have long been saying that Android is insecure and that storing passwords in Chrome is dangerous. ChromeOS and Android both implement FDE. There are some legitimate criticisms of (especially) the latter, voiced by e.g. Matthew Green, but you're just speaking nonsense here. There's very little v…

I am not talking about ChromeOS - I am talking about the Chrome browser. Localstorage, last I checked, which was recently, is plaintext.

> ChromeOS and Android both implement FDE

Which is irrelevant if the runtime is compromised, which appears to be the case.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#84

Earlier quoted context omitted.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

If the app and service were not involved the only reason to mention them is to create doubt they are secure.

The OS these services run on isn't secure, so wouldn't these services by definition not be secure?

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#85

Earlier quoted context omitted.

If the app and service were not involved the only reason to mention them is to create doubt they are secure.

"The strongest chain will break at it's weakest point". If I as a user, believe that a sequence of actions, from my keystrokes to voice input, which I perceive to be a direct interaction with a secure app are in fact insecure, then is the app really secure? I guess that's the question being posed here

There is a balance -- one is reminded of the constant "data charged may apply" footnote to so many free services. The same goes here: you really shouldn't tout your impenetrable security without also informing users that things external to the service may undermine its utility.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#86
post #47

Earlier quoted context omitted.

No, it's not. The encryption is not broken, it's bypassed . The data go to an unintended third party, even when the encryption is legit, rendering the encryption useless. So the word "bypass" is correct.

You are 100 percent correct. Though I think the headline is a bit clickbaity but have to agree, it is accurate.

Accurate, but dangerously misleading.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#87
post #21
post #16

Earlier quoted context omitted.

Agreed 100% - but methinks NYT (and others) still look to them for technical guidance on some matters - however misguided that might be.

The NYT has a _huge_ list of experts to contact for stories like this. They chose not to, in the interests of getting a salacious lede printed quickly.

Well I think they put out the article first and get experts to correct the finer points later. I don't agree this is the best tactic, but reporting first is important.

They have changed the title. Currently: "WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents"

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#88

Earlier quoted context omitted.

"The strongest chain will break at it's weakest point". If I as a user, believe that a sequence of actions, from my keystrokes to voice input, which I perceive to be a direct interaction with a secure app are in fact insecure, then is the app really secure? I guess that's the question being posed here

Also make sure no one is looking over your shoulder or listening nearby. "Signal encryption bypasssed by new look over shoulder attack."

I think it's a little different when the person "looking over your shoulder" is omnipotent.
Post reply on HN