Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Truga
May 4, 2014
Lipstick Apathy

spankmeister posted:

Some guy working at Fox-IT in the Netherlands wrote PolarSSL as a fork from XySSL, not the cia lol.

there's currently a conspiracy theory going on that that guy just lent his name to cia for it to be more legit or something along those lines

which is of course bullshit, sorry about the fake news guys

that siemens phone exploit still owns tho.

Adbot
ADBOT LOVES YOU

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

OSI bean dip posted:

so this came up in the sh/sc help thread


:psypop:

i think i made a mistake in trying to reply to this... mess
i absolutely did not read that post, thank you for your service

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender

anthonypants posted:

i absolutely did not read that post, thank you for your service

someone described it to me as eye-teflon. i pretty much skipped over half of the post to reply

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

OSI bean dip posted:

someone described it to me as eye-teflon. i pretty much skipped over half of the post to reply

i agree with that assessment

Shame Boy
Mar 2, 2010

spankmeister posted:

Some guy working at Fox-IT in the Netherlands wrote PolarSSL as a fork from XySSL, not the cia lol.

that's how i'd disguise a CIA-employed programmer if i were the CIA

hobbesmaster
Jan 28, 2008

COACHS SPORT BAR posted:

I tried about a year ago to do android sans google, and it's a loving mess. Even if you install apps from alternate stores (f-droid, etc), drat near everything expects the play framework to be present and will just crash when the api calls fail. Android without google these days basically means android without apps, I doubt there are really that many people in that segment

there's an alarming number of embedded devices doing this though

burning swine
May 26, 2004



hobbesmaster posted:

there's an alarming number of embedded devices doing this though

oh yeah, I guess there are. welp

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

ratbert90 posted:

Our current product only does SSLv3. There are no plans to update it because I am making a new product.


Also grandstream phones don't support HTTPS.

:allears:

Slap a reverse IIS proxy in front of that bad boy I guess

FlapYoJacks
Feb 12, 2009

OSI bean dip posted:

so this came up in the sh/sc help thread


:psypop:

i think i made a mistake in trying to reply to this... mess

At least he's staying true to his forums name.

cinci zoo sniper
Mar 15, 2013




OSI bean dip posted:

so this came up in the sh/sc help thread


:psypop:

i think i made a mistake in trying to reply to this... mess
sincerely lmao if you read this in full, even

spankmeister
Jun 15, 2008






Truga posted:

there's currently a conspiracy theory going on that that guy just lent his name to cia for it to be more legit or something along those lines

which is of course bullshit, sorry about the fake news guys

that siemens phone exploit still owns tho.

Fox-IT was founded by an ex intelligence guy so :v:

Plorkyeran
Mar 22, 2007

To Escape The Shackles Of The Old Forums, We Must Reject The Tribal Negativity He Endorsed

cinci zoo sniper posted:

sincerely lmao if you read this in full, even

i tried but did not succeed

cinci zoo sniper
Mar 15, 2013




if someone wants to read more of extremely stupid security things, there is a gigantic thread on /r/bitcoin where people are abashed that cia has windows backdoors

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I hope the CIA steals everyone bitcoins

Bognar
Aug 4, 2011

I am the queen of France
Hot Rope Guy

cinci zoo sniper posted:

if someone wants to read more of extremely stupid security things, there is a gigantic thread on /r/bitcoin where people are abashed that cia has windows backdoors

there's a section in there where people are arguing that linux is safe because any attempts to backdoor it would be immediately spotted because ~open source~

cinci zoo sniper
Mar 15, 2013




BangersInMyKnickers posted:

I hope the CIA steals everyone bitcoins

https://www.reddit.com/r/Bitcoin/comments/5y0e33/breaking_cia_turned_every_microsoft_windows_pc_in/dem8wbt

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles


lol

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Volmarias posted:

To play devil's advocate, this is only the numbers for devices that still contact the play store (iirc). All the garbage Chinese spin-offs that don't come with Google preloaded, or where the user isn't signed into a Google account (I ran into someone with a G1 a couple years back who never signed into a Google account on the device, and didn't realize that there was an app ecosystem) won't be counted in these numbers.

It's a good graph for deciding what minimum API to support for your Dildo Auctioning app but less useful if you're a TLA.

Those are still not likely to be on 1.x or 2.x Android, or these days even 4.x Android. Because the cheapo companies just buy whatever chipsets are cheapest at the time to shove into devices and over time that means a lack of availability of drivers/other support to use them with older versions of the OS. So Shanghai Cheap Phone Inc moves along to 5.x or whatever fairly cquickly, and their 2.x phones that were already on the market have all broken already.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/whispersystems/status/839255069090435072

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

don't spread FUD in the secfuck thread jfc

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...
So, having not actually read the source material, and not wanting to read the possibly hyperbolic wikileaks writeup, is there anything in the recent CIA leak which is particularly unexpected? It seems like "no" since normally I'd be reading all about it here with :rip: smilies etc if there was.

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe
most of the people on twitter seem to be like "this isn't anything we didn't already know/suspect"

apseudonym
Feb 25, 2011

Volmarias posted:

So, having not actually read the source material, and not wanting to read the possibly hyperbolic wikileaks writeup, is there anything in the recent CIA leak which is particularly unexpected? It seems like "no" since normally I'd be reading all about it here with :rip: smilies etc if there was.

No

fins
May 31, 2011

Floss Finder

Volmarias posted:

So, having not actually read the source material, and not wanting to read the possibly hyperbolic wikileaks writeup, is there anything in the recent CIA leak which is particularly unexpected? It seems like "no" since normally I'd be reading all about it here with :rip: smilies etc if there was.

yes

https://wikileaks.org/ciav7p1/cms/page_17760284.html

RISCy Business
Jun 17, 2015

bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork bork
Fun Shoe

i didn't see ˙ ͜ʟ˙ in there

shameful

e: that was supposed to be :nsa:

Plorkyeran
Mar 22, 2007

To Escape The Shackles Of The Old Forums, We Must Reject The Tribal Negativity He Endorsed

Volmarias posted:

So, having not actually read the source material, and not wanting to read the possibly hyperbolic wikileaks writeup, is there anything in the recent CIA leak which is particularly unexpected? It seems like "no" since normally I'd be reading all about it here with :rip: smilies etc if there was.

it's mostly just confirmation that the CIA actually did have all the things we sort of jokingly assumed they did.

apseudonym
Feb 25, 2011


This is a better answer than mine

spankmeister
Jun 15, 2008






Plorkyeran posted:

it's mostly just confirmation that the CIA actually did have all the things we sort of jokingly assumed they did.

Yes, and supposedly this is from three years ago.

Plorkyeran
Mar 22, 2007

To Escape The Shackles Of The Old Forums, We Must Reject The Tribal Negativity He Endorsed
there's iOS 9 exploits in the dump so it can't all be that old

apseudonym
Feb 25, 2011

Plorkyeran posted:

there's iOS 9 exploits in the dump so it can't all be that old

The dates don't seem consistent at all, the Android section is definitely mostly written before L shipped (it mentions some upcoming stuff in L in future tense)

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Well that was definitely unexpected :stare:

Wiggly Wayne DDS
Sep 11, 2010



we ran through the dump when it was released in the irc channel, there isn't anything that interesting and sec twitter is slowly catching up things i've not seen them mention yet:

in part of the public-malware analysis/technique re-use wiki they talk about shamoon: https://wikileaks.org/ciav7p1/cms/page_3375106.html

quote:

The Shamoon malware made use of a legitimate, signed driver from a commercial company called Eldos. Eldos sells a software product called RawDisk. RawDisk is a signed driver that allows raw writes to the active partition (which is normally prohibited by newer versions of Windows such as Vista/7).

The authors downloaded an evaluation copy of the driver from Eldos. The license check in the RawDisk driver is flawed in two ways. First, the trial key the program sends to RawDisk contains information about the valid time period this driver can be used (evaluation time frame). However, the Shamoon authors set the system time to a random date within the evluation period for the driver before opening a handle with the driver (they set the time/date back immediately after calling the target driver function).
but the next line shows they take some care with finding other flaws:

quote:

Another flaw that was not leveraged involved RawDisk bypassing license checks if the calling program's name was "RawDiskSample.exe".

worth mentioning is tool obfuscation w/ support for string replacement (examples include other languages). for all the talks about attribution atm this is being overlooked: https://wikileaks.org/ciav7p1/cms/page_14588467.html

one of the branches teaching how to handle the tools properly via ctfs: https://wikileaks.org/ciav7p1/cms/page_16385438.html

some more cisco implant guides: https://wikileaks.org/ciav7p1/cms/page_28049430.html

there's a few people not redacted correctly, nothing special there though

there's only real one top-secret doc of note: https://wikileaks.org/ciav7p1/cms/page_15728967.html
and it's because there had to make a redacted analysis from scratch: https://wikileaks.org/ciav7p1/cms/page_16384369.html

their hackingteam post-mortem is minimal and p crappy. equationgroup is mostly talking about nsa not following their own guidelines - lots of tool re-use and shared custom crypto libraries with negative constants (which people were explaining at the time as just a compiler optimisation that shouldn't be read into)

one opsec guide is empty (probably fully redacted because we can't have anything actually interesting), they left one around though for traveling to germany: https://wikileaks.org/ciav7p1/cms/page_26607630.html

on mysteriously redacted sections: https://wikileaks.org/ciav7p1/cms/space_9076737.html

quote:

Code Signing Research with Kaspersky
subpage says it's

quote:

EDG and COG development on Kaspersky
though

beyond that it's pretty boring compared to other catalogues, maybe they'll unredact something interesting or give technical samples for some relevance

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Thanks!

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!


hehe funny smileys. wait

quote:

(\/) (°,,°) (\/) WOOPwoopwowopwoopwoopwoop!

japan loves futurama???!?!?!

Applebees
Jul 23, 2013

yospos

I keep mine in my back pocket

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Lutha Mahtin posted:

hehe funny smileys. wait


japan loves futurama???!?!?!
that's the juggalo noise

Lutha Mahtin
Oct 10, 2010

Your brokebrain sin is absolved...go and shitpost no more!

anthonypants posted:

that's the juggalo noise

dude it is clearly zoidberg

fritz
Jul 26, 2003

Lutha Mahtin posted:

dude it is clearly zoidberg

curly
howard

fritz
Jul 26, 2003

fritz posted:

curly
howard

not to be confused with 'curry-howard' unless you really want to

Adbot
ADBOT LOVES YOU

ixnay
Jun 11, 2002

rainbow dash why are you making such a cool face?!
https://twitter.com/watermanreports/status/839131826912432128

  • Locked thread