4 ms·
I fail to understand how this is going to shut down the CIA, who is: 1. Not tasked with collection, that would be the NSA. Detailed in the article is a meeti
by bazillion 11y ago
I fail to understand how this is going to shut down the CIA, who is:
1. Not tasked with collection, that would be the NSA. Detailed in the article is a meeting that the CIA apparently hosted detailing possible exploits for Apple's phone systems. What does Debian have anything to do with exploits on Apple's phone systems? The article is talking about an operating system-level change and the presentation at the event referenced was a "compromised" Xcode that could sneak backdoors into an iPhone app.
2. Primarily involved in HUMINT (Human Intelligence) which consists of face to face interaction. The article says that the CIA is trying to expand into cyber warfare. That's because the CIA's cyber capabilities are laughable right now -- what do you think they were in 2012 when the meeting took place as detailed in the article?
3. The documents referenced do not even detail the level of success that the research has had on breaking Apple's encryption and security processes. News flash, Apple's phone is pretty much the most freaking rock solid phone on the market security-wise. It would be the holy grail for an intelligence agency to crack this thing, but instead government, state, and city agencies have to literally take physical phones to Apple and ask for them to unlock the data on them if it's crucial to their investigations.
I think the article mentions the CIA to sensationalize, since pretty much anyone recognizes the initialism and a "Yeah, fight the evil government Debian!" clouds the loosely cobbled-together facts in the article. I was a CIA contractor, and I really wish there was more understanding of the scope and functions of the different agencies instead of painting every government activity as being malicious. That the nature of the CIA and NSA prevent most of the details of their operations from being understood is unfortunate, but even if they were it wouldn't fit the constant anti-government narrative on the site. I'm pondering starting a blog to educate about the roles, responsibilities, and what it's really like working in these agencies. I was an NSA linguist, programmer, and mission manager, as well as a CIA contractor, so I definitely think I have a lot to contribute to the conversation but am constantly drowned out by the rage-filled anti-government sentiment on the site, which you can see if you read my comment history.
- deleted 11y ago[deleted]
- bdcravens 11y agoIt seems to me that you are equating dislike for these organizations to dislike for those like yourself who do the work. To this end, it feels like this produces internal noise. When I was reading the article, I picked up on the reproducible builds; the anti-government sentiment was at best a subtext to me. I feel it's good to have reproducible builds that are clean, regardless of who may be thwarted as a result (CIA, NSA, FBI, AWS, ISIS, malware vendors, adware vendors, whatever)
- rdtsc 11y ago> and city agencies have to literally take physical phones to Apple and ask for them to unlock the data on them if it's crucial to their investigations. If by "unlocked" you mean get access to their data, and phones can just be unlocked by taking them to Apple, they are certainly not the most freaking rock solid phone security-wise.
- bazillion 11y agoIt's understood that the phone manufacturers can unlock their phones with the tools available to them -- that serves many purposes like being able to refurbish old phones. Those accessing the data who are not doing so with the intention of serving the phone owner, however, have to have a court order to access the phone. That to me speaks highly of the phone if access outside the user of the phone is limited to organization who signed the keys locking the phone (and therefore have the certificates to make signed requests to unlock). It's not like you take it to Apple and Apple says to you "Here's the user's data.". There is something like a 60-90 day wait period while they analyze each individual request for approval, and do their due diligence to make sure access is justified. Juxtapose that with a typical android phone that can be rooted without the help of the manufacturer, and then you get that the customer is better served by one process over the other.
- schoen 11y agoYou can separate the ability to reinstall the operating system from the ability to derive the keys to decrypt a particular device (or to instruct a running device to give you root). I think this is described in Frank Stajano's Security for Ubiquitous Computing. Edit: previously in his paper with Ross Anderson https://www.cl.cam.ac.uk/~fms27/papers/1999-StajanoAnd-duckling.pdf https://www.cl.cam.ac.uk/~fms27/papers/1999-StajanoAnd-duckl... My ThinkPad can easily be reinstalled with a new OS, but my OS vendor can't give someone else my full-disk encryption keys or make them root on my device. And even with firmware-level security features we can separate "transfer ownership of device" from "access existing protected device state". I don't see any more reason that mobile phone vendors must be able to bypass screen locks or disk encryption than that desktop OS vendors must be able to do these things. (Sure, in both cases some users would want the vendor to be able to and others wouldn't.)
- mindcrime 11y agoNot tasked with collection, that would be the NSA Not to get too far away from your overall point, which may be valid, but... is it relevant what any of these agencies is "tasked" with on paper? It's quite clear, and has been for decades, that these agencies are so powerful that they are effectively outside / above the law, and can do whatever they want. The NSA wasn't "tasked with" conducting indiscriminate surveillance on damn near everybody alive, but they did it anyway, lied about it, and never got punished. The CIA wasn't tasked with experimenting on innocent American citizens by dosing them with drugs against their will and without they knowledge, but they did it anyway. As far as I'm concerned, every single shred of skepticism and scorn for these agencies that you encounter, is something they earned through their actions. I'm sure there are good people inside the CIA, FBI, NSA, TSA, DHS, etc. And I feel bad for saying hurtful things towards or about those people. But their agencies have created a state of war between themselves and the American people, if not the entire global population. I'm sorry, but if the good people inside these agencies don't want to get slagged, the onus is on them to find a way to change things, or to get out.