Live data from Hacker News

New German law would force ISPs to allow secret service to install trojans

privateinternetaccess.com

111–120 of 245 posts

Re: New German law would force ISPs to allow secret service to install trojans

#111
post #48

What does "trojans at ISPs" even mean? TLS works end-to-end and ISPs can do absolutely nothing to see the plaintext. It's unless the CAs at users-side are manually replaced with fake ones nothing can be done. I've never used Windows since I was a kid but I am sure this is pretty much impossible on Linux for example since adding CAs require root privilege.

FinFisher has "drive by infection" packages for sale called FinFly that require traffic injection, according to their brochure. How exactly those work today, i do not know. For example: until 2011 they used a bug in the self update code of iTunes. Having a network level man in the middle can benefit many complex exploit chains.

I hope someone sees this and can enlighten us on how the technique currently works with TLS being more prevalent.

Re: New German law would force ISPs to allow secret service to install trojans

#112
post #100

Earlier quoted context omitted.

The scary stuff about the current development is, that we get flooded with arguments about hardcore criminals, but if you look at the actual changes to the laws, such restrictions are not made, instead these extreme measures are allowed for petty reasons and some politicians will still keep pushing for even more totalitarianism. These siloviki want mass surveillance comparable to what Chinas Ministry of State Securit…

The surveillance, including the mass surveillance of the communication, existed even in older times. It is, for example, documented that both British and US secret services went through all the telegrams that passed their commercial infrastructure, often based on a simple "gentleman's agreement" with the companies, even in the 19th century, and certainly in the 20th. Other countries were somehow aware of that weaknes…

Just shows how rotten to the core the services are.

Re: New German law would force ISPs to allow secret service to install trojans

#113

Earlier quoted context omitted.

Possibly, but it's much harder to intercept and mitm specific traffic at that level. On the ISP-side, that's different: they can with high certainty say that some traffic is coming from/to a specific suspect, much like a phone surveillance. This might also apply to individual service, e.g. an email provider.

I think you can collect a lot of good data for law enforcement purposes by tapping datacenter networks. Remember the NSA's "SSL added and removed here :-)" slide? Raise your hand if you use TLS between your database server and your web frontend. Keep your hand up if you rotated that certificate in the last month. Keep your hand up if you know whether your database's certificate has been tampered with. (i.e. do you ch…

> Raise your hand if you use TLS between your database server and your web frontend. Keep your hand up if you rotated that certificate in the last month. Keep your hand up if you know whether your database's certificate has been tampered with. (i.e. do you check that it's signed by your internal CA? Then who is signing it? Who maintains the ca-certs package? What does the certificate verification code even look like?)

I’m standing here with my hand up :)

Re: New German law would force ISPs to allow secret service to install trojans

#116
post #48

What does "trojans at ISPs" even mean? TLS works end-to-end and ISPs can do absolutely nothing to see the plaintext. It's unless the CAs at users-side are manually replaced with fake ones nothing can be done. I've never used Windows since I was a kid but I am sure this is pretty much impossible on Linux for example since adding CAs require root privilege.

Conceivably: If you have MITM and can inject... you'd next need web browser 0day exploit chain w/ sandbox escape and then a stealthy trojan to install. This would obviously be quite the capability and require a lot of maintenance to work cross-browser, cross-OS, and evade security products / built-in security features. It is definitely possible however.

Re: New German law would force ISPs to allow secret service to install trojans

#117
post #109

Germany, the US, and Mexico all in the same week? The oligarchs are getting worried, it would seem.

Huh? What do you mean?

Well, as far as I know, all of these countries have political systems in which representatives are supposed to act on the behalf of the people. Basically, we can't all work full time to understand every political thing, and vote on them all, so we have someone do it for us: a representative.

Representatives very rarely represent themselves, and are almost always representing either powerful people ( often through lobbying) or citizens.

Given that an absolute minority of citizens are asking for this, it's fair to say it's a top down decision. Most citizens are concerned with things that aren't changing at all, if you'd like further proof on who the representatives work for.

By virtue of it being a top down decision, it is almost certainly being pushed by a small group of very powerful people. When a small group of people have all the power, that's called an oligarchy.

So the question is, why is the oligarchy pushing so hard for control of the internet right now? Well, it's probably not for fun.. so they are worried, I suppose.

Re: New German law would force ISPs to allow secret service to install trojans

#118
post #16
post #9

Earlier quoted context omitted.

I would be surprised. IIRC those "other countries" are countries like Iran that have also just shut off access to the internet for the country. I still think we have a few more years of internet freedom in Germany before that happens.

Internet freedom in Germany? https://stadt-nachrichten.de/fahndungen/hasskommentare-im-in... https://www.bild.de/news/inland/news-inland/hass-kommentare-... https://www.bundesregierung.de/breg-de/aktuelles/gesetz-gege... Boy China is childs play compared to us.

What does this have to do with "internet freedom" (whatever that means)? Statements that would get you prosecuted when shouted in the streets have that same effect when posted online. Surprised Pikachu face?

Re: New German law would force ISPs to allow secret service to install trojans

#119
post #109

Earlier quoted context omitted.

Huh? What do you mean?

Well, as far as I know, all of these countries have political systems in which representatives are supposed to act on the behalf of the people. Basically, we can't all work full time to understand every political thing, and vote on them all, so we have someone do it for us: a representative. Representatives very rarely represent themselves, and are almost always representing either powerful people ( often through lob…

Why they are so scared of citizenry though? Anyone that is criminal or really needs security will just use Faraday Cages with disconnected computers.

Literally there is nothing they can do against big league criminals with this much mass surveillance, so only logical conclusion is that this is only intended for use on citizenry.

Re: New German law would force ISPs to allow secret service to install trojans

#120
post #48

What does "trojans at ISPs" even mean? TLS works end-to-end and ISPs can do absolutely nothing to see the plaintext. It's unless the CAs at users-side are manually replaced with fake ones nothing can be done. I've never used Windows since I was a kid but I am sure this is pretty much impossible on Linux for example since adding CAs require root privilege.

The "Trojan" is simply the rhetorical framework chosen by German authorities. Their initial successful push for computer surveillance was in the form of the "state trojan", a piece of malware proposed to be installed on the systems of suspected criminals. Successive pushes have aimed at expanding out from there, using the existing capabilities as justification.
Post reply on HN