Live data from Hacker News

Swiss government files criminal complaint over Crypto AG scandal involving CIA

intelnews.org

51–60 of 62 posts

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#51
post #22
post #20

Earlier quoted context omitted.

Towards which conclusion? Backdoors are common practice and so we have to assume their existance in foreign equipment? Or we did it first, so let's give the others a chance to deliver backdoors to us?

To maintain control over critical communication technology.

The problem is that 5g wasn't designed to be secure against malicious carriers & governments. It could have been, and modern cryptographic protocols used over it can be.

The assumption that you can trust communications infrastructure is outdated. It must not matter if an adversary has back doored a router or cell tower or similar to send copies of all traffic to them, since the data should be entirely encrypted (except for some minimal routing information). The 3GPP designed the 5G standards to allow back doors, so we get back doors.

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#52
post #24

Just a simple thought experiment... In light of those events, would you as, for instance, CIA, create your Certificate Authority and offer free certificates for servers, simplifying deployment to be as simple to use as possible? ;) (I am just looking into certificate pinning, but CA can generate another certificate or wildcarded certificate that client trusts, which enables mitm, I am doing it all the time on https p…

Doing this completely undetected is actually harder than you think. Modern browsers check Certificate Transparency lists, and if the certificate is not present in at least two lists then they are simply rejected.

In addition to this you have Certification Authority Authorization (CAA) which uses DNS to tell what CAs are allowed to sign certificates for a certain domain.

There are services you can subscribe to that will tell you when a certificate signed by a (or anyone but) CA for a domain you want to monitor.

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#54

After WW2 we (brits) sold enigma machines to the countries gaining independence from the empire and never mentioned we could read everything they were used to communicate. This is why no one should outsource vital functions to competitors... This should be embarrassing for the Swiss intelligence services whose job it was to detect and prevent these sorts of shenanigans... Also, have I misunderstood? The criminal case…

tracking the history of CIA black operations e.g. Operation Gladio in Europe in the cold war, I'm almost sure that someone from the Swiss side knew this from the beginning.

Operation Gladio is the codename for clandestine "stay-behind" operations of armed resistance that was planned by the Western Union (WU), and subsequently by NATO, for a potential Warsaw Pact invasion and conquest in Europe. Although Gladio specifically refers to the Italian branch of the NATO stay-behind organizations, "Operation Gladio" is used as an informal name for all of them. Stay-behind operations were prepared in many NATO member countries, and some neutral countries.

https://en.wikipedia.org/wiki/Operation_Gladio

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#56
post #22

Earlier quoted context omitted.

To maintain control over critical communication technology.

The problem is that 5g wasn't designed to be secure against malicious carriers & governments. It could have been, and modern cryptographic protocols used over it can be. The assumption that you can trust communications infrastructure is outdated. It must not matter if an adversary has back doored a router or cell tower or similar to send copies of all traffic to them, since the data should be entirely encrypted (exce…

What if the same company also provides the cellphones and computers used to do the encryption of the data being sent?

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#57
post #30

Why now, just to save face? Its not like people still buy cryptography equipment from the Swiss. They compromised various clients, including Iraq during the first gulf war.

I expect it is to imply they had no cooperation with the CIA as far as they know with their own Intelligence agency.

there is a good chance the Swiss intelligent apparatus knew what was going on so if this complaint vanishes or settles quietly we will know what is up

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#59
post #56

Earlier quoted context omitted.

The problem is that 5g wasn't designed to be secure against malicious carriers & governments. It could have been, and modern cryptographic protocols used over it can be. The assumption that you can trust communications infrastructure is outdated. It must not matter if an adversary has back doored a router or cell tower or similar to send copies of all traffic to them, since the data should be entirely encrypted (exce…

What if the same company also provides the cellphones and computers used to do the encryption of the data being sent?

Then you're programming Satan's computer[1] and need to start doing things like using a better trusted OS & compiler. Or go to a different vendor. Since end-user devices need to swap around a lot this tends to be a lot easier than replacing the underlying infrastructure devices.

[1] https://www.cl.cam.ac.uk/~rja14/Papers/satan.pdf

Re: Swiss government files criminal complaint over Crypto AG scandal involving CIA

#60

Earlier quoted context omitted.

>Making that mistake for a layperson is understandable sure, but a website about intel, you have to lol. The website is run by laypersons who actively deal in covering the president or prime minister of hundreds of countries. Covering intel doesn't really prevent this mistake.

I dunno man. Sports commentators deal with hundreds of teams all the time, I don't see them mistaking the owner vs manager of a club, and they would be laughed at if they did, even (especially?) the lay / hobbyist ones. Also, at the very top of their website it says "a specialized intelligence website written by experts", and in the sidebar they list their qualifications - so they apparently want to claim they are no…

>Sports commentators deal with hundreds of teams all the time, I don't see them mistaking the owner vs manager of a club

Sports commentators make mistakes on a regular basis, things like calling a defender a forward or mistaking a players name. They often correct themselves immediately or things move past it so quick nobody cares.

> - so they apparently want to claim they are not layperson

I took your use of the word "layperson" there to mean "not a professional in a field specialized in state politics." The authors of the site are professionals, just that doesn't prevent that mistake. Worded by me, but my point was that they are still normal error prone humans.

Post reply on HN