Live data from Hacker News

Swiss government files criminal complaint over Crypto AG scandal involving CIA

intelnews.org

21–30 of 62 posts

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#21
post #16

Earlier quoted context omitted.

"We're already ahead, we don't need to run any faster, we'll use our energy to do pointless things like spy on everyone instead". Don't let me stop you thinking that but I'll keep running faster, thanks.

The idea that less developed economies have much faster potential growth is well studied in economics: https://en.m.wikipedia.org/wiki/Convergence_(economics) I'm not sure what point you're trying to make here.

The article itself contains a lot of nuances and exceptions, and makes no pretense at trying to predict the future, but you're treating it as if it inevitably predicts an outcome as time tends towards infinity.

You might want to better understand the difference between a non-predictive theory meant as a guide for future research, vs reality, an actual future, and a truly predictive theory.

That said, don't let me stop you from believing what you want to believe. It doesn't take a genius to figure out what my point is, but if your salary depends on you not understanding it, that's OK too.

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#22
post #20
post #4

This case should be quoted in every discussion about 5G mobile equipment here in Europe.

Towards which conclusion? Backdoors are common practice and so we have to assume their existance in foreign equipment? Or we did it first, so let's give the others a chance to deliver backdoors to us?

To maintain control over critical communication technology.

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#23

After WW2 we (brits) sold enigma machines to the countries gaining independence from the empire and never mentioned we could read everything they were used to communicate. This is why no one should outsource vital functions to competitors... This should be embarrassing for the Swiss intelligence services whose job it was to detect and prevent these sorts of shenanigans... Also, have I misunderstood? The criminal case…

tracking the history of CIA black operations e.g. Operation Gladio in Europe in the cold war, I'm almost sure that someone from the Swiss side knew this from the beginning.

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#24
Just a simple thought experiment... In light of those events, would you as, for instance, CIA, create your Certificate Authority and offer free certificates for servers, simplifying deployment to be as simple to use as possible? ;)

(I am just looking into certificate pinning, but CA can generate another certificate or wildcarded certificate that client trusts, which enables mitm, I am doing it all the time on https proxy (http://www.squid-cache.org/Doc/config/ssl_bump/). This way you can decrypt traffic - redirect traffic to your server and impersonate the right one while proxying data from original server)

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#27
post #24

Just a simple thought experiment... In light of those events, would you as, for instance, CIA, create your Certificate Authority and offer free certificates for servers, simplifying deployment to be as simple to use as possible? ;) (I am just looking into certificate pinning, but CA can generate another certificate or wildcarded certificate that client trusts, which enables mitm, I am doing it all the time on https p…

CAs cannot decrypt SSL traffic, or am I missing something.

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#28
post #24

Just a simple thought experiment... In light of those events, would you as, for instance, CIA, create your Certificate Authority and offer free certificates for servers, simplifying deployment to be as simple to use as possible? ;) (I am just looking into certificate pinning, but CA can generate another certificate or wildcarded certificate that client trusts, which enables mitm, I am doing it all the time on https p…

CAs cannot decrypt SSL traffic, or am I missing something.

CAs can issue a new cert for state-run MITM attacks.

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#29

I wonder what the outcome can be of filing a criminal complaint like this? What do they hope to achieve? I can't imagine anyone or any nation will ever be brought to justice over this ?

I think it's more of a gesture. There was also a similar action by the European Parliament against Operation Gladio back in 1990, which was also a gesture.
Post reply on HN