Earlier quoted context omitted.
If you really mean conversations of the original owner, I can't believe that's true after e2e has been enabled. But it could be that messages sent to the original owner are received, since WhatsApp automatically re-encrypts and sends messages if the message has not been received yet and the key has been changed. So basically that would mean the message would be sent when the previous owner already changed their numbe…
WhatsApp also does backup.
“100 spies” will monitor all SMS and email that goes in and out of Norway
41–50 of 50 posts
Re: “100 spies” will monitor all SMS and email that goes in and out of Norway
#42Earlier quoted context omitted.
I'd watch that movie though.
100 people in suits and tie intercepting "Norsemen" memes and analyzing fake-book reviews such as " The Dragon with the Girl Tattoo " edit: apologies just realized the latter was Swedish not Norwegian
Re: “100 spies” will monitor all SMS and email that goes in and out of Norway
#43How does that work with encrypted transport? Yahoo, Microsoft, Google and of course many others, all provide IMAP over TLS so sending email to them and receiving from them doesn't go in the clear.
They get the keys from the NSA. (Sarcasm, but a non-zero fear that it's true.)
Re: “100 spies” will monitor all SMS and email that goes in and out of Norway
#44Earlier quoted context omitted.
Like most gov, they probably have access to a root CA and they MITM.
There are currently no publicly trusted CAs participating in such a scheme. If there were, it'd be trivially detectable due to the millions of fraudulent certificates showing up in Certificate Transparency logs.
Re: “100 spies” will monitor all SMS and email that goes in and out of Norway
#45Re: “100 spies” will monitor all SMS and email that goes in and out of Norway
#46Earlier quoted context omitted.
In the majority of cases, TLS for SMTP (delivery between MTAs) is still trivially downgradeable. So they could presumably downgrade and read SMTP traffic that's going between MTAs in Norway and MTAs outside Norway.
Wouldn't that also be trivially detectable?
Alternatively, the government could also conduct a TLS certificate man-in-the-middle, which would work in most cases since almost no MTAs validate certificates outside of occasionally trying DANE (a spec for pinning certs over DNSSEC).
Re: “100 spies” will monitor all SMS and email that goes in and out of Norway
#47Earlier quoted context omitted.
Wouldn't that also be trivially detectable?
From one party's perspective, it may just look like the other party does not support TLS. Without another point of reference, MTAs can't tell the difference between a lack of TLS support and a downgrade attack. Alternatively, the government could also conduct a TLS certificate man-in-the-middle, which would work in most cases since almost no MTAs validate certificates outside of occasionally trying DANE (a spec for p…
Re: “100 spies” will monitor all SMS and email that goes in and out of Norway
#48Earlier quoted context omitted.
There are currently no publicly trusted CAs participating in such a scheme. If there were, it'd be trivially detectable due to the millions of fraudulent certificates showing up in Certificate Transparency logs.
Of course they won't tell you that they are doing it...
Re: “100 spies” will monitor all SMS and email that goes in and out of Norway
#49Earlier quoted context omitted.
You decrypt the traffic. Or you monitor on a point in the chain where the traffic has already been decrypted. I think what you meant to ask was how do they obtain the decryption keys or establish a point of presence post-decryption?
You can't decrypt the traffic. You can however monitor it at a point that traffic has already been decrypted. SMS messages are not encrypted and email is only encrypted between you and your email provider whether that email goes on to its final email recipient server encrypted or not is entirely up to the email provider.
Sure you can. There are many how-to's on decrypting SSL/TLS using wireshark, you just have to have the keys. Here's one - https://support.citrix.com/article/CTX116557
Re: “100 spies” will monitor all SMS and email that goes in and out of Norway
#50At least the Norwegians (and other Scandinavian countries) are publicly open about what they are doing. You'd probably never see this 'news story' in the UK or US except as the solution to some event that supposedly justified it