19 ms·
WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents
- misterbowfinger 10y agoAccording to the statement from WikiLeaks, government hackers can penetrate Android phones and collect “audio and message traffic before encryption is applied.” How is that possible? Isn't the data encrypted before it's sent over the wire?
- welder 10y agoMalware running on a phone can do anything it wants, take screenshots, record messages/typing, etc. Unfortunately, the article is misleading by claiming encryption was bypassed.
- mattnewton 10y agoBypass could be appropriate in the sense that it was "sidestepped", not "broken". I think it's a fine word but I don't think the average reader knows / cares about the difference.
- bilal4hmed 10y agoThats the thing, they capture the data before its sent over the wire, as you type it or speak it. you ->capture->app->encrypt
- libertymcateer 10y agoThe kernel is owned (or some part of the phone below the application level). The encryption only gets applied at the application level before the messages are sent down the wire. The interception happens prior to the encryption being applied. Think of it as a dongle on the wire between your keyboard and the computer. It doens't matter if the computer is secure - the message is intercepted prior to any encryption. This is, what I am assuming, has happened here. Edit: lots of stuff deleted for very valid criticism, as below.
- dleslie 10y agoI don't trust Google, Facebook, or anyone else who provides freemium services and has ties to the American Government. I don't understand why anyone does.
- Synaesthesia 10y agoIt's funny, I trust Apple because they're not "freemium" as in, they make their profit elsewhere. But I'm not sure I should really! After all they did participate in PRISM AFAIK
- GauntletWizard 10y agoYou're very much misrepresenting the facts. Android very much encrypts data (or gives users the option to, I'm not certain if it's the default). Chrome, the desktop application, does not. Why? Because that's a false sense of security. Chrome would have to also store the encryption key, and store it in the same place and under the same access controls as the encrypted data. This is not real protection. It is up to the user to not run malicious apps under the same security context as Chrome, and to encrypt their hard drive to protect their data at rest. Nothing that chrome can do in its security context is anything more than placebo - as shown by the fact that malware (and legitimate programs!) can read the Firefox local password database.
- libertymcateer 10y ago> Why? Because that's a false sense of security. Chrome would have to also store the encryption key, and store it in the same place and under the same access controls as the encrypted data. I hear you, but this is not the case with Safari. It offers secure local storage. It's the securesettings API. It uses the OS level encryption, and, based on the current state of play, this does not appear to be compromised. > as shown by the fact that malware (and legitimate programs!) can read the Firefox local password database. Is this also the case for Safari? I have not read anything to this effect.
- 10y ago
- guelo 10y agoThink of it as a keylogger capturing the keystrokes before the app sees them.
- ubernostrum 10y agoThe article is about the phone equivalent of installing a keylogger. Even if all the apps you type into encrypt everything end-to-end, a person capturing keystrokes still knows what you typed. This is also why every single reputable source on security is condemning the NYT for running such an irresponsible headline, since it was not about flaws in the secure messaging apps or their encryption in any way.
- ams6110 10y agoIf the device isn't secure, all bets are off. And in my opinion, if you require security that the CIA can't bypass, you won't find it in any mainstream consumer hardware or software.
- libertymcateer 10y agoEdit: deleted, for very valid criticism. Next time I won't post in a rush during work hours.
- shawnz 10y ago> Please be aware that the Chrome browser does not offer a secure local storage protocol for its developers ... Compare this to Safari, which offers secure local storage at OS level security But this is just as secure as full disk encryption of the device right?
- chrisballinger 10y agoNot for malware running in user space.
- md_ 10y agoThe browser runs in user space. Desktop OSes don't offer any sort of partitioning here. So there's very little reason to have any app-level encryption on a desktop OS.
- vetinari 10y agoRunning in user space is not enough. It would need root. It is also hard to keep root, when you have dm-verity and selinux in enforcing mode. Android applications are also sandboxed from each other. You would have hard time getting from one app to another's files, unless the original app published them - or you've got root.
- md_ 10y agoDon't take this the wrong way, but as a non-lawyer, I try to heavily caveat any statement I make about the law. Would you consider heavily caveating statements you make about information security? A lot of what you say here is basically wrong.
- dmix 10y ago
- spullara 10y agoThis headline is extremely dangerous. The phone itself was owned. No encryption was harmed by capturing the keystrokes and audio before it reaches the application. NYTimes should be ashamed of themselves for basically lying about the nature of the hacks.
- trendia 10y agoedit: apparently NYT had a different headline and changed it... ignore this post The current title [0] is wrong, but NYTimes is relatively clear: > Among other disclosures that, if confirmed, would rock the technology world, the WikiLeaks release said that the C.I.A. and allied intelligence services had managed to bypass encryption on popular phone and messaging services such as Signal, WhatsApp and Telegram. According to the statement from WikiLeaks, government hackers can penetrate Android phones and collect “audio and message traffic before encryption is applied.” It depends on how you define "bypass". In my opinion, accessing data before encryption is a form of bypassing... but it doesn't necessarily mean they can decrypt an already encrypted signal. [0] "WikiLeaks: CIA managed to bypass encryption on popular services Signal, WhatsApp " as of this writing
- t0dd 10y agoThey changed the headline: https://twitter.com/nytimes/status/839161021369573378 https://twitter.com/nytimes/status/839161021369573378 edit: A new tweet referencing the article: "WikiLeaks release said CIA managed to bypass encryption in mobile apps by compromising the entire phone"
- whatok 10y agoThey changed the tweet which I guess is factually correct but still misleading.
- 27182818284 10y agoWhen I read "bypass" I kind of read "go the alternate route. As in around the impasse" which in this case the impasse was encryption. I think a lot of people in this thread are hating on NYTimes today for this headline because of the inaccurate WhatsApp encryption news stories of recent. I could see myself being bothered if they had written that the encryption was "broken" or "cracked" as if you destroyed the boulder in your path. Bypass seems fine. Hacker News doesn't normally use bypass as a synonym for break, but for some reason today it i to the commentators
- mootopia 10y agoMention "Signal" in any article and you'll have @tptacek running here to defend it with any costs.
- deleted 10y ago[deleted]
- WillyOnWheels 10y ago> Mention "Signal" in any article and you'll have @tptacek running here to defend it with any costs. You made a new account today just for that? You would enjoy Yasha Levine https://twitter.com/search?q=%40yashalevine%20signal&src=typd https://twitter.com/search?q=%40yashalevine%20signal&src=typ...
- ncallaway 10y agoSignal doesn't even need defending here. The article claims that the CIA has compromised the Android device itself. They are intercepting communications before/after it's decrypted on the device. Signal can help make sure you're transmitting information encrypted over the wire, but it can't really help you if your device is compromised.
- mattnewton 10y agoAgreed, signal on iOS->iOS still seems unaffected.
- keknloller 10y agohaha thank you. at least some people can spot this.
- senorjazz 10y agoAs the lead developer (I think) I would expect him to counter any points made about the service to the positive or negative.
- thraway2016 10y agotptacek != moxie
- mtgx 10y agoTo me this is much more worrying: > As of October 2014 the CIA was also looking at infecting the vehicle control systems used by modern cars and trucks. The purpose of such control is not specified, but it would permit the CIA to engage in nearly undetectable assassinations. https://wikileaks.org/ciav7p1/ https://wikileaks.org/ciav7p1/ Given the fact that car makers don't even have "PC age" security in their cars, things are looking pretty bad for self-driving cars in general.
- izend 10y agohttps://en.wikipedia.org/wiki/Michael_Hastings_(journalist)#Alleged_foul_play_controversy https://en.wikipedia.org/wiki/Michael_Hastings_(journalist)#... Potential assassination?
- Synaesthesia 10y agoThese are great arguments against super power private institutions (corporations) that operate in secret and are essentially unaccountable to the public.
- 1001101 10y agoOne of the many reasons I drive a manual. RIP Michael Hastings.
- v64 10y agoMakes the conspiracy theories regarding journalist Michael Hastings' death in 2013 seem more plausible. [1] Former U.S. National Coordinator for Security, Infrastructure Protection, and Counter-terrorism Richard A. Clarke said that what is known about the crash is "consistent with a car cyber attack". He was quoted as saying "There is reason to believe that intelligence agencies for major powers — including the United States — know how to remotely seize control of a car. So if there were a cyber attack on [Hastings'] car — and I'm not saying there was, I think whoever did it would probably get away with it."[68] Cenk Uygur, friend of Hastings' and host of The Young Turks, told KTLA that many of Michael's friends were concerned that he was "in a very agitated state", saying he was "incredibly tense" and worried that his material was being surveilled by the government. Friends believed that Michael's line of work led to a "paranoid state".[80] USA Today reported that in the days before his death, Hastings believed his car was being "tampered with" and that he was scared and wanted to leave town.[81] [1] https://en.wikipedia.org/wiki/Michael_Hastings_(journalist) https://en.wikipedia.org/wiki/Michael_Hastings_(journalist)
- 234dd57d2c8dba 10y agoYawn, owning the endpoints to break encryption is nothing new and is as old as encryption. NYT is such clickbait these days.
- uladzislau 10y agoYou should consider the assumption that your security IS compromised at any given point in time (bypassed or whatever) then you could foresee and prevent some worst case scenarios which usually come from hubris nonetheless ("hey, our app is 100% secure and tested by the top security experts - not like other apps on the market").
- jt2190 10y agoThis point can't be emphasized enough. Sophisticated operators always assume they're being listened to, and take precautionary steps.
- james_niro 10y agoLol at NYT, it says that when jack into an android phone they are able to route the messages to a third party before it gets encrypted
- jMyles 10y ago> WikiLeaks, which has sometimes been accused of recklessly leaking information that could do harm Nice passive voice there, NYT.
- evjim 10y agoThis is why we should not rely on encrypted apps running on top of some other platform. disclosure: working on an open source alternative for messaging
- tripplethrendo 10y agoWouldn't you also need an encrypted os for your phone?
- evjim 10y agoA fully open source RTOS that is trusted and only running this single application. The only external communication is the encrypted messages.
- amckinlay 10y agoWe really need Qualcomm and others to document their hardware interfaces for modems, baseboards, and SoCs so that open firmware and drivers can be developed for these devices.
- sqeaky 10y agoWhile I completely and I think I understand why, could you expand on this? If I did I would probably not be as accurate as you.
- bitmapbrother 10y agoCIA Android Exploits https://wikileaks.org/ciav7p1/cms/page_11629096.html https://wikileaks.org/ciav7p1/cms/page_11629096.html As you can see they pretty much all reference very old versions of Android (v4) and Chrome.
- throwaway31763 10y agoI thought they were already compromised since both these services use SMS authentication; since the defaults AFAIK aren't particularly concerned about a change in the public key, it's broken for anything secure anyway. Tox on the other hand seems much more secure... though I guess if you're phone is compromised you're pretty much screwed to start with (which is not too hard with all the bloatware one needs these days).
- r3bl 10y agoSee this: https://github.com/TokTok/c-toxcore/issues/426 https://github.com/TokTok/c-toxcore/issues/426 Long story short: if someone obtains your Tox private key, they are able to impersonate you in the conversations with other people without you realizing it. Tox developers admitted this was an issue. Fixing this means changing the protocol itself (which will affect everyone). Tox is still experimental (which they admit here: https://github.com/TokTok/c-toxcore/issues/426 https://github.com/TokTok/c-toxcore/issues/426) and it is not advisable to use it.
- idlewords 10y agoThis headline is false and misleading, and does not reflect the headline on the article (WikiLeaks Releases Trove of Alleged C.I.A. Hacking Documents)
- palavsen 10y agoI found none of these revelations surprising. In this era, you have to assume that someone is monitoring you. You're naive if you think otherwise.
- upofadown 10y ago> According to the statement from WikiLeaks, government hackers can penetrate Android phones and collect “audio and message traffic before encryption is applied.” This a perfectly useless bit of information in that it says nothing about how this penetration could occur. Pretty much anything can be cracked with a trojan. Something like a currently valid remove exploit would be a much bigger deal. I could say that all the secure apps are broken because I can stand behind you and look over your shoulder while listening to anything you might say.
- anigbrowl 10y agoAnd people wonder why I am only lukewarm about encryption and opsec. I use both for myself, but I've given up evangelizing other people years ago because (as I've said here on HN many times): For regular people, the effort of encrypting things is simply not worth it because they're powerless against a really determined attacker. It's rational to protect against casual attacks from spammers and scammers, but protecting oneself against state-level attackers is futile unless you make a full-time job out of it. Someone usually pipes up at this point saying 'we need to limit the powers of the state', like some sternly-worded law is going to undo the existence of the technology or take away the vast economic and political incentives to deploy it. Get real folks, technology doesn't get un-invented, and powerful organizations are just like powerful organisms; they're opportunist, they maximize their own chances of survival, and when they do collapse the resulting power vacuum is filled as rapidly as any other vacuum would be. One can certainly seek to govern the behavior of a state or state organ, but attempting to limit its technical ability is naive, for the same reason that you'd be naive to try to fix police brutality by legislating about the design parameters of police batons.
- uncoder0 10y agoBesides the initial titlegore, these tools really aren't that surprising. I've always operated under the assumption that if the NSA, CIA, etc are in your threat model you've already lost.
- mattcoles 10y agoThis just in: man looking over your shoulder bypasses strongest Signal encryption!
- dang 10y agoMain discussion at https://news.ycombinator.com/item?id=13810015 https://news.ycombinator.com/item?id=13810015.
- icodestuff 10y agoGiven the other revelations of the last few weeks, I have to wonder if these exploits are getting installed on every phone that the CBP demands people unlock. Seems like the obvious thing to do. Best not to trust your phone or any software on it at least without a factory reset, and preferably a software update, after it's been in CBP custody for any time.