After WW2 we (brits) sold enigma machines to the countries gaining independence from the empire and never mentioned we could read everything they were used to communicate. This is why no one should outsource vital functions to competitors... This should be embarrassing for the Swiss intelligence services whose job it was to detect and prevent these sorts of shenanigans... Also, have I misunderstood? The criminal case…
Swiss government files criminal complaint over Crypto AG scandal involving CIA
31–40 of 62 posts
Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA
#32Just a simple thought experiment... In light of those events, would you as, for instance, CIA, create your Certificate Authority and offer free certificates for servers, simplifying deployment to be as simple to use as possible? ;) (I am just looking into certificate pinning, but CA can generate another certificate or wildcarded certificate that client trusts, which enables mitm, I am doing it all the time on https p…
Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA
#33Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA
#34Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA
#35This case should be quoted in every discussion about 5G mobile equipment here in Europe.
Especially since the 5G situation even kinda smells the same:
https://www.washingtonpost.com/graphics/2020/world/national-...:
> As Widman settled in, the secret partners adopted a set of principles for [Crypto AG's] rigged algorithms, according to the BND history. They had to be “undetectable by usual statistical tests” and, if discovered, be “easily masked as implementation or human errors.”
> In other words, when cornered, Crypto executives would blame sloppy employees or clueless users.
https://www.theregister.co.uk/2019/03/28/hcsec_huawei_oversi...:
> Huawei savaged by Brit code review board over pisspoor dev practices
> "The work of HCSEC [Huawei Cyber Security Evaluation Centre]… reveals serious and systematic defects in Huawei's software engineering and cyber security competence," said the HCSEC oversight board in its annual report, published this morning.
Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA
#36Just a simple thought experiment... In light of those events, would you as, for instance, CIA, create your Certificate Authority and offer free certificates for servers, simplifying deployment to be as simple to use as possible? ;) (I am just looking into certificate pinning, but CA can generate another certificate or wildcarded certificate that client trusts, which enables mitm, I am doing it all the time on https p…
To expand on this, and illustrate the dangers of speculation, would you not also establish a legitimate Certificate Authority when your lab geeks realized how critical they would or could someday be, then use your industry reputation to sell certificates like any other company in the industry?
Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA
#37Why now, just to save face? Its not like people still buy cryptography equipment from the Swiss. They compromised various clients, including Iraq during the first gulf war.
Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA
#38This case should be quoted in every discussion about 5G mobile equipment here in Europe.
Towards which conclusion? Backdoors are common practice and so we have to assume their existance in foreign equipment? Or we did it first, so let's give the others a chance to deliver backdoors to us?
Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA
#39Earlier quoted context omitted.
Towards which conclusion? Backdoors are common practice and so we have to assume their existance in foreign equipment? Or we did it first, so let's give the others a chance to deliver backdoors to us?
[oops, misread comment.]
Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA
#40This was publicly known over 25 years ago. There was a 60 Minutes piece in it in the early 90’s. Why are they up in arms about it now?
When swiss newspapers reported on it in 1994, the cold war was still present in the minds of my fellow citizens and the US was seen as an ally and friend, so the general public probably just didn't consider it to be that important if the CIA maybe bugged some conversations. Also, the swiss government "preferred not to know anything" and obstructed investigations, despite some employees of Crypto AG coming forward with information to the federal police.
The world (or rather our view of it) is quite different today. Hidden data collection is a popular topic and it's harder to pretend that there are only friends in the west and only enemies in the east. It's also easier to share information worldwide and media coverage was much larger this time.