Facebook Twitter Instagram Pinterest YouTube Tumblr LinkedIn RSS
    • About
    • Advertise
    • Contribute
    • Donate
    • Forum
    • Contact
    Login
    InfoStride NewsInfoStride News
    • Home
    • Business
    • Celebrity
    • Crime
    • Nigeria
    • Politics
    • Sports
    • Technology
    • More
      • COVID-19
      • Editor’s Picks
      • Health
      • Opinions
      • Press Releases
      • World
    Subscribe
    InfoStride NewsInfoStride News
    Home»Business Matters»Guess Who Wasn't Invited to the CIA’s Hacker Jamboree?

    Guess Who Wasn't Invited to the CIA’s Hacker Jamboree?

    Business Matters By EFFSourceMar 11, 2015No Comments3 Mins Read
    Facebook Twitter WhatsApp Pinterest LinkedIn Tumblr Email Reddit VKontakte

    Apple, that’s who. Or Microsoft, or any of the other vendors whose products US government contractors have successfully exploited according to a recent report in the Intercept. While we’re not surprised that the Intelligence Community is actively attempting to develop new spycraft tools and capabilities—that’s their job—we expect them to follow the administration’s rules of engagement. Those rules require an evaluation under what’s known as the “Vulnerabilities Equities Process.” In the White House’s own words, the process should usually result in disclosing software vulnerabilities to vendors, because “in the majority of cases, responsibly disclosing a newly discovered vulnerability is clearly in the national interest.”

    TCB graphic

    Nevertheless, the Intercept article describes an annual CIA conference known as the Trusted Computing Base (TCB) Jamboree1 at which members of the intelligence community present extensively on software vulnerabilities and exploits to be used in spying operations. At the 2012 TCB Jamboree, presenters from Sandia National Laboratories, which is a contractor for the Department of Energy, described an attack on Xcode, the Apple software used to compile applications in Mac OS X and iOS. The “whacked” Xcode exploit, called Strawhorse, enables intelligence agents to implant a version of Xcode on developers’ computers which, unbeknownst to the developers, would cause software they compile to include a backdoor or other compromise. If successful, the attack could enable a range of surveillance-friendly applications to be covertly made available to the public. The report suggests that the Sandia team discovered and employed a number additional of vulnerabilities in Apple’s hardware and software, including a vulnerability in Apple’s secure element that enabled them to extract a secret key, and one that allowed modification of the OS X updater to install a keylogger. Finally, the report describes similar presentations on Microsoft’s BitLocker software and others.

    See also  Chatting Spot Invents New Wireless Social Media Networking System

    The vulnerabilities involved in these exploits were almost certainly unknown to Apple itself, and the documents released by the Intercept do not indicate that the CIA or its contractors ever considered disclosing them to the company. Yet this is what the administration’s Vulnerabilities Equities Process requires—a balancing test that weighs the risk to average users of leaving unpatched vulnerabilities against the needs of the intelligence community.

    EFF has sued under the Freedom of Information Act (FOIA) to uncover more about the Vulnerabilities Equities Process, which the White House characterized as a set principles that inform “a disciplined, rigorous and high-level decision-making process for vulnerability disclosure.” Naturally, the Office of the Director of National Intelligence and the NSA have been less than forthcoming in response to our FOIA suit, producing only a handful of highly-redacted documents to date. Given the scanty information we’ve received, and the freedom with which the Jamboree attendees seem to stockpile vulnerabilities, we have doubts that the Equities Process is really as “disciplined and rigorous” as the administration claims.

    See also  Elemica CEO John Blyzinskyj Named 2014 Provider Pro to Know

    When asked for comment, an unnamed intelligence official told CNBC: “There’s a whole world of devices out there, and that’s what we’re going to do…It is what it is.”

    • 1. We have no idea if the organizers of the TCB Jamboree were aware of the coincidence, but as any good Elvis fan knows, the King’s personal motto was Taking Care of Business, or TCB for short.
    Related Issues: 
    Coders’ Rights Project
    Privacy
    Security
    Related Cases: 
    EFF v. NSA, ODNI – Vulnerabilities FOIA
    Share this: Share on Twitter Share on Facebook Share on Google+ Share on Diaspora  ||  Join EFF

    Source: Electronic Frontier Foundation (EFF) – eff.org

    Support InfoStride News' Credible Journalism: Only credible journalism can guarantee a fair, accountable and transparent society, including democracy and government. It involves a lot of efforts and money. We need your support. Click here to Donate

    Digital Media EFF EFF News Electronic Frontier Foundation Press Release Technology News
    Share. Facebook Twitter WhatsApp Pinterest Reddit Tumblr VKontakte Email LinkedIn

    Related Posts

    Do something, do something big, says US President Joe Biden on gun control

    Mar 15, 2023

    US Senate panel approves Biden’s pick Garcetti for India ambassador

    Mar 9, 2023

    The Case For Investments In Nigeria’s Renewable Energy By Collins Okeke

    Mar 8, 2023

    Trump says an indictment would not hamper his third presidential campaign

    Mar 5, 2023
    Add A Comment

    Comments are closed.

    Get Social with Us
    • Facebook
    • Twitter 6.5K
    • Pinterest 92
    • Instagram
    • YouTube
    Latest Posts

    I Don’t Regret Not Getting Vaccinated Despite The Consequences – Djokovic

    Mar 23, 2023

    Whatever England Has Achieved In The Past Is Irrelevant Ahead Of Euro 2024 – Gareth Southgate

    Mar 23, 2023

    Send Funds While You Admire The Beauty – Toke Makinwa

    Mar 23, 2023

    My 2nd MUFC Experience Was The Toughest Phase Of My Career – Ronaldo

    Mar 23, 2023

    Subscribe to Updates

    Get the latest breaking news straight into your inbox!

    Random News

    The Judiciary Have Nothing On Me – Nnamdi Kanu

    Apr 10, 2019

    Rumor: Samsung to Release Four New Galaxy Tablets before March 2014

    Dec 20, 2013

    You’re unstable, focus on whereabouts of your imported wife – Atiku knocks Oshiomhole

    Dec 1, 2022

    Musiliu Obanikoro Linked Again To N400m Scam

    Nov 7, 2016

    InfoStride News delivers the latest breaking news, Nigeria news, world news and top stories on business, celebrity, entertainment, politics, sports, technology and more. Experience the best of in-depth coverage, special reports, football highlights, political opinions, crime watch, celebrity gossips etc.

    GooglePlay Store Button

    Support InfoStride News' Credible Journalism

    Credible journalism involves a lot of efforts and money; and can guarantee a fair, accountable and transparent society, including democracy and government. We need your support to continue offering free access to our loyal readers and visitors like you.

    Click here to Donate

    Facebook Twitter Instagram Pinterest YouTube Tumblr LinkedIn RSS
    • Our Terms
    © 2023 InfoStride News. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Sign In or Register

    Welcome Back!

    Login to your account below.

    Continue with Facebook
    Continue with Google
    Continue with Twitter
    Lost password?