Live data from Hacker News

‘Every message was copied to the police’

theguardian.com

71–80 of 193 posts

Re: ‘Every message was copied to the police’

#71
post #6

> There, since 2018, the Telecommunications and Other Legislation Amendment (Tola) has allowed government agencies to compel telecommunications providers to allow authorities to intercept criminal messages – powers that are not yet available to police elsewhere in the world. That "yet" is terrifying. If you thought the PATRIOT Act was an overstep, you need to read TOLA. This is the revival of the crypto wars. Good wr…

I don’t understand how it is legal to eavesdrop without a warrant, even if you are target bad-faith actors and have probable cause - that’s how you get warrants in the first place.

Furthermore, everyone on this thread is talking about more secure communication. But my mind always goes to assuming every communication channel is compromised by default, and then flooding it with many, many false messages and wasting adversary resources chasing them.

Re: ‘Every message was copied to the police’

#72

Never outsource security if you actually want security...

I think that's the wrong lesson here. An0m created two vulnerabilities to its users: - It was specifically marketed to criminal entities. That is, it sharply reduced the search space. In a 33 bit world, An0m is 14 bits. - It was specifically back-doored. "Roll your own" avoids the 2nd case but not the first. By definition, rolling your own already reduces search space to the domain of interest. (Other means of eviden…

Agreed, although I think this is the hard bit:

> - Audit the hell out of these and offer bounties for any vulnerabilities which can be demonstrated.

The NSA backdoors will be pretty hard to find if they are there - It's not like you are going to see something like "If User == "NSA" Then Divulge_Key()". The backdoor is going to be something like a very subtle bug with how a particular crypto library is implemented, or some obscure buffer oveflow attack, and it probably won't even be discernible from an accidental bug.

In reality I doubt there is any way to know if the NSA can eavesdrop, it's a complete coin toss.

Re: ‘Every message was copied to the police’

#73

Earlier quoted context omitted.

Legitimate businesses can much more easily avoid being scammed by vendors because their legitimate businesses are protected by the legal system. They also can openly discuss their experiences with vendors, because they're not hiding from anyone.

How's that working out for victims of ransomware attacks or nation-state corporate espionage?

I've never heard of a business being scammed by a vendor through ransomware. When businesses choose vendors, they do it with legal contracts enforceable in their jurisdictions.

Re: ‘Every message was copied to the police’

#76
post #72

Earlier quoted context omitted.

I think that's the wrong lesson here. An0m created two vulnerabilities to its users: - It was specifically marketed to criminal entities. That is, it sharply reduced the search space. In a 33 bit world, An0m is 14 bits. - It was specifically back-doored. "Roll your own" avoids the 2nd case but not the first. By definition, rolling your own already reduces search space to the domain of interest. (Other means of eviden…

Agreed, although I think this is the hard bit: > - Audit the hell out of these and offer bounties for any vulnerabilities which can be demonstrated. The NSA backdoors will be pretty hard to find if they are there - It's not like you are going to see something like "If User == "NSA" Then Divulge_Key()". The backdoor is going to be something like a very subtle bug with how a particular crypto library is implemented, or…

AFAIU most of the NSA's capabilities come through workfactor-reduction values --- seed values to cryptographic functions which reduce the time to crack a given message (if the secret seeds are known).

Avoiding NIST-recommended ciphers seems to be generally-advisable in this case.

There are other backdoors (see the case of Juniper Networks), but there's probably an enumerable set of pracices.

One helpful option is to use Free Software tools in which single actors are ulikely to be able to subvert the tool, and many have an interest in its integrity.

Re: ‘Every message was copied to the police’

#77
post #67

> the FBI, had conceived, built, marketed and sold the devices. > $1,700 for the handset, with a $1,250 annual subscription > Almost 10,000 users around the world had agreed to pay So the FBI built a 8 figure ARR hardware business...

But they probably had a lot of money to start it right?

Re: ‘Every message was copied to the police’

#78
post #67

> the FBI, had conceived, built, marketed and sold the devices. > $1,700 for the handset, with a $1,250 annual subscription > Almost 10,000 users around the world had agreed to pay So the FBI built a 8 figure ARR hardware business...

It doesn't indicate how high the marketing costs were. Probably too high to sustain a business.

Re: ‘Every message was copied to the police’

#79

Earlier quoted context omitted.

How's that working out for victims of ransomware attacks or nation-state corporate espionage?

I've never heard of a business being scammed by a vendor through ransomware. When businesses choose vendors, they do it with legal contracts enforceable in their jurisdictions.

Vendor-based scams are not the entirety of the threat model.

Re: ‘Every message was copied to the police’

#80
post #78
post #67

> the FBI, had conceived, built, marketed and sold the devices. > $1,700 for the handset, with a $1,250 annual subscription > Almost 10,000 users around the world had agreed to pay So the FBI built a 8 figure ARR hardware business...

It doesn't indicate how high the marketing costs were. Probably too high to sustain a business.

Sounds like it was mostly word of mouth
Post reply on HN