Live data from Hacker News

New German law would force ISPs to allow secret service to install trojans

privateinternetaccess.com

101–110 of 245 posts

Re: New German law would force ISPs to allow secret service to install trojans

#101
post #84

Earlier quoted context omitted.

I guess funding was not a big issue for the CIA...

They are still flush with cash from decades of running cocaine.

Yeah I doubt the CIA has objected because they got all their needs met from congressional funding. They just already had built plenty of dark money reserves.

Re: New German law would force ISPs to allow secret service to install trojans

#102

Pretty shocking in a state that has such strict privacy laws. Not sure how the two can come from the same mouth, and even be in public view. My understanding is that the privacy restrictions are largely the result of half the country having lived under the Statsi, and thus being extremely weary of government eyes. Here it’s out in the open!

> Pretty shocking in a state that has such strict privacy laws

If viewed from the different perspective of government intrusion on tech, it can appear less shocking. A government encouraged by its citizenry to use its leverage over tech companies will continue to do so, and not always in the same ways.

Re: New German law would force ISPs to allow secret service to install trojans

#103

Earlier quoted context omitted.

I think you can collect a lot of good data for law enforcement purposes by tapping datacenter networks. Remember the NSA's "SSL added and removed here :-)" slide? Raise your hand if you use TLS between your database server and your web frontend. Keep your hand up if you rotated that certificate in the last month. Keep your hand up if you know whether your database's certificate has been tampered with. (i.e. do you ch…

Yeah, but Germany's intelligence services aren't the NSA, neither regarding technical ability, nor regarding the lack of mission constraints. I'm sure they'd love to get their hands on DE-CIX as a whole, but they won't unless somebody with a US passport sits in on the meeting - and if they have that person, they don't need German laws. I believe that these changes target ISPs and providers like mailbox.org, posteo et…

Its german BND sitting at DE-CIX, but they fully cooperate with NSA to the point where they had to answer some ugly questions about why the fuck they helped a foreign intelligence service to literally spy on the german governement. Answer was: they don't verify what NSA queries, they automatically run the selector list and send them the data.

Re: New German law would force ISPs to allow secret service to install trojans

#105

Earlier quoted context omitted.

Presumably, Germany would have little trouble compelling at least one root CA to sign any TLS certificates they wanted. Just a cursory search shows that Google Chrome, on Linux, trusts, e.g. > CN = D-TRUST Root CA 3 2013 > O = D-Trust GmbH > C = DE There is certificate transparency and pinning and so on, and they would be caught (probably, maybe) if they abused this carelessly and at scale, but in practice, for a sma…

Google, Mozilla, et al. should make a commitment to revoke the trust of any CA that is found to partake in behavior like that. Even retroactive revocation of existing certificates shouldn't be off the table if the offense is egregious enough. It's actually pretty scary seeing just how many CAs are in the list of trusted CAs on any given device. While no government is beyond reproach, I do wish there were a way for me…

Browsers blacklisted Kazakhstan government certificate used for MITM which was not even trusted. It is absurd to expect anything less than blacklisting such a CA immediately. Certificate transparency is required for all certificates since April, 2018, so you can't really issue rogue certificate.

Re: New German law would force ISPs to allow secret service to install trojans

#106

Earlier quoted context omitted.

Presumably, Germany would have little trouble compelling at least one root CA to sign any TLS certificates they wanted. Just a cursory search shows that Google Chrome, on Linux, trusts, e.g. > CN = D-TRUST Root CA 3 2013 > O = D-Trust GmbH > C = DE There is certificate transparency and pinning and so on, and they would be caught (probably, maybe) if they abused this carelessly and at scale, but in practice, for a sma…

Well. That is the reason for Certificate Pinning. And these days there is no excuse to not enable it server-side. Helped me detect some MITM-Interceptions. Not that the content was malicious (OpenDNS just rerouted my requests to a "This site is blocked page", but the certificate was signed by Cisco, and thus valid. Certificate Pinning still picked it up. Little hint: It was an Archlinux-site.).

Here [1] it says that Chrome stopped supporting HTTP Public Key Pinning (HPKP) with Chrome 72. There are other debates on it. See the discussions for excuses.

Or is cert pinning something different than HPKP?

- [1]: https://security.stackexchange.com/questions/213410/did-goog...

Re: New German law would force ISPs to allow secret service to install trojans

#107
post #64
post #12

FYI: pervasive mass internet surveillance by the US military with the active cooperation of large US telcos AT&T, Verizon, and others already enables this capability in the US and much of the rest of the world. The surveillance allows them to read the TCP sequence numbers or DNS query IDs, and then spoof valid response packets. It’s called QUANTUMINSERT. https://blog.fox-it.com/2015/04/20/deep-dive-into-quantum-in...

Is this relevant since nearly everything is https these days?

DNS usually isn’t, and TLS still runs over TCP, which is vulnerable to this type of hijacking, so yes, it is indeed still relevant due to both resolution as well as transport layer.

NSA would be very bad at their job indeed if they couldn’t issue valid TLS certificates for any domain to themselves.

Re: New German law would force ISPs to allow secret service to install trojans

#108
post #48

What does "trojans at ISPs" even mean? TLS works end-to-end and ISPs can do absolutely nothing to see the plaintext. It's unless the CAs at users-side are manually replaced with fake ones nothing can be done. I've never used Windows since I was a kid but I am sure this is pretty much impossible on Linux for example since adding CAs require root privilege.

Presumably, Germany would have little trouble compelling at least one root CA to sign any TLS certificates they wanted. Just a cursory search shows that Google Chrome, on Linux, trusts, e.g. > CN = D-TRUST Root CA 3 2013 > O = D-Trust GmbH > C = DE There is certificate transparency and pinning and so on, and they would be caught (probably, maybe) if they abused this carelessly and at scale, but in practice, for a sma…

[deleted]

Re: New German law would force ISPs to allow secret service to install trojans

#110

Earlier quoted context omitted.

>Pretty shocking in a state that has such strict privacy laws. Not sure how the two can come from the same mouth, and even be in public view. Because they're not necessarily contradictory. This doesn't just give secret services a blank cheque to spy on everyone, it just provides intelligence agencies with a tool. I'm German and I don't object in principle to the fact that intelligence, under supervision of the govern…

The scary stuff about the current development is, that we get flooded with arguments about hardcore criminals, but if you look at the actual changes to the laws, such restrictions are not made, instead these extreme measures are allowed for petty reasons and some politicians will still keep pushing for even more totalitarianism. These siloviki want mass surveillance comparable to what Chinas Ministry of State Securit…

> It does not matter if Germany is not ruled by an autocratic regime at the moment

I totally get the appeal of that argument, but it completely breaks down once I ask myself how much that autocratic bogeyman regime, once it got into power, would feel bound by privacy protections put in place by their predecessors.

Post reply on HN