1,157 comments

[ 3.7 ms ] story [ 407 ms ] thread
I hope Europe and Germany especially finally wake up and start kicking out these pests. The US/CIA is conducting crimes against humanity on foreign soil. Like the drone war. The US may not be part of the international court but Germany is.
Don't get a false impression, everyone is hacking everybody.

Some are just better at hiding it.

Germany knows they're there, are you kidding?
A slight correction: "Germany is an US occupied country since the end of WWII".

This is the truth about Nato, friendship between US and Japan, EU countries, South Korea, etc... There are no friends in geopolitics, only masters and slaves.

That's an interesting thought, indeed.

The US doesn't benefit financially from Germany, as far as I can tell. The argument could be made that we benefit from Japanese trade, but I find that to be rather weak.

If your claim is correct, then what benefit does the vassalage of Germany and Japan have for the US?

Vassals are not competitors and the US doesn't have to risk them developing their own idea of national interest.

Germany is also part of the anti-Russian buffer zone NATO.

Mr. Putin, is that you?

Edit for downvoters: perhaps the sarcasm was a bit over the top, but my point is when someone compares the EU and NATO to slavery, I start to wonder.

So.. Switzerland is free, since they aren't in the EU, nor NATO, but Finland and Norway are slaves, right?

Where would you rather live, India or any EU country?

Oh and Ukraine isn't in the NATO or the EU either, see how free they are?

European governments have agreements with the CIA to spy on their own citizens (which is in illegal for them do), in exchange for their spy agencies spying on American citizens.
This had the potential of being a positive development brought by Trump's election: many behaviors by the US three letter agencies that were glossed over for the past 8 years (due to the party in power being "on the right side of history") are again reprehensible and deemed a threat to be fought by the tech community.
Do you have any examples of them being glossed over?
The tech community has been pretty up in arms against the three letter agencies ever since Snowden's revelation, so I'm not sure how Trump's election is going to change that; if anything it might produce the opposite effect since these agencies seem to be feuding with Trump on some level. Besides, wikieaks is a pro-Trump organization so I doubt that Trump losing the election would have caused them to go more softly with their criticisms of the government.
> I'm not sure how Trump's election is going to change that; if anything it might produce the opposite effect since these agencies seem to be feuding with Trump on some level

A big part of Trump's appeal is that he's seen as anti-establishment. I don't think it's unreasonable to expect that he may make significant changes at those agencies as a result of their "feuding" with him.

> wikieaks is a pro-Trump organization

I don't believe that for a moment. WikiLeaks helped Trump's campaign, certainly - but their reason for doing so was orthogonal to Trump himself.

If WikiLeak's behavior during the 2016 election was driven by anything personal or partisan, I would say it was Assange's own personal vendetta against Hillary Clinton.

> I don't think it's unreasonable to expect that he may make significant changes at those agencies as a result of their "feuding" with him.

And? What does that have to do with the tech community being critical of three letter agencies?

> but their reason for doing so was orthogonal to Trump himself.

I don't care what the reasoning is, Assange explicitly stated that he wasn't going to release info on Trump because he felt the media was sufficiently critical of him and he has kept up with that promise and maintained a mostly positive disposition regarding Trump, that's Trump support. Don't misunderstand, I don't think supporting Trump invalidates any of the info that wikileaks has released, my point is precisely the opposite, that this info was released despite their support for Trump so if Trump hadn't have won the election, it makes sense that they would have been just as critical if not more so.

Can you source Assange stating this? As far as I remember, his explanation was that since there was already a bevy of mainstream media ready to publish any dirt on Trump, leakers did not have to go to Wikileaks to publish their stories, therefore it was unlikely anyone would send their leaks there.
“I mean, it’s from a point of view of an investigative journalist organization like WikiLeaks, the problem with the Trump campaign is it’s actually hard for us to publish much more controversial material than what comes out of Donald Trump’s mouth every second day," Assange said.

So this seems like a clear admission that they are in possession of controversial material regarding Trump, but Assange figures, why bother publishing it, it's not much more controversial than what comes out of Trump's own mouth, so we won't bother publishing it, nothing to see here.

I'm not a US citizen, but if I was, I would want professionals sworn to defend my country and the constitution to be able to modernize their capabilities. Today, these tools are essential to defense. It may turn out to have been the best defense against RU attempt to Balkanize USA.
The best offense is a good defense. Improving the quality of software in general would be far more beneficial than developing zero-day short-sighted tools.
That wouldn't help you break into a Russian generals email account to read his email to his mistress saying he's going to Ukraine for a couple weeks.

The CIA isn't even really responsible to cyber defense. They are an offensive spy agency.

I've never heard the phrase "the best offense is a good defense," but I have heard a great many times the phrase "the best defense is a good offense." I don't have any data to back it up, but inclined to believe the more popular form of the statement.
I haven't heard of RU attempts to Balkanize USA; could you please elaborate.
Some people have connected Trump's Putin connections with the Russian connections of Calexit to conclude that they are part of a coordinated effort to exacerbate regional divides in the US to the point of Balkanization.
Anyone that thinks the Trump administration is going to lead the charge on reforming these agencies is foolhardy.

Governments rely on information to function.

Once an administration comes into power and sees the amount of information provided to them through these means, there's no way they would relinquish it in any meaningful sense.

> Anyone that thinks the Trump administration is going to lead the charge on reforming these agencies is foolhardy.

I think they were saying that the public (and tech community especially) will demand the reforms because they view Trump as nefarious; not that Trump & co will freely relinquish them.

I agree but unless every other nation stops doing this there is little value in being the only "clean" country (assuming somehow we stop). And what are the implications of doing so? We used to believe that free and open societies would naturally prosper compared to authoritarian/totalitarian societies but what if that was all a lie? "Five Eyes" dates back to the 1940's, ECHELON at least the 1980's - none of this is new. Maybe we are all just naive to the realities of geopolitics? Is this just the modern version of "We sleep soundly in our beds because rough men stand ready in the night to visit violence on those who would do us harm."?

Personally, I'd rather live in a world dominated by America/Europe than one dominated by Russia or China. All parties have lengthy histories of atrocious behaviour but the US/Europe doesn't have a "Great Firewall" and critics of our leadership are not disappeared (yet?). I just hope "If you want a vision of the future, imagine a boot stamping on a human face - forever." remains fictional....

> We used to believe that free and open societies would naturally prosper compared to authoritarian/totalitarian societies but what if that was all a lie?

Then give up your freedom and start advocating for monarchy in America.

Wouldn't it be easier to try and push for a return to a more open/free society? I don't see how a monarchy solves anything in the US.
How do you justify that with

> unless every other nation stops doing this there is little value in being the only "clean" country (assuming somehow we stop)

If there is little value in being "clean", intelligence agencies have minimal to 0 oversight and accountability, and a non-trivial percentage of the population wants them to dominate geopolitics through any means necessary, how will we ever have an open/free society again?

Domestic surveillance using these tools seems like a different issue than whether the US or its allies use these tools for geopolitical advantage?

Hypocrisy aside, in theory it would be possible to have an open society domestically even if these tools are used internationally.

Given the track records of the US intelligence community in that regard [1-4], I honestly don't understand how anyone could possibly believe them when they say they aren't using their tools domestically. There is insufficient oversight of their activities for anything they say to be believed, given their long history of lying directly to the American public. Saying the CIA doesn't use their hacking tools on the American public is like arguing the sky is green.

1. https://www.nytimes.com/2014/11/16/magazine/what-an-uncensor...

2. https://www.thenation.com/article/cias-student-activism-phas...

3. https://www.cia.gov/library/readingroom/docs/DOC_0000538627....

4. https://en.wikipedia.org/wiki/Michael_Hastings_(journalist)

I think you are confusing my hypothetical question with me somehow condoning mass surveillance, disagreeing that it is currently happening, or disagreeing that it wouldn't happen in a hypothetical future?

I have no doubt that these tools are used against domestic targets, perhaps not from the CIA but certainly by agencies like the FBI - I work in aviation and routinely see mystery flights. Everyone in the office can guess what they are (http://imgur.com/a/17hSR - 6 hours of circling - Maybe they had a warrant, who knows.

My point was that even if we could somehow stop domestic mass surveillance, I'm not sure it we would stop using them internationally or even have any obligation to do so?

Nothing will stop them from using their tools anywhere, which is my point. When the agencies themselves are fundamentally untrustworthy, as they have repeatedly demonstrated themselves to be, the distinction between surveillance domestically and abroad isn't meaningful. Especially with the data sharing rules Obama pushed through at the end of his presidency.

I don't think it's possible to value open and free societies while spying on the entire world for the purposes of asserting your geopolitical dominance. Freedom for me but not for thee.

We have one and this shit is what we came up with.
If we are ever going to be dominated by something, I wish it's an Artificial Superintelligence
The same way Obama's election was going to bring transparency and "change"?
This comment is just too depressing and accurate. It kills me I voted for obama and the dems, and they just spied on people nonstop. It is uniparty...
In this case the enemy of your enemy is a deranged megalomaniac. I'll take the enemy thanks.
One very interesting thing is that the exploits, rootkits, etc are all unclassified and the CIA has no copyright on them either. The logic is supposedly that an agent putting a classified rootkit/trojan/whatever on a machine is mishandling classified information and thus it would be illegal.
Does that mean that someone who leaked them could not be prosecuted? Or simply that they would be prosecuted under some other law?
Indeed, that's what the doc implies. They say they reckon the CIA has no recourse. Probably sue-able for breaking their employment contract where they presumably agree to never disclose anything, regardless of classification level. But doubtful that'd be a federal crime.
Or their life expectancy would decrease significantly.
Based on the overview alone (of course I can't read the entire report that fast!), this is exactly what I expect a spy agency would be doing -- if they were not then I would be disappointed.

What exactly in the admittedly shortened list am I supposed to be upset about? It makes no distinction between US citizens and overseas parties. If these actions are being done domestically against US citizens, with no just cause sure I will get upset, but that has yet to be seen.

As usual it seems Wikileaks publishes a sensationalist story around one of their leaks, claiming dozens of zero-day releases where most were already patched. Hell, they included the i0nic jailbreak as one of the 0-day exploits (https://wikileaks.org/ciav7p1/cms/page_13205587.html).

I'll let journalists parse through the full report before coming to any conclusion as of yet. I just find it hard to get excited about any Wikileaks release that has yet to be vetted.

The "with no just cause" part of the argument is what scares me because the government's idea of a just cause for domestic spying and my own, are often very, very different.
One cause for concern is that the CIA appears to not only have lost control of the documentation, but of the tools themselves:

"Recently, the CIA lost control of the majority of its hacking arsenal...and associated documentation. This extraordinary collection...gives its possessor the entire hacking capacity of the CIA."

So, now, you get to worry about anybody else that might have this toolset. (Not withstanding your note that some of it might have already been available)

>> So, now, you get to worry about anybody else that might have this toolset.

You also have to consider who has the capability to actually use these tools - its not like they come with a user manual. Could Joe Schmo download these and start using them tomorrow? Probably not.

Also, I'm pretty sure this isn't "the entire hacking capacity of the CIA". If you consider all the stuff that came out with the Snowden leaks, you'd think this is more likely the tip of the iceberg in terms of tools they're currently using. I would think they're developing new tools and techniques daily.

>its not like they come with a user manual

"including malware, viruses, trojans, weaponized "zero day" exploits, malware remote control systems and associated documentation"

Sounds like they do potentially come with a manual.

>Also, I'm pretty sure this isn't "the entire hacking capacity of the CIA"

Well, yeah. Wikileaks does like to put their spin on things.

They have stated this is part 1 of a long series of Vault7 releases, so it might be possible.
Reading the leak, these are very clearly tool manuals.

Some of the technical documentation is better than the official stuff!

These tools, whether from NSA or CIA, are made to be easy to use, and they come with detailed instructions and user guides.
> this is exactly what I expect a spy agency would be doing

From Wikileaks' overview:

"In the wake of Edward Snowden's leaks about the NSA, the U.S. technology industry secured a commitment from the Obama administration that the executive would disclose on an ongoing basis — rather than hoard — serious vulnerabilities, exploits, bugs or "zero days" to Apple, Google, Microsoft, and other US-based manufacturers. ... "Year Zero" documents show that the CIA breached the Obama administration's commitments. Many of the vulnerabilities used in the CIA's cyber arsenal are pervasive and some may already have been found by rival intelligence agencies or cyber criminals."

By not releasing this information to technology companies affected, they are increasing the risk of the same exploits being used against high profile US targets.

Again, I think there is a difference between the desired and realistic roles of an intelligence agency in disclosing exploits. Sure, I would hope they disclose them. But at the same time if they are actively using an exploit, I have pretty much no expectation of them disclosing it.

I think this has way more to do with our reference-point than anything else. My expectations were never quite as high!

In other words, you feel attempting to constrain the operations of intelligence agencies is equivalent of asking nicely, and that's the way is should be?
I mean the mentioned attempt was not as general as it was made out to be. Obama placed an exception for “a clear national security or law enforcement need”. Pretty much what my expectations were set at. Again I am reluctant to take anything that Wikileaks says as absolute truth, they love to spin.

https://www.nytimes.com/2014/04/13/us/politics/obama-lets-ns...

Not to nitpick, I absolutely agree that the NSA should be responsible for disclosing this type of information to help secure the USA and its infrastructure.

The CIA on the other hand has clear (though not always followed) directive to only act outside the US and to act against foreign nationals.

It's less clear to me that they should be required to disclose these. Another post makes the claim that the CIA may have lost these, that case seems clearer that they must disclose to protect US interests.

The problem is that there are very few IT systems that are purely foreign.

For example, if the CIA finds an exploit in a wireless router made in China and sold all over the world, that hole can also be found by others and used against targets in the United States.

Is being able to hack others worth letting ourselves get hacked?

> Is being able to hack others worth letting ourselves get hacked?

The answer to this for me is a clear no. What I was more questioning is given the CIA's role and job, I don't think it's necessarily their responsibility to do it. We're talking about a government agency who's purpose is to collect information about potential threats against the US, they have no reason to want to make that harder on themselves.

If you want to debate changing the role of the CIA, and if or if not it should exist, that's a different set of questions. But given what their job is, why would they want to turn that funnel of information off? It's not in their interest to do that.

I want everything to be hyper secure on the internet, but I also know that there are threats against the US (some created because of our actions) which the CIA is responsible for trying to keep an eye on.

A similar question: is it worth being hacked so that we can know that there is an imminent attack coming against some US interest?

EDIT: I know that the CIA is responsible for some really ugly things in the world, I'm not defending any of those actions. I'm speaking more of what their theoretical function is and what responsibilities they have in disclosing some of this information.

If while performing counter-intelligence the CIA discovers that a foreign government/company can/is exploiting computer systems within the US, should the CIA have a responsibility to do anything?
I don't believe the clear answer to that is Yes. I'm not sure if it is No either. Maybe they should share that intelligence with the NSA, but I can imagine if sharing that intelligence would compromise the the mission of the CIA then they wouldn't.
If you want to debate changing the role of the CIA, and if or if not it should exist, that's a different set of questions. But given what their job is, why would they want to turn that funnel of information off? It's not in their interest to do that.

However, the CIA is still a part of the US Government, and as such it still should have a responsibility to work towards outcomes that are best for the US overall. When this appears to be in conflict with their direct mission, in many cases the correct response should be to punt the decision upstairs.

You wouldn't expect the US Forestry Service to take decisions harmful to the overall country even if it made their direct mission easier, would you?

by definition a zero day is unknown, if they detect that it's being used in the wild then they can easily trigger the software vendor to issue emergency patches or plant the story somewhere - hell, they can even release counter malware that can mitigate

they have absolutely no reason to reveal their inventory of zero daze; that's not to say they're not morally obligated to do so, but when have morals driven their actions?

> If these actions are being done domestically against US citizens, with no just cause sure I will get upset, but that has yet to be seen.

May I just ask, why does this distinction matter? Why do you believe the world should be divided into "people who were issued bits of paper by my overlords" and "people who weren't"?

I never understood this division in other people's heads. It leads to all sorts of philosophical problems, like for example people believing that war is ethical.

I believe that in my heart as well. However, we don't currently live in a world with a federated global government. The recent election in the US highlighted that people do divide the world into imaginary lines on maps and it had a slogan: AMERICA FIRST. It's not just the political class that sees these divisions, it's a majority of the citizens.

How would you spark a revolution in people's thinking?

I have written about this in the past.

I believe I proposed something like a "no executive" world government, where you had international laws, defined by treaties, and a commitment by some treaty signatories to "arrest" any state actor which broke them. If this coalition of "world police" (which are, of course, armies) were powerful enough, I believe this could lead to less lawbreaking by governments (from the USA to Zimbabwe). Note, the commitment is not to start wars/invade, but specifically to arrest e.g. presidents or generals. You can't do this without an army, but the objective is considerably different from invading, neutralising any opposing forces, and securing a place.

Of course, persuading people something like this is a good idea, your actual question, is just about the hardest problem I've ever thought about solving. I still don't really know where to begin, but I'm interested in teaching people epistemology before other things, as a means to halt the "post truth" stuff (which has been going on for years, not only recently!)

By the way, if anyone wants to work on these idea with me - I'm calling the concept "World Peace, Inc" in my head - please get in touch with me (clues in profile). I'd love for this to be my job rather than the hobby I don't have time for.

> Of course, persuading people something like this is a good idea, your actual question, is just about the hardest problem I've ever thought about solving.

It's borderline impossible. People are social animals. While they don't necessarily form hierarhical societies, they are easily swayed by someone who offers simple solutions to their complex problems and have a bias towards following others vs being their own individual sovereign.

> "World Peace, Inc"

Alright Tony Stark :) Are you recruiting Avengers and trying to successfully privatize world peace?

Sadly, I'm not a billionaire. And privatise is a strong word - I think governments do a crappy job of it and I'd like to try! (I have stood for election, but winning while being nice is hard. note: I haven't stopped trying.)
You know that what you're doing here is creating a world-dominating monopoly on the use of force, and whomever ran that army would be the defacto leader of the world, right?

We're organized as nation-states in the first place so we can protect (generally) and pursue interests based on some sort of shared goal or value. For the United States, it's the constitution (ostensibly), for others it's different reasons. Federations of nation-states contributing to a global force might work without totally corrupting, but not a single "no-executive" force. Further, if everyone contributes forces then countries can opt-out and go their own way... for their own interests. (See the UN)

Coming to an understanding between 10 people on what pizza to order is hard. Coming to an understanding between 8 Billion on who should be able to arrest them is extremely difficult.

> whomever ran that army would be the defacto leader of the world

That is specifically why I don't permit an executive. This isn't one army, it's an alliance of armies. They were (in my original proposal, not in the comment above) controlled by a council of heads of government who had to take (arrest) suggestions from the chief prosecutor of the international court, but were forbidden to take other actions collectively.

In fact, I recall suggesting that such a group of allies would promise to use force only to defend direct attack on their own borders, and to execute arrests.

> We're organized as nation-states in the first place so we can protect (generally) and pursue interests based on some sort of shared goal or value.

I'm not sure I was ever offered a choice of whether or which nation to join, nor given any arguments for it. The reason(s) for their formation are certainly not rational - they are an emergent phenomenon!

> the UN

The UN is a diplomatic mission, which aims to give nations who come into conflict a neutral space in which to talk to one another like grown ups (or, often, not like grown ups.) It is a fundamentally different goal to an organisation which aims to use the traditional enforcement of rule of law to coerce those with political power to act within at least some behavioural boundaries.

> Coming to an understanding between 8 Billion on who should be able to arrest them is extremely difficult.

Actually, again, this hypothetical force only has arrest power over international crimes - specifically, crimes which are committed by people wielding state power. This includes members of governments, civil services, uncivil services (police, army), and so on, but most definitely not civilians.

(An interested edge case I considered was the idea of an impromptu Texan militia who attempted to invade Mexico. I can't remember whether I decided they had designated themselves a pseudo-state or not by doing it. The same reasoning about whether jurisdiction should apply also works for most terrorists, anyway.)

Thank you for the rebuttal. These are definitely potential alternatives but I think they all lead to the same place. When it comes down to stopping a determined belligerent, you have to beat them on whatever the battlefield happens to be.

The group of allies comments make sense, but that assumes a super-state group of allies with shared values are willing to band together to share those values (NATO is a prime example of this, but it's not ALL countries of the world, just those nations that felt the need to counter Soviet / Russian influence)

> controlled by a council of heads of government who had to take (arrest) suggestions from the chief prosecutor of the international court, but were forbidden to take other actions collectively.

In order to effectively "arrest" activities of other countries outside of your typical shame, embarrassment, sanctions or other incentives you need to be able to pull together a force that is more powerful than that country.

In the case of 1-4 party hegemony this isn't really plausible, and that's the current situation (in my opinion). At a minimum you'd get hegemonic blocs like (totally random because they're not opposed but they're known blocs) BRIC vs. NATO.

Once a single country (or cartel of countries) has enough of a deterrent or military force, then they can (effectively) do whatever they would like, including go against any collectively forbidden actions. I'm not saying this is what _will_ happen if countries happen to think participating in a global order is a good idea and are friendly, but that's not the historical precedent. I'm not sure how to counter that, short of the current blocs or potential other future arrangements.

> I'm not sure I was ever offered a choice of whether or which nation to join

The reasons for a number of nation-state formations are very much rational. That said, they are not necessarily permanent or as binding as people think. The idea of being "French" is pretty powerful. If you live in Alsace, maybe you waffle, but it's a unifying thing that has territory tied to it due to a long history. Different for more recent Western assignments of borders, surely and you see the results of that. Just because you're a citizen doesn't necessarily mean you're part of the nation, but my guess is that you probably come to identify somewhat with your country at some point?

The problem of how to assemble the coalition in the first place remains unsolved, indeed. You also need buy in from a major player in each bloc, as you suggest. I believe my original idea was for it to start small (but diverse), and grow over time with success.

My entire scheme is to strike down the convention that someone is only put on international trial after they have lost a war and been captured (I would like justice to be done without having a war first.) this may not be possible, but is surely worth a try.

Re: citizenship, I strongly believe that these feelings of belonging are learned, indeed are engineered in us in much the same way as a religion. My objection is that, observing the emergent behaviour of a system where everyone is under either of these spells, they lead to undesireable behaviours (aggression, proselytising, belief that evil acts are justified, sometimes even committing the evil acts willingly). Both of these systems were, hypothetically, supposed to make people behave better, not worse!

One must make a strong justification for why treating the citizens of the world the same as an American is good for Americans.

If we treat the world like we treat our citizens, then perhaps this leads to greater prosperity, more shared understanding about the rights of man, rule of law, and how to resolve conflicts (see the lately faltering "No two countries with a McDonald's have ever gone to war with each other" rule).

Lately, this has been harder to justify as Americans have felt scared of foreign terrorism (not making a value judgment on that fear, but that the fear exists is real). Because of this the "evangelize to the world" feelings of the Cold War have given way to "protect us from the world - we need to get OURS."

Many (including me) would argue this is short sighted. Best way to combat the narrative is to talk about the impacts of retreat from the world, and of arms races, etc. Communicating nuance, history, etc is hard. :/

> Because of this the "evangelize to the world" feelings of the Cold War have given way to "protect us from the world - we need to get OURS."

But looking from the outside -- when has the US ever done anything but put America first?

They have killed hundreds of thousands, to over a million people over the last 30 years by putting their interests first, by default.

Do keep in mind that Trump received 63M votes out of a total population of 319M (~20%). Even if you consider the election a referendum on globalization (and there are many reasons besides nationalism that people may have voted for Trump, as well as reasons that an anti-globalist might have voted for Clinton), that's pretty far from a majority.

Similarly, Brexit received 17.4M votes out of a total UK population of 64M (~26%).

There are certainly a non-negligible number of people who believe in borders and nations and patriotism, and they can't and shouldn't be overlooked. But "majority" is stretching it.

As for how to spark a revolution in people's thinking: you make your case to the young & open-minded, explaining why it's a good idea, and then you wait for the old and stubborn to die off. Some people will never change their mind, and you can't force them to. Everyone dies eventually, though, and if something is actually a good idea then future generations will have a chance to remake the world in their image.

The right denominator is either eligible voters (241 million) or registered voters (146 million) not the overall population.

[1] - http://www.statisticbrain.com/voting-statistics/

Depends what you're using it for. The parent poster seemed to be implying a wish-list for a future utopian society, in which case the right denominator really is the whole population. (Or even more accurately, the set of all human beings that will be born in the future, but this causes issues with the numerator, since unborn humans don't exist yet.) The fact that children are legally prevented from voting has no bearing when you're talking about a future legal system that doesn't even allow the concept of national sovereignty; only their opinion matters. Indeed, there's reason to believe that their opinion may vary significantly from the majority opinion of people several decades older than them.
The claim made based on the election results was about what it showed about the belief of the "majority of the citizens", so that's the right denominator, but if it matters Trump also didn't get a majority of eligible voters, or a majority of registered voters, or a majority of actual votes cast, or a majority of votes cast for one of the two major party candidates.
Technically, the writer did use the term "majority". That's not really the point though.

There's this obnoxious US attitude that is really wide spread in the population that the US is the best, and that Americans are noble, even though they mess up occasionally.

It's to the point where even when criticizing their own country, Americans will write that the criticism is in the spirit of improving the greatest nation on Earth, etc.

It's just a really noticeable and obnoxious pattern, even among allies. It seems to be very, very deeply ingrained.

I don't perceive people of other advanced Western countries being so jingoistic. Canadians don't crow about how Canada is the best. We might have unrealistic views that we are e.g. more tolerant, or accepting than we really are, but the US attitude is really jarring, even among friends.

> The recent election in the US highlighted that people do divide the world into imaginary lines on maps and it had a slogan: AMERICA FIRST. It's not just the political class that sees these divisions, it's a majority of the citizens.

Trump didn't even get a majority of the votes cast (or even just the votes cast for major party candidates), much less support from the "majority of the citizens".

That has less to do with how I feel and more to do with how the CIA is setup. Their role in domestic affairs is severely restricted, that is primarily the job of the FBI which has more requirements to conduct "searches". For them to be operating to the fullest extent of their perceived role, I can't find myself to be upset.
"their role in domestic affairs is severely restricted"

You're delusional if you still believe this.

It's not delusional to accurately state the law. But there does need to be strong oversight of these organizations to make sure they actually follow the law.

Edit: and yes, there is plenty of evidence that especially during the Vietnam war the CIA was actually breaking the law.

there is no oversight because it relies on the character of humans, who are weak and prone to folly.

There is no paper trail for this abuse. This is a system that should not exist.

I'm willing to acknowledge that you may have access to information that proves your point.

But I know for a fact that the CIA does have a committee of elected officials that oversee it. Whether that is effective oversight is debatable, but the fact is that it exists, and they must legally disclose their actions. This means there are legal means by which they can be held to account in the cases where they do not.

"But I know for a fact that the CIA does have a committee of elected officials that oversee it."

And they let their own inflated egos delude themselves in believing that the overall threat posed by the Russians/Chinese (which in comparison to the US, are much weaker) is greater than that of a government that surveys/records/interferes with the lives of its own citizens.

I think that is a separate issue entirely though. As defined, the role of the CIA domestically is pretty much nil. Personally I believe that if they stretch that role, it should be something that is dealt with separately from a document release. And is probably something better fitted for a different discussion.
As you accept elsewhere, there is the law, and there is reality. Oversight is captured; the intelligence agencies and surrounding industry has been given almost everything they wanted, even retroactively[1].

Information sharing has also removed a lot of practical barriers; what does it mean for the CIA to be constrained if they can use other agencies for domestic work? Interdepartmental rivalry is still a constraint, but hardly one to count on.

When thinking about the value-add of agencies like this, analyzing black-letter law is close to useless. You have to look at what actually happens. Tricky, that, when talking about spies.

[1] One interesting question is how, as a practical matter, to provide systematic oversight of spies with the ability to monitor and anonymously leak details of the overseer's lives, blackmail/manipulate third parties, and selectively leak to the media.

That some governments use that kind of tribal moral relativism to justify war does not mean that war cannot be waged for justifiable and morally good reasons.
I agree with you, sort of. Specifically, I will admit that there are some cases where something some people would call war is justifiable.
Give one example of a war where both sides had a justifiable and morally good reason.
Why on earth would you ever expect both sides to have justifiable reasons?
Justifiable from their perspective. Most border disputes would fall under this, at various points in time both sides have controlled an area and believe that it is rightfully theirs.
"Justifiable from their perspective" is trivial. Given the wealth of examples, which GGP can be assumed to know about, that's not what they were talking about.
It's the only situation where a build up of arms before war is understandable. Massing arms out of defense is basically indistinguishable from preparing an attack.
> war [can] be waged for justifiable and morally good reasons.

I am fairly sure that's not true. A real war, where both parties have a fair chance of winning, only has losers. Or if one side is much bigger, like the Netherlands against the Germans in 1940 or the USA against Iraq more recently, it's more of a coup.

> Why do you believe the world should be divided into "people who were issued bits of paper by my overlords" and "people who weren't"?

Because different people, and different groups of people, have different beliefs and intentions. The current divisions, such as nation states, may seem arbitrary, but some of them are currently necessary.

We quite simply do not live in a unified utopia as some posters here have deluded themselves into believing (which is an easy trap to fall into when one lives in a well-fed, massively rich democracy where one wants for nothing, such as the ones we all live in).

Like it or not, these divisions exist, and will continue to exist well beyond our lifetimes. Groups of humans want to dominate other groups, to exterminate them, or worse. The divisions are necessary to protect the things we value, such as social progress, our loved ones, our innovations, and so on.

In short, there is still a very clear and objective distinction between good and evil in the collective human species, and this leads to the development of the divisions with which you're uncomfortable.

Thankfully, such feelings of "that's icky!" are not (yet) a primary factor in the decision-making process with respect to defending our side of the line. If it were, we wouldn't be having this discussion. We wouldn't be able to have many discussions at all, and particularly not on a medium so free as this one. We'd probably be doing manual labor in between sessions of worship to some supreme leader or god-authority.

Yeah, I'll... I'll take those divisions for now, please.

There's a big difference between war and spying. Accurate intelligence can actually prevent wars as it keeps governments honest about their movements and actions. It can also limit the damage of aggressive actions as it allows us to help target only the actual enemies rather than the enemies plus everyone in the entire village (obviously not 100% accurate).

Your claim that having the tools to spy on people is inherently unethical, but I don't buy that. The ability to hack a TV is nowhere near the ability to destroy a city with a WMD. It's not even on the same slope.

So you didn't read any of it nor wait for anyone else to but have already come to a number of overarching conclusions and dismiss the release as whole?

I guess we can go ahead and close this particular thread then. If you don't want to read any of the source materials, you could possibly at least make the effort to respond to the various philosophical or policy questions this poses, that takes only an opinion.

They provided an overview which I read through, but I find it a bit silly to expect any single person to read through the entire report and fact-check it as well. That is what journalists are for.
>What exactly in the admittedly shortened list am I supposed to be upset about? It makes no distinction between US citizens and overseas parties. If these actions are being done domestically against US citizens, with no just cause sure I will get upset, but that has yet to be seen.

From the Reppublica article: "Three years ago the news that the Agency had spied on the US Senate intelligence committee's years-long effort to investigate CIA's tortures by penetrating the computers of the committee staff members sparked public outrage and political fury."

This is a past revelation that was already investigated, no? Without any direct connection to the current release it muddies the waters.
How does it muddle the waters? People are saying "no big deal I expect my agency to defend me from foreign threats", and it turns out they have been used against domestic do-gooders.

It seems incredibly relevant.

I think it makes an unwarranted (ha!) connection between the current released documents that do not indicate they were used against US citizens, and a previous probed and documented illegal act by the CIA. Not a justification for their previous behavior, more of drawing solid lines between two ideas, where maybe a dash is better fitted.
> this is exactly what I expect a spy agency would be doing

Loosing their "cyber" equivalents of atomic bombs after they deemed it unnecessary to improve the protection of the US against such those weapons is what you expect?

That type of hyperbole isn't helpful. 0-days are hardly equivalent to atomic bombs, much known and patched vulnerabilities.
I'm sorry but I didn't realize it was a requirement for spies to exist to have a free society.
Didn't you know, the best way to ensure the citizenry is informed, is to keep lots of secrets?!?
I would also expect a spy agency to be hoarding exploits. I don't think that's the concerning part of the reveal. Here's what I gather are the main issues the analysis discusses.

1. Poor control of the resources means a proliferation concern. Hacking tools are not classified, because it would then be illegal to deploy them if they were. But leaving them unclassified makes it easier for them to spread outside of the agency.

2. The CIA is duplicating the NSA's capabilities for no real reason other than institutional rivalries.

One of the lesser issues I thought was particularly interesting is that the CIA works to make attribution more difficult, and in particular, to pin things on the Russians. That's got to be relevant in the current political climate.

You don't have to be upset to find something interesting and worthy of discussion.
I believe the revelation here is the the CIA has built a duplicate version of the NSA, but with much further reach and less accountability.
'further reach' is stretching it to put it lightly. all of the cia tools appear to be individually targeted, whereas the nsa's programs are broadly based on mass surveillance.
I don't understand making this point unless it's to give yourself permission not to think about this. Feel free not to.
(comment deleted)
> What exactly in the admittedly shortened list am I supposed to be upset about?

That, with taxpayer dollars, the government of the United States is undermining the security of consumer devices around the world.

Part of the difference between your worldview and the view of those of us who find this behavior childish and unacceptable is that you "expect a spy agency would be doing [this;] if they were not then [you] would be disappointed." Whereas for many of us, the legitimacy of the state is already on thin ice and is subject to descent below the x-axis as the internet comes to supplant it.

Listening to my neighbor through their TV set is just one thing I want the state to stop doing as our species moves into the internet age; other things I want it to stop include all the other things it does.

You don't actually say why they shouldn't be doing this, though. Everyone with this opinion seems to base it on moral grounds around privacy, but in practical terms, is this really harming citizens? So far there's zero evidence these things being used illegally domestically. IE: Without a warrant. There is some evidence that they've prevented some wrongdoing with it, though.

I get the theoretical moral argument. I just don't understand why it matters in practical terms.

If the government wants to blackmail me, or discriminate against me, or whatever, they're going to do it with or without these tools. To not build them is to willfully give up an important competitive edge on the global stage.

Considering the government is letting pedophiles walk[1] because they don't want to release their exploits, do you really think we would know if they were abusing their power?

[1]: https://news.ycombinator.com/item?id=13798924

Ok, so we didn't prevent the maximum amount of wrongdoing? No program is perfect. Those pedophiles would've been just as free had they not developed the programs in the first place.

You're comparing reality against a theoretical world where we can both prevent crimes and never need to develop the tools necessary to do so.

As to the second point, sure, we don't know. That's tangential to my point. Let's assume the government is abusing their power. What does that have to do with these tools? Nothing, besides it maybe makes it a little bit easier for them. But, like I said, they'd do it anyways with sufficient motivation.

I still optimistically believe that an important tenet of liberalism is that you put some trust in your government, but recently it seems for many liberals that trust only extends to cushy (not to say I don't want them) domestic programs like healthcare, equality programs, or whatever the program du jour is. I'm willing to trust that our intelligence agencies aren't some nightmare Orwellian monster hellbent on subjugating the populace. Abuse of power could happen just as easily through other agencies, it just doesn't sounds as scary as when you slap a three letter acronym on it.

> an important tenet of liberalism is that you put some trust in your government

When did this become a tenet of liberalism? I've read a lot of liberal philosophy, from Aristotle to John Stuart Mill, and much more often the opposite is espoused: that the burden of proof of all claims of state authority is on the government to make.

> I'm willing to trust that our intelligence agencies aren't some nightmare Orwellian monster hellbent on subjugating the populace.

This sounds to me like a very privileged, safe point of view. After what these people did to Thomas Drake (and many others like him), I think it's long past time to take away their toys and send them to their room.

> So far there's zero evidence these things being used illegally domestically.

There is evidence that NSA employees or contractors have used domestic surveillance to spy on exes. There is evidence that Marines have shared clandestinely obtained nudie pics of female Marines. Why would the people working at the CIA be any different?

If you take a large human organization, and give them the tools to spy on their fellow citizens, it is likely that those tools will be misused by some people in that organization.

Is it possible that the people at the CIA are abusing their privileges, of course; however, there still needs to made a distinction between what is possible and what was presented in this document drop. Within the drop itself there was no evidence that it was used domestically (even more so systematically), in which case everything within it, is so far, not outside the scope of the CIA.

That is what I and I believe the parent is getting at. Regardless of our moral standings on if the CIA should be doing this, realistically the CIA can be doing it.

You haven't looked at the dodgy stuff the CIA has done over the years, included bringing down governments, funding coups, responsible for the deaths of millions.

Yeah, I guess I don't think those guys should have power like this.

It's also altogether reasonable to believe that they murdered a sitting US President only 5 decades ago.
No. It's not. I've seen multiple documentaries about this (Best Evidence, etc), and was totally convinced. But the stories don't really add up. And too many people would have to currently be complicit (decades later!) for this to be successful. People don't really hold together that long on something like this.
> People don't really hold together that long on something like this.

Dead people.

> You don't actually say why they shouldn't be doing this, though.

It weakens the US position in the world, how many people are going to be thinking today "Hm, I have really sensitive information on my phone, the US can hack Iphones and Androids? Maybe I need a different phone."

There is a risk due to the US intel agencies having so much power over US technology that other countries will end up shying away from US tech.

It sounds like you believe that what you do on the internet is private and that everyone will just agree to leave it at that. Global diplomacy is a competition, and if you aren't doing everything you can, and keeping pace with technology, you will get left behind. It might not be pleasant, but I would rather, have my country gathering intelligence about me in this manner than other countries. Plus warfare has always been one of the biggest drivers of innovation, this war will and is stimulating innovation in cyber security.
your chart is defective, the y-axis is supposed to continue indefinitely in either direction
Oh goodness. Thank you. edited. :-)
> am I supposed to be upset about?

Who do you imagine is asking you to be upset about anything. A strawman?

This is knowledge. Wikileaks is about spreading knowledge. How you react to that knowledge is entirely up to you.

I'm just disappointed with the phone industry for the current state of rampant insecurity.
Is it really that bad?! The FBI took Apple to court because it couldn't crack its iPhones...
Is it really that bad?! The FBI took Apple to court because it couldn't crack its iPhones...
No, spy agencies aren't supposed to spy on every single person in the country.
The internet and all electronics have just become one big spying and manipulation device and this is further evidence of that. No person who values freedom wants anything like that. I don't want to sit at home knowing that someone can listen in and see and record every thing I do! I am so close to throwing all of these electronics devices in the bin.

You are right that a spy agency should be expected to try to find ways into all of these devices. You are of course wrong in trusting that the spy agency is acting in your best interests. They don't have any accountability as we cannot see what they are doing. Wikileaks is the only organisation trying to bring accountability to the unaccountable.

What I find most interesting is that Trump tweets about Obama tapping his phone and then a few days later this leak happens. In the minds of his supporters this makes him credible.

But it also shows that he or Bannon might have known this leak was coming and the "wiretapp" rant was the set up. Which makes things very messy indeed.

> What exactly in the admittedly shortened list am I supposed to be upset about?

This part concerns me:

> The archive appears to have been circulated among former U.S. government hackers and contractors in an unauthorized manner, one of whom has provided WikiLeaks with portions of the archive.

So, not so much the contents of the leak, but that it happened at all, and that Wikileaks is just one of many who have access. If the total cyber arsenal of the CIA were floating around on the web somehow, I'm glad that Wikileaks made that public. Could potentially see a big spike in viruses, and maybe make plans to avoid products with known exploits and stuff.

VLC 2.1.5 compromised https://wikileaks.org/ciav7p1/cms/page_15729066.html

edit: please see response below from remlov

edit: this post was premature, see below posts

> The asset has the ability to plug in a personal thumbdrive to the network.

Sounds like it just patches a local copy of VLC by running an installer. I don't know if I would consider that compromised.

It's a version of VLC that, in addition to the things it normally does, collects information. The operator, who knowingly runs the software, can then collect the information and turn it over to someone else.
Please don't spread disinformation.

"...the asset will have 'downloaded' the portable version of VLC player (2.1.5)..."

This does not sound like a copy of the public version and that it's "compromised". You could check for yourself if you like: https://github.com/videolan/vlc :)

2.2.0 was released in early 2015.
The docs are from 2014
- Smart TV turned into listening devices with fake off mode?

- Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc.

- Dozens of O-day attacks again Andriod and iPhone.

Pretty powerful stuff.

> Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc

I wish I could say that I'm surprised but no... not surprised at all. Same for the IoT stuff.

Why would you be surprised by the fact that if your phone is compromised, even the best encryption software in the world isn't going to help?
Another victim of sensationalism.
The conclusions are correct. Talking about them isn't sensationalist just because you think they're foreseeable.
I refered to "being not surprised that encryption is broken". There was nothing relevant to encr in the document. The title is wrong.
Who said "being not surprised that encryption is broken"??? Read the quote again: "Intercepting audio/texts before encryption"

I'm not surprised that they can INTERCEPT and read ALL your communications... jeez

Ok in that sense i am wrong. But it could mean sometging else.
Ok in that sense i am wrong. But it could mean sometging else.
Yep. We all knew it was happening but turn a blind eye.

And then one of these revelations are exposed and we all start wearing tin foil hats for a month or two.

The big question for me is: What's the alternative?

AFAIK, there's no secure replacement for most IoT stuff, or phones.

> Intercepting audio/texts before encryption by Signal, Whisper, WhatsApp etc.

This basically means if your device is compromised, expect malware to be able to read all content (including Signal, WhatsApp messages). Nothing new. The way it's phrased makes it sound like Signal, WhatsApp have vulnerabilities, but no, the intention is sensationalism over sound analysis.

No mention of Windows Phone. I guess I'm safe =)
Sure, maybe, but there are very few of your kind left. ;)
I'm pretty sure I have a Nokia 3310 in one cupboard or another, maybe I'll dig it out and swap my SIM to it...
Try nokia 3310. They made new ones recently.
Yes, that's nothing new, and it's obvious to us here on HN.

However, I disagree that the intention can only be sensationalism. The average computer/smartphone user (or journalist!) absolutely does not understand that if their device's operating system is compromised, that so are all the apps they run. Saying that messages can be intercepted before they are encrypted is worth pointing out as a realistic consequence of someone's device being compromised; a consequence that J. Random Journalist would not realize if it were not specifically pointed out.

Bypass encryption means they broke the protocol. They could say "also malware can read your private messages and anything else on your phone". But no, bypassing encryption sounds a lot better. Fake news.
I don't read it that way. To me, if they meant they broke the protocol, they would say "broke the encryption" or "defeated the encryption". "Bypass" implies to me that they get the information without interacting with the encryption.
I agree with you on the semantics. They didn't break the encryption, but they certainly did get around it / bypass it.
English is my second language but i used to think security bypass means breaking the protection. Especially considering the title focuses on the messengers.
"Bypass" means to go around something in order to avoid it. If there was a traffic jam on the highway, you could bypass it by exiting the highway and traveling down a side street.

"Bypassing encryption" then would mean to avoid the encryption step. Maybe it has a different meaning in the security community, but if taken literally, the phrase is accurate.

We basically need to just accept: "If you have a device, it is being monitored, PERIOD."
The iOS attack breakdown lists a combination of vulnerabilities in very old versions of iOS, vulnerabilities first published by jailbreak teams, and a couple purchased vulnerabilities. The breakdown ends with a publicly jailbroken iOS version.

The Smart TV implant appears to just be a modified version of an open source firmware replacement project.

> vulnerabilities first published by jailbreak teams,

I guess we now know who is sponsoring these jailbreak guys and why.

Jailbreak teams publish widely and open source (mostly) they are actually the CIA's opponents burning zero days which they would much rather keep to themselves. The CIA would undoubtedly be customers of companies like Vupen and Zerodium though.
What would be the point of the CIA sponsoring jailbreak teams? The exploits they find are generally burned very quickly.
> I guess we now know who is sponsoring these jailbreak guys and why.

One of the vulnerabilities on the iOS page is from a team I had founded a few years ago. I certainly do not recall us getting a check from the CIA.

I was upset that our government is exploiting our consumer devices. Now I'm upset that our government isn't exploiting our consumer devices better.
Maybe it is just my lack of knowledge but why were all the recently leaked hacking tools made by US and none by Russia or China?
Maybe in Russia and China such leaks would be punishable with death penalty effectively.
Russia and China have not got their stuff leaked, yet. Punishments in those countries are far more severe, too.
While one cannot expect editorial independence from Wikileaks, I believe the language and cultural barrier also plays an important part

Not to mention those with that access level on those countries wouldn't release any information like that "for free"

My feeling - based on reading only publicly-available resources - is that China and Russia rely more on more traditional "HUMINT" (Human Intelligence), while the US has come to rely more and more and "SIGINT" (Signals Intelligence).
The CIA dump apparently contains malware stolen from other countries. So perhaps if/when wikileaks starts releasing them, that'll include Russian/Chinese malware.

It may also be that they simply have far smaller security states, with fewer people who feel alarm at the extent of what's happening. Or maybe leaking to Wikileaks just isn't in vogue in those countries.

(comment deleted)
There was recently a leak from BND (Germany) all documents in Germant. No one enjoys reading German.
Wow this is really big. There are tons of documents about the various tools they use, but it seems the majority of the actual source code is still being reviewed and the links just show a link to the file list. I hope they eventually release the source code, as a lot of these tools seem very interesting. I can imagine that many at the CIA are running around on fire, as this seems like a big problem for them.
According to Wikileaks [0], they were explicitly redacted until their safety could be assessed. They didn't want to be responsible for accidentally releasing malware in to the wild.

0: https://wikileaks.org/ciav7p1/#FAQ

Feel much safer knowing the CIA keeps them safe and only use them for good causes /s
I'm pretty okay with wikileaks not releasing hundreds of zero day exploits into the wild en mass.
I'd like to hear a security expert's opinion on whether releasing even patched 0-days could be considered harmful ? even if the 'sploits dont work out of the box, it seems like they would still advance the state of the art, and allow moderately-skilled hackers to build on very sophisticated designs, adapt and make them effective again - "stand on the shoulders of giants" kind of thing.
Releasing the exploits is also the quickest way to get them patched.
Many things are patched in theory but not in practice. For example, exploits on Android are very useful even if they are patched because lots of people don't upgrade their smartphones very often.
In the Equation Group releases, there were 0-days for older versions of Cisco's ASA software.

Others built on that and updated it to also exploit newer versions (9.x, IIRC) of the software.

Thats a very interesting comment...

I am going to make a few assumptions: You have no kids. You're realatively young.

---

That said, lets unpack your comment... sure it would be good to explore this (as many people havent looked into the depth of the layers of cyber culture... few really and honestly understand it) - but the implications are fractally deep... if there are people who are diving into this, we shall never know. cyberwar is a known but also unknown thing... implecations are not known, but tactics appear to be revealing themselves.. how to attack... how to defend.

Firewalls are one-dimensional - we are talking 5+ dimensions with CW, arent we...

What are those 5Ds? think of OSI as 1 and add some layers... I would love your feedback....

(BTW, How many ppl work at [company] which are ex [service] - Why is it called 'The Company')

I wonder how many of the exploits/tools released are still usable today.

Also, the actual video press release had to be rescheduled due to their video stream being attacked.[0]

"NOTICE: As Mr. Assange's Perscipe+Facebook video stream links are under attack his video press conference will be rescheduled."

[0]: https://twitter.com/wikileaks/status/839104886625157120

Streisand effect; didn't know they're holding a press conference.
Are they implying that Facebook is being DOS'ed?
Unbelievable the depth and scope. Absolutely frightening that most of these tools are out in the wild.
They have vim editing tips https://wikileaks.org/ciav7p1/cms/page_3375350.html

No emacs?

They have secret unit testing tips too! https://wikileaks.org/ciav7p1/cms/page_11629048.html
In many pages I explored from the leak I keep coming across this *.devlan.net domain. Whois info belongs to a French personality and is suspiciously updated 2 days ago and it has a month for expiration:

    Updated Date: 2017-03-05T16:38:16Z
    Creation Date: 2004-04-19T13:12:21Z

    Registrar Registration Expiration Date: 2017-04-19T04:00:00Z
    Registrant Name: SADIER, NICOLAS
    Registrant Organization:
    Registrant Street: 5 Bis Chemin Des Hautes Terres
    Registrant City: ST HILAIRE
    Registrant State/Province:
    Registrant Postal Code: 91780
    Registrant Country: FR
    Registrant Phone: +33164954698
    Registrant Email: pservor@free.fr
What's suspicious about that? It's certainly hosted on their intranet, they just picked a sensible name that employees could remember. The publicly-registered devlan.net is probably unrelated or unused.
Now whenever I get into a holy war, at least I'll know Uncle Sam approves of my tribe.
(comment deleted)
I guess some responsible disclosure to the affected vendors would be nice. If the tools are being actively exploiting bugs, which they are, there's not much else to do in order to stop the exploitation. Give it a few weeks and then publish them in the wild.
This idea that the government should somehow be exempt from proper cybersecurity ethics is disgusting. When the CIA or the NSA find zero day attacks in software, they should report them immediately to be fixed, not build tools specifically to exploit them. It's only a matter of time before these attacks either leak or are rediscovered by other malicious parties. The government is effectively turning their own people into cannon fodder for their ridiculous "cyberwar."
LoL why are you so naive? It's CIA, not google Zero day project
The parent isn't being naïve, they take issue with the current state of affairs and tell how they would like it to work. They're not surprised that that's not the case.
Nope, he is very naive. He calls [cyber] war "ridiculous".There is nothing ridiculous about wanting to be ahead of rivaling countries and having backdoors into their software and computers. What is however ridiculous is the attitude that we should all hug each other and make the bad people go away with love and prayer.
Thank you for clearing my point although I still got downvote.
After Snowden, the Obama administration made a commitment to the tech community that it would not hoard security vulnerabilities, and would instead pass them on to vendors to fix.

This release shows that they did not honour that commitment.

A government would only ever disclose a vulnerability once it has a better one to replace it. The government needs a method to counteract an attack from another source(thats their reasoning).
Not necessarily. The reasoning should surely be that if we can discover it and use it against them, then they can discover it and use it against us, therefore we should notify the vendors and have the vulnerability removed.
True, but that's a general indictment of any spy agency for any country. More broadly than just software, their mission is to control information...who gets it / who doesn't.
This might sounds naive, but I am genuinely wondering whether they are failing at this mission in the long run, though? They can hardly believe they're they are the only ones in control of these exploits. Can't the same exploits be used against them?
I think that's an absurd position. The government has a need to be able to access hostile systems. A hacked computer can avoid armed conflict where people die.

A better question is... why aren't major vendors devoting a fraction of the resources to find this stuff and fix t on their own?

They're being paid by the spooks!

On a serious note, doesn't cyberwarfare sound more like it could lead to nasty consequences, such as regular warfare, rather than preventing it?

As nuclear proliferation becomes more and more common, "regular warfare" is going to become impossible.

The reality is that there isn't going to be a traditional war with any nuclear power. WW2 was the last big state on state conflict -- that cannot happen again. Since 1948, the US vs. USSR model has applied, where nuclear powers have proxy wars at the fringes with various minor states.

As nukes become available to 2nd/3rd tier states, you need lower impact fighting methods to avoid setting off a nuclear chain reaction. "Cyber warfare", IMO, is a tool in the toolbox. Instead of proxy states, we fight with proxy corporations.

> WW2 was the last big state on state conflict -- that cannot happen again.

Respectfully, the belief that large-scale war was impossible between modern states was prevalent prior to the First World War.

I strongly believe that there will eventually be another large conflict, and that the only reason there hasn't been one to date is because we've managed to maintain the balance between Russian and American interests throughout the Cold War.

The collapse of the Soviet Union marked the beginning of a transitional state, and we've not reached a stable balance of power since.

Perhaps "cannot" was the wrong word choice. "must not" may be more appropriate.

I share your fears and find it terrifying, as that large scale war with the technology that we have today is a profoundly more damaging thing.

Ok, but the current trend seems to suggest a strong preference for SIGINT, ELINT, ... over traditional HUMINT.

Isn't this overestimating only a peculiar aspect ?

I think what we're seeing is that "SIGWAR" is a thing. Why blow up something if you can undermine it?

If you think about it, it's similar to how the physical world evolved. I was recently up at Fort Ticonderoga, which is an example of a fort designed to resist and leverage the cannon as a defensive weapon. In Europe forts of similar design were nearly impregnable, but ultimately obsolete -- mobility and artillery rendered fixed positions useless. There's a similar thing at play here!

I am not skeptical about this concept in particular, but about the lack of practical confirmation for the results of their tools.

This is perceived (at a later stage & by the public opinion) when many in the government itself publicly question the trustworthiness of the information given.

When you're blacked out by an immense quantity of basically useless infos, you're spending money and resources in an ineffective manner.

Is all this enough to target what has to be targeted, so that you have a real balance between your effort and your results?

I don't think so, a quick look to their budget is enough for me to disagree.

> A hacked computer can avoid armed conflict where people die.

Yet we see armed conflicts with CIA origins within plenty of history books...

Or Why don't we have like a "Open BSD" equivalent on the Android Platform?
> why aren't major vendors devoting a fraction of the resources to find this stuff and fix it on their own?

I'm pretty sure most of the competent ones are... it's just really slow, expensive, hard work, with little financial upside (beyond preventing the financial downside of disastrous long-tail exploits). Spending ever more on it probably isn't an easy sell to business people with normal (read: bad) human probabilistic intuitions. And a lot of the people best at it probably just choose to work for themselves because they can auction their work to IC or criminal collectors for much more than they'd get from a fixed rate bug bounty.

We are past the point of holding them to even basics ethics. The CIA and NSA already see the people as cannon fodder at best. If we can no longer expect moral behavior concerning issues like black sites for torture, drug trafficking, or setting up murder and rape regimes, then why even waste the breath asking for cybersecurity ethics?
The NSA does albeit it's not advertised when they report bugs to companies. Not sure about the CIA but the NSA has a dual mission of intercepting foreign intelligence and helping secure american systems. Hence how we got things like SELinux and other contributions.

They've done some terrible stuff but they are big agencies with many competing objectives within.

There are no "proper cybersecurity ethics". Whatever your chosen ethical framework is, it's not absolute and you don't get to impose yours on all other people.
This is an incredible and sensational claim that, if true, can quite literally "break the internet". Makes me very sad to imagine that CIA grade cyber weapons for getting into iPhones are now in the hands of heaven knows who. Hope Apple security teams are on this.

EDIT: To clarify, I'm commenting on the original situation of the tools getting out of CIA to the entities it was "circulated to", not this leak later by WikiLeaks - presumably the damage has already been done.

This looks interesting: Hive's developer guide. It has a auto-destruct feature, just like in the movies:

https://wikileaks.org/ciav7p1/cms/files/DevelopersGuide.pdf

Seems to have been having issues with premature self destruction:

"Discrepancy report DR-00134-2012 was issued after Operations determined that Hive version 2.5 was self-deleting prematurely. Analysis showed that a calculation involving the current time and the file modification time used to determine the time since last contact could result in a negative number that was then cast from an integer to an unsigned long integer. This resulted in a large positive number that exceeded the delete delay and subsequently caused Hive to self-delete."

I will continue using Swiss cheese and hungry mice as my metaphor for global network security.
"U.S. Consulate in Frankfurt is a covert CIA hacker base "

Germans are usually privacy nuts. I know many who maintain no presence on Facebook, Twitter and Instagram. I wonder how Germany will react to this.

Up to our ears in Erdogan and now this?
Not long ago it was hinted that US ambassy in Paris is a nice CIA antenna too. Nobody denied nobody answered, question still up in the air.

Also, latest Russian project, a large church-like building in Paris is suspected to hide intel dept.

Sorry, news flash, virtually all of the countries' embassies and consulates are a natural place where a lot of intelligence operations are conducted. Counterintelligence operations watch them very closely.

The fact that Frankfurt is a hub among their European intelligence operations is not terribly interesting IMO.

> I wonder how Germany will react to this.

Germany always knew operations were conducted there but now must react to this overt news.

It was pretty much an open secret already.
I wander what phones / computers CIA operatives use - do they have special patched versions which address the zero day exploits they are aware of.
This is a great question. Surely they look for vulnerabilities also in their own systems but then what do they do when they find them? Is there some special set of software that always gets patched because the CIA uses it?
> Is there some special set of software that always gets patched because the CIA uses it?

If so, a diff between the "CIA version" and the "civilian version" would be highly instructive.

Presumably the same thing others do when they know about 0-days? Signatures.
Could you explain a bit more? I'm not sure what you mean.
Sure, this is essentially the argument for disclosure of bugs before they've been patched. If I had known about e.g. shellshock before the patch was out, I could have written a Snort signature looking for it in network traffic and have my IPS drop the packets. I do this on my network with bugs I find before the vendor patches them.

This is an example of security through defense in depth; patching is one layer of defense, but if you can't patch there are other mitigating actions you can take to protect against (especially) known threats. It allows someone with an offensive and defensive mission to simultaneously use exploits while not being vulnerable to them.

Doubtful. Part of being an undercover operative means deniability. Imagine if a foreign power arrested a suspected spy, and found non-standard software on their phone.

So they'd probably use off the shelf software and mitigate risks in other ways.

(Ex: not bringing smartphones to sensitive meetings)

I wonder if, supposing a legit war use, those tools would work. Maybe in taking down some enemy tech infra, but on collecting information, i really have doubts. That would be too much data to process unless they had specific targets. Human intelligence would be much more effective.

Anyway, I remember a story of a US submarine that hacked soviet cables in the 70s or 80s.

More, being those tools not effective, development and maintenance is stupid spending, and certainly the tools are having other uses.

My conspiracy side looks at CIA like a public sector (state owned) company in Brazil: they are not owned by the government, but by the chaste of unionized workers that work there.

I would suspect that at a time of war, especially in the first few months, there is a lot of tactical info to be collected from whatsapp and Facebook conversations between people and their families ("I'm going to be busy tonight with an operation, but I promise I'll call when I'm back, love"). Whether this can be efficiently processed is a different question, which I believe google can answer affirmatively, and likely also palantir and some TLAs
>"As of October 2014 the CIA was also looking at infecting the vehicle control systems used by modern cars and trucks. The purpose of such control is not specified, but it would permit the CIA to engage in nearly undetectable assassinations."

Reminds me of the reporter who was supposedly working on a massive investigation and then died in a flaming car crash while skipping town. Forgot his name

I had the same thought. Rest in peace.
While the above is certainly plausible(killing someone with a car), I highly doubt this is the case here:

https://www.metabunk.org/debunked-michael-hastings-crash-car...

While I don't think the CIA is above killing a US citizen on US soil (you know, for "security" or something), I don't think they need to hack a vehicle to do it, nor would they want to draw the unnecessary speculation and attention. I would expect antics like that to be reserved for high-ranking foreign officials or other hard-to-reach people. If there's one thing that agency should be expected to excel in, it's untraceable targeted killings.
Given the relatively low amount of public scrutiny/outrage/attention/fear that this death caused, wouldn't you say that the car technique would be effective? (whether or not it was used in this case)
It's effective at taking a life. However I disagree that the fallout was "relatively low", compared to even a badly staged suicide, or "gang violence", "road rage", or a "botched robbery". IIRC a democratic organization employee was recently slain in DC from a "botched robbery" or something and nobody blinked an eye except in the more fringe communities. To me, that's how you snuff someone out, or OD them on insulin and have an official coroner report say "natural causes". I think a fiery single car crash at top speed is a pretty high profile event, almost up there with polonium poisoning.
seth rich, killed execution style, nothing stolen, reported a robbery. Assange implied he was the source of the DNC leaks
Just like a guy named Jack Burkman. https://en.wikipedia.org/wiki/Jack_Burkman who offered $105,000 against the $25,000 from the Metropolitan Police Department, for information about his death. With all parties having reasons so see Rich dead, I'd say it may become semi-relevant part in the cinematic workup of the Trump era.
What's the evidence he was killed "execution style"? Note: being shot in the back is not evidence of being killed "execution style".
That is literally the definition of "execution style", when you are killed at close range with no means of escape
> I don't think they need to hack a vehicle to do it,

The CIA has multiple ways to cause a death. No doubt about that. They don't "need" to use any particular method, but if they want to kill someone, that have to choose at least one method.

>nor would they want to draw the unnecessary speculation and attention.

What unnecessary speculation and attention? Is LAPD going to bust out their JTAG debuggers, and compare the collection of firmwares in Hastings' car to a clean sample? Practically nobody believes that the CIA/US gov't killed Hastings by hacking his car. Given the propensity for most Americans to never even consider a thing once its been labeled as a conspiracy theory, I'd say that gives about as good a cover as the CIA (or whomever) would ever need. We already have people hypothesizing this as the manner of Hastings' death; but do we see any apparent effort to dispute/disprove it? No, simply chuckle and call it a conspiracy theory. It will go away on its own without regard to whether it was in fact a conspiracy.

>I would expect antics like that to be reserved for high-ranking foreign officials or other hard-to-reach people.

The spies have to perfect their craft somehow. Where is it written that a method of assassination must vary by the apparent importance of the proposed victim?

why would they resort to elaborate techniques to do so when they could have someone walk up and pick him off with a gun or poison or just have him "disappeared"? You're saying instead they chose a method that requires a sophisticated firmwmare hack that may not even work (just gunning the engine is no guarantee it will kill the man), installing it, and then finding an appropriate time and place to deploy it (while also putting other bystanders at risk). To me it seems quite a stretch. I would prefer Occam's razor on this. I think a more likely scenario is he was being surveilled (and possibly even intimidated) by feds, which led to his anxiety and paranoia (which has been established). Then he got spooked that night, thinking someone was following him (and he may have been right), and flipped out and overreacted. It's also possible his accelerator stuck and he didn't react correctly/in time. Look at my comment below: I'm not saying feds wouldn't kill a US citizen, I just dont think they chose to hack the firmware in this case.

As an aside, I"m not familiar with his car but I find it hard to believe that neither the ebreak, main break, ignition, nor transmission lever (assuming it was auto) could mitigate his situation. I think they would have to hack more than just firmware, since there are mechanical linkages and/or hardware interlocks on some of those components.

Read very closely. I'm not saying they did anything. I never said "they" did anything; but rather just that I don't find any of your reasoning convincing, for the reasons I mentioned. I do think it is a plausible attack.

>why would they resort to elaborate techniques

Spy agencies in general, and the CIA in particular are infamous for concocting and using elaborate sometimes down right goofy techniques to assassinate people, and also for periodically failing at the job. This isn't just hyperbole, or me reading too much spy fiction, it's in the public record if you care to look.

>I'm not saying feds wouldn't kill a US citizen, I just dont think they chose to hack the firmware in this case.

I don't really think they did either, it's extremely unlikely. But I won't rule it out because I haven't seen any convincing reason to do so.

>As an aside, I"m not familiar with his car but I find it hard to believe that neither the ebreak, main break, ignition, nor transmission lever (assuming it was auto) could mitigate his situation. I think they would have to hack more than just firmware, since there are mechanical linkages and/or hardware interlocks on some of those components.

If you care to look into it I think you'll find it to be plausible to take control of the car's accelerator, and steer it with the brakes. In principle it's possible with any car that has electronic ABS, and electronic fuel injection and throttle. On some models, advanced features could simplify the job quite a bit. That's not to say that a quick-thinking person couldn't survive the attempt either, by applying the brake, or shifting the transmission or something.

> Read very closely.

> If you care to look into it (x2)

comments like this really have no place on HN and don't strengthen your position.

I think the CIA's "heart attack weapon" which was exposed to the Church committee in 1975 qualifies well enough as an "elaborate technique". There's also the myriad utterly ridiculous ways that the CIA attempted to assassinate Fidel Castro, and the Bay of Pigs incident. None of these things are secrets and I think any well informed US person is at least familiar with some of the above. Any of the above ought to put to rest your apparent assertion that the CIA has an aversion to elaborate or even dubious assassination schemes. There's enough in the public record to suggest that the CIA might even prefer wacky assassination schemes over the boring straightforward ones.

>comments like this really have no place on HN and don't strengthen your position.

In your own post you admit that you know none of the relevant details (and apparently can't be bothered to look) about some recent event A which was covered widely in the press. But nevertheless, you can't believe that event A could have occurred in some particular way because you think it implausible or because you like a simpler or more familiar explanation. In fact, there is nothing at all implausible about steering a four wheeled vehicle by applying left or right brakes, and the correct spelling is brakes, not breaks FYI. Nor is it implausible for an attacker to take control of a vehicle's accelerator in a modern automobile. No, I am not going to prove that for you. If you think that I or any other poster on HN is your paid technical or historical research assistant / spoon-feeder, you are mistaken.

Yes, they were also trying to assassinate the leader of a country who was also on extremely high alert for that sort of thing. This journalist is regular joe, who also happens to be a drug user. Wouldn't it be easier to just spike his drugs, overdose him, shoot him in a "drug deal /robbery gone wrong".

There are so many better ways to assassinate someone, and I think the CIA of all people would know the appropriate amount of force required. Seriously take off the tinfoil, you're just spreading FUD.

I'm sorry but that thread doesn't debunk this at all
Is there a specific claim there that says to you it isn't debunked?
At the time former US National Coordinator for Security, Infrastructure Protection, and Counter-terrorism Richard Clarke told The Huffington Post the crash was “consistent with a car cyber attack”.

“There is reason to believe that intelligence agencies for major powers [know how to remotely seize control of a car],” he said.

Quite late, but that was never in question. The issue is whether this was. Also, a source on the exact quotation would be nice.
I can't believe this meme won't die -- it's so incredibly disrespectful to his family. Honestly no better than the Sandy Hook Truther bullshit.

Michael Hastings was a recovering alcoholic and meth-abuser whose brother, Jonathan, had flown into town the day before because he suspected that Michael was having a manic breakdown similar to the ones he had in the past. Jonathan had been called to LA since several of Michael's coworkers had reached out about his mental state.

After spending the day with Michael, Jonathan called their third brother to come help get Michael back into rehab. That brother arranged to fly out the next day but that night, at 4:30am, Michael snuck out of his apartment and crashed his car into a tree at very high speed.

Here's what Jonathan Hastings thinks about his brother's death:

I really rule out foul play entirely. I might have been suspicious if I hadn’t been with him the day before he died. After all, he definitely was investigating and writing about a lot of sensitive subjects. But based on being with him and talking to people who were worried about him in the weeks leading up to his death, and being around him when he had had similar problems when he was younger, I was pretty much convinced that he wasn’t in danger from any outside agency.

https://www.salon.com/2013/11/05/michael_hastings_life_and_d...

That doesn't explain the photos of the car's aftermath.

I mean, it's just as likely people pressured his family to say this (either organized crime or the government .. really the same thing).

It's not dying because it's highly suspicious and the narrative doesn't fit, the news reports are conflicting and much of the evidence is gone.

> That doesn't explain the photos of the car's aftermath.

Do you realize how ridiculous this sounds? I take it you're an experienced crash-scene investigator?

How exactly would an accident scene differ if the accident were caused by a CIA-backed exploit vs. your standard high speed crash?

> I mean, it's just as likely people pressured his family to say this (either organized crime or the government .. really the same thing).

No, it's really not just as likely. In fact it's not likely at all.

> Do you realize how ridiculous this sounds?

As ridiculous as shutting down discussions about the unusual circumstances of his death with "it's so incredibly disrespectful to his family"?

OK, so he was a meth user, as are you, he was an alcoholic, as are you, tell me I am wrong.

When did you stop beating your wife on meth while drunk?

When did you stop being a peadophile?

Jesus dude - he was murdered attempting to reveal truth... youre attempting to obfuscate it.

Prove me wrong.

> Jesus dude - he was murdered attempting to reveal truth... youre attempting to obfuscate it

His brother John said he wasn't murdered, his other brother also said he wasn't murdered. They would know because they had both flown to Los Angeles to convince him to go to rehab and were there when he died. They would also know because Michael had already crashed a car into a tree while drunk earlier and had become addicted to Ritalin in the past -- which necessitated a stint in inpatient rehab.

His coworkers don't think he was murdered -- they recognized that he was having a manic episode, which is why they called his brothers to come get him help.

His wife doesn't think he was murdered because she knew that he had starting using drugs again.

So literally nobody that personally knew him thinks he was murdered. He had weed and meth in his system when he died, he told his brother that he had been taking DMT, he had a history of manic-depressive episodes and PTSD.

It's possible that he was a brilliant journalist that uncovered serious crimes from connected people and that he was mentally unwell. You should really reconsider your insistence on some grand conspiracy theory. There are times to be skeptical but these lunatics who ignore all evidence to the contrary and call up his family to share their insane speculation are extremely disrespectful.

Thank you for information I did not have. I appreciate it...

So I retract my assumptions based on info you have provided

Personally, fuck you.

WHO CARES if he was an alcoholic, wouldnt you be in a situation decribed. MAYBE he was touted as such.. do you have proof... These are HEAVY fucking claims against the system - so back your shit up... dont make claims against him.

I'm surprised so many acronyms from their org chart are missing.

FINO is Financial Operations Group. FIO is Field Intelligence Officer. ESD is Executive Services Directorate. Don't see a single term that anyone who spent any time in the intelligence community wouldn't recognize.

The CIA's Remote Devices Branch's UMBRAGE group collects and maintains a substantial library of attack techniques 'stolen' from malware produced in other states including the Russian Federation.

With UMBRAGE and related projects the CIA cannot only increase its total number of attack types but also misdirect attribution by leaving behind the "fingerprints" of the groups that the attack techniques were stolen from.

This has interesting implications for the claim that "Russians" hacked the election (although I can't imagine the CIA wanting to hack the election in Trump's favour).

Well you need to make it seem as if "the bad guys" are a threat regardless of the attack vector, digital or otherwise.
I'm wondering if these documents are going to match the same ones that were taken by Harold Martin III and if the CIA will out him as the Wikileaks source.
These documents were being passed around by former CIA hackers. It says this right on the page. Harold has already been disproven to have any connection to leaks. He was just a hoarder with a mental illness.

This hasn't stopped people from connecting every leak since his arrest to him.

Actually, WikiLeaks press release says:

> The archive appears to have been circulated among former U.S. government hackers and contractors in an unauthorized manner, one of whom has provided WikiLeaks with portions of the archive.

and later specifically mentions Martin:

> Over the last three years the United States intelligence sector, which consists of government agencies such as the CIA and NSA and their contractors, such as Booze Allan Hamilton, has been subject to unprecedented series of data exfiltrations by its own workers.

> A number of intelligence community members not yet publicly named have been arrested or subject to federal criminal investigations in separate incidents.

> Most visibly, on February 8, 2017 a U.S. federal grand jury indicted Harold T. Martin III with 20 counts of mishandling classified information. The Department of Justice alleged that it seized some 50,000 gigabytes of information from Harold T. Martin III that he had obtained from classified programs at NSA and CIA, including the source code for numerous hacking tools.

EDIT: I would infer from this that WL mention Martin to shore up their claim that the CIA hacking archive is circulating among contractors, not to hint that he's a source.

That video of Hillary touting that "17 different intelligence agencies yada yada Russia is who hacked my emails" is going to be even more amusing now.
The term "hacked the election" goes beyond the literal computer hacking of the dnc. It also covers the well-targeted "fake news" propoganda program ... something not touched by the release of these tools.

The "hack" of the election was trickery to twist a system to a desired end. Like all good hacks it ignored definitions to employ whatever techiques were availible regardless. That some were not traditionally called "hacking" means nothing given the overall effectiveness of the program.

The Russians really seem like to most likely there still. It would’ve taken quite a bit of knowhow and resources so the Russians would be one of the few organization with motive and opportunity so at this point it seems highly likely that it was the Russians. It could also be some nation state that wants us to think that they are Russian (which I don’t know who would have motive for this). The only other option would be a corporation or hacker group that is really good and knows enough to be able to (and also have a motive to) implicate the Russians convincingly, but that seems unlikely.

That’s the analysis I heard so it doesn’t really change the overall analysis but I’m no expert and I’m open to other views.

There also still hasn't been any public evidence that Wikileaks got their Podesta email data from Russians yet. So far we only know the DNC leaks were very likely Russian. That means until today only about ~50% of the 'election hacks' have been attributed to Russia with public evidence.

Now this leak calls into question some of the evidence about the DNC hack [1]. This evidence being the malware was Russian. But there were many other pieces of evidence that pointed to Russia so I'm personally not anymore persuaded it wasn't Russia for the DNC stuff. The Podesta stuff is still up in the air AFAIK. [edit: see pvg reply]

Either way this leak will just add to the deniability angle for the partisan hawks. Although this is probably way over the head of CNN/Fox News crowd so it's also possible it will have zero effect.

[1] Previous leaks mentioned NSA/Five Eyes collected foreign malware. This leaks adds CIA to that group and further solidifies the "misdirected attribution" angle.

> So far we only know the DNC leaks were very likely Russian.

We don't know that at all. There isn't a single piece of evidence for it anywhere.

Unfortunately for this we aren't going to get some 1080p video of someone in a mask sneaking into the DNC server room, just the fact that the 17 agencies all agree based on what they've seen believe that to be the case.

Unfortunately everyone these days think everything is a conspiracy or has to have HD recordings of something they think happened as public evidence or it is false, but that's not how the world really works...

The thing is, "17 agencies agree" doesn't really mean anything, if the evidence that all 17 agencies are relying on is a single report from a private security company hired by the DNC, and not independent investigation. If all of those agencies had looked at the original evidence themselves, the story would be different.
Also, the "17 agencies" statement came from James Clapper, and not individually issued from each of the agencies themselves. It also bears mentioning that the "17 agencies" include groups that I really, really doubt bothered to investigate ANYTHING to do with a politician getting his emails hacked - do people actually believe that the coast guard was tracking down Russian hackers after DNC secrets? What about the department of energy? These are some of the "17 agencies" mentioned.
If 30 helens agreed, it would be a different case.
>" just the fact that the 17 agencies all agree based on what they've seen believe that to be the case."

This simply isn't true. The whole "17 agencies" thing is a talking point that first came up in one of Hillary Clinton's debates and gets repeated without challenge.

The "17 agencies" didn't all independently make their own assesments about what happened and decided it was the Russians. Instead, James Clapper (at the time, the Director of National Intelligence) made the claim that the Russians were behind certain hacks. Clapper is the ultimate head of sixteen out of seventeen of the agencies.

The actual agencies involved include parts of the coast guard and the department of energy and other groups that seem REALLY unlikely to have conducted an in-depth, independent investigation into the hacking of a politician's emails.

Also, this is the same James Clapper who lied under oath to congress. Specifically, when asked “Does the NSA collect any type of data at all on millions or hundreds of millions of Americans?” He responded, “No, sir.” Wyden asked “It does not?” and Clapper said, “Not wittingly."

This is perjury and he should have been prosecuted for it. At a minimum, lying under oath makes it less likely that anything else he claims should be taken at face value.

He wasn't going to out a secret program in a public hearing.

The folks asking the questions had security clearance and could have asked the question during a classified briefing but they chose not to.

That doesn't make perjury legal.
If grandstanding to out a secret program when he knew the answer and was supposed to be asking that question in private I'd say it was fine, and it seems everyone else thought so also hence no charges.
That's irrelevant.
Seems the consensus was the grandstanding was less important than national security since nothing came of it. I'd agree.
I don't believe it was perjury -- a statement made with the intention to deceive.

NSA makes a distinction between data and metadata, as we know. If you assume that distinction, then the question is -- "does the NSA collect actual communications content on millions or hundreds of millions of Americans" -- something which, to our knowledge, is not the case.

Can it? Potentially yes. But we haven't seen anything that suggests that it actually does.

At best, his response contains an assumption which is arguably normal for an NSA director to make, and which may have be conveniently advantageous to hold. But I'm sure, even if you ask him today, he will say that metadata does not constitute intelligence collection.

To prove perjury you need to demonstrate mens rea (guilty intent) and I think it's plausible that he did not intend to mislead the investigation. It was a hard question to answer, because he could not answer in a way that would reveal the existence of the program to collect metadata either.

I'm not a lawyer and can't speak to whether or not he's guilty of perjury. But, he's definitely a fucking liar, and you can't argue with that.
> "This is for you, Director Clapper, again on the surveillance front. And I hope we can do this in just a yes or no answer because I know Senator Feinstein wants to move on. Last summer, the NSA director was at a conference, and he was asked a question about the NSA surveillance of Americans. He replied, and I quote here, ‘The story that we have millions or hundreds of millions of dossiers on people is completely false.’

> "The reason I’m asking the question is, having served on the committee now for a dozen years, I don’t really know what a dossier is in this context. So what I wanted to see is if you could give me a yes or no answer to the question, does the NSA collect any type of data at all on millions or hundreds of millions of Americans?"

To answer "no" to this question is to say that the NSA does not "have millions or hundreds of millions of dossiers" on Americans. I see no reason to believe why that's not the case. You're welcome to explain to me why storing communications metadata at the NSA is worse than requiring telcos to store it, but that's hardly the slam dunk "he's definitely a fucking liar" case you want it to be.

It's also unreasonable to expect the DNI to voluntarily admit to the existence of a centralized metadata repository in public, on TV. That's what the "he lied" folks expect to have happened here.

At the end of the day, "Clappergate" is just "where should the metadata live," and that is, to my mind, a very minor argument.

https://arstechnica.com/security/2016/12/the-public-evidence...

There is some evidence, but no definitive evidence.

'"[SecureWorks] researchers assess with moderate confidence that the group is operating from the Russian Federation and is gathering intelligence on behalf of the Russian government," the report from SecureWorks concluded.'

The "evidence" appears to be simply that one anonymous group about which nothing is known was going after targets that would presumably be of interest to Russia.

But that's simply heresy: such targets might also be of interest to western intelligence, or really anyone who wanted to stir up trouble by framing another country.

All we can say is that the correlation is interesting, but that's about it.

This is why we have intelligence -- the evidence for almost anything of consequence will never be able to meet a judicial, syllogistic standard. The idea that we need mathematically perfect deduction before we can make actionable conclusions is an assumption on your part.
And the people inside the government to whom the intelligence is provided have every right to trust the source. However, to us in the public, we don't know these people, and have zero reason to trust them, absent actual factual evidence. What, you wouldn't put it past them to lie all the sudden?
The logical end of that position is that states aren't allowed to keep secrets, which you are welcome to believe is possible, but it's not the world I believe we live in.
The circumstantial evidence in the Podesta phishing is pretty decent, not really 'up in the air'.

https://www.secureworks.com/research/threat-group-4127-targe...

https://twitter.com/pwnallthethings/status/81662155364329472...

(the second link is a lengthy thread)

Right, someone found a phishing link sent to Podesta that reused a GMail login page by autogenerating URLs, hundreds of hashed urls were reversed and a bunch of the target emails were people/companies of interest to Russia. I was only thinking about what the US gov released regarding the DNC leaks. I forgot about that one.

It's very possible that many people had access to Podesta's email but the timing of that phishing attempt and the Wikileaks leak was a little too convenient to ignore.

(comment deleted)
There is no hard evidence where the DNC/Podesta leaks came from. However, Julian Assange has repeatedly said that the source is not the russian goverment or a affiliated state party [1] and in a other interview has hinted that the source may be Seth Rich [2], a former DNC staff member that was murdered in Washington DC.

[1] https://www.youtube.com/watch?v=uyCOy25GdjQ

[2] https://www.youtube.com/watch?v=Kp7FkLBRpKg

Attributing the release of such secrets to someone who is already dead seems like it could be a very effective way of hiding one's source. ;)
Is Julian Assange a reliable actor in this? He has every motive to deny that Russia are the source of the leaks.
Why wouldn't he suddenly be? Because he exposed the corruption of the party you supported? It doesn't work that way really. Either he is reliable, or not reliable to begin with. I have every reason believe he is, and he has demonstrated that people turn a blind eye on things if it fits their narrative of the world and politics.
You can trust the leak without trusting the leaker. I believe everything wikileaks has leaked has been legit. I also believe they frequently make extremely misleading statements(like the Seth Rich stuff) to push their own goals and I wouldn't doubt for a second that they would lie to push forward their own goals/or mask them.
Why wouldn't he suddenly be? Because he exposed the corruption of the party you supported?

He was never neutral or objective on the subject of Hillary Clinton. And isn't it convenient that despite our knowing of multiple politicians whose private email got hacked, hers is the only one he felt was worthy of publishing...

So, yeah, not exactly a "sudden" lack of objectivity on his part. Also it's been demonstrated his followers will turn a blind eye to things that don't fit their narrative.

We never needed to trust Assange, because we knew the source of the leaks - Snowden. I trust Snowden, I have never particularly trusted Assange.
> However, Julian Assange has repeatedly said that the source is not the russian goverment or a affiliated state party

How would he know? Isn't wikileaks set up so that people can submit data anonymously? Is he claiming that they got the data through different channels? Why would an insider purposefully leak the data in a way that de-anonymized him to Assange and possibly others, instead of using the established channels?

Wikileaks offers that possibility, but you can always include self-identifying documents in there.

I’m a lot more puzzled by the fact that Assange would say anything about the uploader, even if it is negative. I guess denying it’s the most likely suspect re-rolls the dice in most people’s head.

> How would he know?

Not all leaks are submitted through the web forms. Craig Murray has stated that he received some of the leaks in person from a DNC insider during a face to face meeting in Washington, and he couriered those leaks to wikileaks himself.

http://www.washingtontimes.com/news/2016/dec/14/craig-murray...

Yeah, but why would an insider do that? It just seems like it's exposing him/herself to undue risk for no real benefit.
Huh, I had never heard that, why is that? Does Murray have a credibility problem, has he no evidence for his claim? Assume that any explanation that amounts to suppression by the "liberal media" or the "establishment" will fall on deaf ears.

Murray's Wikipedia page is not full of alarm bells, it does mention him appearing on Alex Jones's radio program but to discuss a non-crazy subject.

> There is no hard evidence where the DNC/Podesta leaks came from. However, Julian Assange has repeatedly said ...

Assange's claims are not hard evidence either, nor do I trust him.

US intelligence agencies say the Russians were involved and that kind of activity by the Russians is corroborated by intelligence agencies in Europe.

The nature of intelligence operations is that, if done correctly, there is no hard evidence unless the perpetrator wants there to be.

> Assange has repeatedly said that the source is not the russian goverment or a affiliated state party

False!

He does not answer the question about someone affiliated with Russia handing him the information.

He always repeats this carefully worded answer: "our source is not the Russian government and it is not [a] state party."

Why so carefully worded -- why can't he say "no one affiliated Russia gave me the data"?

Because he knows it came through an intermediary for Russia and wants to be able to lie, but still have a weaselly excuse if he's caught.

The fact that he's spent a lot of time spreading the Seth Rich idea is even more suspect. It's a conspiracy theory straight out of the KGB's cold war book.

Seth Rich was murdered and his watch was yanked at. He fought back at his attacker(s). "Nothing was stolen!"

The professional assassin got into a fight with the victim and then shot him, but forgot to actually steal something? Not very likely.

If Assange knows and has hard evidence that it isn't from any Russian connected source then he could present that and this would do huge damage to the US.

So why doesn't he ? If it was really the CIA that hacked the DNC then why would they be so stupid to blame Russia if Assange could so easily falsify that claim ? That's a huge reputation risk.

Assange only said that it wasn't the Russian Government themselves. Doesn't rule out it being a team of hackers with connections to Russian IC or even directly to the Kremlin.

Or even Russian hackers acting on their own but with the wink wink approval of Putin. Kremlin may even fund groups like startups. Give out money, see what happens. It's like Al Qaeda - they don't need to have an org chart or any explicit communication.

What public evidence is there that the DNC leaks were related to Russia?
There's no evidence. It makes for a good romance though...
> that "Russians" hacked the election

That's not the claim. In fact, multiple people have said that is not the claim.

The claim is that the Russians influenced the election in favor of Trump by promoting propaganda against Clinton.

Yeah it's irritating how our media is ignoring the propaganda machine and looking at "hacks" instead.
Through leaks like this one. Leaks that can be partially validated or corroborated, but which (by their nature) cannot be entirely proven true.

And those leaks were very transparently beneficial to a person/group who are also going to benefit from this one.

I don't trust the CIA at all. But I don't trust Wikileaks either. I see way too many self-described "skeptical" types who aren't approaching any of this with any shred of skepticism.

(comment deleted)
Objective proof is usually not considered "propaganda". We used to call it "investigative journalism".
There's also an argument to be made that Hillary would not have been the nominee had the DNC played fair. The leaked emails show that they actively worked to suppress Bernie, who had huge rallies, similar to Trump.
A US political party playing favorites with it's own candidates (however upsetting that is), is very different from a foreign state engaging in a successful propaganda campaign to influence the US election.

The DNC problems are part of a long term reshaping of US political identities. The Russia issues are a serious near-term national security concern.

Absolutely no one intelligent thinks that. And rally size means literally nothing.
Actually, that was the claim, but once people started undermining the story they had to shift to the word "influence" to save face. This kind of shit is why middle-class rightwing America cheers when Trump calls out fake news. A complete inability to honestly say, ok, we don't know, or ok, we fucked up. Nope, the story always was X... sure it was.
I think it's a little more nuanced than that.

I think the more likely objective (assuming the Russians were behind this, which for the time being is a fair assumption) is that they wanted to delegitimize a President Clinton. Everyone thought she would win. I think it's a bold claim to make that the Kremlin set out on a campaign to elevate an obtuse philanderer in a field of 16 who ignores any semblance of political norms. Rather, I think they just wanted to further tarnish Clinton's image, as President, as a corrupt establishment figure.

> although I can't imagine the CIA wanting to hack the election in Trump's favour

Doesn't preclude planting 'evidence' of Russian hacking to stir up a red scare (towards renewed cold war -level funding of the intelligence community) irrespective of the election's outcome. I.e., the fact that anyone actually uncovered secret data through some other means could have just been unrelated/incidental. E.g., if Wikileaks got their material from an inside whistle-blower as they've insinuated.

I wouldn't either be surprised if the 'evidence' of Russian interference was just circumstantial rather than planted... E.g., "Woah, we found evidence of probing originating from Russia (in the pile of probing evidence from script-kiddies all over the world, mostly Nigerian princes but those don't bolster our narrative)!"

https://www.youtube.com/watch?v=7j_ZfKmcnSk

https://en.wikipedia.org/wiki/Operation_Northwoods

http://www.mintpressnews.com/migrant-crisis-syria-war-fueled...

>although I can't imagine the CIA wanting to hack the election in Trump's favour

CIA is overwhelmingly republican, just like the FBI. So yes they would.

Source?

I've always understood the FBI v. CIA conflict as a classic Red vs Blue security alignment. FBI aligned with Defense and CIA aligned with State.

Trump has been aggressively critical of the CIA and has, to some extent at least, ignored their intelligence briefings. He openly opposes much of what they advocate. I don't think they like him.
Actually, if you look at donations in the last election government employees in all branches donated over 85% to Clinton. So I'm not sure I'd say overwhelmingly Rebublican by any means.
I think it's vitally important, at least in this forum where tech knowledge is fairly high to avoid saying that "Russia hacked the election" without any sort of qualifier. Because the implication is that they hacked voter booths or somehow changed votes.

In reality they allegedly hacked computers of people related to a single party and brought to light the illicit activities that party was doing.

tl;dr Saying Russia hacked the election is the same as saying that some kid hacked the FBI when all he did was deface their website. It implies a level of sophistication that did not happen.

Agreed. All this fuss gives Russia more prestige/soft power.
> In reality they allegedly hacked computers of people related to a single party and brought to light the illicit activities that party was doing.

My understanding was the Security professionals expected that the most likely scenario was that both parties were hacked: one side was revealed and the other one used for leverage.

Well, you've nailed it in your parenthetical comment. Lack of a credible motive is one of the telltale signs of conspiracy theories, but has never kept conspiracy nuts from presuming all kinds of nefarious motives if they fit into their preconceived world-view.

Of course the CIA could have constructed a complicated false flag operation to get Trump elected, but they lack a reasonable motive. Similar things can be said about many conspiracy theories, only few of them attribute credible motives to the state actors and/or individuals involved.

IMO it just doesn't make much sense, though, as soon as you picture actual groups of people running these schemes. It's super secret and all, but behind the iris-scanner doors and extreme vetting, people are sitting in offices, drink coffee, have meetings, etc. There's oversight, reports to file and activity logs. Now how should a group of employees, in this environment, sit together and decide to manipulate an election in their own country? That just doesn't seem feasible.

I honestly imagine the day-to-day activity there to be way more mundane than we imagine. It's probably just sifting through thousands of pages worth of intelligence (transcribed phone calls from terrorism suspects, reports from people at foreign embassies, etc) for things that are usable. Probably often with few results. I don't even think the amount of information is the real limitation. It's probably the quality.

But considering that Wikileaks is essentially a Russian intelligence services front at this point, spreading this kind of disinformation does a great deal to muddy the waters about the hacking.
Why would anyone consider that?

(Yes I know the accusations, but they don't appear backed by evidence or reason).

The guy went from "cryptoanarchy" to having a TV show on RT(a propaganda network)and saying Russia has "vibrant" criticism of Putin's regime (beyond absurd). Not to mention him somehow being able to facilitate Snowden's entry into Russia.

I'm no fan of imperialist American foreign policy, but Russia is just as grotesque.

http://www.repubblica.it/esteri/2016/12/23/news/assange_wiki...

This doesn't prove your original claim in any way.
> saying Russia has "vibrant" criticism of Putin's regime

No, he didn't. I know The Guardian said he did, but they mislead readers so badly that the interviewer they were quoting specifically called them out for bad journalism. Wikileaks has gone off the rails lately, but the "vibrant" thing is from a hitpiece that's inaccurate in almost every way.

Assange said "In Russia, there are many vibrant publications, online blogs, and Kremlin critics such as [Alexey] Navalny are part of that spectrum." This wasn't part of a statement about Russia not needing dissent like Wikileaks, but about whether Wikileaks was competent to provide it. He continued "in Russia there are competitors to WikiLeaks, and no WikiLeaks staff speak Russian, so for a strong culture which has its own language, you have to be seen as a local player" and made similar comparisons to China and East Timor.

The question was about Wikileaks efficacy compared to Russian activists, not whether Putin suppresses critics. Note that Assange cited Navalny, a man Putin has put in prison. That shows pretty clear awareness of what criticism means in Russia, but The Guardian pulled the quote without the followup or example.

Worse, The Guardian also cited Assange as offering "praise for Trump" in the interview. That's flatly dishonest - no such statement appears, they just claimed it did. When asked, he described Trump as "gathering around him a spectrum of other rich people and several idiosyncratic personalities".

https://theintercept.com/2016/12/29/the-guardians-summary-of...

I literally linked to the actual interview. I know exactly what he said and my original statement still stands. And there's so much "vibrant" criticism in Russia that the guy he mentions is in prison? If that doesn't refute his argument (assuming it wasn't ironic), I don't know what does.

Here's someone who also went to prison for protesting against Putin who says that Assange uses rhetorical dodges, but it's out in the open in Russia that he works with the Kremlin.

http://www.thedailybeast.com/articles/2016/10/27/pussy-riot-...

The very famously anti-Putin pussy riot has stated that Wikileaks has become a Russian propaganda front. I wonder why Wikileaks didn't cite them as part of their 'vibrant ciriticism'?
I continue to think quoting the word "vibrant" without the end of the sentence is badly misleading. I mean, he's talking about whether Russia has Wikileaks-equivalents, and you answer that it's different from the US because the biggest leakers and critics are in prison or exile? The analogy to Manning and Snowden makes itself...

Yes, Assange is soft on Russia and Trump (and apparently Roger stone just copped again to a Trump-Assange connection). No, it wouldn't surprise me even a little bit if he's looking to the Kremlin for leaks and protection, and so publishing at their discretion. Yes, Russia clearly engages in censorship and violence against critics on a level not at all comparable to the US.

(The Manning/Snowden comparison on "in prison" is obvious, but I do realize the difference. The US doesn't have an epidemic of murdered journalists and civil rights advocates in exile, and wealth and fame aren't required to survive dissent.)

But because I worry about all of that, I wish the discussion of the topic wasn't so often allergic to context. Most articles and public statements on the issue are easily shredded for horrible inaccuracies, when even a straightforward summary of events is deeply alarming.

''' A member of Russian punk band Pussy Riot says WikiLeaks founder Julian Assange directly collaborates with Moscow.

“But Julian Assange, he openly works with [Russia],” Nadya Tolokno told The Daily Beast in an interview Thursday. "It’s not a secret. He’s connected with the Russian government, and I feel that he’s proud of it.

“I generally support the work that WikiLeaks is doing, but I’m not that thrilled about his decisions that are unethical, in my view, concerning his connections to the Russian government.” Tolokno said she visited Assange at the Ecuadorian Embassy in London two years ago, saying their meeting convinced her WikiLeaks has ties to the Kremlin.

“He couldn’t deny it,” said Tolokno, whose full name is Nadezhda Tolokonnikova. "He often works with the Russian propaganda machine, and he doesn’t try to hide it.

“Julian Assange doesn’t try to hide that fact because he hosts at the Ecuadorian Embassy the editor-in-chief of the Russian propaganda team, Russia Today, and he has projects with them,” she added.

Tolokno added she confronted Assange about advancing Russian interests ahead of America’s.

“I understood his position: He’s in a state of war with the American government,” she said. "He’s smart and charismatic and will use any means to destroy the American government.

“And we had a conversation if it was really the ethical thing to do that with the hands of another government [Russia] which is, in fact, much worse and a real authoritarian government.” ''' http://thehill.com/blogs/in-the-know/in-the-know/303172-puss...

That's what anti-putin russian activists think of wikileaks.

Can you point to any instance where WikiLeaks has released information that was not authentic and correct?
Can you point to any instance during the election when a leak was not precisely timed/filtered to damage the Clinton campaign and/or advantage the Trump campaign?
Wikileaks' political alignment doesn't have anything to do with the authenticity of the material they provide.
No, but it does have to do with what authentic material they provide. There's a reason courts require "the whole truth"
What would "the whole truth" mean in this context? An explanation of how we got here, starting with the Big Bang?
More than zero disclosures focusing on the Trump campaign, rather than the Clinton campaign.

These were not just random samplings. They were cherry-picked from a huge collection and delivered with perfect timing. This is agency work, not Assange.

But it has a lot to do with the information they omit, amirite? Isn't that why they accused the panama papers of being a CIA operation without any evidence, because they wanted to give cover for the Russian establishment they cut television deals with?
If anything Wikileaks presented a pretty ripe opportunity to replace Clinton with a candidate that could beat Trump in the general election. Nobody seized it and the Dem's lost. But yeah, blame Russia.
>Elect a despised criminal to be party's candidate >Don't understand why they lost >Blame Russia >Continue getting nowhere

Yes, Trump is the crazy one.

Except that they absolutely did nothing of the sort, they waited to leak their information until the primary was already over...
There's at least one case where they've deliberately excluded documents from a leak without a good explanation, which I think qualifies as a lie by omission: https://www.dailydot.com/layer8/wikileaks-syria-files-syria-...

Also, while I doubt they've ever released fake documents as part of a leak, they do often push incorrect and/or unverified theories and ideas on Twitter.

> But considering that Wikileaks is essentially a Russian intelligence services front at this point

Trump is crazy & I'm willing to believe the Russians helped him, but this is an equally baseless accusation.

Wikileaks has a history of pissing off both the left & right in the United States. I have a hard time believing the claims they're part of the Republican party.

"Republican Party"? OP said Russian intelligence.
I think that was the joke.
Kind of snaked its way around there. I give it a 5/7 for execution.
Can you point to a time Assange pissed off russia? Why did Assange brag about 'kompromat' he held on putins administration, and then take a meeting with Putin after Russia threatened him? Why did he cut a tv deal wth Russia state controlled media a month later, and then neglect to release his 'kompromat'? Why did he censor emails showing Russian banks ties to the Syrian war, and why did he tow the kremlin line and accuse the panama papers leaks as being funded by soros and the USA without providing any proof?

To act like Wikileaks hasn't cut a tv deal with a Russian propaganda network and doesn't parrot its talking points runs pretty counter to recent history. And today they're at it again, trying to foster doubt about the safety of secure messaging apps among journalists (unsurprising, given Putins history of murdering journalists).

You guys sound crazy. RT routinely gives airtime to all sorts of fringe characters that other stations don't, it doesn't mean those people work for, have "cut deals with" or are otherwise owned by Putin himself.

As to "when did he piss off Russia", did you ever consider that maybe he doesn't get many leaks from there? If someone leaked stuff to Wikileaks and then Assange sat on it for his own reasons, the leaker would just go somewhere else. It's not like there's a lack of outlets that would publish such info: any western newspaper would do it. Wikileaks came on the scene because western media proved that they would not publish leaked material that made the US administration look bad, as the NYT's handling of Iraq related matters made clear. It was only after Wikileaks gave leakers another outlet that Anglospheric newspapers started to get the balls to publish government secrets, knowing full well that if they didn't Assange would use his own channels to do it for them.

And today they're at it again, trying to foster doubt about the safety of secure messaging apps among journalists (unsurprising, given Putins history of murdering journalists).

If phones are hackable they're hackable, that has nothing to do with Putin. Remember we're talking about the CIA here, not the FSB?

>You guys sound crazy.

There's not much there in terms of evidence or substance, so I'll skip that. But I would suggest that sometimes nations have conflicts with each other, and further suggest that Russia and the USA have one such hostile relationship - sometimes these hostilities take the form of interfering with each others plans and goals. I'd also point out that Russia has invaded a string of neighbors after coordinated cyber and information warfare campaigns, as well as the recent string of dead Russian diplomats who all purpotedly had contact with Michael Steele. Hopefully the idea that a country who is actively fights to disrupt the current world order may take steps to further this goal doesn't appear crazy to you, because that seems like a bizarre mischaracterization of some rather straightforward concepts.

>RT routinely gives airtime to all sorts of fringe characters that other stations don't, it doesn't mean those people work for, have "cut deals with" or are otherwise owned by Putin himself.

This is another criticism that is really odd to me, because again it's mischaracterizing what is happening. """ Russia’s propaganda efforts aren’t partisan per se, though in the US election their preferred candidate was Trump. “The Russians don’t care who they’re helping, whether it’s the left or right wing. There are no barriers, as long as it weakens the system,” says Meister. “What Russia wants is to further its own interests, and at the moment, right-wing parties tend to speak to those interests more than the left,” says Meister """ [http://www.cjr.org/special_report/putin_russia_propaganda_tr...]

So what I hear is "Russia is funding every extreme viewpoint they can find", for you to rebut with "Russia funds leftists and the right, therefore they're not against the united states" strikes me as nonsensical.

>As to "when did he piss off Russia", did you ever consider that maybe he doesn't get many leaks from there?

Again, you're not actually arguing against my point. [https://en.wikipedia.org/wiki/Cut-out_(espionage)] [https://en.wikipedia.org/wiki/Agent_of_influence]

> If someone leaked stuff to Wikileaks and then Assange sat on it for his own reasons, the leaker would just go somewhere else. It's not like there's a lack of outlets that would publish such info: any western newspaper would do it. Wikileaks came on the scene because western media proved that they would not publish leaked material that made the US administration look bad, as the NYT's handling of Iraq related matters made clear. It was only after Wikileaks gave leakers another outlet that Anglospheric newspapers started to get the balls to publish government secrets, knowing full well that if they didn't Assange would use his own channels to do it for them.

You're trying to blur the lines between what happened when wikileaks was founded vs today. To make it much simpler, Pussy Riot is a very vocal anti-Putin group, who put it very plainly: """ A member of Russian punk band Pussy Riot says WikiLeaks founder Julian Assange directly collaborates with Moscow.

“But Julian Assange, he openly works with [Russia],” Nadya Tolokno told The Daily Beast in an interview Thursday. "It’s not a secret. He’s connected with the Russian government, and I feel that he’s proud of it.

“I generally support the work that WikiLeaks is doing, but I’m not that thrilled about his decisions that are unethical, in my view, concerning his connections to the Russian government.” Tolokno...

Trump is crazy & I'm willing to believe the Russians helped him

Do you know how I know that you know nothing about US politics?

So will this zero days be reported to Google,Apple,Microsoft & Co.? Or is this more a "FYI document"? It seems you can be on the safer side if you use a more exotic phone OS which is not widely used or a more dumb feature phone.
Security through obscurity isn't a thing
It's not security through obscurity (which I agree is bad). It's more like "more security" through "less market share".
If they call in James Clapper, will he perjure himself again?

http://www.hasjamesclapperbeenindictedyet.com/

It would have been illegal for him to tell the truth in that testimony, since it was public. I know people don't like that, but it's true. He could either lie or break serious secrecy laws. There's no immunity just because you're talking to congress.
In that case, you say "I can't answer that question" and let the system do its job.

You don't lie.

No. The only way he couldn't answer the question was if the program existed, thus revealing the existence of the program, so he had to lie.
Thus my point. The CIA should not be running programs that "do not exist". Classified, sure, but not hidden programs nobody knows about. That is not what we are paying them for.
You are mounting the most ridiculous defence of perjury I have ever seen. Do you seriously think that Congress passed laws they intended to be interpreted in the way you propose? That they want to be lied to?

Clapper lied under oath. He should have paid the penalty for that. He didn't because the US Government has decided that it either can't or doesn't want to control the shadow state.

"I can neither confirm nor deny the existence of such a program." This has been absolutely formalized since the 70s.