Author Topic: Wikileaks  (Read 4092 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Wikileaks
« on: March 08, 2017, 02:08:20 AM »
I want to know what AVAST as to say about the story of CIA breaking into laptop, smartphones and other devices.

https://www.washingtonpost.com/news/the-switch/wp/2017/03/07/why-the-cia-is-using-your-tvs-smartphones-and-cars-for-spying/?utm_term=.3c8d9d3cc8e3

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Wikileaks
« Reply #1 on: March 08, 2017, 07:27:35 AM »
Then you should check avast blog as that is usually where they post what they think   ;)

It is no surprise that these big spy organisations with budget bigger then some contry have ways of entering your smart device, it would be a bigger surprise if they did not. Remeber this is what they work with 24/7

Anyway, this is not new. Malware for smart devices has been around for some time

http://blog.trendmicro.com/trendlabs-security-intelligence/android-based-smart-tvs-hit-by-backdoor-spread-via-malicious-app/

http://blog.trendmicro.com/trendlabs-security-intelligence/internet-things-ecosystem-broken-fix/



« Last Edit: March 08, 2017, 09:07:22 AM by Pondus »

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re: Wikileaks
« Reply #2 on: March 08, 2017, 08:38:44 AM »
The problem with smart devices is that people often don't change the standard factory password on them.
Another problem is that many "smart devices" either don't have a password at all or the user can't even change it.

There is nothing new here.
It has been already that way since the first smart device.

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48551
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Wikileaks
« Reply #3 on: March 08, 2017, 03:39:59 PM »
Snowden made everyone aware of the lack of privacy some years back.
This simply confirms his original leak and goes a few steps further.
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline stibi

  • Sr. Member
  • ****
  • Posts: 383
Re: Wikileaks
« Reply #4 on: March 08, 2017, 05:53:10 PM »
And maybe some  smart devices are not really smart enough  :)

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Wikileaks
« Reply #5 on: March 08, 2017, 05:57:04 PM »
And maybe some  smart devices are not really smart enough  :)
Yepp, just click the second link i posted above


Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Wikileaks
« Reply #6 on: March 08, 2017, 06:23:04 PM »
Hi bob3160,

Lucky that we two cannot be  blamed for this, we are too old, as old-director, Michael Haydn, says in his comment, it is the Millenials.
Millenials are a disloyal bunch America can no longer count on to enlist for this kind of work.

As I see it the USA becomes more and more a "divided house" and divided houses cannot stand
according to Mark 3:25 and do we now have: "The Divided States of America"?  ;D

I think it will be hard to get back the old reliable mentality from before the Civil War, like in the Southern States.

polonus
« Last Edit: March 08, 2017, 06:26:37 PM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48551
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Wikileaks
« Reply #7 on: March 08, 2017, 06:31:38 PM »
Hi bob3160,

Lucky that we two cannot be  blamed for this, we are too old, as old-director, Michael Haydn, says in his comment, it is the Millenials.
Millenials are a disloyal bunch America can no longer count on to enlist for this kind of work.

As I see it the USA becomes more and more a "divided house" and divided houses cannot stand
according to Mark 3:25 and do we now have: "The Divided States of America"?  ;D

I think it will be hard to get back the old reliable mentality from before the Civil War, like in the Southern States.

polonus
Back then, slavery was the norm. I certainly wouldn't call that a good mentality.
To outsiders it looks like something is broken. We re simply going through a new period of adjustment.
It is hard for Washington to realize that politics as usual is no longer acceptable or tolerated. :)
The message will eventually sink in. :)
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37527
  • Not a avast user
Re: Wikileaks
« Reply #8 on: March 08, 2017, 06:47:14 PM »
Quote
It is hard for Washington to realize that politics as usual is no longer acceptable or tolerated.
But it should be possible to present it in a normal civilised way and not like a reality show


Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48551
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Wikileaks
« Reply #9 on: March 08, 2017, 06:59:33 PM »
Quote
It is hard for Washington to realize that politics as usual is no longer acceptable or tolerated.
But it should be possible to present it in a normal civilised way and not like a reality show
Since I'm not the one in Washington, I can't speak for any one else.
Neither side at the moment is being civilized  :o
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline cruiser25

  • Jr. Member
  • **
  • Posts: 72
Re: Wikileaks
« Reply #10 on: March 08, 2017, 10:59:42 PM »
Wikileaks presented documents which listed all major antivirusbrands and that CIA have tried or tries or allready managed to by pass or compromise them to get acces to our computers. And of course that´s what spy agencies do. But another problem is that it seems that not only Wikileaks got acces to the documents including numerous of codes which maybe is a bigger threath to us ordinary users. I read a report by virus bulletin which stated that when securitysoftware get acces to when you are connected via https connections and scans the connection it will not highten the security in fact it makes it less secure. If i´m not misstaken wasn´t this something that Avast incorporated in their software a while ago ? So one thing is for sure forget about privacy anymore. Sad but true. And I think it´s going to worsen in the future when it seems that "everything" in a near future will be connected to the internet. And i´m not wearing a foilhat ;)
Just want to ad one thing, according to the Avast blog Avast products were the only one that didn´t compromise the security when scanning the https connection. It was rated with an A. That´s one comfort. For what it is worth.
« Last Edit: March 09, 2017, 08:23:12 PM by cruiser25 »

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 33897
  • malware fighter
Re: Wikileaks
« Reply #11 on: March 09, 2017, 12:07:13 AM »
@cruiser25,

That is why with the broken infrastructure we have, nobody seems to like to put in an effort to mend it,
we have to redefine the main term in this spelled "TRUST".

When are you able to fully trust an e2e encryption and the role of that CDN in it against data breaches and cloudbleeds? When your VPN or proxy has been turned against you, no longer keeping you safe, what then?

Who allowed a true amateur to develop a language like PHP that is insecure by design, and never should have been used as CMS apart from building a html website?

Why is Microsoft sitting on an enormous problem with double extensions for over a decade, and that has not be solved so gigantic amounts of user can be infested by executable second extensions that stay invisible by default?

These are real questions, so "What's up doc". Can you explain that to us, dear Mr. Michael Haydn, sir?
Why don't we improve the global Internet infrastructure? Poundering the problems is getting to the core of the problem. The infrastructure is holed like Swiss cheese and beyond. And top governance of the global Internet structure are not doing a thing about it or sitting on their hands.

IT staff and developers learn nothing about security or have to specialize in it as Technical IT, and when they have know-how or pass a particular security exam, CIA is the first institute to approach and gratulate them, depending from what part of the world they come. That is the situation shortly sketched before you. A security officer may do some resource engineering of worked out schemes put out before him, but he will never govern the lay-out he has to go by.  Seems almost like we do not want to arrive at a more secure infrastructure because of vested interests, like we have found some here.

polonus
« Last Edit: March 09, 2017, 12:12:30 AM by polonus »
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

REDACTED

  • Guest
Re: Wikileaks
« Reply #12 on: March 10, 2017, 06:13:37 AM »
I read a report by virus bulletin which stated that when securitysoftware get acces to when you are connected via https connections and scans the connection it will not highten the security in fact it makes it less secure. If i´m not misstaken wasn´t this something that Avast incorporated in their software a while ago ? So one thing is for sure forget about privacy anymore. Sad but true. And I think it´s going to worsen in the future when it seems that "everything" in a near future will be connected to the internet. And i´m not wearing a foilhat ;)
Just want to ad one thing, according to the Avast blog Avast products were the only one that didn´t compromise the security when scanning the https connection. It was rated with an A. That´s one comfort. For what it is worth.
Do no evil with Avira (or nasty HTTPS handshakes)
https://blog.avira.com/evil-nasty-https-handshakes/
----------------------------------------------------
Avast 2016: HTTPS scanning in Web Shield - FAQs
https://www.avast.com/en-us/faq.php?article=AVKB190
----------------------------------------------------
http://www.zdnet.com/article/google-and-mozillas-message-to-av-and-security-firms-stop-trashing-https/
Quote
The researchers urge antivirus vendors to stop intercepting HTTPS altogether, since the products already have access to the local filesystem, browser memory, and content loaded over HTTPS.

Additionally, they charge all security companies with acting "negligently".

"Many of the vulnerabilities we find in antivirus products and corporate middleboxes, such as failing to validate certificates and advertising broken ciphers, are negligent and another data point in a worrying trend of security products worsening security rather than improving it," they write.
« Last Edit: March 10, 2017, 06:26:13 AM by avon »

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89029
  • No support PMs thanks
Re: Wikileaks
« Reply #13 on: March 10, 2017, 11:12:35 AM »
Your blog.avira link is coming up 404 error.

Your 3rd link has been discussed/posted in at least couple of other topics already.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security