Live data from Hacker News

“100 spies” will monitor all SMS and email that goes in and out of Norway

translate.google.com

31–40 of 50 posts

Re: “100 spies” will monitor all SMS and email that goes in and out of Norway

#31

At least the Norwegians (and other Scandinavian countries) are publicly open about what they are doing. You'd probably never see this 'news story' in the UK or US except as the solution to some event that supposedly justified it

Guess again.

https://www.ft.com/content/eef717f2-bb6e-11e8-8274-55b729265... https://www.army.mod.uk/who-we-are/corps-regiments-and-units...

etc.

There is so much information available in democracies if you have the time to work through it, that they are effectively protected just by the sheer amount of documentation an interested observer has to plough through.

Start with the annual budgets - they´re extremely informative as to what the real issues are.

Re: “100 spies” will monitor all SMS and email that goes in and out of Norway

#32

How exactly does this work with encryption, which is becoming more and more prevalent? E.G., Tor...

You decrypt the traffic. Or you monitor on a point in the chain where the traffic has already been decrypted. I think what you meant to ask was how do they obtain the decryption keys or establish a point of presence post-decryption?

Re: “100 spies” will monitor all SMS and email that goes in and out of Norway

#33

At least the Norwegians (and other Scandinavian countries) are publicly open about what they are doing. You'd probably never see this 'news story' in the UK or US except as the solution to some event that supposedly justified it

Meh, we have had the same thing as you guys for a long time. FRA (the signal intelligence in sweden) has been recording our border-passing communications for many years. This is maybe not new knowledge, but definitely not that widespread.

The information gathered (oh, they have access to XKeyscore) is then shared within X eyes (nine? fourteen?) program. The extent of FRA's intelligence operations was not known before snowden.

Some of it became more public knowledge in 2008 when there was a new law that gave them permission to do cable interception. It was later confirmed that they had been doing cable interception before the law was enacted, in conflict with the law, but "with acceptance" of the administration.

Sweden is really not much better than other countries. Norway is following suit, but with a slightly "better" law that at least requires secret court orders to store other things than metadata of things passing the border.

Edit: oh, and they are allowed (or at least not strictly disallowed) to do targeted hacking, which they have done in cooperation with other (NSA) intelligence agencies.

But, at least we do not have a secret bugdet like other democracies :) . They got about 1 billion SEK last year, or about 0.1% of the national budget.

Re: “100 spies” will monitor all SMS and email that goes in and out of Norway

#34

How does that work with encrypted transport? Yahoo, Microsoft, Google and of course many others, all provide IMAP over TLS so sending email to them and receiving from them doesn't go in the clear.

Like most gov, they probably have access to a root CA and they MITM.

Re: “100 spies” will monitor all SMS and email that goes in and out of Norway

#35

How does that work with encrypted transport? Yahoo, Microsoft, Google and of course many others, all provide IMAP over TLS so sending email to them and receiving from them doesn't go in the clear.

Like most gov, they probably have access to a root CA and they MITM.

Didn't a new Norwegian CA offer free https certs a while back?

Re: “100 spies” will monitor all SMS and email that goes in and out of Norway

#36

How does that work with encrypted transport? Yahoo, Microsoft, Google and of course many others, all provide IMAP over TLS so sending email to them and receiving from them doesn't go in the clear.

Like most gov, they probably have access to a root CA and they MITM.

There are currently no publicly trusted CAs participating in such a scheme. If there were, it'd be trivially detectable due to the millions of fraudulent certificates showing up in Certificate Transparency logs.

Re: “100 spies” will monitor all SMS and email that goes in and out of Norway

#37
This is a proposed bill and is far from being implemented yet. It is currently being evaluated by all involved departments, institutions and companies and has predictably received sharp critique from many angles. It will be interesting to see if it survives the process at all.

Re: “100 spies” will monitor all SMS and email that goes in and out of Norway

#39
post #32

How exactly does this work with encryption, which is becoming more and more prevalent? E.G., Tor...

You decrypt the traffic. Or you monitor on a point in the chain where the traffic has already been decrypted. I think what you meant to ask was how do they obtain the decryption keys or establish a point of presence post-decryption?

You can't decrypt the traffic. You can however monitor it at a point that traffic has already been decrypted. SMS messages are not encrypted and email is only encrypted between you and your email provider whether that email goes on to its final email recipient server encrypted or not is entirely up to the email provider.

Re: “100 spies” will monitor all SMS and email that goes in and out of Norway

#40
post #14

Earlier quoted context omitted.

In the majority of cases, TLS for SMTP (delivery between MTAs) is still trivially downgradeable. So they could presumably downgrade and read SMTP traffic that's going between MTAs in Norway and MTAs outside Norway.

Wouldn't that also be trivially detectable?

Of course, as long as you're one of the parties involved in the SMTP communication.

The problem is that even though you're trivially able to detect that TLS is not in use, the vast majority of mail providers won't act on that knowledge by refusing to send mail unencrypted (except maybe for some hosts explicitly whitelisted for that approach).

Why? Too many broken TLS setups, historically. Might be better now, I vaguely remember some push towards that from the big providers.

Post reply on HN