Live data from Hacker News

New German law would force ISPs to allow secret service to install trojans

privateinternetaccess.com

51–60 of 245 posts

Re: New German law would force ISPs to allow secret service to install trojans

#51
post #47

Earlier quoted context omitted.

Possibly, but it's much harder to intercept and mitm specific traffic at that level. On the ISP-side, that's different: they can with high certainty say that some traffic is coming from/to a specific suspect, much like a phone surveillance. This might also apply to individual service, e.g. an email provider.

If it's in a data center security services have physical access.

But they'd need to filter out traffic for a specific suspect. It's unlikely that their approach will be to try to install trojans on every client computer that has traffic that goes through some DC. And if they want to take over a server they know the location of: they already can.

From my experience in a case where a previous version of that tech has been involved (though normal LE, not intelligence), they do take all the available measures to only hit the target, it's not a shot gun approach.

Re: New German law would force ISPs to allow secret service to install trojans

#52

Pretty shocking in a state that has such strict privacy laws. Not sure how the two can come from the same mouth, and even be in public view. My understanding is that the privacy restrictions are largely the result of half the country having lived under the Statsi, and thus being extremely weary of government eyes. Here it’s out in the open!

There is something hilarious and schizoid in how Germany is perceived and the realities about this country.

They have strict privacy laws? First Nazi personel in the first half then Stasi personel in the second half of the 20th century were simply requalified and rehired, each bloody time. How do you think?

They are top environmentally-friendly country? Highest polluting coal power plants in EU are located in Germany.

Re: New German law would force ISPs to allow secret service to install trojans

#53
post #44
post #33

Earlier quoted context omitted.

I'm learning German at a fairly low level so I ask this from the perspective of wanting to learn, not as a challenge. Wouldn't "have to" be "müssen"? In what cases would you use "sollen" to have a similar meaning? And "sollten" is either Präteritum or Konjunctive II, which as I understand it would both mean "should have", though in different senses. Why is that a more proper translation of "should"?

Most of the times, "sollen" and "müssen" are interchangeable. However, there are fine nuances between the words. In that case, "müssen" is more direct and used as a command which has consequences when not followed while "sollen" is more of a prompt or demand that hasn't to be followed.

I think a better translation for 'sollen' would be 'shall'.

Re: New German law would force ISPs to allow secret service to install trojans

#55

Is the Trojan based on magic? How will redirecting target computer infect it. What about out tipping off the suspect when it fails to implant? This idea is fantasy.

Well either those advising the legislature, who actually carry out the hacks for the security services in Germany, are idiots; or they're very clever people and know exactly what they're doing.

Or I guess it could be security theatre, or a diversion, but neither of those seems compelling here.

My vote is that, whilst I can't understand how it's accomplished as it seems contrary to technical possibility, that the people with billions of funding to make these things possible (Five Eyes, etc.) are probably capable of many things that look like magic.

?

Re: New German law would force ISPs to allow secret service to install trojans

#57
post #48

What does "trojans at ISPs" even mean? TLS works end-to-end and ISPs can do absolutely nothing to see the plaintext. It's unless the CAs at users-side are manually replaced with fake ones nothing can be done. I've never used Windows since I was a kid but I am sure this is pretty much impossible on Linux for example since adding CAs require root privilege.

Presumably, Germany would have little trouble compelling at least one root CA to sign any TLS certificates they wanted. Just a cursory search shows that Google Chrome, on Linux, trusts, e.g.

> CN = D-TRUST Root CA 3 2013 > O = D-Trust GmbH > C = DE

There is certificate transparency and pinning and so on, and they would be caught (probably, maybe) if they abused this carelessly and at scale, but in practice, for a small number of targets, it would be trivial to wait for users to connect to a less secured TLS site or even a plain-HTTP site (plenty still exist), and then use a browser exploit as the stage 1, followed by whatever escalation of privilege exploit and rootkit is needed. TLS is really good at preventing always-on dragnet surveillance of everyone's internet traffic, but not a counter measure against targeted nation state level attacks.

Re: New German law would force ISPs to allow secret service to install trojans

#58

Pretty shocking in a state that has such strict privacy laws. Not sure how the two can come from the same mouth, and even be in public view. My understanding is that the privacy restrictions are largely the result of half the country having lived under the Statsi, and thus being extremely weary of government eyes. Here it’s out in the open!

>Pretty shocking in a state that has such strict privacy laws. Not sure how the two can come from the same mouth, and even be in public view.

Because they're not necessarily contradictory. This doesn't just give secret services a blank cheque to spy on everyone, it just provides intelligence agencies with a tool.

I'm German and I don't object in principle to the fact that intelligence, under supervision of the government, has the ability to say, infiltrate criminal networks using software like this. Under certain circumstances the police was always able to wiretap a phone, I don't see the difference here other than this taking into account the changing circumstances of internet communication.

Also from a cultural standpoint if anything people in Germany are more sceptic of erosion of privacy by private power than by the state, we're not the US. The former is pretty much unconstrained, the latter is so tightly limited in scope by law it's not really a practical issue. The scary thing about the Stasi wasn't that they were inteliigence, every country has intelligence officers who can bug someone's home, it was that the GDR was an autocratic regime.

Re: New German law would force ISPs to allow secret service to install trojans

#59
post #31

Is it possible to modify HTTPS traffic? Wouldn't they have to replace the CA certs on the target machine first before being able to modify that traffic?

They just have to hijack one existing CA that's within their jurisdiction and force it to issue MITM certs. Key pinning or certificate transparency may mitigate this. Or the MITM box could use some kind of HTTP downgrade attack and not worry about certificates at all.

I would hope that any CA they try to force this on sues them, as that leaking would surely destroy their business.

Re: New German law would force ISPs to allow secret service to install trojans

#60
post #45
post #22

In english with more info: https://www.privateinternetaccess.com/blog/new-german-law-wo...

Ok, changed to that from https://netzpolitik.org/2020/staatstrojaner-provider-sollen-... . See also https://news.ycombinator.com/item?id=23783406 . Thanks!

Thank _you_ for the great moderation!
Post reply on HN