Dumbo: CIA system to take over webcams, microphones
wikileaks.org
wikileaks.org
So?
This just in - people with physical and administrative access to a machine can install monitoring software - news at 11. Be sure to tell every MSP or Enterprise IT group to tune in.
If you are a US citizen, that tells you how you tax money is being spent. If you are a foreigner, you may have a few more ammunitions to get the funding for whatever security project you are working on.
Even on HN very few front page items are really worthy of anything more than procrastination material and it succeeded perfectly well at that: both you and I had better things to do than comment on this article.
That's a very blasé attitude btw, reminds me of the first time I have seen a wild tortoise, my family just commented: "yeah I see them all the time on TV, what's the interest?"
https://www.wired.com/2012/05/cctv-hack/
This was public then and you can expect the black hats knew this years before. So again, what is new about this other than CIA? Yes, the CIA does these things; they wear black hats and that's also something we've known for quite some time.
Perhaps a more enlightening article would have been a wiki dump of manufacturers and distributors of these 'security' cameras not giving a shit about this problem.
But hey, Snowden.
The field guide provides great detail on operations and limitations of a specific existing tool (sample GUI screen shots, potential detection threats from personal security products and full crash dumps, detection of cam software process restarts, abilities to stall NIC cards, abilities to BSOD, ability to corrupt existing files, limitations based on cam emulation, limitations of previously saved cam files, the tool's PE names(32bit wscupd.exe, 64bit running outside of system32 wermgr.exe. GUI.exe present in the same folder as above PEs), example of the log.txt file written to the attacking USB, information on differences between winXP requirements vs other systems(scanner.sys driver needs)).
Second, CBP asks for your password. This is not the same as an administrator password, and certainly in the case of some business travelers, they may not know the admin creds.
You also don't need a warrant for breaking into the systems of a non-citizen outside the borders of country initiating the hack.
As long as the various intelligence agencies are not operating within the borders of their own countries, targeting their own citizens or sharing information in totality with foreign agencies as quid-pro-quo to achieve the same (Five Eyes), I have no moral issue with intelligence agencies doing what they're supposed to do.
But this is exactly how it works under the precise legal framework you've laid out. This is the problem.
To attack allies internal enemies needs to be prohibited.
You honestly believe that those "words on paper" have any kind of restrictive capacity on these agencies? If you really do, I've got a bridge to sell ya.
You mean the U.S. wholesale spying on the British for the British to circumvent British privacy laws and the British doing the same for the U.S.?
In a situation like this, there's little point in saying that intelligence agencies can't spy on Americans, because they're doing it anyway, they're just using a proxy to do so to bypass American laws.
Here is an article from yesterday's Hollywood Reporter where a "genealogist" who just happens to work for the US federal government and has a Top Secret security clearance and claims to use "a global network of public databases" proudly talks about stalking and doxing a local Los Angeles celebrity:
http://www.hollywoodreporter.com/features/angelyne-la-billbo...
Here is some old news about NSA analysts stalking spouses/girlfriends/women they were interested in:
https://www.washingtonpost.com/news/the-switch/wp/2013/08/24...
CIA/NSA analysts now think that abusing their illegal domestic surveillance programs to stalk and dox people is a fun hobby.
maybe they have stuff like james bond watches that can burn stuff with lasers & stuff.
Dumbo itself needs admin access, but nobody said they don't use multiple tools in combination.
There is a very big difference between the security of peoples financial and tax records compared to say... some 70yr olds private email account stored on a poorly secured home server. Not to mention someone like Putin would likely have layers of shell companies and layers of diversions where it wouldn't be of much use.
People like to pretend Wikileaks can hack and leak anything, and it's merely a political descision for them on who gets hacked. But they are merely a platform for leaks, publishing almost exclusively either opportunistic hacks (Manning leaks) or low hanging fruit (personal email servers) they recieve from other people. They don't direct a network of hackers to do their politically motivated bidding.
https://www.c-span.org/video/?431852-1/william-browder-overt...
edit: I was having trouble with the C-Span player recently, so here's a youtube cap. https://www.youtube.com/watch?v=S-RsAGjUXtg
One of the senators put it well when they said something like 'it plays out like a novel nobody would buy'.
That's an honest question. He's widely assumed to be corrupt, to have a large amount of money personally, and an enormous amount more at 1+ removes held by people connected to him. There's no sign that he intends to leave power, which means he can store plenty of it without any paperwork at all - just an implicit "you'll use this as I ask if I ever do ask".
But he's also virtually untouchable, and his wealth-hiding seems to be less "no one can find it" and more "no one can prove it so undeniably that it becomes inconvenient". I'm not convinced there's anything 'leakable' that would be particularly important.
----
Furthermore, beyond the campaign coverage, Wikileaks has revealed a lot of non-election related things over the last year, including CIA programs to remotely hijack any Samsung SmartTV and turn it into a listening device.
Wikileaks appear to be staying true to their mission. It's sad that there is such a strong impulse to discredit the organization as a whole, and ignore/derail large amounts of the absolutely critical work they are doing, just because the group exposed the corrupt practices of one's favored political candidate.
It takes a certain willful blindness to think otherwise.
That seems to be pretty much what you'd expect from Wikileaks, no? A bunch of links to raw documents and cited critiques on international meddling and journalistic practice? That stream includes a criticism of U.S. meddling in international affairs, two leaks against the Trump admin, and a criticism of the WaPo's incompetence in sanitizing their leak, thus risking their inside man.
How does it reveal "the side" that Wikileaks is on? If it's simply a matter of willful blindness, please enlighten me; I've got my eyes open here.
"The Brutal Kangaroo project consists of the following components: Drifting Deadline is the thumbdrive infection tool, Shattered Assurance is a server tool that handles automated infection of thumbdrives (as the primary mode of propagation for the Brutal Kangaroo suite), Broken Promise is the Brutal Kangaroo postprocessor (to evaluate collected information) and Shadow is the primary persistence mechanism [...]"
And if 32-bit XP is supported, you can almost guarantee that Windows 2000 is supported by this attack as well, since XP is literally built on the 2K kernel.
Well, never could say I trusted Wikileaks with 100% accurate information.
Regardless of the authenticity of the information, they clearly only release information when it is politically beneficial for their(?) motives.
Then came the promises of damning Bank of America leaks that never materialized, holding on to Guantanamo docs until NYT scooped them, the 2010 insurance file that was never cracked, the 2016 insurance file that was never cracked, ...
Well they're still supporting "the people", just not the ones you align with. Which of course means they've lost all credibility and we should ignore them now, right?
How are they supporting the people? How does this benefit society? All this does is attempt to take away the spotlight from other shit happening in our country. Every major country develops hacking software. This isn't news. This isn't even surprising or ground-breaking. It's not even that invasive, it requires physical access AND an admin account!
This is just a distraction. Society is no better off with this information being public.
I think WikiLeaks started with noble intent but it's really the depths of naivete to think a small volunteer org can play spy games with the big boys.
What we need is a fully decentralized WikiLeaks type platform that is easy enough to use that regular non crypto nerds can use it. No identifiable centralized organization can really be trusted to be objective or impartial or to be resistant to compromise.
There is so much agenda driven propaganda on social media now.
But hey, nothing grows at a regular speed and in straight line, this may still happen.
Wikileaks will next reveal water is wet. Why does anyone pay attention to these charlatans?