4 ms·
Prior to accessing this file collection, please understand that this material was seized from a terrorist organization. While the files underwent interagency re
by elorm 9y ago
Prior to accessing this file collection, please understand that this material was seized from a terrorist organization. While the files underwent interagency review, there is no absolute guarantee that all malware has been removed.
The CIA cannot guarantee that files they have spent 6 years poring through are free off malware? Wonder why anyone will download these documents after this.
- jorblumesea 9y agoProbably just legalese in case anything happened. I bet CIA lawyers are the most paranoid people on the planet.
- TinyRick 9y agoOr in case someone finds the malware they injected into it. </tinfoil hat>
- moxious 9y agoWould the CIA really do tha...oh.
- gozur88 9y agoThat seems like a pretty obvious play, IMO. I'd be surprised if they didn't.
- wallace_f 9y agoDon't be ridiculous. Any reasonable and representative democracy like ours would not be a government interested in subverting the privacy and rights of its own people. /s
- deleted 9y ago[deleted]
- bousaid 9y agoHave you ever read the terms and service of any piece of software or service? They’re full of similar protective clauses.
- Bromskloss 9y agoWhat would be the problem with downloading and reading them? You don't have to _run_ them, to the extent that they are programs.
- jlgaddis 9y agoYeah, it's not like there's ever been vulnerabilities in Microsoft Word, PDF readers, image viewers, or media players. /s
- mynewtb 9y agoYou cannot ever guarantee that, see N=NP.
- jmite 9y agoRice's theorem, actually
- mbrock 9y agoThis is not a true implication. If all the executables in the archive were, say, loop-free trivial programs, then of course you could instantly confirm an absence of malware. If there are some loops and complications in there, you would do some more logical work, and then depending on the power of your logical system, either conclude safety or unsafety, or time out. Rice's theorem does not mean that static analysis is impossible, even of machine code!
- jmite 9y agoRight, but Rice's theorem means that you either have false positives, false negatives, or "Unknown" answers in any static analysis. Which means that the CIA could never guarantee the absence of malware, for example, if any of the programs timed out in the static analysis.
- mbrock 9y agoIt seems likely that they wouldn't be able to guarantee that, but we need to be more clear. The fundamental limitations of computer science, as expressed by Rice's theorem, says that the CIA cannot make a program that given any archive says in finite time whether there is malware there. It doesn't say that for some specific archive the CIA cannot guarantee the absence of malware. There are infinitely many EXE files that you can prove malware-free, and this set expands with the progress of static analysis. But of course, if one EXE file says "if (unsolved_math_problem()) { malware(); } else { harmless(); }" then the CIA would have to spend a lot of effort proving its status.
- isfield 9y agoMaybe download and copy to isolated vm view and nuke the vm. Or I'll just read what everyone else says is in there :D