49 ms·
CIA malware and hacking tools
- sschueller 10y agoI hope Europe and Germany especially finally wake up and start kicking out these pests. The US/CIA is conducting crimes against humanity on foreign soil. Like the drone war. The US may not be part of the international court but Germany is.
- dovdovdov 10y agoDon't get a false impression, everyone is hacking everybody. Some are just better at hiding it.
- empath75 10y agoGermany knows they're there, are you kidding?
- pabloski 10y agoA slight correction: "Germany is an US occupied country since the end of WWII". This is the truth about Nato, friendship between US and Japan, EU countries, South Korea, etc... There are no friends in geopolitics, only masters and slaves.
- LyndsySimon 10y agoThat's an interesting thought, indeed. The US doesn't benefit financially from Germany, as far as I can tell. The argument could be made that we benefit from Japanese trade, but I find that to be rather weak. If your claim is correct, then what benefit does the vassalage of Germany and Japan have for the US?
- pjc50 10y agoVassals are not competitors and the US doesn't have to risk them developing their own idea of national interest. Germany is also part of the anti-Russian buffer zone NATO.
- asveikau 10y agoMr. Putin, is that you? Edit for downvoters: perhaps the sarcasm was a bit over the top, but my point is when someone compares the EU and NATO to slavery, I start to wonder.
- literallycancer 10y agoSo.. Switzerland is free, since they aren't in the EU, nor NATO, but Finland and Norway are slaves, right? Where would you rather live, India or any EU country? Oh and Ukraine isn't in the NATO or the EU either, see how free they are?
- mason240 10y agoEuropean governments have agreements with the CIA to spy on their own citizens (which is in illegal for them do), in exchange for their spy agencies spying on American citizens.
- luso_brazilian 10y agoThis had the potential of being a positive development brought by Trump's election: many behaviors by the US three letter agencies that were glossed over for the past 8 years (due to the party in power being "on the right side of history") are again reprehensible and deemed a threat to be fought by the tech community.
- SippinLean 10y agoDo you have any examples of them being glossed over?
- root_axis 10y agoThe tech community has been pretty up in arms against the three letter agencies ever since Snowden's revelation, so I'm not sure how Trump's election is going to change that; if anything it might produce the opposite effect since these agencies seem to be feuding with Trump on some level. Besides, wikieaks is a pro-Trump organization so I doubt that Trump losing the election would have caused them to go more softly with their criticisms of the government.
- LyndsySimon 10y ago> I'm not sure how Trump's election is going to change that; if anything it might produce the opposite effect since these agencies seem to be feuding with Trump on some level A big part of Trump's appeal is that he's seen as anti-establishment. I don't think it's unreasonable to expect that he may make significant changes at those agencies as a result of their "feuding" with him. > wikieaks is a pro-Trump organization I don't believe that for a moment. WikiLeaks helped Trump's campaign, certainly - but their reason for doing so was orthogonal to Trump himself. If WikiLeak's behavior during the 2016 election was driven by anything personal or partisan, I would say it was Assange's own personal vendetta against Hillary Clinton.
- root_axis 10y ago> I don't think it's unreasonable to expect that he may make significant changes at those agencies as a result of their "feuding" with him. And? What does that have to do with the tech community being critical of three letter agencies? > but their reason for doing so was orthogonal to Trump himself. I don't care what the reasoning is, Assange explicitly stated that he wasn't going to release info on Trump because he felt the media was sufficiently critical of him and he has kept up with that promise and maintained a mostly positive disposition regarding Trump, that's Trump support. Don't misunderstand, I don't think supporting Trump invalidates any of the info that wikileaks has released, my point is precisely the opposite, that this info was released despite their support for Trump so if Trump hadn't have won the election, it makes sense that they would have been just as critical if not more so.
- chillydawg 10y agoOne very interesting thing is that the exploits, rootkits, etc are all unclassified and the CIA has no copyright on them either. The logic is supposedly that an agent putting a classified rootkit/trojan/whatever on a machine is mishandling classified information and thus it would be illegal.
- colinbartlett 10y agoDoes that mean that someone who leaked them could not be prosecuted? Or simply that they would be prosecuted under some other law?
- chillydawg 10y agoIndeed, that's what the doc implies. They say they reckon the CIA has no recourse. Probably sue-able for breaking their employment contract where they presumably agree to never disclose anything, regardless of classification level. But doubtful that'd be a federal crime.
- rl3 10y agoOr their life expectancy would decrease significantly.
- goodroot 10y agoI will continue using Swiss cheese and hungry mice as my metaphor for global network security.
- TheArcane 10y ago"U.S. Consulate in Frankfurt is a covert CIA hacker base " Germans are usually privacy nuts. I know many who maintain no presence on Facebook, Twitter and Instagram. I wonder how Germany will react to this.
- jagermo 10y agoUp to our ears in Erdogan and now this?
- agumonkey 10y agoNot long ago it was hinted that US ambassy in Paris is a nice CIA antenna too. Nobody denied nobody answered, question still up in the air. Also, latest Russian project, a large church-like building in Paris is suspected to hide intel dept.
- kweks 10y agoPoster is referring to this thing, for anyone curious: http://www.gettyimages.fr/%C3%A9v%C3%A9nement/russian-orthodox-cathedral-sainte-trinite-under-construction-in-paris-667550103#russian-orthodox-cathedral-saintetrinite-and-russian-orthodox-and-picture-id599854670 http://www.gettyimages.fr/%C3%A9v%C3%A9nement/russian-orthod...
- mietek 10y agoIs the suspicion that the domes are actually radomes?
- wyldfire 10y agoSorry, news flash, virtually all of the countries' embassies and consulates are a natural place where a lot of intelligence operations are conducted. Counterintelligence operations watch them very closely. The fact that Frankfurt is a hub among their European intelligence operations is not terribly interesting IMO. > I wonder how Germany will react to this. Germany always knew operations were conducted there but now must react to this overt news.
- dvcc 10y agoBased on the overview alone (of course I can't read the entire report that fast!), this is exactly what I expect a spy agency would be doing -- if they were not then I would be disappointed. What exactly in the admittedly shortened list am I supposed to be upset about? It makes no distinction between US citizens and overseas parties. If these actions are being done domestically against US citizens, with no just cause sure I will get upset, but that has yet to be seen. As usual it seems Wikileaks publishes a sensationalist story around one of their leaks, claiming dozens of zero-day releases where most were already patched. Hell, they included the i0nic jailbreak as one of the 0-day exploits (https://wikileaks.org/ciav7p1/cms/page_13205587.html https://wikileaks.org/ciav7p1/cms/page_13205587.html). I'll let journalists parse through the full report before coming to any conclusion as of yet. I just find it hard to get excited about any Wikileaks release that has yet to be vetted.
- colinbartlett 10y agoThe "with no just cause" part of the argument is what scares me because the government's idea of a just cause for domestic spying and my own, are often very, very different.
- tyingq 10y agoOne cause for concern is that the CIA appears to not only have lost control of the documentation, but of the tools themselves: "Recently, the CIA lost control of the majority of its hacking arsenal...and associated documentation. This extraordinary collection...gives its possessor the entire hacking capacity of the CIA." So, now, you get to worry about anybody else that might have this toolset. (Not withstanding your note that some of it might have already been available)
- at-fates-hands 10y ago>> So, now, you get to worry about anybody else that might have this toolset. You also have to consider who has the capability to actually use these tools - its not like they come with a user manual. Could Joe Schmo download these and start using them tomorrow? Probably not. Also, I'm pretty sure this isn't "the entire hacking capacity of the CIA". If you consider all the stuff that came out with the Snowden leaks, you'd think this is more likely the tip of the iceberg in terms of tools they're currently using. I would think they're developing new tools and techniques daily.
- alva 10y agoVLC 2.1.5 compromised https://wikileaks.org/ciav7p1/cms/page_15729066.html https://wikileaks.org/ciav7p1/cms/page_15729066.html edit: please see response below from remlov edit: this post was premature, see below posts
- dvcc 10y ago> The asset has the ability to plug in a personal thumbdrive to the network. Sounds like it just patches a local copy of VLC by running an installer. I don't know if I would consider that compromised.
- tinus_hn 10y agoIt's a version of VLC that, in addition to the things it normally does, collects information. The operator, who knowingly runs the software, can then collect the information and turn it over to someone else.
- remlov 10y agoPlease don't spread disinformation. "...the asset will have 'downloaded' the portable version of VLC player (2.1.5)..." This does not sound like a copy of the public version and that it's "compromised". You could check for yourself if you like: https://github.com/videolan/vlc https://github.com/videolan/vlc :)
- teamhappy 10y ago2.2.0 was released in early 2015.
- jug5 10y agoThe docs are from 2014
- bhouston 10y ago- Smart TV turned into listening devices with fake off mode? - Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc. - Dozens of O-day attacks again Andriod and iPhone. Pretty powerful stuff.
- joeyspn 10y ago> Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc I wish I could say that I'm surprised but no... not surprised at all. Same for the IoT stuff.
- nightpool 10y agoWhy would you be surprised by the fact that if your phone is compromised, even the best encryption software in the world isn't going to help?
- homakov 10y agoAnother victim of sensationalism.
- monochromatic 10y agoThe conclusions are correct. Talking about them isn't sensationalist just because you think they're foreseeable.
- homakov 10y agoI refered to "being not surprised that encryption is broken". There was nothing relevant to encr in the document. The title is wrong.
- joeyspn 10y agoWho said "being not surprised that encryption is broken"??? Read the quote again: "Intercepting audio/texts before encryption" I'm not surprised that they can INTERCEPT and read ALL your communications... jeez
- dandare 10y agoMaybe it is just my lack of knowledge but why were all the recently leaked hacking tools made by US and none by Russia or China?
- raverbashing 10y agoWhile one cannot expect editorial independence from Wikileaks, I believe the language and cultural barrier also plays an important part Not to mention those with that access level on those countries wouldn't release any information like that "for free"
- rogerthis 10y agoMaybe in Russia and China such leaks would be punishable with death penalty effectively.
- chillydawg 10y agoRussia and China have not got their stuff leaked, yet. Punishments in those countries are far more severe, too.
- LyndsySimon 10y agoMy feeling - based on reading only publicly-available resources - is that China and Russia rely more on more traditional "HUMINT" (Human Intelligence), while the US has come to rely more and more and "SIGINT" (Signals Intelligence).
- zigzigzag 10y agoThe CIA dump apparently contains malware stolen from other countries. So perhaps if/when wikileaks starts releasing them, that'll include Russian/Chinese malware. It may also be that they simply have far smaller security states, with fewer people who feel alarm at the extent of what's happening. Or maybe leaking to Wikileaks just isn't in vogue in those countries.
- deleted 10y ago[deleted]
- akerro 10y ago
- aeleos 10y agoWow this is really big. There are tons of documents about the various tools they use, but it seems the majority of the actual source code is still being reviewed and the links just show a link to the file list. I hope they eventually release the source code, as a lot of these tools seem very interesting. I can imagine that many at the CIA are running around on fire, as this seems like a big problem for them.
- imron 10y agoAccording to Wikileaks [0], they were explicitly redacted until their safety could be assessed. They didn't want to be responsible for accidentally releasing malware in to the wild. 0: https://wikileaks.org/ciav7p1/#FAQ https://wikileaks.org/ciav7p1/#FAQ
- e12e 10y agoFeel much safer knowing the CIA keeps them safe and only use them for good causes /s
- swalsh 10y agoI'm pretty okay with wikileaks not releasing hundreds of zero day exploits into the wild en mass.
- digler999 10y agoI'd like to hear a security expert's opinion on whether releasing even patched 0-days could be considered harmful ? even if the 'sploits dont work out of the box, it seems like they would still advance the state of the art, and allow moderately-skilled hackers to build on very sophisticated designs, adapt and make them effective again - "stand on the shoulders of giants" kind of thing.
- dublinben 10y agoReleasing the exploits is also the quickest way to get them patched.
- danyim 10y agoI wonder how many of the exploits/tools released are still usable today. Also, the actual video press release had to be rescheduled due to their video stream being attacked.[0] "NOTICE: As Mr. Assange's Perscipe+Facebook video stream links are under attack his video press conference will be rescheduled." [0]: https://twitter.com/wikileaks/status/839104886625157120 https://twitter.com/wikileaks/status/839104886625157120
- pottersbasilisk 10y agoUnbelievable the depth and scope. Absolutely frightening that most of these tools are out in the wild.
- ttctciyf 10y agoThey have vim editing tips https://wikileaks.org/ciav7p1/cms/page_3375350.html https://wikileaks.org/ciav7p1/cms/page_3375350.html No emacs?
- dvcc 10y agoThey have secret unit testing tips too! https://wikileaks.org/ciav7p1/cms/page_11629048.html https://wikileaks.org/ciav7p1/cms/page_11629048.html
- yread 10y agoAnd Visual Studio https://wikileaks.org/ciav7p1/cms/page_11629039.html https://wikileaks.org/ciav7p1/cms/page_11629039.html
- alpb 10y agoIn many pages I explored from the leak I keep coming across this *.devlan.net domain. Whois info belongs to a French personality and is suspiciously updated 2 days ago and it has a month for expiration: Updated Date: 2017-03-05T16:38:16Z Creation Date: 2004-04-19T13:12:21Z Registrar Registration Expiration Date: 2017-04-19T04:00:00Z Registrant Name: SADIER, NICOLAS Registrant Organization: Registrant Street: 5 Bis Chemin Des Hautes Terres Registrant City: ST HILAIRE Registrant State/Province: Registrant Postal Code: 91780 Registrant Country: FR Registrant Phone: +33164954698 Registrant Email: pservor@free.fr
- btym 10y agoWhat's suspicious about that? It's certainly hosted on their intranet, they just picked a sensible name that employees could remember. The publicly-registered devlan.net is probably unrelated or unused.
- ttctciyf 10y agoAnd watch out if you don't test! https://wikileaks.org/ciav7p1/cms/files/359jzz.jpg https://wikileaks.org/ciav7p1/cms/files/359jzz.jpg (via https://wikileaks.org/ciav7p1/cms/page_13763158.html https://wikileaks.org/ciav7p1/cms/page_13763158.html )
- megous 10y agoI guess some responsible disclosure to the affected vendors would be nice. If the tools are being actively exploiting bugs, which they are, there's not much else to do in order to stop the exploitation. Give it a few weeks and then publish them in the wild.
- rosalinekarr 10y agoThis idea that the government should somehow be exempt from proper cybersecurity ethics is disgusting. When the CIA or the NSA find zero day attacks in software, they should report them immediately to be fixed, not build tools specifically to exploit them. It's only a matter of time before these attacks either leak or are rediscovered by other malicious parties. The government is effectively turning their own people into cannon fodder for their ridiculous "cyberwar."
- PleaseHelpMe 10y agoLoL why are you so naive? It's CIA, not google Zero day project
- daenney 10y agoThe parent isn't being naïve, they take issue with the current state of affairs and tell how they would like it to work. They're not surprised that that's not the case.
- hubert123 10y agoNope, he is very naive. He calls [cyber] war "ridiculous".There is nothing ridiculous about wanting to be ahead of rivaling countries and having backdoors into their software and computers. What is however ridiculous is the attitude that we should all hug each other and make the bad people go away with love and prayer.
- PleaseHelpMe 10y agoThank you for clearing my point although I still got downvote.
- imron 10y agoAfter Snowden, the Obama administration made a commitment to the tech community that it would not hoard security vulnerabilities, and would instead pass them on to vendors to fix. This release shows that they did not honour that commitment.
- codeisawesome 10y agoThis is an incredible and sensational claim that, if true, can quite literally "break the internet". Makes me very sad to imagine that CIA grade cyber weapons for getting into iPhones are now in the hands of heaven knows who. Hope Apple security teams are on this. EDIT: To clarify, I'm commenting on the original situation of the tools getting out of CIA to the entities it was "circulated to", not this leak later by WikiLeaks - presumably the damage has already been done.
- eternalban 10y agoThis looks interesting: Hive's developer guide. It has a auto-destruct feature, just like in the movies: https://wikileaks.org/ciav7p1/cms/files/DevelopersGuide.pdf https://wikileaks.org/ciav7p1/cms/files/DevelopersGuide.pdf
- abrkn 10y agoSeems to have been having issues with premature self destruction: "Discrepancy report DR-00134-2012 was issued after Operations determined that Hive version 2.5 was self-deleting prematurely. Analysis showed that a calculation involving the current time and the file modification time used to determine the time since last contact could result in a negative number that was then cast from an integer to an unsigned long integer. This resulted in a large positive number that exceeded the delete delay and subsequently caused Hive to self-delete."
- addedlovely 10y agoI wander what phones / computers CIA operatives use - do they have special patched versions which address the zero day exploits they are aware of.
- DickingAround 10y agoThis is a great question. Surely they look for vulnerabilities also in their own systems but then what do they do when they find them? Is there some special set of software that always gets patched because the CIA uses it?
- LyndsySimon 10y ago> Is there some special set of software that always gets patched because the CIA uses it? If so, a diff between the "CIA version" and the "civilian version" would be highly instructive.
- Godel_unicode 10y agoPresumably the same thing others do when they know about 0-days? Signatures.
- redblacktree 10y agoCould you explain a bit more? I'm not sure what you mean.
- Godel_unicode 10y agoSure, this is essentially the argument for disclosure of bugs before they've been patched. If I had known about e.g. shellshock before the patch was out, I could have written a Snort signature looking for it in network traffic and have my IPS drop the packets. I do this on my network with bugs I find before the vendor patches them. This is an example of security through defense in depth; patching is one layer of defense, but if you can't patch there are other mitigating actions you can take to protect against (especially) known threats. It allows someone with an offensive and defensive mission to simultaneously use exploits while not being vulnerable to them.
- rogerthis 10y agoI wonder if, supposing a legit war use, those tools would work. Maybe in taking down some enemy tech infra, but on collecting information, i really have doubts. That would be too much data to process unless they had specific targets. Human intelligence would be much more effective. Anyway, I remember a story of a US submarine that hacked soviet cables in the 70s or 80s.
- rogerthis 10y agoMore, being those tools not effective, development and maintenance is stupid spending, and certainly the tools are having other uses. My conspiracy side looks at CIA like a public sector (state owned) company in Brazil: they are not owned by the government, but by the chaste of unionized workers that work there.
- PKop 10y ago"Deep State" https://en.m.wikipedia.org/wiki/Deep_state_in_the_United_States https://en.m.wikipedia.org/wiki/Deep_state_in_the_United_Sta...
- cancancan 10y ago> Anyway, I remember a story of a US submarine that hacked soviet cables in the 70s or 80s. Operation Ivy Bells https://en.wikipedia.org/wiki/Operation_Ivy_Bells https://en.wikipedia.org/wiki/Operation_Ivy_Bells One of the tapping devices http://i.imgur.com/PgOJSTp.jpg http://i.imgur.com/PgOJSTp.jpg I believe a few of those devices are on display in some museum in Russia.
- beagle3 10y agoI would suspect that at a time of war, especially in the first few months, there is a lot of tactical info to be collected from whatsapp and Facebook conversations between people and their families ("I'm going to be busy tonight with an operation, but I promise I'll call when I'm back, love"). Whether this can be efficiently processed is a different question, which I believe google can answer affirmatively, and likely also palantir and some TLAs
- u_wot_m8 10y ago>"As of October 2014 the CIA was also looking at infecting the vehicle control systems used by modern cars and trucks. The purpose of such control is not specified, but it would permit the CIA to engage in nearly undetectable assassinations." Reminds me of the reporter who was supposedly working on a massive investigation and then died in a flaming car crash while skipping town. Forgot his name
- struct 10y agoMichael Hastings? [0] [0] https://en.wikipedia.org/wiki/Michael_Hastings_(journalist) https://en.wikipedia.org/wiki/Michael_Hastings_(journalist)
- 1001101 10y agoI had the same thought. Rest in peace.
- knowaveragejoe 10y agoWhile the above is certainly plausible(killing someone with a car), I highly doubt this is the case here: https://www.metabunk.org/debunked-michael-hastings-crash-cars-just-dont-blow-up-kim-dvorak.t2148/#post-62380 https://www.metabunk.org/debunked-michael-hastings-crash-car...
- digler999 10y agoWhile I don't think the CIA is above killing a US citizen on US soil (you know, for "security" or something), I don't think they need to hack a vehicle to do it, nor would they want to draw the unnecessary speculation and attention. I would expect antics like that to be reserved for high-ranking foreign officials or other hard-to-reach people. If there's one thing that agency should be expected to excel in, it's untraceable targeted killings.
- rattray 10y agoGiven the relatively low amount of public scrutiny/outrage/attention/fear that this death caused, wouldn't you say that the car technique would be effective? (whether or not it was used in this case)
- dogma1138 10y agoI'm surprised so many acronyms from their org chart are missing. FINO is Financial Operations Group. FIO is Field Intelligence Officer. ESD is Executive Services Directorate. Don't see a single term that anyone who spent any time in the intelligence community wouldn't recognize.
- imron 10y agoThe CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation. With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from. This has interesting implications for the claim that "Russians" hacked the election (although I can't imagine the CIA wanting to hack the election in Trump's favour).
- jug5 10y agoWell you need to make it seem as if "the bad guys" are a threat regardless of the attack vector, digital or otherwise.
- at-fates-hands 10y agoI'm wondering if these documents are going to match the same ones that were taken by Harold Martin III and if the CIA will out him as the Wikileaks source.
- dmix 10y agoThese documents were being passed around by former CIA hackers. It says this right on the page. Harold has already been disproven to have any connection to leaks. He was just a hoarder with a mental illness. This hasn't stopped people from connecting every leak since his arrest to him.
- ttctciyf 10y agoActually, WikiLeaks press release says: > The archive appears to have been circulated among former U.S. government hackers and contractors in an unauthorized manner, one of whom has provided WikiLeaks with portions of the archive. and later specifically mentions Martin: > Over the last three years the United States intelligence sector, which consists of government agencies such as the CIA and NSA and their contractors, such as Booze Allan Hamilton, has been subject to unprecedented series of data exfiltrations by its own workers. > A number of intelligence community members not yet publicly named have been arrested or subject to federal criminal investigations in separate incidents. > Most visibly, on February 8, 2017 a U.S. federal grand jury indicted Harold T. Martin III with 20 counts of mishandling classified information. The Department of Justice alleged that it seized some 50,000 gigabytes of information from Harold T. Martin III that he had obtained from classified programs at NSA and CIA, including the source code for numerous hacking tools. EDIT: I would infer from this that WL mention Martin to shore up their claim that the CIA hacking archive is circulating among contractors, not to hint that he's a source.
- alphonsegaston 10y agoBut considering that Wikileaks is essentially a Russian intelligence services front at this point, spreading this kind of disinformation does a great deal to muddy the waters about the hacking.
- imron 10y agoWhy would anyone consider that? (Yes I know the accusations, but they don't appear backed by evidence or reason).
- alphonsegaston 10y agoThe guy went from "cryptoanarchy" to having a TV show on RT(a propaganda network)and saying Russia has "vibrant" criticism of Putin's regime (beyond absurd). Not to mention him somehow being able to facilitate Snowden's entry into Russia. I'm no fan of imperialist American foreign policy, but Russia is just as grotesque. http://www.repubblica.it/esteri/2016/12/23/news/assange_wikileaks-154754000/ http://www.repubblica.it/esteri/2016/12/23/news/assange_wiki...
- lolc 10y agoFirst time I hear that Assange "the guy" was "somehow" instrumental in Snowden's flight.
- alphonsegaston 10y agoHere it is from the horse's mouth, strangely enough also featured on the Russian propaganda network: https://www.rt.com/news/313829-assange-advise-snowden-russia/ https://www.rt.com/news/313829-assange-advise-snowden-russia...
- baursak 10y agoThis doesn't prove your original claim in any way.
- Bartweiss 10y ago
- therealmarv 10y agoSo will this zero days be reported to Google,Apple,Microsoft & Co.? Or is this more a "FYI document"? It seems you can be on the safer side if you use a more exotic phone OS which is not widely used or a more dumb feature phone.
- LyndsySimon 10y agoAn obscure OS would potentially help protect you on that one layer, but it's hardly a panacea. For one thing, an obscure OS means fewer friendly eyes looking for vulnerabilities. For another, you're still going to be vulnerable to things like a baseband attack: https://dwaterson.com/2013/11/18/vulnerabilities-of-the-second-operating-system-of-your-smartphone/ https://dwaterson.com/2013/11/18/vulnerabilities-of-the-seco...
- strictnein 10y agoSecurity through obscurity isn't a thing
- therealmarv 10y agoIt's not security through obscurity (which I agree is bad). It's more like "more security" through "less market share".
- cQ5ktKqTvOPZ 10y agoIf they call in James Clapper, will he perjure himself again? http://www.hasjamesclapperbeenindictedyet.com/ http://www.hasjamesclapperbeenindictedyet.com/
- strictnein 10y agoIt would have been illegal for him to tell the truth in that testimony, since it was public. I know people don't like that, but it's true. He could either lie or break serious secrecy laws. There's no immunity just because you're talking to congress.
- degenerate 10y agoIn that case, you say "I can't answer that question" and let the system do its job. You don't lie.
- strictnein 10y agoNo. The only way he couldn't answer the question was if the program existed, thus revealing the existence of the program, so he had to lie.
- degenerate 10y agoThus my point. The CIA should not be running programs that "do not exist". Classified, sure, but not hidden programs nobody knows about. That is not what we are paying them for.
- zigzigzag 10y agoYou are mounting the most ridiculous defence of perjury I have ever seen. Do you seriously think that Congress passed laws they intended to be interpreted in the way you propose? That they want to be lied to? Clapper lied under oath. He should have paid the penalty for that. He didn't because the US Government has decided that it either can't or doesn't want to control the shadow state.
- 10y ago
- mpeg 10y agoI don't really get into political commentary, and I'm not a US citizen, but there's some great RE tips in there. I genuinely lol'ed at their assessment about Comodo's whitelist-only firewall/av. Also, this: https://wikileaks.org/ciav7p1/cms/page_17760284.html https://wikileaks.org/ciav7p1/cms/page_17760284.html (゚ヮ゚)
- benmcnelly 10y agoThats how you know the leak is real, because this is classic internal Wiki shenanigans, you can't make this up. Also, though there are some talented people working here (you can identify some of their github accounts, thanks to wikileaks tying users to their posts by ID) but I think a LOT of these tools are made/stolen/purchased from elsewhere..
- apo 10y agoIn what is surely one of the most astounding intelligence own goals in living memory, the CIA structured its classification regime such that for the most market valuable part of "Vault 7" — the CIA's weaponized malware (implants + zero days), Listening Posts (LP), and Command and Control (C2) systems — the agency has little legal recourse. The CIA made these systems unclassified. Why the CIA chose to make its cyberarsenal unclassified reveals how concepts developed for military use do not easily crossover to the 'battlefield' of cyber 'war'. To attack its targets, the CIA usually requires that its implants communicate with their control programs over the internet. If CIA implants, Command & Control and Listening Post software were classified, then CIA officers could be prosecuted or dismissed for violating rules that prohibit placing classified information onto the Internet. Consequently the CIA has secretly made most of its cyber spying/war code unclassified. The U.S. government is not able to assert copyright either, due to restrictions in the U.S. Constitution. This means that cyber 'arms' manufactures and computer hackers can freely "pirate" these 'weapons' if they are obtained. The CIA has primarily had to rely on obfuscation to protect its malware secrets. One of the more interesting passages. The arsenal must not be classified to protect those who deploy it from legal action. This cyberwarfare kit, which can just as easily be used to destroy the US as one of its enemies, is public domain software created and released at US taxpayer expense.
- pjc50 10y ago> Command & Control and Listening Post software were classified, then CIA officers could be prosecuted or dismissed for violating rules that prohibit placing classified information onto the Internet. Consequently the CIA has secretly made most of its cyber spying/war code unclassified. This is almost hilarious. Not that being classified would make any difference: cyber-"weapons" have something in common with biological weapons in that they're prone to leaking and blowing upwind, but also once used it's possible for the enemy to vaccinate against them.
- djsumdog 10y agoThe US chemical weapons program is downright frightening. Unlike these exploits which you can just leave in an office and never use (and which con subsequently go stale as people find and patch exploits), chemical weapons were stored in massive US facilities and many of them have started leaking over the years: https://www.youtube.com/watch?v=FjA0EQPeUGM https://www.youtube.com/watch?v=FjA0EQPeUGM
- cliffy 10y agoHave there been any leaks showing TLAs using Intel's ME or AMD's PSP as a means to compromise a target?
- randomname2 10y agoOne of the findings: Notepad++ has a DLL hijack [1] [1] https://wikileaks.org/ciav7p1/cms/page_26968090.html https://wikileaks.org/ciav7p1/cms/page_26968090.html
- mpeg 10y agoAny executable is vulnerable to DLL hijacking, they're just looking for easier targets that load known DLLs (with known function signatures) from their own folders (NOT system folders). I'm assuming the goal is to minimise detection by what they call PSPs (av / security products) This is not a flaw within notepad++
- rrggrr 10y agoCIA needs to work with the tech community to patch the vulnerabilities, and the US business community for awareness of the vulnerabilities. The cat is out of the bag and CIA's mission is very much consistent with a direct defense effort to ensure foreign powers and organized criminal entities cannot use the CIA's compromised assets against US citizens.
- bluejekyll 10y agoActually, it's the CIAs job is to actively collect information on foreign governments and nationals. This information is then supposed to be given to other organizations in the government to be used to guide decisions on foreign policy and potentially active missions to disrupt foreign activity. I would argue that the group you are talking about is really the NSA. They should be doing everything in their power to make the US more secure, not easier to spy on.
- rrggrr 10y agoI agree with you. NSA or NIST should be tasked. On the other hand, its their mess and they should clean it up.
- brakmic 10y agoWikiLeaks Vault7 Year Zero 2017 https://archive.org/details/WikiLeaksYearZero2017V1.7z https://archive.org/details/WikiLeaksYearZero2017V1.7z Passphrase is SplinterItIntoAThousandPiecesAndScatterItIntoTheWinds
- jlgaddis 10y agon.b.: The actual file is at https://archive.org/download/WikiLeaksYearZero2017V1.7z/WikiLeaks-Year-Zero-2017-v1.7z https://archive.org/download/WikiLeaksYearZero2017V1.7z/Wiki... Torrent: https://archive.org/download/WikiLeaksYearZero2017V1.7z/WikiLeaks-Year-Zero-2017-v1.7z.torrent https://archive.org/download/WikiLeaksYearZero2017V1.7z/Wiki...
- agopaul 10y ago"and even Samsung TVs, which are turned into covert microphones." - Sounds very Orwellian
- thraway2016 10y agoEDIT: This post is no longer relevant. Meta: 351 points in < 2 hours and it's bouncing between #10 and #16. Conclusion: HN is flagging this fairly aggressively. Question: Why? This is not overtly political, and it is definitely in the interest of the community, with the potential to be at least half as interesting as the Snowden documents or the hack of Hacking Team.
- phpnode 10y agoI didn't flag it, but I'd imagine a lot of people don't trust the source (any more). Edit: Why the downvotes? I didn't indicate my position, I pointed out that some people don't trust WikiLeaks any more, which is obvious - go and look at the responses they get on twitter.
- jMyles 10y agoDid I miss a memo? Wikileaks has done tireless work in this field and has largely been correct about its claims and the authenticity of its documents. If not Wikileaks, whom do we trust for this sort of info?
- idlewords 10y agoYou missed a pretty big memo.
- thraway2016 10y agoThe infosec community has this insane conspiracy theory that Assange is owned by Putin.
- wired_devil 10y agoPretty cool names for the tools... Is this really real or a honeypot?
- r721 10y agothe grugq: "I guess the .ru investigation in the US is getting too hot, time to throw a big distraction at the CIA; drive wedge between executive & IC" https://twitter.com/thegrugq/status/839138456894763008 https://twitter.com/thegrugq/status/839138456894763008
- teekert 10y agoWell, traveling to the US I have had to fill out a green form stating that I'm not a terrorist or a 40-45 Nazi. I guess they capture a lot of pathological truth-telling terrorists/Nazis with this piece of paper
- vidarh 10y agoThat's form I-94W [1] for those who are curious. We also had to promise we'd not been traficking drugs and were not planning on engaging in illegal or immoral activities, and more. I always wonder how many idiots have been denied entry because they were dumb enough/drunk enough to think it'd be fun to tick the wrong box on that form. I also love how under the Paperwork Reduction Act they have had to estimate the burden of filling it out, but seemingly not consider whether or not is serves any actual purpose to ask those questions in the first place. [1] https://www.cbp.gov/sites/default/files/documents/%20I-94W%20English%20%2811-11%29%20FINAL%20%28reference%20only%29.pdf https://www.cbp.gov/sites/default/files/documents/%20I-94W%2...
- ermir 10y agoThe purpose of these forms is to have an excuse to deport or deny your entry if it becomes convenient. The excuse will be that you lied on your form, regardless of what you put in it.
- alain94040 10y agoYou misunderstand the point of the form. The point is that if later you are suspected of one of those activities, you can be deported because you lied on the form, even though it might be impossible to convict you for the activity itself.
- tannhauser23 10y agoThis is absolutely correct. Plus, what they did may not be illegal per se, but we might not want them in the country. For example, I'm not aware of any U.S. law that specifically makes it illegal to have been Nazi concentration camp guard. But we don't want people like that in the country and want to deport them if they are ever found here. Hence the purpose of the immigration form.
- patrickaljord 10y agoUse of undisclosed zero day vulnerabilities by governments is not really news. But the article makes it sounds like these OS come with a rootkit pre-installed to exploit those vulnerabilities. My guess is that they first need to find a way to install these on targeted devices. Any idea?
- 40acres 10y agoIt's very sobering to realize that if the government wanted to track my every movement they could easily do so. Arguing about the security features of Android vs. iOS just seems redundant now.
- everybodyknows 10y agoNew York Times weighs in: https://www.nytimes.com/2017/03/07/world/europe/wikileaks-cia-hacking.html https://www.nytimes.com/2017/03/07/world/europe/wikileaks-ci...
- 5ersi 10y agoOS-level backdoors can be easily patched. Unlike hardware based backdoors, curtesy of Intel AMT.
- ajross 10y agoAnd yet the leaked tools don't seem to have much in the way of hardware-based exploits, which might say something about the feasibility of this kind of thing on actual systems. Obviously it can be done, but it were as pervasive as the tinfoil hatters believe, surely it would have shown up here. No?
- moduspwnens14 10y agoThe document covers how they put a good amount of effort into ensuring there's not a clear link back to the CIA or relevant parties if one of these things is discovered. I imagine having hardware level vulnerabilities would much more quickly point directly to the only agencies capable of such techniques.
- ajross 10y agoThat's sort of my point though. If hardware back doors exist (and I don't argue that they can't!) they're exotic, highly protected and rarely used. They aren't routine instruments of state surveillance.
- moduspwnens14 10y agoYes--sorry. My comment was in support of your point.
- blauditore 10y agoThis may sound stupid, but I'm wondering if using Windows Phone 8 (not Windows 10 mobile) might be a strong measure for protecting oneself against such attacks. First, it's quite restricted in terms of deep system access towards devs and users. Apps are sandboxed and extremely isolated from each other. Then, its market share is so low that probably no one makes an effort to build targeted attacks towards it.
- Rick-Butler 10y agoSecurity through obscurity isn't a good practice in general. Because few people use it, security testers probably don't spend much time on it. So it could be easier to find vulnerabilities. It's also end of support 7/11/2017, so nothing will get patched after (unless you pay for extended support). That leaves you exposed to any critical vulnerability found after that point. So obscurity might save you from widely targeted attacks at the majority (android, iOS), but wouldn't stop any targeted attack against you.
- roryisok 10y agoI was just wondering the same, looking down at my trusty old lumia here. Unfortunately no desktop OS seems to be safe
- dandelion_lover 10y ago> Unfortunately no desktop OS seems to be safe What about Qubes OS?
- roryisok 10y agonever heard of it until now
- whorleater 10y ago> Apps are sandboxed and extremely isolated from each other One could make the same argument for iOS. > Then, its market share is so low that probably no one makes an effort to build targeted attacks towards it. No one also makes an effort to find and disclose exploits either. Security through obscurity alone is an awful idea.
- logicallee 10y agoI never read wikileaks but I did glance at a couple of things here - https://wikileaks.org/ciav7p1/cms/page_14587109.html https://wikileaks.org/ciav7p1/cms/page_14587109.html which are "do's and don't's" for malware writers. I like this: S//NF) DO NOT perform operations that will cause the target computer to be unresponsive to the user (e.g. CPU spikes, screen flashes, screen "freezing", etc). But the rationale is only: (S//NF) Avoids unwanted attention from the user or system administrator to tool's existence and behavior. It should go farther. When a user's impact is affected, this is a firm and definite step toward living in a police state. I like the idea of a state where the director of the CIA can tell the President "We do not have private files on anyone, nor anything not directly related to imminent terror action and the like. We live in a free world, and if we didn't have people abducting others for ransom, planning terrorist activities, or the like, nobody country would need such capabilities. Generally I am against a surveillance state and for one of these reasons I do not read these documents. I also like this part: (S//NF) DO make all reasonable efforts to minimize binary file size for all binaries that will be uploaded to a remote target (without the use of packers or compression). Ideal binary file sizes should be under 150KB for a fully featured tool. To put this in perspective, if you were to load the front page of the wall street journal right now, your browser would download something like 900 KB. I think getting 100 kb slipped in here or there that makes sure I'm not running a huge terrorist network is worse than the total inability for the government to do this if someone is. it shouldn't impact my experience and it should be denied. It's problematic that some of this is extralegal, but I'd rather not know about it than to have to have someone acknowledge its existence. Sorry. if bitcoin assholes weren't ransoming people's pc's and life's work, or if people weren't being abducted for ransom, or if people weren't radicalized in a matter of weeks and then transmitted secret payments and chose to plough into a group of people celebrating independent democracy (the French 14 July thing with the truck), I might have a little more sympathy toward the idea that there doesn't need to be anything except might makes right on the Internet, letting users and terrorists do whatever they want and fend for themselves. - Edit: the cleanup/uninstall section explicitly mentions in the rational, not collecting private (unwanted) data. This might not be great but certainly sounds like the kind of hidden machinery you would want, in the kind of world we live in.
- mrcactu5 10y agoJust something totally ridiculous. These spyware / malware competitions remind me of poker in that these are games of imperfect information and we just throw hoops tring to gain a tiny bit more information than the next guy, to improve our bets.
- t0mk 10y agoTIL that CIA is using Atlassian Stash for internal code hosting. Many references to the stash.devlan.net, would be nice to see some code, I just found some python scripts: https://wikileaks.org/ciav7p1/cms/page_9535551.html https://wikileaks.org/ciav7p1/cms/page_9535551.html
- TheHippo 10y agoThere are even images here: https://wikileaks.org/ciav7p1/cms/page_13205694.html https://wikileaks.org/ciav7p1/cms/page_13205694.html
- y_u_no_rust 10y agoI'm sure the NSA will get a kick out of this one def dcode(data): key = 20 newdata = '' for i in data: i=ord(i) if i< key: i = 256 + (1) newdata += chr(i-key) return newdata def ncode(data): newdata = '' key = 20 for i in data: i = ord(i) if i + key >= 256: i = i - (256) newdata += chr(i+key) return newdata
- abrkn 10y agoAnd they're using git flow
- afandian 10y agoI am completely bemused that on the one hand the CIA is quite happy to literally murder, rape and and torture left right and centre, overthrow foreign governments, interfere with elections etc ... but is careful about adhering to the finer points US Constitution.
- Donzo 10y agoThis is because if they answer to anyone, it's the US Gov that is structured by the Constitution. They have no issue with commiting those attrocities in foreign lands, in which Constitutional protections and rules do not apply to them.
- huffmsa 10y agoThat's why the CIA doesn't operate inside of the United States. It is beholden to the laws of the United States and tasked with protecting and upholding the Constitution. But there are no stipulations against doing bad things in non-US lands.
- 1001101 10y ago> That's why the CIA doesn't operate inside of the United States. False [1] [2] [3] [4] [5] [6] [1] https://en.wikipedia.org/wiki/Project_ARTICHOKE https://en.wikipedia.org/wiki/Project_ARTICHOKE [2] https://en.wikipedia.org/wiki/Crusade_for_Freedom https://en.wikipedia.org/wiki/Crusade_for_Freedom [3] https://en.wikipedia.org/wiki/Project_MKUltra https://en.wikipedia.org/wiki/Project_MKUltra [4] https://en.wikipedia.org/wiki/Operation_Mockingbird https://en.wikipedia.org/wiki/Operation_Mockingbird [5] https://en.wikipedia.org/wiki/Project_SHAMROCK https://en.wikipedia.org/wiki/Project_SHAMROCK [6] https://en.wikipedia.org/wiki/HTLINGUAL https://en.wikipedia.org/wiki/HTLINGUAL
- huffmsa 10y agoWhy the CIA isn't supposed to operate inside the United States.
- 10y ago
- deleted 10y ago[deleted]
- samirm 10y ago>These techniques permit the CIA to bypass the encryption of WhatsApp, Signal, Telegram... So much for guaranteed encryption and safety.
- lmm 10y agoControl of the local device has always meant game over. How could it be otherwise?
- NoGravitas 10y agoYou know that, and I know that, but it has to be made explicit for journalists and the general public to understand it.
- homakov 10y agoThere was no bypass of encryption.
- neotek 10y ago"There is an extreme proliferation risk in the development of cyber 'weapons'," says man eagerly proliferating cyber weapons.
- debatem1 10y agoWhile I'm glad they published this much, I wish they had published the tools themselves. As is, this is really just enough information to get worried and not enough to fix anything.
- teekert 10y agoHad the CIA's efforts been targetted towards improving encryption and security, US citizens and its government may well have had the ability to communicate safely. They may well have been able to trust new smart gadgets such as smart TVs and smart phones. Instead the CIA aided the nefarious people of the world by not reporting and exploiting security holes in devices used by the citizens it should protect. Now it has leaked said exploits and the CIA has helped their enemies in spying on every aspect of US life to a degree never seen before.
- nkassis 10y agoThat's part of the NSA's mission.
- gressquel 10y agoI looked through the leak, they promised source codes, all I found was source codes from various public projects. For the CIA tools, there was only descriptions and guides to how to get it implemented and in use, not the actual source code.
- tannhauser23 10y agoWikileaks said they have the source code but they're not releasing it for now: "Wikileaks has carefully reviewed the "Year Zero" disclosure and published substantive CIA documentation while avoiding the distribution of 'armed' cyberweapons until a consensus emerges on the technical and political nature of the CIA's program and how such 'weapons' should analyzed, disarmed and published." Source: https://wikileaks.org/ciav7p1/ https://wikileaks.org/ciav7p1/
- sand500 10y agoSend vulnerabilities to appropriate software vendor, wait 30-90 days then release to web publically?
- deleted 10y ago[deleted]
- zepto 10y agoWhen will people stop pretending that Wikileaks is anything other than an anti-American political faction that is allied with Russia? If Assange truly believed in transparency and a new kind of open democracy, he would stop preferentially targeting the US and get on with showing the world how all of our governments are the same in this regard.
- angry-hacker 10y agoBut Russia is not even trying to show they care about democracy or all the rights U.S preaches. We already know what Russia is.
- zepto 10y agoAre you suggesting that the two are the same?
- jowiar 10y agoQuit with the fucking conspiracy theories. Seriously -- can we get a fucking mod in here to get rid of this shit.
- dmix 10y agoI support your plea for avoiding hysteria but this stuff passed dismissal as mere conspiracy long ago. All plausible angles must be considered with this stuff. The CIA and FSB are in the business of deniability so it takes more than just a surface level reality check to discredit.
- jowiar 10y agoI live in DC, and have a bunch of friends in common with Seth. The crowd of tinfoil-hat-wearing jackasses spreading this bullshit do nothing but continue to cause pain for his family and friends. Y'all can hide behind your keyboards, but there are real people here. Think about them for a change.
- dmix 10y agoFair enough, the Seth reference was probably unwise. Wikileaks has responded to these claims saying that they weren't implying that Seth was the leaker or that the murder was in any way related to the publication. https://twitter.com/wikileaks/status/763565863861616640/photo/1 https://twitter.com/wikileaks/status/763565863861616640/phot... (Although I don't think deleting random comments on HN will help stop people spreading the conspiracy and that wasn't the only point the OP made)
- praneshp 10y agoKudos for standing up for your friend. Sorry your comment got downvoted, and will probably end up flagged.
- andihow 10y agoshill detected
- elif 10y ago
- rgacote 10y agoGlad to see CIA hackers are Dr. Who fans! "Weeping Angel" makes it look like a Samsung television is off while it is really on and recording the room. Precisely what the Weeping Angel does during the Dr's first encounter.
- rattray 10y agoThese techniques permit the CIA to bypass the encryption of WhatsApp, Signal, Telegram, Wiebo, Confide and Cloackman by hacking the "smart" phones that they run on and collecting audio and message traffic before encryption is applied.
- RichardHeart 10y agoYou know the expense of doing this is over 100 Billion a year (especially if you include lost business for American corps over the mistrust). You have to wonder what the upside is, in dollars. I have to imagine its very, very low, and perhaps only justified in having a lottery ticket to prevent an extinction level event like WW3?
- anigbrowl 10y agoIt's like nuclear weapons; if you don't have one, then you're nobody, if you do then you're untouchable, at least by conventional means.
- booleandilemma 10y ago[Deleted]
- cloakandswagger 10y agoRTFA. They didn't release the tools.
- kregasaurusrex 10y agoI found the Windows exploits dealing with legacy fax DLL's to be comical. It's arguably the lowest hanging fruit that continues to be the crux of proper security practices.
- Keyframe 10y agoIs anyone actually surprised? Even military has USCYBERCOM. What do you think their type of 'weapons' are? My only surprise it that this has leaked.
- doubt_me 10y agoI am surprised it took this long to leak. There is no possible way they didn't expect this to happen eventually.
- dmix 10y agoI'm surprised so much of this work done by NSA is being duplicated by the CIA. Not just a waste of tax payer money but also an even larger risk of lacking oversight than NSA. We all knew NSA was doing this stuff and dug into their oversight mechanisms. But the CIA is a larger and better funded organization than the NSA, so the implications of this are as large as the Snowden stuff. Not to mention that before Obama left office he made intel sharing between these agencies and domestic agencies even easier. So this can't easily be dismissed as 'not surprising that spy agencies are hacking foreign entities'. This just provides further insight into how widespread these powerful tools are within the US government. Whether it's surprising or not is not really the only relevant question.
- chatmasta 10y agoInteresting page titled "ConnectifyMe Research" [0] appears to be reverse engineering Connectify [1], which is an In-Q-Tel funded project! [0] https://wikileaks.org/ciav7p1/cms/page_16385111.html https://wikileaks.org/ciav7p1/cms/page_16385111.html [1] https://en.wikipedia.org/wiki/Connectify https://en.wikipedia.org/wiki/Connectify
- randiantech 10y agoI think it would be completely fair to see all countries affected by CIA's hacking to take the exact actions US did with Russia.
- agumonkey 10y agotorrent for distribution https://file.wikileaks.org/torrent/WikiLeaks-Year-Zero-2017-v1.7z.torrent https://file.wikileaks.org/torrent/WikiLeaks-Year-Zero-2017-... ps: Password: SplinterItIntoAThousandPiecesAndScatterItIntoTheWinds Hash: 7BF9A9F2A2809E13BD57A96A360725F1688A0D51
- arca_vorago 10y agoTaking the chance to vent just a bit. These are the sort of things I have been telling people about but have been derided as paranoid and a conspiracy theorist. The Samsung TV was a great example of this, which I called would be more than just samsung sending voice data. Also, so many people have loved to respond to people talking about this with some variation of, "but you're not important, why would they bug you". It really makes me wonder how often those responses were sock puppets attempting to control and derail the narrative, but criticisms like that are so trite eand easily debated. I have spent a lot of time since the Iraq war (USMC), trying to understand how we got entangled in such a fucking mess, and have continually come to the conclusion that the deep state, of which the CIA is a major part, has actively been working against what I consider the true interests of the United States. While I agree we need an international intelligence collection unit, let's not forget that originally the CIA's mandate was just to almagamate intelligence from military intelligence units, not to go do shadow operations all over the globe. Truman even wrote an article about how that was not his intention after the JFK assassination, but the article only ran once and Dulles personally flew out to talk to him about a retraction. Ok, though, perhaps that ship has sailed, and ops are a permanent part of collection. My issue then, is with the disparity between operational intention and what I consider true national interests. I understand a certain amount of realpolitik pragmatism is necessary in the function of nation states and diplomatic international affairs, but I think it has become realpolitik run amok with no anchor on core principles, creating blowback after blowback, to the point that such blowback no longer just seems like incompetence and seems like intentional malice. Never forget where the CIA came from. It was formed as the OSS by Wall Street Bankers/Lawyers with help from the much older MI6! Those foundations have largely been maintained through their selection process (Yale skull and bones/wolf/scroll and key heavy) The main connection I have eeked out that I don't think most understand though is the relationship between the Wall Street group and The City of London/Vatican/Swiss Banking groups and their many associated secret society groups and orders of knighthood. In the end, I have postulated that the corruption of the country has been top down, and deliberate. The CIA is a key node point in this corruption, and I question their loyalty to the constitution. Compartmentalization has been used and abused to the point that the mostly good worker bees doing the intel work don't understand the bigger picture plays at work here, and I think it is telling that the decryption passphrase was JFK talking about scattering them to a thousand winds. There is plenty of evidence that The Company has been operating domestically, unconstitutionally, and against their mandate, for quite some time. I promise you these tools have been used domestically on American whistleblowers, dissidents, and general rabbelrousers considered enemies of the the company. This has been the danger I have been speaking about with the total surveillance state, because now between the company and the agency, all will take is a few turns of some keys and the totalitarian dystopia is fulling engaged, and if you think this was ever about national security I have a bridge to sell you in the pacific. Of course there will be those who claim releases like this are a detriment to national security, and what I claim is the fact that these tools have been used domestically for the purposes of the deep state is the real threat to national security. The agency and the company should be working to help us secure our systems, not NSL gagging tech companies to insert backdoors or give the source so they can do their own 0days, so don't fall for the inevitable cries of but this hurts us and is legitimate. I mean there is evidence they were even corrupting NIST committees! This kind of bullshit is not about national security. I can't believe how easily people accept unconstitutional moves as long as some offical or other claims national security (usually with no evidence). This is about the deep state maintaining power. For us, the hackers and geeks of the world, they left us alone for a bit, after they lost the 90's cryptowars. It's back on though. This is the danger of tivoization, of proprietary licenses, of closed source code (including BSD licenses that allow such actions). We need to open source everything, start encrypting everything, and making it easier for the layman to use the tools. Stop using windows and osx, even for gaming. Stop installing windows at your business. Start using HIDS like OSSEC. Start checking your logs. Start checking your checksums. Start hardening your systems and your kernel (grsec). Stop using stock android, and don't use IOS. Desoder microphones on systems. Build faraday cages. Get an SDR and do bug sweeps. When the surveillance engine is turned on, FOSS hackers will be the only ones free.
- frogpelt 10y agoThose who live by the sword will die by the sword.
- MrNoad 10y agoSontaran and weeping angel? Well somebody go get The Doctor.
- thraway2016 10y agoAny guesses on why CNN and MSNBC are completely avoiding reporting this news?
- acdha 10y agoBecause the story broke this morning and it takes time for someone to read the dump, write a story, get comments from technical experts, etc? There's not really a big dramatic revelation here – “Intelligence agency spies on people - film at 11!” – so they probably aren't pulling people off of bigger stories to cover it.
- angry-hacker 10y agoBecause they are too busy reporting "not fake news" such as: "Alec Baldwin says he might give up his Trump impression on 'SNL'". If you get your news from CNN, you're brainwashed.
- Aaron1011 10y agohttp://money.cnn.com/2017/03/07/technology/wikileaks-cia-hacking/ http://money.cnn.com/2017/03/07/technology/wikileaks-cia-hac... http://www.msnbc.com/andrea-mitchell-reports/watch/former-cia-director-wikileaks-dump-could-be-very-damaging-892208195559 http://www.msnbc.com/andrea-mitchell-reports/watch/former-ci... "Completely avoiding"?
- mikeyouse 10y agoIt's like 80% of the first page real estate on MSNBC right now: https://i.imgur.com/KDLbXOx.png https://i.imgur.com/KDLbXOx.png
- alxdistill 10y agoMaybe this is a stupid question but how does one go about verifying the information wikileaks releases is accurate? I assume the people who submit info are verified in some way, does wikileaks then pass on that verification info to the public or are we supposed to just trust that they are providing truthful information in an unbiased way?
- elif 10y agofor many of the emails, including a lot of the important ones, we have DKIM signing proving that the body and most headers were unaltered and came from the sending domain's actual server. For the rest, there is no absolute mathematical proof so indeed we must rely upon the lack of counter-claims of legitimacy and the validity of the presented facts themselves. Knowing how grey that area can be, WL takes great care to release only when they have high confidence their reputation can't be harmed by claims. It is certainly a higher bar than is set by the anonymous-quote-happy US press.
- ww520 10y agoWikileaks has pretty good track record. I believe so far every single one of the leaks have turned out true, or no one has challenged their authenticity.
- 1_2__3 10y agoWhich is it? Your phrasing implies those are the same thing. They're not.
- monochromatic 10y agoThey're not the same, but they're pretty well indistinguishable for anyone who isn't omniscient.
- chatmasta 10y agoThe CIA has a long standing "no comment" policy when asked about the authenticity of any documents. So you can't rely on the absence of a counter-claim to prove the veracity of the documents. I wouldn't rule out an intentional leak to spread misinformation.
- deleted 10y ago[deleted]
- ataur 10y agoMakes me think of this article about the American surveillance state http://harvardmagazine.com/2017/01/the-watchers http://harvardmagazine.com/2017/01/the-watchers
- luckydude 10y agoHas anyone with a clue actually gone over the code? If so, is there a description of how it works? Unless things like smart TV's are shipped with malware, or unless they reach out and ask for malware and install it themselves, wouldn't having all your devices behind a NAT box make all this stuff benign? Or am I too naive?
- socmag 10y agoIt seems to be a dump of a git "wiki" that is shared between a bunch of devs within the agency. The content mostly centers around typical wiki style documents where developers are chatting between each other and leaving useful snippets of code and discussing different attack vectors and approaches. It's organized into folders relating to different technologies, platforms and tools. There isn't a "use me to gain root on an iPhone" program anywhere that I can see, although there are some hints that those things actually exist in the main git repo. In general there seems to be a lot of information on performing pre-cursor work to get devices into a state where they can be compromised via firmware rewrites etc. There is quite a lot of interesting information that I'm sure will be of use in hardening systems in years to come, so it isn't all bad news. It reads as kind of a "Book of tips and tricks" mainly as well as the results of various attack attempts. Linux seems very low on the list in priorities for attack development. I did see something about opening a side channel inside an SSH session, but it doesn't seem to be a focus. "X capability that injects a pthread into an OpenSSH client process creating a surreptitious sub-channel to the remote computer." Certainly looks like they are having a lot of fun attacking Windows boxes and Apple phones mainly, plus Android devices and a smattering of common routers and other gear. They also seem to have a great sense of humor. Some of the comments are hilarious, as are their project code-names. I laughed at the code sample for a Windows keyboard logger using DirectInput. Does that thing really work? :-)
- jjawssd 10y agoIf I was CIA and I wanted to waste time by arguing and distracting forum readers, what would I be posting in this thread?
- moonshinefe 10y agoShhh, look over there. Russians and Julian Assange's agenda! You don't want to weaken the US do you?
- anigbrowl 10y agoIf I were the CIA I'd be quite pleased for people to know how clever and powerful I am so they don't mess with me. Human assets are rare and precious, but I have no problem flinging a few technological ducats in the general direction of the peasants. This may or may not be an accurate read of events, but in my view many major 'leaks' of recent years are backdoor propaganda; the State Department Cable archive was embarrassing only if you consider it as a leak, but a really great way to express our government's outlook on a wide variety of topics that would result in conflict if done through formal channels. One can't really know what teh motivations of the people revealing teh information is, and one can imagine many benefits as well as headaches from its release, so it's best not to get too invested in any one one model.
- ryanisnan 10y agoSince the inception of Smart TV's, I've often wondered, is it still possible to buy a modern "stupid" TV?
- angry-hacker 10y agoA monitor maybe? Not that they make that big ones... maybe buy a big panel, build a frame or mount it inside the wall.
- tomjakubowski 10y agoYes, but you have to shell out more money. Look up "digital signage" displays.
- unfunco 10y agoGood design is as little design as possible. I bought a Bravia, it doesn't connect to the Internet and it doesn't have a camera or microphone aimed at me, it performs quite well at being a television.
- astrange 10y agoYou can just not tell it your wifi password.
- mikeyouse 10y agoI did that and manually set my IP address to 1.1.1.1 with a 255.255.255.255 subnet mask. I figure that's one more level of protection so if my wireless radio can be turned it, it won't be able to connect to a network that's baked into the firmware or something. (E.g. if Samsung has a test net that their TVs automatically connect to if in range.)
- pinaceae 10y agoSo what exactly is the goal of this leak beyond embarrassing and weakening the US?
- drvdevd 10y agoI just have to say... glossing over the details quite a bit, not reading the article. Mostly I've just read peoples' thoughts on here and Twitter. But my initial gut feeling/reaction about this news is that it's distinctly un-interesting as compared with, say, Shadow Brokers or Snowden. Just my initial reaction...
- mrpippy 10y agoAlso: OmniGraffle and Sublime Text license keys (registered to "Affinity Computer Technology") https://wikileaks.org/ciav7p1/cms/page_25264141.html https://wikileaks.org/ciav7p1/cms/page_25264141.html https://wikileaks.org/ciav7p1/cms/page_9535650.html https://wikileaks.org/ciav7p1/cms/page_9535650.html
- mo17i 10y agoI tried Sublime Text license key and it worked!
- thecynh 10y agoAren't they verified server-side somehow? … I assumed the 10 seats would have been gone almost immediately.
- codezero 10y agoAccording to LittleSnitch Omnigaffle 5 doesn't phone home at least when entering license keys. It may do so at some other time though.
- subroutine 10y agoSpeaking of little snitch... http://i.imgur.com/JR5Ehbc.png http://i.imgur.com/JR5Ehbc.png
- djsumdog 10y agoCongratulations. You're on (another) list.
- mrlatinos 10y agoOoo now I can say my text editor is commissioned by the CIA!
- jlgaddis 10y ago
- ptrptr 10y agoCan anyone confirm that due to SIP in 10.10 it won't work on newer version of macOS?
- deleted 10y ago[deleted]
- Animats 10y agoThe Samsung TV attack seems rather lame. The attack apparently has to be installed via a USB device, which means somebody has to physically reach the TV. If you can get that far, there are other ways to plant a bug. The documents don't indicate they've been able to install it remotely. Looking into remote update was on the to-do list. There's little interesting technical detail in any of this. It looks like stuff that would be classified CONFIDENTIAL; it's mildly embarrassing, but doesn't give much away.
- whiskeySix 10y agoSo... uh... where can one find these tools? Asking for a friend.
- futurebnd 10y agoThis one is great: '* Linksys WRT54G flashed with DD-WRT v24sp2 used as surrogate for testing MikroTik MIPS-LE binaries. No actual RouterBoard (i.e. MikroTik) hardware was used https://wikileaks.org/ciav7p1/cms/files/UsersGuide.pdf https://wikileaks.org/ciav7p1/cms/files/UsersGuide.pdf
- aRationalMoose 10y agojust saw half of these comments on /r/hacking. literally word for word.
- abandonliberty 10y agoIt's interesting to note that Julian Assange didn't demonstrate control of the wikileaks private key during his Reddit AMA 1 month ago: https://www.reddit.com/r/IAmA/comments/5n58sm/i_am_julian_assange_founder_of_wikileaks_ask_me/dc8pgqr/ https://www.reddit.com/r/IAmA/comments/5n58sm/i_am_julian_as... Considering the political situation unfolding in the US and who this leak weakens, there is some evidence that wikileaks is not in the hands of a neutral party. There is clear motive right now for undermining the CIA. This may not have been an act of altruism like Snowden. While shockingly damaging to the American arsenal, the CIA is by far the biggest loser. This comment was immediately down voted on Reddit. Someone is seeking to control the narrative.
- Daishiman 10y agoI think that anyone who has been following the Wikileaks social media accounts has noticed what can only be described as a blatant subverting of those accounts by another party.
- tmccrmck 10y agoWhat are some examples?
- eli_gottlieb 10y agoJulian Assange can't demonstrate control over the Wikileaks key. That's a pretty damn solid canary for control over Wikileaks being out of the proper hands.
- deleted 10y ago[deleted]
- coldtea 10y agoCan't or won't?
- Daishiman 10y agoThe insane, continued obsession over Hillary's emails and the phrasing of the social media accounts is definitely not congruent with the clear-headed logic and essays that Assange has written in the Wikileaks manifesto, "Cypherpunks", and others. The Wikileaks Twitter handle just used a Fox News video as evidence for something. You could say the man's gone insane, but the theory of these accounts and the WL org being subverted by a state power sounds more plausible at this point.
- EternalData 10y agoI applaud what seems like a coordinated attempt to outdo each other when it comes to extreme transparency. 1) Wikileaks revealing the CIA has undermined consumer goods with malware. (this looks like a bigger deal than the Snowden revelations on the NSA side). 2) Russian opposition leader Navalny revealing that former Russian President Medvedev has been accused of amassing a billion-dollar plus property empire, based largely on bribes and subterfuge. I can only hope this extreme transparency, despite the biases of its torchbearers, lights its way into every hall of power from the White House to the Great Hall of the People.
- ExactoKnight 10y agoConspiracy as Governance. Assange wrote a paper predicting this 10 years ago as his vision, and it's clearly coming true: https://www.wired.com/2016/10/want-know-julian-assanges-endgame-told-decade-ago/ https://www.wired.com/2016/10/want-know-julian-assanges-endg...
- myegorov 10y agoLooks like the CIA is screwing the public by mutual consent. The public is demanding more of the same, just as long as it's directed at whoever is out their favor. Here're the two topmost comments on NYT at the moment[0]: karma2013 New Jersey 3 hours ago If anyone still has doubts that Wikileaks and the Russians are working together to undermine and destabilize our government institutions, erode public confidence in our government, and generally wreak havoc in our country, this latest document dump should erase all doubt. We are under attack by an adversarial nation, with a President here at the helm who seems not to take any of this seriously. Spy agencies spy, this should come as no shock -- this is how they infiltrate potential terrorist plots against America and keep us safe. We are less safe today thanks to Wikileaks and Assange's unholy alliance with Putin.. Thomas Marin County, CA 3 hours ago Where's the hacking of trump's taxes and his Russian connections?? This information is needed NOW! [0]https://www.nytimes.com/2017/03/07/world/europe/wikileaks-cia-hacking.html https://www.nytimes.com/2017/03/07/world/europe/wikileaks-ci...
- goodroot 10y agoThe assumption here is that those people are part of the public and are not shilling a 'more correct record'.
- foxfaction 10y agoJust for your own knowledge, Correct the Record was dissolved after the election and the primary internet PR organization is now called "Share Blue"
- nosuchthing 10y agoIf you've spent anytime on twitter or reddit lately, there's an increasingly large amount of political astroturfing from special interest organizations. https://en.wikipedia.org/wiki/50_Cent_Party https://en.wikipedia.org/wiki/50_Cent_Party http://www.sfgate.com/technology/businessinsider/article/US-Government-Funded-Domestic-Propaganda-Has-4668001.php http://www.sfgate.com/technology/businessinsider/article/US-... https://en.wikipedia.org/wiki/Smith-Mundt_Modernization_Act_of_2012#Smith-Mundt_Modernization_Act_of_2012 https://en.wikipedia.org/wiki/Smith-Mundt_Modernization_Act_... https://www.theguardian.com/technology/2011/mar/17/us-spy-operation-social-networks https://www.theguardian.com/technology/2011/mar/17/us-spy-op...
- SadWebDeveloper 10y agomeh CIA tools still require "intervention" or well "manually infecting things", on the other hand NSA tools don't... so the day, all the NSA tools gets available then it will be doomsday for all sysadmins in the world.
- staunch 10y agoThe technology used by the CIA and NSA is all stuff people on HN can totally grok. That's kind of exciting and disappointing at the same time. Some people on this site could probably do better than the CIA and NSA is doing. Some people here probably wrote some of leaked stuff. Hah! I like the way the teams are broken up by device target but I think they should probably have an even more decentralized setup. Or maybe just more teams doing the same work. Wikileaks tries to make a political point about wasted effort, but more people means more exploits found, etc.
- defgeneric 10y agoSaw this at a glance: > Add to your Vim configuration: " :w!! " write the file when you accidentally opened it without the right (root) privileges cmap w!! w !sudo tee % > /dev/null https://wikileaks.org/ciav7p1/cms/page_4849889.html https://wikileaks.org/ciav7p1/cms/page_4849889.html Much of it is like this, little recipes ranging from building EFI executables to setting up a Debian machine and so on. Like collected stackoverflow answers. It's interesting to see how they write up these little how-tos in a way that gets the reader very quickly up to speed and hacking on a particular problem.
- jlgaddis 10y ago> The technology used by the CIA and NSA is all stuff people on HN can totally grok. Yep, the typical stuff: CentOS, Debian, Ubuntu, Python, Ansible, Packer(.io), vim, Sublime Text, SourceTree, Git, ... Plenty of references to Stack Overflow, Reddit, and such too.
- rand83746 10y agoAnd this whole thing seems to be a Confluence dump.
- rodionos 10y ago> Self-delete is used to insure that any Hive implant that lays dormant ... for a predetermined amount of time > effectively destroys itself with the only remnant being a “configuration file” > (.config) and a log file (.log) left behind in /var directory. .log & .config in /var
- samstave 10y agoCIA: "Hey! lets see how the whole world responds to this 'leak' while we know we are 10+ years ahead of them... lets figure out how they all responds, the fucking idiots....
- lngnmn 10y agoLooks like a fake. Tons of publicly available crap in the files section and 3 pdfs with words SECRET and even TOP-SECRET in the names. This could be a dump of any amateur team whatsoever with just these 3 files added.
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- davesque 10y agoHonestly, what's the news here? The US's top spy agency is engaged in spy activity? This shouldn't come as a surprise to anyone just as it shouldn't have surprised anyone that Russians hacked the DNC. What's more interesting and important to consider is the way in which this is yet another move in the information war that Russia is waging with its enemies. Their intentions in this war are not to "uncover the truth" or whatever the purported mission of Wikileaks was at one point.
- kome 10y agoIt's like a friendly reminder about how Stallman was right about everything...
- kulu2002 10y agoThat's absolutely true!
- devopscicle 10y agoHey, not even the CIA can crack the Intel management engine.
- jl6 10y agoI'll add my view that I don't see this as being all that surprising. Didn't we all expect that this is the sort of thing that TLA's get up to behind closed doors? My main complaint is that even though I'm otherwise fairly well aligned to the US (ideals, principles, culture and such), I'm not a US citizen and therefore get treated as an enemy :(
- no_wizard 10y agoI feel like this might get lost in the shuffle, so I'm posting it independently. I'm not shocked at any of this. The writing has been on the wall as early as 2001 that the NSA and CIA has been gearing up and building these exploits out. Here is a nice PBS documentary on the subject of FISA & NSA surveillance, and of course the CIA is no lone wolf, these agencies were given carte blanche by previous administrations to work together. While I believe they are different in aspects of what they do, from this perspective, I think its fair to say that likely if the CIA has it, the NSA has it, and if the NSA has it, the CIA most likely has it or can get it. To illustrate a nice timely, take a look at this gem from 2001 https://ca.pbslearningmedia.org/resource/fl32-soc-ussfisa/united-states-of-secrets-warrantless-wiretapping/ https://ca.pbslearningmedia.org/resource/fl32-soc-ussfisa/un... Around the same time, we even had this pop up: its a run down as to why the NSA needs to have this 'legal authority' to act with impunity for 'American interests' http://nsarchive.gwu.edu/NSAEBB/NSAEBB178/surv34.pdf http://nsarchive.gwu.edu/NSAEBB/NSAEBB178/surv34.pdf and of course, we have the NPR story that breaks it all down over the NSA wiretapping debate: http://www.npr.org/news/specials/nsawiretap/legality.html http://www.npr.org/news/specials/nsawiretap/legality.html Take special note here: hardly any at length commentary at all so far and the news is pretty sparse. Largely, it seems people were not paying attention, yet right here its clear as day that the NSA was gearing up to expand and use its surveillance capabilities. Of course, around all this, it is clear the NSA and the CIA would be sharing exploits like these, it is likely these were all used in joint context with each other: https://www.cia.gov/library/readingroom/docs/DOC_0006184107.pdf https://www.cia.gov/library/readingroom/docs/DOC_0006184107.... and of course, the ACLU has a relevant statement on this as well, i think its quite a good summary of the feelings at the time: https://www.aclu.org/other/how-anti-terrorism-bill-puts-cia-back-business-spying-americans https://www.aclu.org/other/how-anti-terrorism-bill-puts-cia-... Then, we have these here, around 2004-2006: The first real report coming out is from the ACLU, reporting about the NSAs massive build up since 9/11 and how its creating a lot of questionable actions to be undertaken by the agency, in which they allege, at the time, among other things, that the NSA is spying on US citizens: https://www.aclu.org/files/FilesPDFs/surveillance_report.pdf https://www.aclu.org/files/FilesPDFs/surveillance_report.pdf My favorite quote: National Security Letters. These obscure devices, which can be written by FBI officials in field offices without the approval of a judge, give the government broad power to demand records. Once upon a time this sweeping power could only be used to get information about “agents of a foreign power” from banks, credit agencies and Internet service providers. But the Patriot Act changed the law to allow their use against anyone, including persons not suspected of a crime. The bill quietly signed into law by President Bush in December 2003 but wait, there is more! Around the same time, the GAO had noted that there was an increasing amount of trouble coming from cyber security experts about cybersecurity infrastructure in the states. How easy they were to exploit, their threat to infrastructure, and how it could affect people. How is this related? This same type of report details alot of the exploits that the NSA has used, such as stuxnet, which come to light many years later: http://www.gao.gov/new.items/d04321.pdf http://www.gao.gov/new.items/d04321.pdf and less us not forget, the NSA tried to sway attention away from itself by releasing this tidy memo, which got leaked, in and around 2004: https://epic.org/privacy/nsa/foia/EPIC-NSA-USSID-18-and-Domestic-Procedures.pdf https://epic.org/privacy/nsa/foia/EPIC-NSA-USSID-18-and-Dome... In which they promise to quote 'no longer use their spying apparatus on US citizens knowingly'(i'm paraphrasing) and of course, We have this report from 2006 from the Indiana Law Journal detailing all of the potential pitfalls and abuses of the FISA courts. In essence, to sum it all up, it states: Accordingly, to extend the “special needs” doctrine to the NSA program, which authorizes unlimited warrantless wiretapping of the most private of conversations without statutory authority, judicial review, or probable cause, would be to render that doctrine unrecognizable. The DOJ’s efforts to fit the square peg of NSA surveillance into the round hole of the “special needs” doctrine only underscores the grave constitutional concerns that this program raises oh and i didn't forget: we got concrete evidence of state sponsored Russian hacking against US systems since as early as 2008: http://nsarchive.gwu.edu/NSAEBB/NSAEBB424/docs/Cyber-027.pdf http://nsarchive.gwu.edu/NSAEBB/NSAEBB424/docs/Cyber-027.pdf relevant quote: The head of the Russian Army Centre for Military Forecast, Colonel Anatoly Tsyganok, made comments to the Russian news outlet, Gazeta, about the cyber attacks on Estonia. He believes that there was nothing wrong with the attacks because there are no international agreements established. Colonel Tsyganok also believes that NATO couldn’t do anything to stop the attacks and that they were highly successful. The most telling example of Russian government involvement in cyber warfare was with Herman Simm selling IT secrets to the Russian Foreign Intelligence Service that was discussed in Section VIII of this monograph. This case showed that the government of the Russian Federation is actively seeking information on cyber defenses and is willing to pay large sums of money (Mr.Simm is accused of selling cyber security secrets for millions of dollars) to receive information on cyber security. I feel like the tech public that should be doing the diligence on this has been asleep at the wheel. On the recent stories from NSA surveillance, the CIA leak we are reading here, or other government programs. Its not crackpot. Its not a conspiracy. The evidence has been out there in our faces for years. I feel like we fell asleep at the wheel as a tech community to stand up to this.
- jungletime 10y agoWikileaks seems to be supporting Trump as the lesser of two evils. Why they see the other side as more evil, is not entirely clear, or on what information it is based on. it could be they know more than we, and can't release it. Or it could be something like getting revenge for the apparent assassination of DNC leaker.
- jwtadvice 10y agoAnyone in the know how about whether the CIA subverted the security of software or whether they inserted vulnerabilities into software? One of the shocking and disgusting things from the NSA leaks was that it actively sought to create new vulnerabilities and to create subverted software industry products in the United States. So far it looks like the CIA is using discovered vulnerabilities (imo better than sabotaging industry). But given the size of the leaks I'm having difficulty confirming that this is indeed the case.
- Frogolocalypse 10y agoThe solution is for the US to ensure vulnerabilities are identified and patched.
- Florin_Andrei 10y ago> the omission of emails pertaining to russia creates a narrative. Maybe Assange dislikes the taste of polonium in his tea, or something.
- Bogdanovich 10y agoHe hiding from the United States in Ecuadorian Embassy for many years. No surprise he is biased against US. Unites States pretends to be the country that does 'good' things, and blames all other countries that do 'bad' things. That's why Snowden is so painful, and Assange is so painful.
- giaour 10y agoAssange is hiding from the government of the United Kingdom, which has agreed to extradite him to Sweden, where he faces trial for rape.
- hollander 10y agoThis is an excellent example of telling the facts while distracting from the truth. He's afraid that he will be extradited to the US after being extradited to Sweden. The rape accusations are thought to be just a trick to get him to Sweden. If he had the guarantee that he would not be extradited he would go to Sweden immediately.
- Ntrails 10y ago> If he had the guarantee that he would not be extradited he would go to Sweden immediately. He can claim this, allowing him to imply that he is of course innocent, safe in the knowledge that it's impossible for the Swedish prosecutor to make such a guarantee.
- benedikt 10y agoAlso Sweden does not extradite anyone that has a chance of facing the death penalty. And Assange said he would allow himself to be extradited to if Manning was commuted. She was, Assange is still in the Ecuadorian embassy. The UK has much favourable extradition treaties with the US than Sweden has.
- Sinbe 10y agoIs it legal to access the docs on wikileaks? is it legal to post a link here to those docs?
- exabrial 10y agoI'll be really honest... I don't think any of the stuff I've seen so far is "news". We already know our smartphones, tvs, and IOTs are very vulnerable to attack. Shouldn't we expect intelligence agencies to take advantage of it? The only "real" news would be if the Trump administration plans to continue the illegal monitoring of US citizens without warrants from the previous administration.
- Girlang 10y agoWhat's wrong with the CIA spying on non-citizens abroad?
- marmot777 10y agoIn media accounts, I keep seeing quotes that cyber security experts were alarmed by the revelations. I'm no expert but to me all of the revelations have been open secrets for years. Are cyber security experts really alarmed by the revelations? I'm not saying the info itself isn't alarming but "alarmed" implies shocked by information you didn't already know about. It occured to me that some of these experts could have their own motives (promotion?) for getting quoted in the media. What am I missing in my understanding of this in saying that I wasn't alarmed (in the sense of surprised) by anything I've read so far? Most of the source code they released has been circulating for several years? This is basically publicity for already existing open secrets? That is, this was an act of political theatre?
- benkarst 10y agoDoes anyone have any comments about technical aspects of the documents released? Seeing how this is Hacker News and all...
- c0nsume 10y agoYeah, this to me is the wiki of an average tech startup. Lots of mundane stuff like how to use git, how to install wireshark. If you don't know how to install wireshark or how to use git maybe you shouldn't be in the fucking CIA trying to defend the country from foreign adversaries. Not because these things show proficiency in being a 'tech' person, but because one would expect a well funded intelligence agency to be far beyond the use of popular pc tools. While I'm sure there are some advanced researchers there, it makes me wonder where the pros work. The Chinese or Russians sure as shit are not sitting in a lab somewhere trying to install wireshark.
- dangSuxAlienDik 10y agoTHE ECOLI IN GMO FOODS IS MICROSCOPIC UFOS They secretly swapped out most of the corn syrup to be GMO Corn syrup >read every soda, cereal, cake, candy bar, cookie, donut, fruit bar, fiber bar THEREFORE 1000s OF VIRAL DOSES PER PERSON PER YEAR And one year here, down there is 100,000,000 years or some shit, so they breed MILLIONS THEY SNUCK ECOLI into GMO FOODS, escpecially gmo corn syrup, increasing the vaccine/ufo dosage of americans 10000% or more. ECOLI AND VACCINES ARE LITTLE UFOS r eddit.com/r/conspiracy/comments/5xrt9i/vaccines_virus_are_little_ufos_graphs_and_details/ for those of you with your 3rd eyes its super easy to prove: just look in ur body and say dont show me ur ufo at the arm you were injected in or find a hormone and ask it if it has a boyfriend, lays eggs etc put a mosquito on ur desk in a plastic bag and try to visualize its UFO super easy
- known 10y agoThank you Assange; "Never do anything against conscience even if the state demands it." --Einstein
- SomeStupidPoint 10y agoI... Uh... I'm disturbed by lots of things the CIA does, and I'm sure there's something incriminating in here. But isn't it a little weird we're suddenly talking about the CIA's capability instead of the investigation in to the administration's Russian connections? You know, the one that seems to have every high level official with illicit contact, including the AG lying about contact to Congress and a campaign adviser making serious allegations just last week? We definitely have to do something about the CIA and their shenanigans, but this "leak" is mostly them doing their job effectively made out to be scary by people with a known bias. Maybe we can stop chasing random scary thing, and focus on the election that had a major PSYOP by a foreign power that resulted in an administration with unusual to illicit ties to that foreign power. Im all for holding out intel community to account for their behavior, but now isn't really the time for it. We have more major issues to deal with.
- aussieguy1234 10y agoWikileaks has the code for these tools but wisely didn't release it. Hopefully they will notify vendors of the security vulnerabilities being exploited
- jankedeen 10y agoPoisoning or making disclosure questionable the public medium of communication has long been the control mechanism of autocracy. We have known for a long time that some governments and vested interests have no interest in critical discourse regarding their basic mythologies of substance and staple. That is: if we all stood up today and said we don't believe in your economy and the dollar and democracy and evil and good they would have to kill the people who don't believe the fiction(s) or make another set of fiction(s) palatable. This effort is not unbelievable but maybe the details are unreal.
- duhhumbug 10y agoAssange was rendered to a black site before this fake interview: https://m.youtube.com/watch?v=ApG1XdI-Dd4 https://m.youtube.com/watch?v=ApG1XdI-Dd4 , where facial transfer software like this was used: https://m.youtube.com/watch?v=ApG1XdI-Dd4 https://m.youtube.com/watch?v=ApG1XdI-Dd4
- alva 10y agoQuite a lot of the twitter security scene seem to be pointing towards Hal Martin. Apparently timeline and level of classification is consistent. https://www.wsj.com/articles/former-nsa-contractor-indicted-for-stealing-top-secret-documents-1486597329 https://www.wsj.com/articles/former-nsa-contractor-indicted-...
- 69mlgsniperdad 10y agoMaybe someone can clear this one up. So from the Snowden leaks, we know the extent of the NSA toolkits and the requirements which need to be met to utilize them. Now we know what the CIA has to work with, which requires the same authorizations, however apparently they encounter less oversight/obstructions(irrelevant), and after Apple refused to unlock the San Bernardino Shooter's iPhone, we found out the FBI was playing some sort of politics, by claiming that justice might not be served without Apple's intervention, and proceeded to publicly shame the ethical position they took. So why on earth was Obama trying to force Apple's hand in that matter? Soon as Apple said no, the FBI somehow found the single magical person willing and able to defeat the privately enhanced security of the 5s the shooter carried? Makes no sense to me.
- whereisthegun 10y agoThe value of all of these electronics devices becomes increasingly smaller the more you find that they are all just listening and recording everything you do and sending that information to some powerful entity. The people who run these electronics companies might want to think about that if they have the best interests of their shareholders in mind.
- demarq 10y agoThis and every conversation on the intetnet to do with the leaks quickly devolves into "did russia do it?" The content of the leak is mind blowing, how are people not paying attention to this. No one seems to find the content shocking. It's just disappointing, especially on hn. I guess this just another thing that's going to be hypernormalized. :(
- kahrkunne 10y agoI'd just like to point out that the CIA has gone so far as to have a meme warfare department. CIA agents posting on HN is well within the realms of possibility. Don't take everything you read here at face value
- worthshare 10y agoHow we can save ourselves from this situation?
- doggydogs94 10y agoEthics aside, the CIA looks like a cool place to work. Look at the cutting edge stuff they are up to.
- the_cyber_pass 10y agoNot really, I was looking through it and it looks to me like organizations NCC group has more advanced people in it. The advantage the CIA has is you get to go all the way with exploits instead of having to restrain yourself.
- palavsen 10y agoThis is insane!