Is There A Positive Aspect To CIA Spying?

The latest release from WikiLeaks detailing how the CIA has allegedly stockpiled a plethora of tools to hack a variety of everyday devices, from phones, to televisions to cars, is a stark reminder about the fragile state of Internet security. 

The US government has amassed extraordinary hacking powers largely in secret, and this leak might just force us to grapple with whether we are comfortable with that.

The most widely reported aspect of the purported leak is the allegation that the CIA has myriad ways to hack popular smartphones like iPhone and Android devices, and that the agency could be allowing its hackers to take control of internet connected televisions and covertly listen in on conversations in people’s living rooms. 

This type of attack has been the worry of many privacy advocates for years, as more and more televisions and other household devices, collectively known as the Internet of Things, are increasingly connected to the Internet while always “listening”.

There was never a doubt that the US and other government around the world would quickly move to leverage the ability to exploit these features, as more and more consumer electronics companies have made them standard in all sorts of household items. 

The former Director of National Intelligence James Clapper even made clear in testimony to Congress last year. But just how often governments have exploited this type of technology is still largely unknown.

While many of the headlines accompanying these documents will send a shiver down the spine of readers, there is some good news in the WikiLeaks documents. 

Contrary to some early reports suggesting that the CIA can “defeat” popular end-to-end encrypted messaging apps like Signal and WhatsApp, the WikiLeaks release is further evidence that encryption does work to protect people’s privacy.

The documents do purport to show is that the CIA has a host of exploits to attack the operating systems of popular mobile devices like iPhones and Androids, a deeply worrying prospect, to be sure, but to “defeat” secure messaging apps, government hackers essentially have to gain access to your phone itself before they can read your messages. 

So if you’re using an app like Signal, the content of those communications are at least still likely protected from their vast surveillance nets that otherwise indiscriminately capture billions text messages and emails per day.

This is encouraging news. The Snowden revelations were so offensive to so many people because the government was secretly using mass surveillance to spy on hundreds of millions of people at once, the vast majority of them innocent. 

With countless users switching over to end-to-end communications in recent years, it means intelligence agencies like the CIA must target individuals one by one, which, in turn, means the cost for each surveillance target goes up, and forces them to prioritise a much smaller number of people.

Still, the amount of smartphone vulnerabilities and exploits detailed in these documents was shocking even to experts. “It certainly seems that in the CIA toolkit there were more zero-day exploits”, an exploitable vulnerability in software not known to the manufacturer, “than we’d estimated,” Jason Healey, a director at the Atlantic Council think tank, told Wired Magazine. He added: “If the CIA has this many, we would expect the NSA to have several times more.”

As Edward Snowden himself tweeted recently: “Why is this dangerous? Because until closed, any hacker can use the security hole the CIA left open to break into any iPhone in the world.” He called it “reckless beyond words.”

For years, civil society groups have been calling on US intelligence agencies to disclose these vulnerabilities to tech companies instead of hoarding them in secret. Intelligence agencies should help make the everyday devices we rely on safer, rather than less secure. 

The government has claimed that they run the vulnerabilities they know about through an interagency “equity process” to determine whether they should disclose and help fix them. But the surprising amounts of exploits in the WikiLeaks release suggests this process is either woefully inadequate or largely only exists on paper.

Undoubtedly, there will be a heated debate over WikiLeaks and the value of having these documents in the public record for the days and weeks to come, as any publication by WikiLeaks inevitably does. 

But whether Trump administration officials like it or not, the hacking powers of our government is a vital topic that needs much more public debate, and this latest release may end up fueling it.

But in the mean-time, perhaps you might download Signal.

Guardian:

 Assange Says CIA Lost Control Of Its Cyber Weapon Documents:

CIA leak 'absolutely' an 'inside job':           Signal: The Snowden-Approved Crypto App Comes to Android

 

 

« A Common Language For Sharing Intelligence On Cybersecurity Threats
New Malware Hides In Memory »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Jooble

Jooble

Jooble is a job search aggregator operating in 71 countries worldwide. We simplify the job search process by displaying active job ads from major job boards and career sites across the internet.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

NetExtend

NetExtend

NetExtend services include backup and recovery, endpoint protection, network monitoring, cloud portal and billing and payment solutions.

Japan Information Security Audit Association (JASA)

Japan Information Security Audit Association (JASA)

JASA is non-profit association active in developing and managing the quality of Information Security Auditing and Auditors in Japan.

SBS CyberSecurity

SBS CyberSecurity

SBS CyberSecurity is a premier cybersecurity consulting and audit firm.

Cyber 2.0

Cyber 2.0

Cyber 2.0 is the only system in the world that blocks all forms of cyber attack within the organization, including new and unfamiliar attack methods.

PECB

PECB

PECB is a certification body for persons, management systems, and products on a wide range of international standards in a range of areas including Information Security and Risk Management.

SynerComm

SynerComm

SynerComm is an IT solution provider specializing in network and security infrastructure, enterprise mobility, remote access, wireless solutions, audit, pentesting and information assurance.

Thinkst Applied Research

Thinkst Applied Research

Thinkst is an Applied Research company with a deep focus on information security.

SolutionsPT

SolutionsPT

SolutionsPT enables customers to strengthen their Operational Technology (OT) network to meet the ever increasing demand for performance, availability, connectivity and security.

CASES.lu

CASES.lu

CASES.lu is a government-driven initiative offering awareness-raising, a web resource and other tools to assist SMEs concerning information security.

Emirates International Accreditation Center (EIAC)

Emirates International Accreditation Center (EIAC)

EIACI is the national accreditation body for the United Arab Emirates. The directory of members provides details of organisations offering certification services for ISO 27001.

Prolimax

Prolimax

Prolimax deliver innovative solutions to IT Manufacturers, Distributors, Resellers and End-users including Data Erasure and secure IT Asset Disposition (ITAD)

VIBE Cybersecurity International

VIBE Cybersecurity International

VIBE’s certificate-less authenticated encryption enables scalable, flexible key exchange, and other advanced cryptographic functions using identity-based elliptic curve cryptosystems (ECC).

Raonsecure

Raonsecure

Raonsecure is one of Korea’s leading ICT security software companies – providing a variety of PC and mobile security solutions to financial institutions, government, and enterprise.

Bloc Ventures

Bloc Ventures

Bloc Ventures is an investment company providing long-term, ‘patient’ equity capital to early stage unquoted deep technology companies.

Aceiss

Aceiss

Aceiss empowers access security, providing unprecedented visibility and insights into user access.

Josef Ressel Centre for Intelligent & Secure Industrial Automation

Josef Ressel Centre for Intelligent & Secure Industrial Automation

The Josef Ressel Centre for Intelligent and Secure Industrial Automation investigates the fundamentals of digital assistants for industrial machines that enable intelligent and secure operation.