{"id":6882,"date":"2017-03-07T08:30:21","date_gmt":"2017-03-07T16:30:21","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/03\/07\/news-673\/"},"modified":"2017-03-07T08:30:21","modified_gmt":"2017-03-07T16:30:21","slug":"news-673","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/03\/07\/news-673\/","title":{"rendered":"WikiLeaks&#039; CIA document dump shows agency can compromise Android, TVs"},"content":{"rendered":"<p><img decoding=\"async\" src=\"http:\/\/zapt0.staticworld.net\/images\/idgnsImport\/2015\/08\/id-2961152-looking_out_for_security_holes-100602775-medium.jpg\"\/><\/p>\n<p><strong>Credit to Author: Grant Gross| Date: Tue, 07 Mar 2017 08:22:00 -0800<\/strong><\/p>\n<p> WikiLeaks has released more than 8,700 documents it says come from the\u00a0CIA&#8217;s Center for Cyber Intelligence, with some of the leaks saying the agency had 24 &#8220;weaponized&#8221; and previously undisclosed exploits for the Android operating system as of 2016. <\/p>\n<p> Some of the <a href=\"https:\/\/wikileaks.org\/ciav7p1\/cms\/page_11629096.html\" target=\"_blank\">Android exploits<\/a> were developed by the CIA, while others came from the U.S. National Security Agency, U.K. intelligence agency GCHQ, and cyber arms dealers, according to the\u00a0<a href=\"https:\/\/wikileaks.org\/ciav7p1\/index.html\" target=\"_blank\">trove of documents<\/a>\u00a0released Tuesday.\u00a0 <\/p>\n<p> Some smartphone attacks developed by the CIA allow the agency to bypass the encryption in WhatsApp, Confide, and other apps by collecting audio and message traffic before encryption is applied, according to the WikiLeaks analysis. <\/p>\n<p> The documents show the CIA &#8220;hoarding&#8221; undisclosed, or zero-day, exploits for a number of systems, despite promises from former President Barack Obama&#8217;s administration to share the vulnerabilities with vendors, according to the WikiLeaks analysis. <\/p>\n<p> The CIA declined to comment on the authenticity of the leaks. The documents, which cover the years 2013 to 2016, amount to the &#8220;largest ever publication of confidential documents on the agency&#8221; and the &#8220;entire hacking capacity of the CIA,&#8221; WikiLeaks claimed. <\/p>\n<p> Some documents released describe how the spy agency used malware and hacking tools to target iPhones and smart television sets. Others detail\u00a0the CIA unit&#8217;s efforts to compromise Windows, Apple&#8217;s OS X, Linux, and routers. <\/p>\n<p> One attack, called <a href=\"https:\/\/wikileaks.org\/ciav7p1\/cms\/page_12353643.html\" target=\"_blank\">Weeping Angel<\/a>, targets Samsung smart TVs and was developed by the CIA and the U.K.&#8217;s MI5, according\u00a0to WikiLeaks&#8217; analysis of the documents. <\/p>\n<p> The Weeping Angel attack attempts to place the target TV in a &#8220;fake off&#8221; mode to trick the owner into believing the devices is off when it is on. In the fake off mode, the TV set can be used as a bug, recording conversations in the room and sending them over the internet to a CIA server. <\/p>\n<p> In late 2014, the CIA was also looking for ways to\u00a0<a href=\"https:\/\/wikileaks.org\/ciav7p1\/cms\/page_13763790.html\" target=\"_blank\">infect\u00a0vehicle software systems<\/a>, according to one document. <\/p>\n<p> The CIA unit&#8217;s cyber weapons could create serious problems if the agency loses control of them, WikiLeaks editor Julian Assange said in a press release. <\/p>\n<p> &#8220;There is an extreme proliferation risk in the development of cyber &#8216;weapons,'&#8221; he\u00a0said. &#8220;Comparisons can be drawn between the uncontrolled proliferation of such &#8216;weapons&#8217;, which results from the inability to contain them combined with their high market value, and the global arms trade.&#8221; <\/p>\n<p> Samsung and Google, the creator of the Android operating system, didn&#8217;t immediately respond to questions about potential CIA attacks against their products. <\/p>\n<p><a href=\"http:\/\/www.computerworld.com\/article\/3177797\/security\/wikileaks-cia-document-dump-shows-agency-can-compromise-android-tvs.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"http:\/\/zapt0.staticworld.net\/images\/idgnsImport\/2015\/08\/id-2961152-looking_out_for_security_holes-100602775-medium.jpg\"\/><\/p>\n<p><strong>Credit to Author: Grant Gross| Date: Tue, 07 Mar 2017 08:22:00 -0800<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p> WikiLeaks has released more than 8,700 documents it says come from the\u00a0CIA&#8217;s Center for Cyber Intelligence, with some of the leaks saying the agency had 24 &#8220;weaponized&#8221; and previously undisclosed exploits for the Android operating system as of 2016.<\/p>\n<p> Some of the <a href=\"https:\/\/wikileaks.org\/ciav7p1\/cms\/page_11629096.html\" target=\"_blank\">Android exploits<\/a> were developed by the CIA, while others came from the U.S. National Security Agency, U.K. intelligence agency GCHQ, and cyber arms dealers, according to the\u00a0<a href=\"https:\/\/wikileaks.org\/ciav7p1\/index.html\" target=\"_blank\">trove of documents<\/a>\u00a0released Tuesday.\u00a0<\/p>\n<p> Some smartphone attacks developed by the CIA allow the agency to bypass the encryption in WhatsApp, Confide, and other apps by collecting audio and message traffic before encryption is applied, according to the WikiLeaks analysis.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3177797\/security\/wikileaks-cia-document-dump-shows-agency-can-compromise-android-tvs.html#jump\">To read this article in full or to leave a comment, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[714],"class_list":["post-6882","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6882","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=6882"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6882\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=6882"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=6882"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=6882"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}