Live data from Hacker News

‘Every message was copied to the police’

theguardian.com

101–110 of 193 posts

Re: ‘Every message was copied to the police’

#101

Earlier quoted context omitted.

That's a function of there not being penalties. You'd see that change if the laws changed.

Penalties for what exactly, here? Good Samaritanism?

The whole thread here is about penalties for assisting criminal enterprises with a SIM tied to your identity.

Re: ‘Every message was copied to the police’

#102
> Either because of a lack of technical knowhow, or fear for his safety, Ramos refused, and pleaded guilty to running a criminal enterprise, a charge for which he was sentenced to nine years in prison

Wait a second, why would he have to go to prison? If all he did was selling phones, what charges could there possibly be?

I'm also missing a third option that he refused to cooperate "for idiological reasons".

Re: ‘Every message was copied to the police’

#103

Never outsource security if you actually want security...

Never roll your own security if you actually want security, either. What are we supposed to do :).

Do not rely on technical means to solve an administrative problems. Vito Corleone didn't have messenger apps, email or ERP systems, but his enterprise ran like like a clock. So should yours.

Re: ‘Every message was copied to the police’

#104

Earlier quoted context omitted.

Vendor-based scams are not the entirety of the threat model.

Vendor-based scams are what this thread and this article is about. The root quoted that An0m was a 'trick' that couldn't be repeated again. My point is that legitimate businesses would have never had to worry about such tricks, being scammed by a vendor like this is a problem unique to illegal businesses.

OK, I see what you're saying.

Though I think there are actually at least two discussions being had here, apparently talking past one another:

One, that a vendor which promises some service but fails to deliver on it, as An0m did here, would be subject to civil claims for fraud or false representation. This seems to be your general argument.

Another is that any given business has concerns over surveillance and privac breaches, whether from law enforcement or other entities, and that any use of digial communictations and data systems exposes them to this risk. Paper-based systems have, of course, far lower capabiliies to data processing, but also to data exfiltration*.

Both are risks.

You're focused on one. Others take a broader view, myself included.

Re: ‘Every message was copied to the police’

#105
post #38

Earlier quoted context omitted.

Why not both? Encrypt your message with your home grown encryption, then send it through standard TLS. Both would have to fail for the message to be revealed. Sometimes when I'm wearing my tinfoil hat I wonder if the advice to avoid rolling your own crypto is a conspiracy. The powers that be want to maintain their backdoors, maybe? Probably not. Of course, it's definitely true that there are more attack vectors out t…

I think that this isn't strictly true. If you naïvely apply bad encryption before good you may weaken the entire system. For a silly example, imagine your "homegrown" crypto adds a publicly known plaintext to the start of the cyphertext. I think this is discussed in Schneier's textbook.

You're technically right, but it's practically true for good algorithms. Yes, if you apply a rot(-13) before your rot(13) "encryption" it's going to make it worse.

I think that if we are going to be concerned about multiple layers of encryption, as you say, then we should be equally concerned with things such as what encoding we use to send text with, or whether we use gzip or bzip. It would suck having to worry about all that; good encryption algorithms work regardless of how their plaintext is encoded, and home grown encryption is just another form of encoding.

Re: ‘Every message was copied to the police’

#106
It is a fascinating case, but apart from the technical aspect of it.. how is that not entrapment? FBI effectively created a tool explicitly designed for criminal element and 'marketed' as such.

I would ask about legality, but I am worried its in a very, very grey area.

Re: ‘Every message was copied to the police’

#107
post #86

Earlier quoted context omitted.

Sounds like it was mostly word of mouth

Those mouths probably didn't work for free

Free to the makers of the device though, it's not like they were charging the manufacturers for paid promotions like an Instagram influencer would - they recommended this device to their associates because they thought this would help them coordinate their activities more efficiently whilst reducing their personal risk.

Re: ‘Every message was copied to the police’

#108
post #42
post #34

Earlier quoted context omitted.

You would think that, but the whole an0m thing showed that it wasn't really the case.

That’s one case. It doesn’t apply to all criminal organizations. The cartels in Mexico are sophisticated enough to build their own cell networks [1] to evade wiretapping. Why couldn’t they also recruit engineers to build their own crypto and secure protocols? [1] https://www.npr.org/2011/12/09/143442365/mexico-busts-drug-c...

that's not a cellphone network that's a VHF/UHF radio repeater network. basically same idea as ham radio hilltop repeater stuff in the US, but built for private purposes, and using COTS radios capable of basic encryption.

Re: ‘Every message was copied to the police’

#109

Earlier quoted context omitted.

Penalties for what exactly, here? Good Samaritanism?

The whole thread here is about penalties for assisting criminal enterprises with a SIM tied to your identity.

And if I place a call for someone on good-faith belief that they need assistance?

Re: ‘Every message was copied to the police’

#110
post #75

There is nobody in the world easier to fool than a technically illiterate person with vague and malformed ideas about privacy and security. Once you've got them all worked up over illusory threats you can sell them any snake oil you want.

Your comment I think is on point. The article here makes it sound more... sophisticated than it is.

https://www.xda-developers.com/fbi-backdoor-pixel-arcaneos-a...

  Unlocking the phone with a normal PIN code shows some normal apps like Tinder, 
  Netflix, and Facebook, but none of the apps actually open when you tap their 
  icon. However, unlocking the Pixel phone with a different PIN code reveals icons 
  for a clock app, a calculator app, and the device’s settings. Tapping the 
  calculator icon doesn’t actually open a calculator app, however. Instead, it 
  opens a login screen for the ANOM service
What percentage of HN's population would find this convincing? What's interesting here is that any one of us could have pointed out the absurdity of this, but black markets don't have a way to propagate such information it seems.
Post reply on HN