Wikileaks releases CIA's Marble: Malware obfuscation tools
wikileaks.org
wikileaks.org
From what I've read so far, this is pretty freaking cool. It's super interesting to read these docs and see their thought process involved, especially since the product their building is so different from what people are making on a day to day business. It actually looks pretty fun to work on. Also, I think it's neat to read about their need for developing frameworks that can be used around the agency to accomplish stuff.
Unfortunately, I didn't ready anything about self modifying code, which is probably the most difficult malware to detect and probably to write. Maybe it's in there though, I didn't read the whole document. I came to the comments about half way through to see dozens of people talking about whether they support Wikileaks or not which I think is fine, free country, but I'd like to actually know what some people who work with this kind of stuff think.
A framework for compiling to self modifying, yet correct, code wiukd be super cool. I wonder if it always has to be written by hand? Probably not but maybe that's a separate tool Wikileaks has yet to release.
The exception to that is packers and other obfuscation techniques, which are related to self-modifying code. The general idea with these is that you take your real program and compress/encrypt/mangle/etc it and store that data in an executable. The code in that executable de-compresses/decrypts/demangles that data, sets it as executable, and then runs it. Unlike traditional self-modifying code, packing is orders of magnitude easier to write for the malware developer. The advantage here is that an antivirus tool can't determine what your real program does statically unless it understands how you mangled it, which is hard to do in general. To "unpack" an executable you've got three general techniques:
1. Packers tend to get reused a lot, so just have a person write an unpacker for popular packers by hand, and do some pattern matching to figure out which packer an executable is using. This doesn't work for everything, but it's fairly simple.
2. Dynamic Analysis. Run the executable and watch the contents of memory as the program unpacks itself, the real program should pop right out. Of course you have to run the executable in some sort of sandbox environment, and there's ways for the malware to detect that and alter it's behavior. This also isn't the most efficient process, so you can't really do this to executables during, say, an antivirus scan.
3. Symbolic Analysis. Basically static analysis on steroids to figure out what the executable will do without actually running it. The malware can't stop this with sandbox detection. But it's super slow and is still an active area of research.
Of course nowadays the makers of fine malware detect whether they are running inside a sandbox, and won't activate.
Another comment about the content of this article:
Three quarters down the wiki page there is code for "adding foreign language" to the code. The options are are to add code comments in Arabic/Chinese/Russian/Korean/Farsi. My gut reaction is the purpose of this added language is to obfuscate the true source of the code - i.e. the code has Chinese comments in it so it must be from China. Ahh. I guess this makes sense to do. Only problem now is that the Chinese/Russian/Farsi/etc characters that they included in their code is now public. (Obviously now the CIA will change the foreign language words they insert)
I'd posit if someone had an X-year-old (i.e. x=7) copy of some malware, and the malware had these specific foreign language comments as shown by the article, there's a good possibility the source of the malware would be from the us government.
Analysts never use the language of the code comments for attribution, because such things are trivial to forge.
My comment:
So I see now (thanks to you) that it is just showing test cases (test warbles) to demonstrate that these scrambling techniques work with foreign languages. However, why would the us gov need to make sure that this program can successfully obfuscate Unicode strings in Chinese/Russian/Arabic/Farsi?
My gut reaction: while code comments would be trivial to forge, it appears the us gov is still using foreign language strings in some way - maybe having just one string constant originally in a foreign language that is then obfuscated/scrambled (such as by xoring every char against a random key)
Personally I do not believe self-modifying code would make much sense in their use case. In fact, this would not be possible on iOS due to kernel-based security protections.
It's hairier for people with clearances. Technically you could have your clearance revoked for accessing classified information despite the fact that it's public. I don't know if that's ever happened, but it's a possibility.
https://www.usingenglish.com/reference/idioms/in+that+vein.h...
https://en.wikipedia.org/wiki/Metamorphic_code
https://web.archive.org/web/20070602060312/http://vx.netlux....
If your perspective is that more secrets are being kept by more egregious actors than the US, the truth welcomes your contribution...
The only person less likely to criticize Russia than Trump is Assange.
Wikileaks lost any proximity to an alleged moral high ground when they stopped leaking everything they got, and started editorializing their release schedule for political impact, started talking about US politics, and held back bad things about people they like.
(I say this as someone who is very pro-Snowden.)
1/ http://thehill.com/blogs/ballot-box/presidential-races/29345...
2/ http://theweek.com/speedreads/645239/julian-assange-tells-me...
3/ http://www.nbcnews.com/news/us-news/russia-hack-u-s-politics...
It's fair if you align yourself with American foreign policy interests, I do too, but to single out other publications that don't follow that agenda is just a case of having self interested double standards. All of the criticism of Wiki leaks and non-America MSM has all sounded like that to me. "They are selectively publishing different things than we want to be selectively published. Waaah".
But let me guess what the go to response would be: "whataboutism" (aka you can't call me a hypocrite, because some guy made a term for it).
Therefore, for WikiLeaks to become highly partisan is a radical departure from their original mission; moreover, it has happened without WikiLeaks acknowledging that this is the case. I think you can't same the same for the NYT.
1. http://www.nytimes.com/2013/11/10/public-editor/sullivan-les...
Going back further in time, there was actually a stated goal of Wikileaks. It wanted to make sure that leaking is so ubiquitous, common and supported that states can't afford to have deep secrets. Looking at the recent support of government leaking after the US election Wikileaks did gain large step towards that on both side of the political spectrum, be that intentional or not.
Why is anyone holding a site meant for whistleblowing and leaking of confidential information and the website of a newspaper to the same standard?
Apples and oranges, IMO: It's not really fair to get mad at an orange for not giving you apple juice.
>Therefore, for WikiLeaks to become highly partisan is a radical departure from their original mission; moreover, it has happened without WikiLeaks acknowledging that this is the case. I think you can't same the same for the NYT.
Well said. I don't get the partisanship from Wikileaks. What do they gain by picking sides? What is encouraging (or discouraging) Wikileaks to play cherry picker?
This is a mischaracterisation. If Assange wanted due process, he could leave the embassy and face the British (and then possibly Swedish) court systems. The only person choosing to arbitrarily detain Assange without due process is himself.
That's not due process.
So given that they can't select the sources, the claims of them being "selective" just sound ignorant to anyone who knows how they operate, especially when those same claims are so often repeated in publications which are openly selective.
Second, if they were trying to be just a funnel but realised that they were only getting information from limited sources with a known agenda, then they would also know that they are facilitating a political agenda. They could be open about this. But they are not. They are keeping critical details of their own activities secret (ie they choose to be selective), which is directly contrary to their stated philosophy.
In a more empirical sense, an organisation can only be judged by its output, not by its slogans or cheerleaders. In that sense Wikileaks is clearly an organisation promoting a political agenda.
Yes, but that opinion is that powerful, unaccountable organizations shouldn't be able to keep deep secrets from the general public when they do things like manufacturing consent for war.
Being open about sources defeats the whole purpose.
https://duckduckgo.com/?q=trump+foreign+policy&t=fpas&iax=1&...
Show me the set of NYT/WaPo/ETc pieces consistently outlining an editorial position for any one of the following issues:
Unaccountable global free trade deals are a bad idea, Assad is not an evil guy that should be replaced via direct or indirect US action, That Syrian rebel groups are in fact heavily islamised, that Putin is not trying to be Stalin 2.0, that the Ukraine is a mess due to problems on all sides, that a Palestinian 1 state solution is preferred to the current 2 state strategy, or equating the level of theocratic social repression in Iran and Saudi Arabia.
Does the occasional piece crop up hinting that these could concievably be valid positions if they weren't actually incorrect? Yes. Does that mean they are consistently viewed or even evaluated by pinning down biases and weighing them against objective comparitive philosophical standards, particularly applied to the topic at hand? Ha!
Saudis @ NYT from a selection of recent articles:
"Trump has made it clear he is not worried about supporting human rights or freedom; [...] that all those difficult questions about gender equality and the like are going to be off the table for the next four years, and that Iran is very much on the table,” Mr. Riedel said." https://mobile.nytimes.com/2017/03/14/world/middleeast/moham...
"The sale of oil provides billions of dollars in annual allowances, public sector sinecures and perks for royals, the wealthiest of whom own French chateaus and Saudi palaces, stash money in Swiss bank accounts, wear couture dresses under their abayas and frolic on some of the world’s biggest yachts out of sight of commoners." https://mobile.nytimes.com/2017/03/01/world/middleeast/saudi... and https://mobile.nytimes.com/2016/12/27/world/middleeast/saudi...
"Activists in the country have long protested its patriarchal society that essentially prohibits women from traveling, marrying or attending college without permission from a male relative, who is called their guardian." https://mobile.nytimes.com/2017/01/05/world/middleeast/saudi...
"Western human rights organizations criticized both the trial and the sentences, saying that the accused were denied proper legal representation, charged over activities that should not be crimes and pressed into signing “confessions” that were used against them." https://mobile.nytimes.com/2016/12/06/world/middleeast/saudi...
What content would change your mind?
Is the standard so low that we can't even mention that a non profit(?) organization devoted to releasing leaks of wrongdoing shouldn't be blatantly partisan?
Edit: I misread the last part of your comment about "whataboutism". Yet my question still applies, isn't it?
I have yet to see anyone even claim that Wikileaks participates in the hacks themselves, let alone to provide evidence thereof.
Assange has said they have information on Trump that they weren't releasing.
Could you point me to a source for that?
The fact that it was 'associated with the election campaign' and 'entertaining' made me feel it was there. I don't remember seeing other docs that satisfied both criteria, but it is only a guess and I could be wrong.
"Don't do X, it's bad for The Party" is frankly far more cancerous for the process than any truths getting revealed. The weaknesses are there either way, but highlighting them and tearing away at them would (should) lead the way for stronger parties (in the sense of fewer weaknesses to exploit; better control over the leadership by the constituents, and so on) to evolve.
But no - it's not enough that the public be sold on the idea of "only two flavors" when it 'matters', but we have to let the weak, flaw-riddled leaders of those parties limp on even if they're completely alienated from its base, because we can't risk 'not towing the party line.'
Apathy for that exact kind of 'suck it up' logic is (in my opinion, anyways) one of the hugely deciding factors in the numbers that abstained from the election this time. Frankly, organizations like WIkileaks should be doing more to tear away at existing parties and partisanship - for disillusioned voters, that'd actually be restoring faith in the system.
One the one hand, he has the US wanting to prosecute him and on the other hand, if the claims are to be believed, Russia is happy to use WL as a channel to air their dirty US intel bits, by context implying that he is de-facto forced to take a Russia aligned position since they are the only ones with power covering him.. And of course outing this bias essentially means he plays the one card that might keep him from say, disappearing into a river or mysteriously ingesting rare radioactive isotopes..
If the shoe were on the other foot and the US were not so interested in prosecuting him to cover themselves, and it were Russia/China/Etc forcing him to hole up somewhere I'd wager that the US would be more than happy to play the same game of using wikileaks as a channel, with Assange staying mum, and Russia/China/Etc would be crying foul..
Of course this only presumes the 'wikileaks as russian channel' info is even true, since pretty much anyone not in the gung-ho US camp is branded as a Russian shill (Assange, Snowden) or a deranged lunatic hell bent on global destruction (Assad, Hussein, Khomeni, Chavez, etc.)
By the way, ever notice you don't hear so much about Anonymous these days since about the time of the elections and Hillary's server getting discovered?
There are much much much bigger factors at play than Assange's bias or non bias in this drama..
If anything, Wikileaks were one of the only ones doing anything to stop Trump that people should've gotten on board with. HRC was far from the only option and by far not the best one (and this isn't 'hindsight' - many were arguing it well before the primaries), yet she was the DNC's golden girl so any potential for internal reconsideration was squashed, and the base left disillusioned.
Even if you weren't on board with Bernie (and I don't see how, for the same reasons HRC publicists would say the same for hrc, 'because she has the same policies' - except with Bernie having a track record of following through on his convictions), you should have seen the need for an actually-democratic internal process within the party, rather than strongarmed support among the elite and nomination-by-fiat rather instead of even considering who'd make a stronger candidate.
Unless HRC hasn't learned her lesson for 2020, I'm sure you'll see other names come up then - but those people were here now, and you and the base could've heard their names a lot more than you did (which was probably not at all). Instead, the DNC bet it all on their hugely-flawed 'golden girl' and lost.
But no - clearly _Wikileaks_ fucked up. They should've just ignored the flaws like good little citizens and let her run unquestioned like you did. (Not trying to sound so facetious, but if that's really your argument...)
If your perspective is that the US is truly the most secretive and "egregious" actor on the modern stage, then you are shockingly naive. Or, more likely, misled by the skewed "truth" you are reading.
I thought you were talking about seemingly-Wikileak relevant things like secret police stuff, control over national media, poisoning of political enemies, assassinations... Y'know. Boring stuff. Not "egregious" I guess.
How about "secret police stuff" like the illegal abductions of people to put them into torture "black sites" all over the world? [0]
Massive control over global media trough lobbying and propaganda instruments? [1]
A long history of successful, and not so successful assassination attempts aimed at the "ideological opposition" all over the world? [2]
The point here not being that the "US is the worst", the point being that the US hardly has the "moral high ground" on these issues just because they use these methods mostly against external "enemies" and not their own population. Questionable methods are questionable because of their methodology, not because of their targets.
[0]https://en.wikipedia.org/wiki/Extraordinary_rendition
[1]https://www.theguardian.com/technology/2011/mar/17/us-spy-op...
[2]https://wikispooks.com/wiki/US/Foreign_Assassinations_since_...
0. People straight up disappeared in Syria, people arrested and locked up for political reasons in Russia - DOMESTIC stuff.
1. (Leaving aside that sock-puppet commenters are not the same as "massive control over global media".) The use on a massive scale of paid trolls by Russia, and the outright censorship of mass media outlets in countries from Russia and China to US allies like Turkey and Saudi Arabia.
2. Assassinations of journalists in Russia, and of some particularly high-value opposition targets abroad.
The US influence on global media extends far further than a mere sock-puppet program which btw predates the notorious Russian "troll factories" by a couple of years. Only very few people know what classified operations are running in addition to that sock-puppet operation, but you can be certain there are more operations like that. Like influencing foreign media trough NGO's [0] in addition to that US media are the dominant news outlets on a global scale.
And again: If you want to complain about assassinations then the US is in no position to point fingers at anybody. Just because the US does conduct these kinds of operations on a global scale mostly targeting foreigners, while being rather successful in suppressing publicity about similar actions on a domestic scale, does not make these actions any "better" or "just". Even the US has no shortage of journalists dying in rather mysterious circumstances, Gary Webb comes to mind and if they don't die under weird circumstances they are straight up put on drone kill lists [1].
I realize this is a matter of "national pride" for many US Americans, to keep the facade of "We are the exceptional good guys, number one in everything!" intact, but as somebody who's seen "both sides" of this I consider that a rather absolute and dangerous view on reality.
Note: Not a fan of using huffingtonpost as a source, but it's the only English-language source I found about this due to it being a rather German-centric issue.
[0] http://www.huffingtonpost.com/till-bruckner/think-tanks-lobb...
[1] http://www.independent.co.uk/voices/i-am-on-the-us-kill-list...
You bury it in there ("The point here not being..."), but I think you agree with me. No?
What service do Wikileaks provide to leakers in those cases?
You're now throwing up a diversion by suggesting that surveillance be the only criterion by which to judge a state (or non-state) actor's badness (or goodness).
There is plenty to criticise the US on. I strongly recommend (and have frequently posted to HN) examples such has histories of violence against labour movements, corporate crime generally, the Johnson County War, the West Virginia Coal Wars, and more. There are authors such as Howard Zinn, or Noam Chomsky, or Mark Twain, or Upton Sinclair, or Martin Luther King, Jr., among many others, who can detail atrocities and evil done by and on account of the US.
But, in recent years, the United States hasn't, to the best of my knowledge, made a habit of hunting down and killing its own dissident journalists, politicians, and activists, as Russia has. On which Wikileaks is ... very curiously silent. An action I'll argue is markedly worse than just listening in on conversations, as it takes the value of such surveillance one step further: the acting on it with lethal force.
Has the US managed to kill people? Sure: drone strikes (of questionable validity, but against a generally defined enemy, modulo innocents slaughtered), the killing and subsequent coverup of Reuters photographers in Iraq in 2007 (http://www.cnn.com/2010/WORLD/meast/04/05/iraq.photographers...), the friendly-fire killing and cover-up of Pat Tillman in Afghanistan, massive security failures in avoiding the 9/11 attacks.
But consider then, Russia's apparently false-flag attacks on its own people (Moscow apartment bombings), the assasinations already mentioned, Syrian attacks, and more.
And from Wikileaks: an increasingly inexcusable silence.
This from a former defender of Assange, and a current defender of both Snowden and Manning.
Those are all evidence that other parties have secrets.
Off course, we will be sure you're wrong, but please, go ahead. Name a "random poor third world country" that has a military base in one of its neighboring countries. And while you're at it, which one has a base in Kuwait, Turkey, Iraq, Bulgaria, Romania, Djibouti, etc, etc, etc.
The US may not be the 'worst' but we certainly have our hands bloodier than most nations.
1. The Catholic Church, particularly the 30 Years War and Huguenots (themselves not entirely blameless).
2. The Spartans and Helots.
3. England / Britain: North America, India, China, and Australia.
4. Belgium and the Congo.
5. Japan, and ... pretty much everyone in their neighborhood: Korea, China, the Philippines, Indonesia, etc., etc.
6. The Mongols.
7. Nazi Germany.
8. Putin's Russia.
9. Communist Russia.
10. Czarist Russia.
People are pretty damned good at being bloody bastards in general.
The United States certainly has a greater capacity than any other nation, state, or empire in all of history. On balance, it's been ... relatively benign. Not perfectly so by a long shot (see my comments elsewhere in this thread: Zinn, Chomsky, Twain, Sinclair, etc.). Absolutely could have been better. Should be introspected.
But in the context of "is Wikileaks anywhere arguably near unbiased", absolutely not.
When Nazi Germany tried to take over the world, the world banded together to stop them.
If the US funds a revolution in some developing country or other; that country doesn't have the means to rise up against the US and do anything about it, and the UN or the EU or what have you sure as hell won't declare war on the US because of some regional instability in the Middle East or Africa.
That's why the US are dangerous, not because they commit atrocities on the scale of Nazi Germany (which they don't, not even close).
Again, the real question here is Wikileaks increasingly glaring bias problems. The point isn't that Wikileaks have falsified information concerning real evils done by the US. It's that they've been conspicuously, and I have to say, having dug deeper, INEXCUSABLY quiet (if not silent) on the activities of others.
I absolutely grant that the US is, by virtue of its power and capabilities, deserving of extreme scruitiny. What we're looking at goes beyond that.
Wikileaks has a credibility and bias problem. The more so as its actions now appear petty and vengeful based on personal animus between Assange and Clinton.
And yes, Wikileaks are actively soliciting leaks -- against Britain's Labour party:
https://wikileaks.org/WikiLeaks-offers-award-for-LabourLeaks...
But not on Russia. Or China. Or Syria. Or North Korea. Or Venezuela. Or Marie le Pen. Or Rupert Murdoch.
(So far as I am aware.)
The "CIA uses your smart TV to spy on you" story is more myth than reality and it was completely created by Wikileaks. (When your threat model is "CIA agents enter your home to plant bugs" then getting rid of your Smart TV isn't much protection.)
I follow all of their leaks, but i'm not aware of these "summaries" you are referring to. It sounds like perhaps your interaction with wikileaks is mediated by the media, and your problem is with the media.
For instance, this link we are commenting on is directly to a primary document, with no summary provided. The only "summaries" i am aware of, would be their tweets, which are inherently oversimplified.
I recommend the wikileaks subreddit for navigating the "unreadably large cache" if that is an issue you are facing.
> The source code shows that Marble has test examples not just in English but also in Chinese, Russian, Korean, Arabic and Farsi. This would permit a forensic attribution double game, for example by pretending that the spoken language of the malware creator was not American English, but Chinese, but then showing attempts to conceal the use of Chinese, drawing forensic investigators even more strongly to the wrong conclusion
There's no evidence the CIA has ever done this. This is pure conjecture based on the fact that there's demo code showing that the library supports Unicode.
They're pretty obviously trying to push the idea that attribution of hacks (such as the DNC hack) can be really easily spoofed, and you shouldn't trust them. And it's working:
https://www.rt.com/news/382940-wikileaks-vault7-marble-frame...
http://www.mirror.co.uk/news/world-news/-wikileaks-vault-7-m...
http://www.dailymail.co.uk/news/article-4367746/WikiLeaks-sa...
OK, and? Is it incorrect that they can spoofed? If not, doesn't that necessarily mean that you can't take "the Russians did this" at face value?
It's based on the re-use of the same exact techniques, including command-and-control server addresses and encryption keys that have been used in many, many other attacks that align extremely closely with Russian interests.
Successfully hacking, over the course of about a decade, American government interests, Eastern Ukrainian militias, Russian dissidents, the Olympic anti-doping committee investigating Russia's wide-spread doping scandal, journalists investigating the downing of MH17, etc. would be a very convoluted and expensive way to spoof attribution of this one attack.
Is there an official source that actually breaks down the similarities to which attacks? I have my doubts about the attribution of the DNC hack to _state_ agents. The only specific I've read was the Gucifer 2.0 windows language being set to Russian.
Every other attribution has been a "trust us, we've seen this before" but I am very skeptical of intelligence and law enforcement agencies unattributed claims and I think they've earned that distrust.
You are correct that the publicly available evidence doesn't point directly to the GRU, but rather merely to an anonymous extremely well-resourced group whose interests align extremely well with Russian military interests. While the GRU is the most reasonable conclusion, this would leave open, for example, the possibility that some contractor to the Russian military is operating with independence, not actually under direct order from the Kremlin.
The intelligence community claims to have knowledge, through conventional intelligence rather than forensics, that this was done by the GRU themselves, under order from the highest levels of leadership. This presumably means they know who the hackers actually are, whom they report to, and the general structure of the agency. They claim they have multiple, strong, independent sources confirming this, but they can't reveal their intelligence publicly without compromising those sources.
Where is the conjecture? the exact quote is "this would permit" not "this has happened"
> They're pretty obviously trying to push the idea that attribution of hacks (such as the DNC hack) can be really easily spoofed, and you shouldn't trust them.
They are ~revealing~ the capability and intent of attribution obfuscation. I disagree with your assessment that they are ~pushing~ something, implying that there is something which is not self-evident which requires some kind of coercion for belief.
It is very easy imply something and push a specific agenda without technically lying.
What if I take out an add that says:
"elif regularly participates on hacker news--a forum for computer programmers and 'hackers', and he is a programmer who can create malicious programs. The libraries he uses support multiple languages, like Chinese and Russian, giving him the capability to make it look like these programs were created by foreigners."
I'm just describing your capabilities. But the way I said it implies to non-experts that your actually writing malicious code, because they lack the context to understand what they're reading.
They don't understand that all programmers have the capability to create malicious programs. And most importantly, just like the readers of Wikileaks commentary, they don't realize that supporting Unicode is very common, and it's necessary if you want to parse text written in it. It's not a specialized capability that you'd only want if you intended to write in Russian or Chinese.
Wikileaks is implying -- heavily enough that every news article I've seen mentions it (some, even, without the "might" or "could") -- that the main reason the CIA would support Unicode is so that they can trick people into thinking they're Chinese.
Mentioning (the quite obvious fact) that it's possible to include foreign text in code as an effort to confuse adversaries, while discussing an actual implementation of text obfuscation, will confuse reasonable people who lack the technical understanding of what this is into thinking the software obfuscates text by somehow changing the language it's in.
Here's a more egregious example:
This doc (https://wikileaks.org/ciav7p1/cms/page_13763790.html) contains one line "Vehicle Systems (e.g. VSEP)." It doesn't elaborate what "Vehicle Systems" they mean or define "VSEP," but given the other projects worked on by the same team (all using embedded systems to spy on you), the most reasonable interpretation to me is that they'd be trying to intercept GPS and other sensor data, including voice and video from cameras and microphones.
Wikileaks wrote "As of October 2014 the CIA was also looking at infecting the vehicle control systems used by modern cars and trucks. The purpose of such control is not specified, but it would permit the CIA to engage in nearly undetectable assassinations." In this case, they added the word "control" from nothing, making the completely unsupported claim that the CIA is investigating the possibility of assassinating people by hacking their cars (which, hey, might be true... but there's nothing supporting that idea here).
Sure enough, dozens of article were written about how the CIA is killing people by driving their cars off cliffs.
This framework is used to obfuscate. The document itself seems to suggest they built this framework to be very generic and prevent attribution.
Where in this document do you see Wikileaks is misdirecting attribution? It is possible the CIA does miss-attribution, but none of these documents suggest that (which is not in line with how Wikileaks is framing it)
I think it's interesting you respond this way. Because I thought it was pretty public knowledge that Wikileaks does not release all the information they get. And they especially don't release the information at the very same moment they get it.
You'd think if your quote was aligned with their values, that such wouldn't be the case.
Nonsense.
Discovering and revealing the truth, and the timing of those actions, can absolutely be political.
If one out of 4 PARTY-X Congressmen are cheating on their wives, and one out of 5 PARTY-Y Congressmen are cheating on their wives...
But somehow wikileaks publishes a list of Congressmen cheating on their wives a week before the election, and they're all PARTY-X on the list, and no PARTY-Y, you get to wonder if it was political.
The truth is Assange is paid to hurt the US, and censor information that damages Russia. That's why he does things like publish the personal info of CIA personnel children, censor emails damaging to Russia, and hold regular meetings with arms of Russian propaganda. Assange has tacitly admitted this and didn't even try to deny it.
If you're running a media outlet, and use your editorial discretion to only disclose specific truths that align with your broader interest, you're not worthy of claiming to be acting in the public interest.
Facts are never black and white things. The meaning of truth is dependent on the context surrounding it.
"Knowledge of how to create an atomic bomb" would still qualify, but also gets torn down pretty quickly - that information isn't owned, and can't be restriced to trustess - the "information" simply derives from science, and is non-excludagle to any intelligent society no matter what you do to try and "exclude" them. So even in that case, you must fall back to regulating the physical - limiting supply of nuclear materials, policing/spying on use of facilities that 'could' be used to create them, or so on.
Information freedom isn't just some 'inevitable truth' - it's the nature of information itself. Arguing against it isn't even futile, it demonstrates a fundamental lack of understanding. (Which I suppose could have been guessed at by the spelling of the first 3 words of your comment, but I suppose others can get the benefit)
Actually, I am pretty sure we don't. Those codes come in pairs and are all subject to two person control. Also, those guys that turn the keys can use their own judgment to veto the launch. In the event a leak was known or an unknown reason to launch came through I suspect they wouldn't.
Those codes won't let them re-target the missiles either, we will be firing them at whatever the predesignated target is. I am not sure if anyone else is up to the task of firing back in the ten or so minutes before all of our cold war enemies are erased.
So how about back to the practical example about what information can go free in the event of government transparency. Surely there are some plausible examples that can also make your point.
there should not be secret attacks on every computer on the planet.
But you realize the US isn't the only one hacking systems, right?
I would think Wiki's justification is that the US has far more culpability in world affairs than most other countries. They get involved in disputes that most other countries can't touch.
In terms of risk, the US has a massive intelligence and political footprint that simply leaks more. The opportunity and impetus to leak are simply greater in all regards.
In comparison, China and Russia run much more despotic regimes. They have fewer qualms routing out political opposition, and simply have less open and democratic societies. There is a vastly smaller opportunity due to size as well.
Secondly there is element of "outcome". Exposing US government has clear benefit of keeping people informed and hence help them make better voting decisions. Telling Chinese people that their government is systematically harvesting organs of Tibetian people has no new information or benefit.
That's how good they are at regulating their information, and is precisely the reason why we need Wikileaks.
There's plenty that WL doesn't know that you might die never having known, and your great-grandchildren might ever only hear about in history books (and maybe not even then, depending on who the victors are).
I think the point is good overall.
They should leak interesting material they are given - that's their purpose.
A current example would be STEM outreach to underrepresented groups: disadvantaged minorities and women in particular. Housing, employment, and educational opportunity efforts would be other examples that come to mind.
Can you point to any active solicitation Wikileaks have made, say, for materials specifically addressing political oppression within Russia or concerning its foreign policy?
Sincere question. I'm not, though I've not particularly looked.
As an analogy when the US/UK/other western gov criticises Assad or Kim Jong Un over human rights abuses we don't generally complain that it's unfair because the US/UK also have plenty of human rights abuses under their belt. Yes that's a problem but it doesn't take away from the original complaint which is still valid.
But I'd wonder who wants me to know that, and why.
Wikileaks is a spotlight. It shines brightly, and exposes much, but only where it shines.
And if I notice that it's shining only in specific places ... well, that's a curious fact in itself.
And I absolutely disagree with you that bias doesn't matter. Ultimately it's the only thing that matters. Much as, say, US print and broadcast news was conspicuously silent on matters concerning advertiser interests, or government interests in contexts in which the government had leverage over the press.
Wikileaks themselves are no different in that regard, though the business model and relationships are slighly rearranged.
...
The report claims batch of emails were not included in the cache of documents Wikileaks published under the name the “Syria Files”in 2012. The emails allegedly show correspondence between the Central Bank of Syria and Russia’s VTB Bank. When the Daily Dot asked Wikileaks for comment, the transparency organization denied removing the batch of emails and vaguely threatened the journalist, saying, “You can be sure we will return the favor one day.”
It’s entirely possible that the hackers removed the email batch from the data dump it provided to Wikileaks. But it also seems very unlikely. As Daily Dot reporters Dell Cameron and Patrick Howell O’Neill point out in their story, they received 500 pages showing every step the hackers went through to infiltrate the Syrian government’s networks. The reporters say, “the court records leaked to the Daily Dot reveal the Moscow bank’s emails were, in fact, part of the larger backup file containing numerous emails currently found on the WikiLeaks site.”
https://www.google.com/amp/gizmodo.com/wikileaks-may-have-wi...
Oddly enough, they never question why Assange, after bragging about his intention to dump 'kompromat' on Putin in November 2011, suddenly changed his mind in doing so and then signed a tv deal with Russian state media 2 months later. It surely didn't have anything to do with the death threats Russian intelligence issued against Wikileaks, nor with Assange's meeting with Putin in December 2011.
All the other sources wrote attributed the claims to Daily Dot. If they have independent verification of the hacker data we would have multiple independent claims and it would be a different matter. As it stand, it is only a single small news site from Texas that is staking their reputation behind this claim.
"WikiLeaks was originally established with a "wiki" communal publication method, which was terminated by May 2010.[34] Original volunteers and founders were once described as a mixture of Asian dissidents, journalists, mathematicians, and start-up company technologists from the United States, Taiwan, Europe, Australia, and South Africa.[35] As of June 2009, the website had more than 1,200 registered volunteers.[35][36][37]"
Why, for example, was the Panama Papers leak (or other major financial disclosure leaks) not handled through Wikileaks?
(Edward Snowden's disclosures would be another example, though that did target the US.)
And how would that go, exactly? "Excuse me China/Russia, do you have any secrets you'd like to share? Please upload to us..."
Lol. Soliciting spies sounds like a good way to get killed. If you're so eager, you go ahead and do it - but good luck trying to convince others they some 'obligation' to lest you brand them 'partisan'.
"WikiLeaks offers award for #LabourLeaks "23 September 2016
"Wikileaks offers £20,000 reward for #LabourLeaks with information on how the Labour Party’s top officials have attempted to stop Jeremy Corbyn becoming and staying on as leader.
"With our #DNCleaks, Wikileaks exposed how those at the top of the US Democratic Party had worked tirelessly to tilt the scales in favour of Hillary Clinton as she faced off against Bernie Sanders in the race to be the Democrat presidential candidate. Our revelations eventually prompted the resignation of five of the most senior members of the Democratic Party in the aftermath of the Democratic Convention, including DNC Chair Debbie Wasserman Schultz...."
https://wikileaks.org/WikiLeaks-offers-award-for-LabourLeaks...
What, do you want people to receive spy training and move to russia?
In that case - why not do it yourself? If there's a moral obligation there, isn't it yours as much as theirs (if not more, as you're the one who feels it is 'unfair' otherwise)?
Take that along with Assange's history of arrest in the 90's[1], I find it hard to take at face value that he just stopped hacking systems.
The relevant section of the essay:
> One of the things Julian found it hardest to admit to was the amount of hacking he did himself. He had worked out that being an ‘editor’ was somehow a necessary front for much that he did. He objected to the idea that WikiLeaks ‘stole’ secrets: according to him they simply understood, at a deeply sophisticated level, how the flow of information in society could be altered.
[0] https://www.lrb.co.uk/v36/n05/andrew-ohagan/ghosting [1] https://en.wikipedia.org/wiki/Julian_Assange#Hacking
Maybe, maybe not. How would we know they do that?
https://www.nytimes.com/2016/09/01/world/europe/wikileaks-ju...
> WikiLeaks, he told a Moscow newspaper, had obtained compromising materials “about Russia, about your government and your businessmen.”
> Mr. Assange, asked soon after by Time magazine whether he still planned to expose the secret dealings of the Kremlin, reiterated his earlier vow. “Yes indeed,” he said.
> But that promised assault would not materialize. Instead, with Mr. Assange’s legal troubles mounting, Mr. Putin would come to his defense.
There's also the fun time they came out against leaks that hurt Trump on the baffling assertion that Trump deserved to get to read them before release: https://twitter.com/wikileaks/status/817322050297745408
> The Obama admin/CIA is illegally funneling TOP SECRET//COMINT information to NBC for political reasons before PEOTUS even gets to read it.
Odd stance for the organization to take.
PS. Everyone here should play the 4 hour game Orwell which does a great job of communicating the social ethics at play in surveillance abuse of technology: https://news.ycombinator.com/item?id=13549725
Including/especially the CIA. Most people know the CIA; few know someone you also know. They carry more reputation that most government organizations. It's a public service to leak this.
Besides, most of what the leak has shown is that there is an economic investment in remote code execution, but nothing that new or unknown.
Or, you know, you spend a decade hiding in some embassy indulging your prosecution complex and thinking up elaborate revenge scenarios for everyone who ever dared to question your genius.
* Arabic
* Chinese
* Russian
* Korean
* Farsi
Interesting...http://searchsecurity.techtarget.com/news/450416071/WikiLeak...
You can't. LOLZ. Yet.
https://wikileaks.org/ciav7p1/cms/page_16384857.htmlI doubt the CIA is only involved in one technical attack and not others.
Disclaimer: I know and have worked with the people on Operation Blockbuster.
I don't know if the CIA did or would want to do this specific attack.
But, I could grasp at straws to fit the Sony attack in line with the narrative of what I would call "1950s American Imperialism".
In my view, the Americans took covert or overt actions for many decades now to undermine economically competitive countries. We've bombed Germany, Italy, Japan, Serbia, Korea, China, Vietnam... we've invaded Iraq... we've taken actions against many Latin American governments and Iran...
Over the years, the powers at be have been pretty good at framing other nations for attacks or dangers, in order to drum up public support to attack them. Gulf of Tonkin, WMDs, USS Vincennes...
So, in short, if you had definitive proof that Russian and NK hacking were in fact orchestrated by the CIA...
... then the economic imperialism narrative would hold as pretty plausible motives!
The most blatant endgame here for the US is "NK hacked us. They have nukes! It's time to invade!". And then NK becomes a new market for the West to take over for cheap as they did in Communist Yugoslavia and so on
But "They have nukes!" would be reasonable enough reason to invade. Why not work with that narrative as opposed to "They're hacking us!"?
Some might say the US has a moral obligation to pursue regime change in N Korea, but US foreign policy has focused on isolating as opposed to invasion
Perhaps it is convenient fear-mongering and deepening of arguments. America seems to be pretty good at spreading multi-faceted arguments about why you shouldn't even _think_ about the legitimacy of a multi-polar world.
I guess my point is, the American government and official state media seem pretty content to have these multi-bullet playbooks against nations that are quite deeply fulfill the criteria of "non-western", "non-democratic", "non-capitalist", but still quite serious "economic and militaristic threats"
Stuxnet was (in a sense) a much more interesting topic than this leak. It showed that the retaliation is pursued not only by isolation and sanctioning, but with (subtle & undercover) direct attacks too.
LOL
90% of intelligence community cyber security spending is on offensive projects, so this revelation should not be too surprising. (http://www.reuters.com/article/us-usa-cyber-defense-idUSKBN1...)
In theory, 50% offense and 50% defense should be the only budget for a sane operation.
2) Cyrillic is an alphabet, not magic incomprehensibility dust. There are plenty of Russian speakers who are not beholden to their spooks.
3) Assange has an agenda in addition and orthogonal to fighting secrecy. I'm not saying he's insincere; I'm saying that some leaks are clearly more equal than others. It would not surprise me in the least if he were to sit on some leaks in order to not piss off a source providing others, especially around hard deadlines.
I think I heard the first heard the "Russia switches back to typewriters" story pre-Snowden.
Electronic typewriter bugs are also not unheard of: http://www.cryptomuseum.com/covert/bugs/selectric/.
>A source at Russia's Federal Guard Service (FSO), which is in charge of safeguarding Kremlin communications and protecting President Vladimir Putin, claimed that the return to typewriters has been prompted by the publication of secret documents by WikiLeaks, the whistle-blowing website, as well as Edward Snowden, the fugitive US intelligence contractor.
>The FSO is looking to spend 486,000 roubles – around £10,000 – on a number of electric typewriters, according to the site of state procurement agency, zakupki.gov.ru. The notice included ribbons for German-made Triumph Adlew TWEN 180 typewriters, although it was not clear if the typewriters themselves were this kind.
>“After scandals with the distribution of secret documents by WikiLeaks, the exposes by Edward Snowden, reports about Dmitry Medvedev being listened in on during his visit to the G20 summit in London, it has been decided to expand the practice of creating paper documents.”
>Unlike printers, every typewriter has its own individual pattern of type so it is possible to link every document to a machine used to type it.
Now, their hacking tools are obviously not in paper form but I bet they're much more tightly controlled than the CIA/NSA tools. They probably have a much smaller team of people who have access to such tools so it's much harder for them to leak. It's also easier to do counterintelligence on people who do have access and you can bet every one of those people is monitored to some degree.
US has thousands of contractors who work for CIA/NSA/DIA and other intelligence agencies and many, supposedly, can easily walk out with some of the most sensitive documents that the USG possesses. [1] One of these contractors, supposedly, leaked out these files to WikiLeaks [2]. FBI is now on a hunt to figure out who it was.
Russians don't have a huge network of contractors. I couldn't find the exact figure but by a quick estimation, Russians have 100x less people doing the intelligence work. They also have much, much smaller budgets because of their economy. So it's easier for them to keep secrets from leaking.
CIA probably (most definitely?) has moles inside of FSB so FSB secrets do leak. Just not to WikiLeaks.
[0] http://www.telegraph.co.uk/news/worldnews/europe/russia/1017...
[1] http://www.federaltimes.com/articles/fbi-arrests-contractor-...
[2] https://www.wsj.com/articles/authorities-questioning-cia-con...
> Russians returned to typewriters for all their top secret stuff
That's what they're telling people, I wonder how much truth there is to it. At the very least it provides a plausible cover story for when people ask why there aren't big leaks.
So like in usual organised crime most of people in charge are relatives or close friends and different spheres of influence are controlled by different groups of them. Most work there to make money on corporate raid or government contracts.
There is always wars for power between different groups inside those agencies which make people working there more careful about everything they doing since others always watching. So just like most of criminals they tend to not leave tons of documents in their email.
PS: And one more reason is obviously fact that no one want to end up drinking polonium tea or just get few bullets in back. Criminals don't have problem with killing traitors or those who failed to keep secrets.
https://www.bloomberg.com/view/articles/2017-01-30/how-russi...
Leaks include president Medvedev personal email and his secretary email, then Vladislav Surkov secretary emails and multiple entrepreneurs related to Kremlin. Though I doubt there was a lot of interest to them outside of Russia.
Apparently, he claimed on Fox News that he had something on Trump, but that it wasn't interesting enough to release it.
Not saying that this is a regular trend or something, but it seems like there is some evidence from Assange himself that they don't publish everything they have verified.
Further down someone asked: "What would be the advantage to making your exploits appear to come from other countries?". If you want to sow doubt about the validity of evidence presented this seems like a good way to do so (not that we shouldn't be skeptical given the tools available).
Could be a fun one for game DRM? Or apps where an API key is hidden in the binary?
Do you need THE best software-development talent to be able to build comprehensive surveillance like the big agencies? Like THE Christiano Ronaldo or THE Michael Jordan of programming.
Or is this more about funds and the power to set such a system in motion?
My thought is that much of the problem is tactical, logistical, organisational, and capabilities-oriented.
Consider the problem domain:
1. There's a vast amount of information flowing around the world. Much of it remains at best poorly protected, and until recently, that was even more the case.
2. Much of surveillance revolves around access to the channels themselves. Which means places such as satellite uplink/downlink centres, transoceanic cable landfalls, major switching hubs, telecoms hubs (AT&T's notorious San Francisco closet), etc.
3. Then you've got the problem of simply ingesting the information. For that, you need fat pipe of your own, and massive storage.
4. Then the problem of classifying and prioritising the information, or identifying and tracing specific targets. Again, in both cases, scale matters more than capability, where scale is both a matter of data (transmission, storage, processing) and above all access.
If you want to tap a specific landline, or cellphone, or cloud / online storage provider, do you have the tactical assets in place to be able to do so? E.g., official or unofficial liasons with the organisation in question. If official, how do you maintain that relationship (what balance of carrots and sticks). If unofficial, do you risk burning through such assets by utilising them. Google, to take an example, apparently looks poorly on employees directly accessing user data, and could well discipline or terminate any staff or contractors who do so. This doesn't mean that the NSA doesn't have and cannot use such assets, but they can likely only use each one a small number of times, possibly only once. That raises the costs for any such access, though again, scale offers a potential counterweight. (Rinse, wash, and repeat for all non-Google organisations, I'm actually raising them as an example here on account of their apparently stringent internal controls.)
5. Technical capabilities. For any given channel, there are the fundamental information-theoretical problems of establishing a link, transferring, and comprehending data. Depending on the complexities involved, this may be easy or hard, but there's almost certainly a fixed setup cost for any given service. This also means that the surveillance entity will likely target technical sources by some balance of total size (likelihood that any given target will be on it) and specific interest (that a particular target is there).
Such resources are again finite, and suggest yet another possible defeat: by embracing rapid change, workfactor for achieving technical penetration increases.
I'm arguing my own way through this, but in general, I'd think that size matters more than skill, though the two complement, and there are almost certainly instances in which brute intelligence and capability in conceiving of exploits is an essential factor.
For example the official pretext for WWII was started as a false flag: https://en.wikipedia.org/wiki/Gleiwitz_incident US did it at the start of Vietnam War: https://en.wikipedia.org/wiki/Gulf_of_Tonkin_incident
We gain a lot from this. We can for example manufacture "Russian hysteria" - "Look we found a Russian rootkit on a DNC server". We can attack our allies and then make it look like the Chinese did it, and so on. It is immensely useful.
Implying a 'Russian rootkit' was planted in a false flag operation?
So the CIA pretended to be Russia helping to get Trump elected -- why?
Why do you think they might want to pretend to be someone else?
It can confuse the attribution so that trust is spoiled, so that energy is spend uselessly, so that another country takes the blame, for false flag attacks to justify other strategic moves.
Like it's the case with the NSA: http://www.networkworld.com/article/3137065/security/shadow-...
It's unethical to pull on a little piece of metal?
We detached this comment from https://news.ycombinator.com/item?id=14008045 and marked it off-topic.
If anything wikileaks has shown a superior journalistic record in publishing whatever comes across their desk, so I don't see people criticising wikileaks on this the weakest of points as anything but intellectually dishonest at best.
Who said advertising doesn't work? Especially political.
It's obviously that no matter how big NSA conspiracy is every dollar spent, every meeting occur, every decision made all have to be controlled and documented. And any 3rd party company working for agency must have official contract, must report taxes and sometimes can even sell all the same tools for other governments. So it's thousand people participate at every single step.
In world of paranoid and corrupt ex-KGB mafia nothing like that required. All you need is just few experts and enough of money. Russia have plenty of online criminals: carders, illegal pharmacy and drug dealers, owners of credit card processings used for fraud, money laundering payment systems, botnet owners, spyware developers and most of them are controlled by state or somewhat under special agency protection racket.
Need 0-day exploit? Rootkit? Spyware? Any unique tools? Anything can is there for money! DDoS attack or a lot of proxy servers at any location needed? Plenty of services there and agencies obviously know owners. No documentation or reporting needed since corrupt government agencies are closely tied to those criminals for years.
So the same attacks that would involve at least few hundred of people in usual US three letter agency would likely require to just few dozens in Russia. What's more important no one would ever tell the difference between this activity and usual agency behaviour that related to usual corruption schemes.
So if you seriously think there is Russian government behind some attacks then shouldn't expect any leaks about that. If there is something important for Kremlin they wouldn't mind to dump money on it, but there will be very few people aware of it and of course there will never be any documents or other traces since they would be done as any other attack against commercial company or opposition politician.