Apple iOS 10.2.1 protects users from Weeping Angel
Security community says Vault 7 content is "no surprise", but reckless


Most iOS devices are protected against the CIA's alleged Weeping Angel attacks revealed by WikiLeaks last night, Apple has claimed.
In a statement sent to IT Pro, the Cupertino company said: "The technology built into today's iPhone represents the best data security available to consumers, and we're constantly working to keep it that way.
"While our initial analysis indicates that many of the issues leaked were already patched in the latest iOS, we will continue work to rapidly address any identified vulnerabilities. We always urge customers to download the latest iOS to make sure they have the most recent security updates."
What proportion of the issues "many" represents is unclear.
Microsoft and Samsung both said they are currently "looking into" the matter, but gave no further information on the current scope or validity of the attacks detailed in the so-called Vault 7 cache.
No surprises
While hardware makers rush to investigate and patch the alleged vulnerabilities, the security community has raised an eyebrow at the surprise the leaks have generated with regard to the vulnerabilities themselves.
Slawek Ligier, VP of security engineering at Barracuda, said: "The types of capabilities described in the WikiLeaks [files] are not new and many of the exploits were demonstrated as technically possible for a while now."
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Matthew Ravden, VP at security systems specialist Balabit, added: "Assuming these revelations are true (and they certainly appear to be authentic), it's probably fairly shocking to the general public to see the lengths to which a sophisticated government-sponsored organisation will go to find ways of 'listening in', through TVs, smart-phones or other 'connected' devices.
"For those of us in the security industry, however, none of this is particularly surprising. The resources available to the CIA, MI5, or the FSB are such that they can do pretty much anything. They live by a different set of rules from the rest of us."
Fake news and questionable morals
Although it has been reported that the the Vault 7 files show the CIA can break the encryption of secure apps like WhatsApp, Signal and Telegram, this is based on a misunderstanding of the content of the leaks.
Ed Johnson-Williams, a campaigner for the Open Rights Group, said in a blog post: Some journalists ... have reported this story as showing that the CIA can bypass the encryption on messaging apps like Signal and WhatsApp. This is emphatically not accurate. The apps themselves are secure. They are probably uncritically repeating a WikiLeaks tweet to that effect.
"There is a big difference between phone operating systems being hacked and message encryption being broken. If a messaging app's encryption has been broken, that would affect every user of the app. The encryption in Signal and WhatsApp has not been broken ... [they] remain very good ways to communicate when using a mobile phone for nearly everyone. The worst thing to do would be to throw our hands up in the air and give up on our digital security."
Johnson-Williams pointed out that if the CIA and other intelligence agencies "hoard" these vulnerabilities, then they are also open to use by criminals and the intelligence agencies of non-friendly countries.
Ligier sounded a similar note, saying: "To me the disturbing part of the report is that it appears that spy agencies ... are more interested in stockpiling the vulnerabilities for a future exploit rather than working with vendors to close the gaps. If the CIA knows of the specific exploit, chances are that the MI6, FSB, MSS, and Mossad are aware of it as well.
"Not working on closing the gap and hoping that we will be the only ones able to exploit it, puts all of us at risk. And frankly, the United States has much more to lose through potential industrial espionage than other countries."
Digital personal safety
Although the encryption of WhatsApp, Signal and Telegram hasn't been broken, devices themselves remain vulnerable. There are still ways consumers can keep themselves safe or at least safer from hacking of all types.
Johnson-Williams said: "From a personal security point-of-view it's important to keep all of this in perspective. Most people are at far greater risk of their devices being infected from clicking a link in a phishing email than they are of being hacked by the CIA using a vulnerability in their device."
Similarly, Ligier said that while there's no way to stop devices being turned into "little spies", the risks can be mitigated.
Reflecting Apple's comment, he said users should always update to the latest firmware and software "especially if the update lists security fixes". He also warned against rooting or jailbreaking phones, as well as being careful when opening email attachments or clicking on links as "more than 90% of attacks start with the email".
"We all need to work together to protect the advantages the global internet offers to all of us and assure that the dark side does not win," he said.
Image credit: Bigstock

Jane McCallion is Managing Editor of ITPro and ChannelPro, specializing in data centers, enterprise IT infrastructure, and cybersecurity. Before becoming Managing Editor, she held the role of Deputy Editor and, prior to that, Features Editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, and business strategy.
Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
Wikileaks 'hacked' by OurMine
News The whistleblowing site was supposedly breached, but the attack was found to be a simple DNS spoof
By Adam Shepherd Published
-
Sweden drops rape charges against Julian Assange
News Assange may still remain in hiding, however
By Nicole Kobie Published
-
Cisco discloses Vault 7 vulnerabilities
News Internal analysis seems to have identified bug revealed by WikiLeaks
By Jane McCallion Published
-
WikiLeaks ‘exposes people’s personal data’ in leaked files
News Rape victims and other innocent people named in WikiLeaks documents, says AP
By Joe Curtis Published
-
Pressure mounts on US justice department to drop Wikileaks investigation
News Human rights organisations claim investigation could put all journalists at risk of prosecution
By Caroline Donnelly Published
-
Julian Assange unlikely to be charged by US government
News No way to prosecute Assange without also taking legal action against journalists.
By Khidr Suleman Published
-
Bradley Manning found guilty of espionage
News US Soldier Bradley Manning could face up to a 136-year jail sentence.
By Khidr Suleman Published
-
Anonymous attacks UK gov websites in Assange protest
News ‘Hacktivists’ target Ministry of Justice website over handling of Wikileaks founder asylum case.
By Jane McCallion Published