The Truth About the WikiLeaks C.I.A. Cache
nytimes.com
nytimes.com
I don't think they realize this is the reason many people don't get their news from main stream media anymore. Because you can just read the source's blog and twitter feed.
So in this case a journo is frustrated that a source who they should have been able to echo, and call that news, has their own agenda.
There is zero evidence of this within the leak.
I mean: We're still dealing with climate change denialism after years of the media allowing false equivalence to obscure the overwhelming scientific consensus around it. Major news organizations will run headlines based straight off the contents of tweets by wikileaks inspite of their repeated false claims in the past like with the "leaks" post-coup in Turkey, or Assange's statements about the Panama papers
It's stuff like this that give me, someone who believes fake news are just articles about things that didn't happen published by news organizations that don't exist on social media, major trust issues with American media today (and don't even get me started on British media)
Grouping all "media" together isn't meaningful; it's like saying "all programmers are lazy". It doesn't provide information that helps identify and solve a problem.
Some specific news outlets, especially Fox and the WSJ, actively promote climate denial.
Yes, mainstream media has gotten better about that topic in particular, but in general journalists still go for the easier "stories" that can be portrayed as competing sides, or simple narratives in general rather than what would actually inform people about the world.
Journalists, AFAIK, are supposed to avoid inserting their own judgement, give the reader the information (including opinions of different sides), and let the reader make their own decisions.
We can say that journalists should present "facts", but who says what the facts are? In the end, it comes down to expressed judgments by humans.
That being said, that can be taken to too much of an extreme, as it has been with climate change. I don't need opposing opinions about whether the Sun will rise tomorrow.
I read the article and it looks straightforward to me, but I don't independently know the facts. The analysis seems solid, but perhaps someone knows something I don't.
Unfortunately I've rarely seen so much noise (i.e., non-contributing comments) on HN, though the level tends to rise when someone doesn't buy into a Wikileaks' message.
Since this article does not bring anything new to the table for us HNers and has a reasonable number of upvotes, people start creating noise here.
This sounds so serious and involved, but probably took 10 seconds and just involved ctrl-f or (even) grep.
On the surface, Whatsapp, Signal, etc being compromised can mean either they are individually compromised or the platform they're on is somehow compromised, or something else... in my experience journalists have the incentive to just pick the headline that is the most sensational rather than the most informative.
For what it's worth, iOS has come out of this looking very safe. The CIA is essentially riding on the coattails of jailbreaks, which have been getting increasingly rare.
> in my experience journalists have the incentive to just pick the headline that is the most sensational rather than the most informative.
Considering what the article actually says, it seems this author and publication didn't do that.
I'm looking forward to The NY Time's Zeynep Tufekci's real discussion about Operating Systems that spy on us, collect our data and share that data; tracking across the internet; lack of security updates on phones; a tie-in with PRISM (allowing the NSA unfettered access to company databases) and anything else her top-notch "security researchers" turn up.
Maybe she can add a few words about the lack of oversight, transparency and accountability our tech & phone companies enjoy for the privilege of cooperating with certain government agencies. Let's get your "sources" to add a few words about backroom deals that circumvent The Constitution and the laws of this land too. It's a big topic with many players.
Be careful though, Mrs Tufekci. This kind of real news will get you into hot water with your masters.
I'm sure she'll get to it after another hit-piece on Wikileaks for actually bringing this discussion to the table instead of trying to kill it. That is, once she gets over her political biases (which are sprinkled throughout the article) and does some real journalism.
Security and Privacy are issues that need "real attention" and not something that gets tacked on at the end of an article and forgotten.
*edit: word
1) There's nothing in what she wrote to suggest that she's minimizing the dangers posed by telcos and goverment.
2) She just wrote a whole book about resisting the government using the internet. (https://www.amazon.com/Twitter-Tear-Gas-Fragility-Networked/...). She has a long history of documenting the ways governments and telcos meddle with popular action, in real time, too. (e.g. https://twitter.com/zeynep/status/449896348142555138 , which I just found by Googling "zeynep telco").
I'll restate what the article actually said, since some people seem to have missed it. She writes that Wikileaks characterized Signal and WhatsApp as being useless for secure communication; that this is not the case; and that the media reported this uncritically.
Rather than raise questions about Tufekci, I think it's more important to ask why Wikileaks is now trying to spread FUD about some of the best tools that we have.
http://technosociology.org/?page_id=1687
In this connection, she's particularly concerned that misreporting the nature of attacks, (edit:) or reporting them without context, will cause people to make bad security decisions. That issue is raised in reporting on these tools just as it was raised in the WhatsApp reporting, and it's the focus of her editorial here.
I don't think Tufekci wants people to refrain from talking about the terrible state of information security in general, or about how we could improve it. (While she also dislikes Wikileaks in general, which is very apparent in this editorial and slightly complicates the point, I don't think she means to suggest that we shouldn't know or talk about these capabilities or how to respond to them.)
If this stuff is worth bringing to the table then Wikileaks can bring it to the table with facts, not sensationalism and misinformation.
> That is, once she gets over her political biases (which are sprinkled throughout the article) and does some real journalism.
It says quite clearly at the top of the page: The Opinion Pages, and it even has "contributing op-ed writer" in all caps.
This isn't news because we've known for ages and ages that governments do evil things, known for ages. None of the evils listed are new or that interesting. Nothing to see here.
To me, that is like saying, "come on, it's murder. We've had murder since Cain killed Abel. Wikileaks attempt to expose such an ancient crime isn't news. Now look what Kanye said..."
Conflating the two is dangerous, people will stop using Signal if they think it's insecure. She's right to call out Wikileaks for lying about this stuff, and at no point in the article does she imply the governments actions are acceptable either.
Huh?
> CIA hacker malware a threat to journalists: infests iPhone, Android bypassing Signal, Confide encryption https://wikileaks.org/ciav7p1/#PRESS
If the argument is this tweet is misleading, this 14 words of content, a link and a hashtag. If that requires a 5,000+ character response to show how, I'm cool with that argument. I really am. I can see how it is misleading.
Equally, if you can read into those 14 words something misleading, I think a non-misleading interpretation is equally valid. In which case, the argument "the 14 words set the wrong agenda it's no big deal" is a little less compelling, and reads exactly like what I wrote. But what do I know? We are all free to disagree.
The controlled media will quibble over symantics of a Tweet and ignore the shocking truth that innumerous government agencies can aquire blackmail on anyone they want at any time without even breaking the law; and if they fear a journalist or leaker sufficiently, cause a high speed car or plane crash to get rid of them.
It's an opinion piece. It's literally right there in the title that you should expect someone to be expressing an opinion, not engaging in objective reporting.
You're spreading the exact misinformation that the entire article is trying to correct.
And which masters would those be, Mr. Rodriguez? Perhaps you're unaware of the background, Mr. Rodriguez, but everything I've seen from her and a lot of other people who know and care about security have been laying into mainstream news media for quite a while over their reckless and breathless inaccurate reporting on security and encryption, and pointing out that media outlets are going to get people killed by turning them away from secure options and toward things that major governments can crack and spy on.
But acknowledging that wouldn't let you spout creepy and condescending comments like the one I'm replying to, now would it, Mr. Rodriguez? So I can see why you didn't go there.
It works surprisingly well!
The article then goes on to explain what should have been researched from the beginning and delivers the brilliant sentence
This should not come as a surprise.
Right. Here is the salient excerpt from the WikiLeaks release linked in the tweet (!):
These techniques permit the CIA to bypass the encryption of WhatsApp, Signal, Telegram, Wiebo, Confide and Cloackman by hacking the "smart" phones that they run on and collecting audio and message traffic before encryption is applied.
You turned a tweet into a press article, didn't bother to read the referred article and then have the audacity to depict that as some sort of deliberate misinformation campaign in yet another article instead of simply admitting you rushed for the clicks. On the upside, it is now much clearer that it's maybe not only WL that is in the business of misinformation..
Wikileaks tweets are also quite demagogic and are tailored for maximum effect, these "techniques" do not actually allow the CIA to bypass the encryption, bypassing the encryption is a whole other thing completely what it does is allow the CIA to read anything on the phone and use any of it's hardware sensors.
Overall the problem with this leak specifically it that there is so far nothing damning, this is exactly the toolkit a modern intelligence agency should have, in fact this is likely to kiddy stuff not the rogue nation targeting kinetic payloads.
What it doesn't show is who these tools target, if Wikileaks to be believed the NSA only targets journalists and human rights activists whilst in reality this isn't the case.
Unlike the NSA the CIA is also not interested in mass surveillance, the CIA produces intelligence analysis primarily revolving around humint sources and targets, which means that their operations tend to be much more targeted a SIGINT agency which relies on bulk data collection.
The definition of the word bypass is, "a secondary channel, pipe, or connection to allow a flow when the main one is closed or blocked." How is a rootkit not bypassing encryption? It doesn't break encryption.
> Unlike the NSA the CIA is also not interested in mass surveillance...
Why do you believe this to be true?
> Overall the problem with this leak specifically it that there is so far nothing damning
The wholesale violation of 4th Amendment protections isn't damning to you?
Where is there a violation of the 4th Amendment? The 4th Amendment is not about capabilities, which always have existed in one form or another (e.g., reading people's mail), but about legal authorization to use them.
I really cannot understand the difference between "bypassing" the encryption and allowing the CIA to read anything on the phone. Those sound like trivial synonyms.
Reading the clear text pre or post description isn't bypassing encryption because this can be done regardless of the type or method of encryption used.
If I beat you with a wrench until you tell me your password it doesn't mean I managed to bypass the encryption of your password manager.
I understand bypass to mean "go around" basically. So if I bypass something, I have found a way to avoid it. I really think this is the common usage.
I'm not really interested in another repeat of the "there is nothing here" discussion. We seem to get that for each of these releases; lots of people swarming in to tell us they were perfectly aware of all these things since, well, forever.