8 ms·
The CIA probably isn't stupid. Why would they waste attacks like the ones you listed if the silly stuff simply works for most targets. Also those "silly stuff"
by softblush 10y ago
The CIA probably isn't stupid. Why would they waste attacks like the ones you listed if the silly stuff simply works for most targets. Also those "silly stuff" things are perfect because anybody could have developed them and not necessarily a nation state actor.
Also just because some information got leaked, doesn't mean that there aren't more units / projects at the CIA where maybe the more skilled people are working and where the "good" attacks don't get leaked.
This looks to be the kind of stuff for the day in, day out operations.
- vocatus_gate 10y agoAdd to the fact that many systems around the world are woefully unpatched, so the "silly stuff" still works against them. I've done a lot of work outside the U.S., especially in 3rd world countries, and it's astounding how outdated much of the IT infrastructure is. We're talking entire networks still running pirated Windows XP and Vista.
- tptacek 10y agoThis might be true for things like exploits, where every time you use them you stand a chance of burning them, so you're incentivized to keep using whatever's working. But it's not true of rootkit and implant techniques; in fact, the opposite is true: the dumber your implants, the more likely it is that your target will discover you compromised them.
- lazaroclapp 10y agoThe more likely it is that your target will discover someone compromised them, yes. But finding a DLL injection exploit only says "hacked by someone", whereas finding a microcode-level rootkit in the CPU pretty much says "hacked by a state actor". Which, sometimes is what you want to say (see e.g. Stuxnet), but often not. If you know the first has a 99% chance of going undetected, and the second a 99.9% chance, do you always want to risk the one that pretty much acts like a calling card?
- eganist 10y agoIn Ptacek's defense (heh), I'm willing to wager those hypothetical detection rates are far off the mark by orders of magnitude. I'd expect a microcode-level rootkit to run a five-nines success rate evading detection unless used against someone who's paranoid enough to have _something_ in place to detect it, and I'd venture further that the 3LAs of the world are smart enough not to target the infosec-paranoids of the world.
- lazaroclapp 10y agoI am sure the numbers are way off, but not sure only the microcode one is. My suspicion is that against most non-intelligence targets, the DLL injection approach is quite unlikely to be found out either, at least once the initial intrusion has been accomplished. In both cases, the implants will likely only be detected if the machine in question is used to stage another attack or exfiltrate data over the network, in which case the level of the rootkit running on the host will matter very little for detection. Admittedly, the best rootkits probably target the network equipment as well as the host. At the host level, most organizations wouldn't be able to detect an unmasked trojan running as its own separate user process unless its signature was already known or its behavior caught by a blacklist-based IDS.
- the_cyber_pass 10y agoThe problem doing DLL injections is you are dropping things directly to the disk which is a great way to get AVs attention. Heuristics based detection can be a pain in the ass here and you want your rootkit to be able to be 'unique' for every installation if possible. Also rootkits are way overrated. What you do when you compromise an organization is you open a connection to your C&C on a few machines to keep your foothold if any reboot. If you need to get in you just connect to one of those boxes and just continue on. You never have to drop anything on the hard disk which makes it much stealthier.
- striking 10y ago> microcode-level rootkit There's two ways microcode goes on Intel CPUs. The first is when it gets flashed in at the factory onto an OTP ROM. The second is when it gets uploaded to a block of internal RAM by your computer, every time it boots. That's why packages like this one (https://www.archlinux.org/packages/extra/any/intel-ucode/ https://www.archlinux.org/packages/extra/any/intel-ucode/) exist. One is set at the factory, one is set by your computer every time, once at boot, before the completion of boot. Also, it's very carefully signed, so even if you managed to put a bootkit before the OS boot, you would need to steal Intel's microcode key. Microcode is not targetable. Few things at that level are. (A decent example of something that might be more targetable at that level is a hard drive controller. Less difficult but still not easy.) The amount of engineering needed to pull off an exploit that is "99.9% chance" unnoticeable, but still persistent, is much more than that of a "99% chance". (I know nothing of AMD's CPUs and their microcode, but I'm guessing it's much of the same.)
- jgalt212 10y ago> the more likely it is that your target will discover you compromised them fair enough, but the like the person above said, it can be very important to hide/obfuscate the identity of the snooper. Stuxnet would have been more effective if experts could not immediately point to US/Israel.
- lomnakkus 10y agoI don't doubt your expertise, but I think you're making a lot of declarative and slightly inflammatory statements without supporting them with concrete evidence. Is there publicly available evidence that you could refer to?
- TheSpiceIsLife 10y agoThe lower level / juniors / new hires probably cut their teeth on the simple exploits, and as they gain experience move on to the more advanced. Also, the hextuple-agent in me wants to think the simple exploits were leaked intentionally to distract from the whatever-else-it-is-they-don't-want-you-to-know.
- revmoo 10y ago> Also, the hextuple-agent in me wants to think the simple exploits were leaked intentionally to distract from the whatever-else-it-is-they-don't-want-you-to-know. Bingo!. This was confirmed for me this morning when the Today show spent its second day covering actual news! They immediately jumped on the Russia angle.
- the_cyber_pass 10y agoI doubt it, I think they hired out of some no name information security firm. These people probably are not the group developing the exploits either. I know if I was in their shoes I wouldn't waste my time using anything fancy, but this whole thing reads like some mid level member trying to create documentation to move up the corporate ladder. I don't want to rush to judge them because not everyone can be at the top and if it works it works. If I can pop a box using powershell, it's way easier than having to develop some kernel level hack. Additionally when anyones 'private' conversations get leaked they always look like a fool because it shows us being vulnerable and asking dumb questions, but a lot of the posts really do remind me more of the sysadmin who learned some python instead of the cutting edge of private industry.
- paulddraper 10y agoNot only is there the difficulty to think about, there's also risk management for discovery of your exploits. Creating antibiotic-resistant bacteria is a bad idea. Don't use linezolid when you could use vancomycin. Don't use your fancy rootkit if the boring DLL injector you give the contractors works just as well.
- lqdc13 10y agoWhy not just use an off-the-shelf rootkit with off-the-shelf obfuscator + whatever exploits they discovered? None of the code has to be extremely valuable. If I were CIA in the current political climate, I would simply slightly modify a Russian exploit toolchain and exfiltrate data to CIA controlled C&C. One dev can do the work and with a couple of days of effort it would get past all major AVs.
- paulddraper 10y agoIf it's public the vulnerability might be patched. The whole point of these is that they were secret (though the concepts may or may not be novel).
- gpm 10y agoMight not want to do that in case the Russian's backdoored theeir exploit toolchain somehow and you didn't notice. Creating this sort of malware isn't expensive, so why not do it.
- XorNot 10y agoI think this crowd tends to vastly underestimate the ease of deploying and testing this stuff in a targeted and useful way. There's a big difference between broadband spray and pray malware, and malware you actually want to hit a target with. If you know average tools won't detect it, then why get fancy when you have something that's proven reliable and if discovered is unlikely to have your victim substantially improve their processes?
- joshgel 10y ago
- benbenolson 10y agoAccording to a recent Wikileaks tweet, this leak is only 1% of the files that they have on the CIA. So most likely, they have many more exploits that are more significant.
- rspeer 10y agoYou're extrapolating from Wikileaks hyping itself in a tweet and calling the result "most likely". Find a better justification for your beliefs.
- croon 10y agoSo yet another thing Wikileaks (Assange) wants us to take their (his) word for.
- 69mlgsniperdad 10y agoAre you implying that he did something dishonest? I can't recall one example even. Although, I do recall a handful of politicians and news stories claiming the DKIM verified emails were likely fake. For example, I remember when Donna Brazile said that it wasn't her who sent the email leaking debate questions. Russians probably broke DKIM, and Brazile was probably coerced into admitting she's a liar.
- deno 10y agoWhat exactly are you suggesting? That they defeated modern cryptography or compromised Google to unprecedented degree?
- 69mlgsniperdad 10y agoThe last sentence was sarcastic.
- deno 10y agoSorry! You’ve run into Poe’s law.[1] [1] https://en.wikipedia.org/wiki/Poe%27s_law https://en.wikipedia.org/wiki/Poe%27s_law
- 69mlgsniperdad 10y agoTechnically, there is absolutely nothing impressive whatsoever, in the archive released yesterday; I went through the entire thing. Relative to the Snowden leaks, the CIA tools look benign. The biggest difference between the two sets of leaks(and subsequent NSA revelations) however, is scale & automation. NSA's tools are built almost entirely by contractors. The 'hacking' tools are integrated with deployment tools, as well as data collection. For example, say I work for the NSA and I want to see Bob's desktop wallpaper. I already have some generic social network information, as well as ISP info on bob, and he has already been assigned a 'selector,' which I use to query Bob's information, which was gathered from all sorts of sources. Assuming I don't already have a RAT or similar installed on Bob's computer, a further step is required. The NSA has many redundant attacks entirely automated, and most of the massively successful attacks, require some sort of MITM attack. Schneier released a video(on October 26th 2016, I think - if not real close to that date,) of some sort of intelligence meeting he spoke at, with just a handful of people, where he claimed he was going to bring something to light that had not previously been revealed anywhere in public. He revealed that the majority of home routers in the U.S.(commonly believed to be the ones provided by ISP, which run a custom Linux distro, with half a dozen internal subnets, mine runs on Arris hardware, has full busy-box, and used to contain a root pivot script that was previously accessible via ssh, on an accidentally unsecured network interface, within an obscure IP range, whos shell login turned out to be the commonly available Arris rolling code('arris pw of the day?'). The embedded Linux running on the device is based on the "RDK project" as is the DVR's and modem/router combos from a variety of other ISP's. Supposedly this is patched(for arris) but I haven't attempted any further investigation since August 2016. I believe the backdoor was simply a poorly designed interface between the router and the technician GUI software.) Sorry for the unnecessary details, but I've already typed it out now. Schneier revealed that these routers(HE never specified which, but said they are everywhere), referred to by the NSA internally as 'diodes'. The diodes are used(automatically) to provide better proximity to other users, not necessarily the target, where the plethora of attacks are then executed from. The initial development costs are immensely greater than those of the CIA's, much easier and cheaper to use, by the lay person, and are more carefully controlled/depend on the system hosted by the NSA. While proximity attacks are not the only method of intrusion/full control, the next best, or perhaps better alternative is Acidfox, which is often delivered via email/browser, and requires user intervention. Clearly the NSA is leaps and bounds ahead of CIA in terms of sophistication, as well as control/oversight, as you can't just walk out the door with an archive containing 75% of their tools(they depend on infrastructure.) The CIA attacks depicted in the Wikileaks archive, almost all require manual intervention, are less reliable, and 'janky' as hell. The CIA has a record of using their tools for less than honorable/legal purposes(which may be further elaborated on, depending on what goes down with the Trump wiretaps,) either way, the CIA hacks seem like a waste of time and money (5000 employees at the consulate in Germany) and redundant. The CIA must be able to utilize the NSA's vastly superior technology/information after receiving a warrant, which makes the motives and means all the more suspicious. Who knows what will come out, but one thing is for certain, there will be a lot more information revealed pertaining to the illegal, unwarranted, for personal gain, sharing of their tools with ex employees and contractors, in the coming weeks. I could go on for ages on this stuff, but I usually just get instantly downvoted, and I'm not providing sources(as it's all from memory[pro memory,] but it's all easily duckduckgo-able [or google.]) There are certainly more sophisticated employees and programs at the CIA(obviously), but I have a feeling that the shindig over in Germany consists mostly of this sort of thing, cheaper, younger, less experienced kids, copy & pasting junk together, customized and deployed on a case by case basis. I also have a feeling that the reasons Obama set that up, is going to be an interesting narrative which we will soon watch unfold. (hint: 7th floor group; aka 'shadow government') P.S. I refuse to go back and grammar check this monstrosity. Edit: Maybe someone can answer this question for me.. So from the Snowden leaks, we know the extent of the NSA toolkits and the requirements which need to be met to utilize them. Now we know some of the CIA's capabilities, and after Apple refused to unlock the San Bernardino Shooter's iPhone, we found out the FBI was playing some sort of politics, by claiming that justice might not be served without Apple's intervention, and proceeded to publicly shame the ethical position Apple took. So why on earth was Obama trying to force Apple's hand in that matter? Soon as Apple said no, the FBI somehow found the single magical person willing and able to defeat the privately enhanced security of the shooter's 5S? Makes no sense to me.
- ww520 10y agoMay be the simple DLL can be installed without privilege elevation. Simple to use.
- BorisMelnik 10y agoDefinitely correct, they are not stupid. These tools are more of a "keep it around in case we need it" type of thing. The CIA works abroad, not on American soil, so none of these tools are being used against the American people anyway (thats the NSA's job). I imagine this is part of a network or "library" of exploits they have, in case they encounter say a North Korean laptop with Windows 98 and they need something in a pinch. >doesn't mean that there aren't more units Exactly, thats why they call it a "leak" and not a "turn the hose on full blast."
- bigbugbag 10y ago> Also just because some information got leaked, doesn't mean that there aren't more units / projects at the CIA where maybe the more skilled people are working and where the "good" attacks don't get leaked. Actually the vault7 leak is the first in a series and it is clearly stated that this is only a portion of the CIA tools: > Recently, the CIA lost control of the majority of its hacking arsenal including malware, viruses, trojans, weaponized "zero day" exploits, malware remote control systems and associated documentation. (..) The archive appears to have been circulated among former U.S. government hackers and contractors in an unauthorized manner, one of whom has provided WikiLeaks with portions of the archive.
- hulahoof 10y agoCan anyone confirm if 'the CIA lost control' refers to the August 2016 Shadow Brokers / Equation Group auction? At the time I recall the tools being attributed to the NSA however it seems to fit the timeline ...
- tonyedgecombe 10y ago"The CIA probably isn't stupid." I don't think you can underestimate how stupid these big bureaucracies can be.