Live data from Hacker News

New German law would force ISPs to allow secret service to install trojans

privateinternetaccess.com

161–170 of 245 posts

Re: New German law would force ISPs to allow secret service to install trojans

#161
post #13
post #11

"Sollen" translates to "should" and not "will" That means there is a element of uncertainty there whether they actually will.

Actually it translated to "have to", not "should" (which would more properly be "sollten").

Full text from the netzpolitik article:

> Provider sollen Internetverkehr umleiten, damit Geheimdienste hacken können

> Geheimdienste wollen Hardware bei Internet-Providern installieren, um Staatstrojaner in Datenverkehr einzuschleusen. Das steht in einem Gesetzentwurf zum Verfassungsschutzrecht, den die Bundesregierung nächste Woche beschließen will. Die Provider wollen keine Hilfssheriffs sein.

> [...]

> Konkret müssen Anbieter die Installation des Staatstrojaners „durch Unterstützung bei der Umleitung von Telekommunikation … ermöglichen“.

So it translates to "would have to, if the law goes into effect unchanged".

Re: New German law would force ISPs to allow secret service to install trojans

#162

Is it possible to modify HTTPS traffic? Wouldn't they have to replace the CA certs on the target machine first before being able to modify that traffic?

I think your worry is a bit out of scope. There is a thing called "Verhaeltnismaessigkeit" in Germany, and in most other countries where "The Rule Of Law" applies, to paraphrase Trudeau. Meaning: You are not allowed to burn down the house just because the neighbor was playing the music too loudly. So others are not to caught in the cross-fire of this operation. So it will be a very technical challenge to overcome the…

There is no certificate pinning anymore, it's deprecated. Your whole argument is based on the state actually playing nicely and assume a meaningful oversight of intelligence, both are hopelessly naive.

Re: New German law would force ISPs to allow secret service to install trojans

#163

Earlier quoted context omitted.

Why they are so scared of citizenry though? Anyone that is criminal or really needs security will just use Faraday Cages with disconnected computers. Literally there is nothing they can do against big league criminals with this much mass surveillance, so only logical conclusion is that this is only intended for use on citizenry.

I've tried to explain my thoughts on this before, so I'll give it the ol college try again. I propose that the decentralized anarchistic, freedom of thought nature of the internet has essentially forced an acceleration the timetables for the totalitarian dystopian system. The internet caught the oligarchs off guard, in the big scheme of things (the oligarchs make plans that their grandchildren execute)... and it took…

It weirds me out that you're probably the first person I've seen in years on the internet saying something this "bold" and unambiguous.

I often wonder if there's some system in place which separates us. Or perhaps the combo of logic, intuition, and honesty is just super rare. I don't know, but I hope you're doing well and having a reasonably fulfilling adventure amongst this hellishly senseless superstition culture.

Friendly reminder to go out and see the stars from time to time.

Re: New German law would force ISPs to allow secret service to install trojans

#164
post #114

What was that German government malware that was found on regular computers like ten years ago? Could have sworn there was something like that.

Were you thinking of this?

https://www.ccc.de/en/updates/2011/staatstrojaner

https://www.ccc.de/en/updates/2015/bkag

Re: New German law would force ISPs to allow secret service to install trojans

#166
post #90
post #82

Earlier quoted context omitted.

Tor might not protect anonymity effectively in that case, but in the case given it would still offer protection because of the way the relay circuits are designed.

Unless it's an exit node. 251 of 1,249 exit nodes reside in Germany, or roughly 20%. Exit nodes aren't supposed to modify traffic, so if the compromise is happening upon leaving the exit node en route to whatever destination, that would still trickle back through all the hops.

True. I was thinking about recent initiatives like https://blog.torproject.org/more-onions-porfavor where security is enhanced by having people put their sites on tor. This is more the i2p model though.

Re: New German law would force ISPs to allow secret service to install trojans

#167
post #48

What does "trojans at ISPs" even mean? TLS works end-to-end and ISPs can do absolutely nothing to see the plaintext. It's unless the CAs at users-side are manually replaced with fake ones nothing can be done. I've never used Windows since I was a kid but I am sure this is pretty much impossible on Linux for example since adding CAs require root privilege.

The law only requires an ISP to redirect traffic to a target specified by the Verfassungschutz (Constitutional Protection Office) or BND (Federal Information Office), for the purposes of listening in or modifying traffic. It doesn't seem to require installing or providing TLS cracking.

Re: New German law would force ISPs to allow secret service to install trojans

#168

Earlier quoted context omitted.

Yeah, but Germany's intelligence services aren't the NSA, neither regarding technical ability, nor regarding the lack of mission constraints. I'm sure they'd love to get their hands on DE-CIX as a whole, but they won't unless somebody with a US passport sits in on the meeting - and if they have that person, they don't need German laws. I believe that these changes target ISPs and providers like mailbox.org, posteo et…

Its german BND sitting at DE-CIX, but they fully cooperate with NSA to the point where they had to answer some ugly questions about why the fuck they helped a foreign intelligence service to literally spy on the german governement. Answer was: they don't verify what NSA queries, they automatically run the selector list and send them the data.

Yes, but as you see, that's already legal (especially if with US-involvement). This is different from that, as it contains the requirement for the provider to manipulate traffic.

Re: New German law would force ISPs to allow secret service to install trojans

#169
post #2

The German surveillance state is very capable and often understated. They even “ran” Crypto AG with the NSA for decades and even profited from it. https://en.wikipedia.org/wiki/Crypto_AG

The German surveillance state was created and ran by ex-Nazi secret services (Aufklärung Ost), introduced by the CIA (BND = Organisation Gehlen). You have look up the various fascist scandals they have been involved in.

Re: New German law would force ISPs to allow secret service to install trojans

#170

To not even be sure whether a website you visit, or a file you download is actually what its creator says it is, is like picking up an orange but the government secretly replaces it with an apple that contains almost no vitamin C in it at all. You have the right to seek out and eat an orange for your immune system and survival, and no government should have the right to interfere with that, at any time. This law is a…

> Whoever proposed it should be ashamed of themselves Name and shame: Interior Minister Horst Seehofer of the conservative-authoritarian CSU. He and his party friends are who want this. We have the chance to kick them out of office in 2021, it's time for the stranglehold of Conservative internet-printers (Internetausdrucker, a German word for tech illiterates) as Interior Ministers to end once and for all .

How's the CSU authoritarian? That's like throwing expletives around; you might as well call them Nazis and get it over with.
Post reply on HN