Before everyone loses their minds over the latest and greatest Wikileaks reveal, one should immediately note that these “exploits” (such as they are) are entirely open source.
That’s right. As in, there’s nothing that Vault 7 reveals that any other motivated cracker (term for a malicious hacker) could not exploit. From the UK Independent:
The public files don’t include the cyber weapons themselves, according to a statement. The organisation will refrain from distributing “armed” software “until a consensus emerges on the technical and political nature of the CIA’s program and how such ‘weapons’ should analyzed, disarmed and published”, it said.
The files were made available by a source who intended for them to start a conversation about whether the CIA had gained too much power, according to the organisation.
Odd admission, is it not? In fact, if you go directly to Vault 7 you can discover for yourself that the information presented isn’t weaponized at all… just a litany of opportunities that someone — anyone — could weaponize… or just make public and close the loopholes in the hardware/software of your choice:
As an example, specific CIA malware revealed in “Year Zero” is able to penetrate, infest and control both the Android phone and iPhone software that runs or has run presidential Twitter accounts. The CIA attacks this software by using undisclosed security vulnerabilities (“zero days”) possessed by the CIA but if the CIA can hack these phones then so can everyone else who has obtained or discovered the vulnerability. As long as the CIA keeps these vulnerabilities concealed from Apple and Google (who make the phones) they will not be fixed, and the phones will remain hackable.
The same vulnerabilities exist for the population at large, including the U.S. Cabinet, Congress, top CEOs, system administrators, security officers and engineers. By hiding these security flaws from manufacturers like Apple and Google the CIA ensures that it can hack everyone; at the expense of leaving everyone hackable.
In short: Apple and Google aren’t ironclad, and CIA (and anyone else with resources) can exploit these loopholes, leave them alone, or watch to see if other agents — private or public — exploit these loopholes.
Of course, it’ll provide great copy for those who like to chase bright shiny objects… namely, those who read newspapers and enjoy getting played by clickbait.
…but this isn’t remarkable. In fact, it’s proper process. It’s the stuff that makes NCIS great television but seems to horrify the easily misled and shock the unprepared when the bad guys do likewise to the United States.
This is the work the intelligence community ought to be doing. Fears of weaponization are overblown — like the libel against every hacker being a malicious cracker, it’s little more than gun control for the information age.
Apple and Google aren’t going to be fireproof. Frankly, I would want CIA et al. to be exploring these pathways and watching them like a hawk, especially in an era where electronic grids can go down in the flash of an eye.
More to the point, a big reveal such as this shows how spent a force Wikileaks really is.
The DNC hacks were useful in and of themselves (Podesta’s “Catholic Spring” is still shaking the Catholic Church and the bevy of NGOs huddled around the Vatican Bank pretty hard — see: Cardinal Burke, Malta), but Vault 7 at first glance? Appears to look more like Geraldo Rivera going in and opening Al Capone’s vault…. empty and pointless.
