Live data from Hacker News

Swiss government files criminal complaint over Crypto AG scandal involving CIA

intelnews.org

41–50 of 62 posts

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#41
post #36

Earlier quoted context omitted.

To expand on this, and illustrate the dangers of speculation, would you not also establish a legitimate Certificate Authority when your lab geeks realized how critical they would or could someday be, then use your industry reputation to sell certificates like any other company in the industry?

Sure I could. Then I just need to convince ISPs (or Cisco :D) to channel traffic trough my equipment. On the other side, as a government agency with ties all over the world, decades of practice in eschelon, cryto ag, on-the-fly replacing chips on cisco equipment, unlimited founding,..

Perhaps you don't even need to convince Cisco. Just find some vulnerabilities in their OS, sit on them and pull them out when you need.

I wonder what percentage of internet connections hops through a cisco device at some point...?

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#42

After WW2 we (brits) sold enigma machines to the countries gaining independence from the empire and never mentioned we could read everything they were used to communicate. This is why no one should outsource vital functions to competitors... This should be embarrassing for the Swiss intelligence services whose job it was to detect and prevent these sorts of shenanigans... Also, have I misunderstood? The criminal case…

> The criminal case should be against the company executives surely, not "persons unknown"

I don't know about Switzerland, but in some European countries this enables a judge to be designated to carry out a formal investigation and to then decide who to specifically go after. In addition, filing a complaint against a specific person opens you to be sued back if that person is then shown to have done nothing wrong. This means that it is very common for criminal complaints to be initially filed against "persons unknown".

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#43

I wonder what the outcome can be of filing a criminal complaint like this? What do they hope to achieve? I can't imagine anyone or any nation will ever be brought to justice over this ?

I think it's more of a gesture. There was also a similar action by the European Parliament against Operation Gladio back in 1990, which was also a gesture.

Exactly. If this wasn't persecuted the message would be "yeah, screw people over and ruin the swiss reputation, we don't really care". Now even if the evidence isn't court-proof, or it's not possible to attach it to specific people, it still shows that things like this won't be ignored.

If I was responsible for selling rigged encryption equipment, I'd be wary that this might backfire on me - even in a decade or two.

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#44

Earlier quoted context omitted.

It was there like 20 minutes ago, quoting her saying (paraphrasing, from my memory) "We'll deal with this when we have all the facts". Maybe one of the editors is watching this thread. Making that mistake for a layperson is understandable sure, but a website about intel, you have to lol. Probably why they fixed it up so quickly.

>Making that mistake for a layperson is understandable sure, but a website about intel, you have to lol. The website is run by laypersons who actively deal in covering the president or prime minister of hundreds of countries. Covering intel doesn't really prevent this mistake.

I dunno man. Sports commentators deal with hundreds of teams all the time, I don't see them mistaking the owner vs manager of a club, and they would be laughed at if they did, even (especially?) the lay / hobbyist ones.

Also, at the very top of their website it says "a specialized intelligence website written by experts", and in the sidebar they list their qualifications - so they apparently want to claim they are not laypersons. Lol, but you are trying to claim it?

Granted it's pretty subjective, so whatever. I don't think my standards for this topic are much different from other people's standards for other topics with similar shapes.

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#45

Protip: Nobody knows who owns any business entity, if they dont want you to know. Here German intelligence and US intelligence owned a Swedish entity. Thats how free trade works.

That has nothing to do with free trade - it's about privately held stocks. Which is a worldwide thing.

Yes but no capital controls on who can own what and where

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#46
post #14

Protip: Nobody knows who owns any business entity, if they dont want you to know. Here German intelligence and US intelligence owned a Swedish entity. Thats how free trade works.

Swiss.

Whoops too late to edit

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#47

I wonder what the outcome can be of filing a criminal complaint like this? What do they hope to achieve? I can't imagine anyone or any nation will ever be brought to justice over this ?

If they can identify people involved, they can issue arrest warrants and a red corner notice via Interpol. That can make travel very difficult for the people involved and they'll essentially be unable to leave their own countries without risk of arrest. They won't realistically ever be able to prosecute, but they can make life a bit uncomfortable as a gesture. And if relatives or friends of those people vacation in Switzerland, they can always pull them in for "questioning about a suspect" as another form of harassment.

Small countries can never threaten a big state realistically, however they have the ability to harrass people who work for these big states in the hope of discouraging future action

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#48
post #4

This case should be quoted in every discussion about 5G mobile equipment here in Europe.

Every country designing and making their own 5G equipment seems impractical (not to mention expensive, likely full of bugs=backdoors, etc), I think the correct conclusion to draw from that is that you need to use end-to-end (really point-you-trust-to-other-point-you-choose-to-trust) encryption.

It's like checksums, really ;) Point-to-point is helpful, but not sufficient.

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#49
post #4

This case should be quoted in every discussion about 5G mobile equipment here in Europe.

Every country designing and making their own 5G equipment seems impractical (not to mention expensive, likely full of bugs=backdoors, etc), I think the correct conclusion to draw from that is that you need to use end-to-end (really point-you-trust-to-other-point-you-choose-to-trust) encryption. It's like checksums, really ;) Point-to-point is helpful, but not sufficient.

I don’t think GP asked for every country manufacturing their own equipment, rather they should ask for significant insight and auditing into the design and making of critical infrastructure

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#50
post #24

Just a simple thought experiment... In light of those events, would you as, for instance, CIA, create your Certificate Authority and offer free certificates for servers, simplifying deployment to be as simple to use as possible? ;) (I am just looking into certificate pinning, but CA can generate another certificate or wildcarded certificate that client trusts, which enables mitm, I am doing it all the time on https p…

Considering that a majority of the Lets Encryot userbase would probably be running http rather than https if it weren't for free certs, it's still probably preferable to have only one or a handful of malicious entities able to observe traffic. You're not wrong though overall, the certificate model doesn't have built in protections for malicious CAs.

Overall I would argue that companies that are dealing with sensitive data should be using EV certs anyway to help users defend against phishing attacks which Let's Encrypt doesn't offer to my knowledge. This is tangential to your point though.

Post reply on HN