Live data from Hacker News

WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

nytimes.com

1–10 of 250 posts

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#2

  According to the statement from WikiLeaks, government 
  hackers can penetrate Android phones and collect
  “audio and message traffic before encryption is applied.”
How is that possible? Isn't the data encrypted before it's sent over the wire?

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#4

According to the statement from WikiLeaks, government hackers can penetrate Android phones and collect “audio and message traffic before encryption is applied.” How is that possible? Isn't the data encrypted before it's sent over the wire?

Malware running on a phone can do anything it wants, take screenshots, record messages/typing, etc. Unfortunately, the article is misleading by claiming encryption was bypassed.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#5

According to the statement from WikiLeaks, government hackers can penetrate Android phones and collect “audio and message traffic before encryption is applied.” How is that possible? Isn't the data encrypted before it's sent over the wire?

Thats the thing, they capture the data before its sent over the wire, as you type it or speak it. you ->capture->app->encrypt

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#6

According to the statement from WikiLeaks, government hackers can penetrate Android phones and collect “audio and message traffic before encryption is applied.” How is that possible? Isn't the data encrypted before it's sent over the wire?

The kernel is owned (or some part of the phone below the application level). The encryption only gets applied at the application level before the messages are sent down the wire.

The interception happens prior to the encryption being applied. Think of it as a dongle on the wire between your keyboard and the computer. It doens't matter if the computer is secure - the message is intercepted prior to any encryption.

This is, what I am assuming, has happened here.

Edit: lots of stuff deleted for very valid criticism, as below.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#7
This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#8
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

edit: apparently NYT had a different headline and changed it... ignore this post

The current title [0] is wrong, but NYTimes is relatively clear:

> Among other disclosures that, if confirmed, would rock the technology world, the WikiLeaks release said that the C.I.A. and allied intelligence services had managed to bypass encryption on popular phone and messaging services such as Signal, WhatsApp and Telegram. According to the statement from WikiLeaks, government hackers can penetrate Android phones and collect “audio and message traffic before encryption is applied.”

It depends on how you define "bypass". In my opinion, accessing data before encryption is a form of bypassing... but it doesn't necessarily mean they can decrypt an already encrypted signal.

[0] "WikiLeaks: CIA managed to bypass encryption on popular services Signal, WhatsApp " as of this writing

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#9

Edit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.

> Please be aware that the Chrome browser does not offer a secure local storage protocol for its developers ... Compare this to Safari, which offers secure local storage at OS level security

But this is just as secure as full disk encryption of the device right?

Re: WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents

#10
post #8
post #7

This headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.

edit: apparently NYT had a different headline and changed it... ignore this post The current title [0] is wrong, but NYTimes is relatively clear: > Among other disclosures that, if confirmed, would rock the technology world, the WikiLeaks release said that the C.I.A. and allied intelligence services had managed to bypass encryption on popular phone and messaging services such as Signal, WhatsApp and Telegram. Accordi…

They changed the headline: https://twitter.com/nytimes/status/839161021369573378

edit: A new tweet referencing the article: "WikiLeaks release said CIA managed to bypass encryption in mobile apps by compromising the entire phone"

Post reply on HN