The CIA Campaign to Steal Apple's Secrets (2015)
theintercept.com
theintercept.com
> The modified version of Xcode, the researchers claimed, could enable spies to steal passwords and grab messages on infected devices. Researchers also claimed the modified Xcode could “force all iOS applications to send embedded data to a listening post.” It remains unclear how intelligence agencies would get developers to use the poisoned version of Xcode.
Sounds suspiciously like XCodeGhost: https://en.wikipedia.org/wiki/XcodeGhost.
This is probably worth a reference to Ken Thompson's "Reflections on Trusting Trust".
I'd be more concerned if the intelligence agencies of the world WEREN'T doing this. It's their purpose. It's what we pay them for with our taxes.
Of course we should also always root for tech companies to stay one step ahead. But infosec is an arms race, and I sure hope my own country's intelligence agencies (CSIS and the CSE in Canada) are doing their best to stay ahead of, say, North Korea or Russia.
(Please note: I'm not saying violating our privacy is OK, any more than I'm saying it's cool to launch nuclear weapons. But if anyone's going to have the ability to hack my phone or launch a nuke, I want it to be the people on my own team. This seems like basic self-interest and survival strategy.)
One would hope that they were trying to gain access to someone else's devices, as opposed to turning the guns towards their own citizens and economy. If a soldier showed up at my door and pointed their gun at me, my reaction wouldn't be "of course you're doing that, your job is to point guns."
But somethings like breaking encryption, exploiting iPhones, etc. while they may be used against Americans can also be used against others.
Essentially there's an arms race, and we use our tax money to sponsor our government in this race, with the hopes that they'll side with us. There really isn't another option unless you want to give a private entity this power, or not participate in the race (which I don't advise).
> But somethings like breaking encryption, exploiting iPhones, etc. while they may be used against Americans can also be used against others.
Both of these can have a chilling effect on free speech, therefore I'm against the CIA doing this to citizens. The potential threat against citizens nowhere near outweighs the need to uphold our constitution.
Ironically though, the average American citizen is probably under more CIA surveillance than the average foreign person such as myself.
Why keep pretending the CIA is a foreign intelligence service?
Apple devices are sold all over the world, so there's no way of gaining access to the enemy's devices without that method also being applicable to everyone else. Actually using them on everyone else is a different matter.
Which enemy?
Regional rivals: North Korea and Iran
Authoritarian partners/allies: Turkey, Saudi Arabia, a bunch of other Middle Eastern countries
A bunch of countries flirting with authoritarianism: Brazil, Hungary, Poland, Israel
If that sounds dumb to you, you should rethink the statement about Poland and Hungary.
That's only true of some methods like using exploits and other vulnerabilities, or mass-surveillance style methods. It's not true of other types like confidence tricks and social engineering, eavesdropping and potentially watching passwords being entered or getting them on camera, phishing, fake wifi points, tailored viruses, or cookie hacking. Those methods can be designed for a specific target. Of course, there's also the good old-fashioned method of getting a warrant for data.
The entire concept that the government has "a right" to this data - an argument I've seen judges actually make to justify these activities - is ludicrous. They don't have a right to it by default. They have a compelling interest in the data/information if and only if there is enough reason to believe someone is up to criminal activity. In which case they should have no problem at all getting a warrant.
If anything, a citizen is more capable of carrying out a terrorist attack, or just doing any action some foreign power wants to perform in that country.
The exception for domestic citizens seems to be just a concession for the masses and their representatives, not a pragmatic choice.
Edit: a pragmatic reasoning could be compartmentalization — keeping citizens under the watch of a separate entity (e.g. FBI) but it doesn't explain why domestic mass surveillance should be ruled out.
It's a matter of who we have a responsibility towards.
The government we elect in our own country is responsible to us, and as a people we widely do not want our government spying on us. (This is true in most if not all countries.)
But that same government is NOT responsible to the citizens of other nations. The CIA has no responsibility towards Canadians (like myself) or anyone else who isn't American.
I'm not arguing that this is ethically right. I'm just saying it's pragmatic.
If you're not a citizen of my country, my country has no legal obligations to you outside of international law. And no country, to my knowledge, has ever tried to introduce the right to privacy into international law. Every country hates spies within its own borders, but seeks to have them inside of everyone else's.
That was a slogan of the revolution, but there were more than one; it wasn't the unique complaint. There was also a fairly specific list of grievances in the Declaration of Independence.
The early revolutionary war history overly simplified is something like this. Britain increases taxes on America. America stops paying taxes. Britain increases military presence to force America to pay taxes. America fought against the British military.
During the increased British military presence in America the British goverment did terrible things, including living in civilians homes and eating their food. This is what the parent comment meant when he said "The American revolution was started because citizens did not want the government in their homes." Ultimately, the British goverment was in American homes to help the tax collection effort, so your idea of early Americans caring a lot about taxation is also true.
Thanks!
Also, the whole trial by jury of peers was really great for those like John Hancock (the guy who signed his name really big on the Constitution) who got in trouble with the British for smuggling and then would be invariably found not guilty by his employees. When military trials came into place, Hancock and his distributor buddies started getting jail time.
Also, by the way, Hancock shipping basically had a mob, who were responsible for a bunch of the rioting in Boston and likely the related Tea Party.
Just wanted to point out that America wasn't exactly formed out of ideology.
By the way- that big signature? Essentially the largest political middle finger ever.
However, there's nothing stopping them sharing capabilities with the Five Eyes and asking one of them to spy on a US citizen...
Look for WMD's in middle eastern countries to justify policy?
https://en.wikipedia.org/wiki/Nuclear_weapons_and_Israel#US_...
Nope, if you create a weapon you better be prepared for your enemy to use it against you.
In an ideal world, no one can hack my phone. This is why I support Apple and Google and Microsoft and all the others doing their very best to keep my devices as secure as possible.
In the worst-possible world, enemy nations have hacked my phone. Because if they've hacked my phone, they've also hacked those of my politicians and military.
In the real world, the only way for my country to be able to defend against enemies is to be as-good-as or better than those enemies at hacking my phone.
That's why I support it. Because I have a sneaking suspicion that truly awful people are working hard to hack every device out there, and the best infosec defense is a good infosec offense.
I don't disagree with you that "if you create a weapon you better be prepared for your enemy to use it against you". But a worse scenario than that is for my enemy to beat me to the punch and I'm standing here with sticks and stones.
The thing about an arms race is that once it starts, it's pretty much impossible to get out of. I didn't start the infosec arms race. It would be nice if the race didn't exist at all. But it does.
Only a "political doofus" would prefer to pretend otherwise.
Sadly, the omniscient and incorruptable rep of the NSA/CIA and associated TLA have been significantly tarnished by Snowden and the current external political interference. This is a crisis, because there are likely people in powerful positions of those orgamizations who do not have their countries interests at heart. Whatever ideology (white nationalist or communist) or external subversion they are not being adequately policed in the current situation.
I would prefer they spend their efforts spying externally rather than internally and keeping everyone's private information safe. For example focus on vulns in Huawei 5G base stations or foreign anti-virus installations instead. I think that's safer for us tax payers. Heck, use the social credit system for your own ends, as they did with Tindr.
They should also absolutely be looking for vulnerabilities in Huawei products. They should be looking for them in any product with significant market share. But there's no reason to think they can't do both.
All that aside: Theres a social credit system with Tinder? Am I reading you correct? Tell me more! That sounds way more interesting...
Thought experiment: You're a chinese spy. Your enemy is pouring tonnes of effort into hacking the phones made by your own country, but have chosen to put zero effort into hacking those made by theirs.
Which phone do you use?
Meanwhile, your own people are good at hacking both American and Chinese phones.
So in this scenario, the USA's decision to not try to hack products made by American companies leaves them at a decided disadvantage to China's decision to hack all of them.
Another point worth making is that the government can't really be on your team, as they tend to hog the ball/puck.
That's kind of the root problem of democracy, isn't it? If a government truly is "of the people, by the people, for the people", then they are by definition on their people's team, and their people should trust them.
But, if they can't in fact be on your team, and if you can't trust them, then you can't really have a democracy, can you? You end up with something else, something that looks like democracy but really isn't.
Why do they explicitly violate the law (re: Iran/Contras)?
Why...
Research, which is what this article appears to be primarily about, the CIA is permitted to conduct domestically.
None of these agencies are "on my own team". They are all adversaries. I feel far more threatened by US government hacking precisely because I live inside US jurisdiction. If we were to have a difference of opinions, and they were to snoop around in my data and decide they didn't like what they found, well, I'm sitting right here; they could easily ruin my life.
What are the Koreans or the Russians or anyone else going to do to me? They're an ocean away and I pose no conceivable threat to them. Harassing me would be expensive and pointless; they're not going to bother.
https://en.m.wikipedia.org/wiki/Poisoning_of_Alexander_Litvi... https://en.m.wikipedia.org/wiki/Sergei_Skripal
It's ranging from secret services trying to use people to bomb planes and public places, to dissidents active abroad being threatened, beaten up or assassinated by suspected secret services of their origin countries. On source of such activity is Assad's regime in Syria.
https://www.middleeastmonitor.com/20190119-is-assad-trying-t...
It's uncommon, unlikely, but not that unique.
However:
1) I maintain that the only reason to fund an intelligence agency is to expect them to perform intelligence activities, and today that requires being the best in the world at black hat infosec.
2) I mistrust my government less than I mistrust yours or Russsia's, because at least my government depends on me for votes and taxes and general compliance with laws.
But this also means that they have way more reason to lie to you and to mislead you.
I mean, if they successfully lie to me, they get my taxes.
If they successfully lie to you, maybe you don't invade our country.
The US has such an overwhelming military advantage over North Korea or Russia that it doesn't have to gain a leg up in infosec. All it has to do is level the playing field by making sure that everyone's running as securely as possible.
I'll rely on the one dozen Naval Carrier Strike Groups to keep me safe. Really doubt that reading Kim Jong Un's email is going to make a difference.
You're absolutely right! It's unquestionably the job of the US intelligence apparatus to help secure American interests.
With that said, Apple is a multi-national company, with millions of units used by people of all nationalities. And a vast amount of American military superiority is based on superior technical intelligence.
A carrier group can solve, at great expense in blood and treasure, a problem that intelligence can often solve more quickly and at an earlier point in time. With that in mind, it seems reckless to not take seriously the value of intelligence.
Again, you're completely correct in every way. Apple is an American company! It's just perhaps possible that there could be a bit of subtlety to this.
1: https://www.vadesecure.com/en/nsa-malware-malware-protection...
With that in mind, do you think it would be wise for an intelligence agency to refuse to consider searching for exploitable holes in a platform that is known for a fact to occasionally used by adversaries? Bear in mind that, of course, there are plenty of other groups and agencies doing the same thing.
Do you think this choice would better serve to advance American interests? If so, why? Would the weaknesses the CIA could find cease to be if the CIA was not looking for them? Perhaps you imagine a scenario in which the CIA finds every exploit first, and in doing so causes them to get fixed rapidly. Would you be comfortable with an intelligence agency working hand-in-glove with a major American company selling supposedly-secure consumer goods? Would you trust such an arrangement to protect you?
There are many, many platforms that are "occasionally used by adversaries". The Intelligence Community has put exceptional resources towards one that has a very significant market share among it's citizens. And given the wholesale surveillance we are already under, I can't accept that this was an innocuous decision.
Trust is built through positive actions over time. I have zero trust for our Intelligence Community as is; and I've actually worked with US intelligence. If they devoted a majority of their efforts to finding and patching security risks through public and open source means, I would slowly start to trust them again.
The IC invests massive resources into enhancing security. I've seen it firsthand - software projects like SELinux and a whole slew of research projects come to mind in addition to stuff I worked on. Though if you've only ever been exposed to the other side of the house, it's easy to be ignorant that the defensive missions exist at all. Certainly it tends to not make any news, ever.
>I'll rely on the one dozen Naval Carrier Strike Groups to keep me safe. Really doubt that reading Kim Jong Un's email is going to make a difference.
That's a weak strawman argument.
The fact that spying on foreign enemies now requires the capability to spy domestically is definitely a red flag. But saying we don't need infosec when that Naval Carrier Strike Group can be owned, rendered useless by a cyber attack is naive.
Moreover, rogue hacker groups from all across the world posess the power to covertly & remotely target critical infrastructure of virtually any nation. What good is a Naval Carrier Strike Group going to do against that?
The thing I'm 100% not okay with is when TLAs use social pressure, legal pressure or traditional espionage to insure there are exploits they can exploit - this has never ended well and is always a concession in security that increases our vulnerability to bad actors. I have a modicum of trust for TLAs in the traditional espionage realms, but they have entirely burned my opinion of them when it comes to tech at this point... The NSA compromising ECC `Dual_EC_DRBG` is just a level of stupidity that demonstrates a clear lack of responsibility to civilians.
I'll grant you that if the CIA broke into Apple and stole keys, that would stealing along with breaking and entering or the cybercrime equivalent. But that's not what the article says.
The Intercept longs for its Snowden glory days.
Did you read the article? The CIA -- in addition to pentesting -- is trying to exfiltrate GID keys of Apple devices. That is quite literally, trying to steal Apple's secrets -- not checking which systems have vulnerabilities.
They really didn't. There were cryptophones, such as Cryptophone, doing secure messaging and stuff before Apple. Julian Assange used one IIRC. High-assurance security did stuff like Sectera Edge with some side-channel shielding, too. Then, there were companies like OK Labs building minimal, trusted, computing bases into phones with stuff like Android sandboxed in user-mode. Sensitive stuff ran outside. Then, Apple got into the game. They could still copy some of these techniques for improved security on top of what they're doing already.
https://web.archive.org/web/20080408152145/http://www.gdc4s....
https://web.archive.org/web/20110219075132/http://www.ok-lab...
Cryptophone and the other products were a niche market and no one really knows if they are good enough to withstand a nation state attack or if they are just good enough to provide better opsec for companies than regular phones did.
I always like to remind people when this comes up - The CIA is a civilian agency. They are not military. They have no legal right to engage in anything remotely resembling military action. Their only legal behavior is to collect international intelligence, though they seem to be capable only of doing everything outside their mandate and not within it. Why they weren't disbanded after the USSR imploded into bankruptcy 2 weeks after they had delivered a report claiming that the USSR was 'not a paper tiger' and 'growing stronger every day' and that they would continue to present the largest threat to the US on the global stage for the foreseeable future I have no idea. Most amateurs could have told you the USSR was on its last legs after years of scientists and members of their military reporting not being paid for years at a time. But the CIA was absolutely certain that they were doing great. And they should know, they had devoted stupendous resources to their intelligence work there. But, nope, they didn't see it coming at all.
I think that communication technologies, and high speed internet becoming so widespread, created a big new battlefield which is particular because it's not so violent and ugly.
There aren't clear military laws about the internet like there is for other battlefield like the geneva convention, and that's makes all of this so interesting.
I have information regarding top secret Apple swipe to unlock technology patent.....