Wickr is set up like an expected honeypot would be set up. So for people that don't or aren't willing to understand that, I'm wondering if this document validates them, or if the skepticism of this document's classification level validates the idea Wickr should be avoided for sensitive communications.
Which leaves anyone planning on doing something the US gov’t (or China, or Russia if within their reach) wouldn’t like left with some unpalatable and inefficient options.
Either they blend in enough to not get any attention, or don’t seem “dangerous” enough in the sense they are likely to get anywhere, or don’t use any technology more complicated than a piece of paper and a #2 pencil.
The last one was what osama bin laden was doing, and they still found him - it just took awhile.
As long as the folks being targeted are legitimately out to do harm against innocents, these capabilities are ‘ok’ (scare quotes intentional here).
They’re going to be turned against political opponents or people that just seem ‘bad’ though at some point, and almost certainly already have been for years.
I won't detail the designs here, but we are talking very cheap to build and design.
I am sure such devices exist and are in the wild, being used by spies.
That said -- I am mostly disappointed with the degree to which our intelligence agencies are inwardly focused rather than breaking up foreign spy rings and operations.
There are some scarey, harmful, and extremely complicated foreign spy rings on US soil. They have people working for all major tech companies and they are embedded in key positions.
The FBI should be making "see something? say something" pushes in tech companies. They should have better followup and reward systems.
Never heard of data diode before. The hardware setup gives such a peace for the paranoic mind. Love it!
I'm sure this will not foster distrust, will do wonders for morale among immigrant tech workers, and will in no way leave them primed to be recruited by foreign intelligence services.
So yes, you should make sure if your threat model cost benefit says you should:
* You have a secure keyboard mechanism. No third party keyboard apps, used a wired / built in keyboard.
* You use a secure OS and keep up to date. You verify updates are public and not made 'just for you', you turn off auto updates.
* You watch the network behavior of your devices with external proxy devices to see if anything weird is happening, you filter out network interactions you don't like, use a VPN with the proxy device and so on.
The more you use 0days, the more they get noticed and the more likely you are to burn them, so you've just increased the stakes towards surveilling you. Now the minimum standard to make you a person of interest has increased significantly, reducing the probability of it.
I only worry about innocent westerners living in a society that is creeping toward authoritarianism in the name of some politically polarizing politician. I do not empathize with hackers breaking into systems and causing major problems.
And there are other threats you'll want to defend from as well, including governments and agencies with smaller budget.
Anyway, if endpoint security is part of your threat model, you'll be pleased to know I've spent the past decade looking into how to address the problem https://github.com/maqp/tfc
If this information has been publicly released, I would assume that it does not comprehensively list all of the methods/sources that could be in use. Thus, I would not trust this document to be accurate.