Live data from Hacker News

‘Every message was copied to the police’

theguardian.com

121–130 of 193 posts

Re: ‘Every message was copied to the police’

#121
post #67

> the FBI, had conceived, built, marketed and sold the devices. > $1,700 for the handset, with a $1,250 annual subscription > Almost 10,000 users around the world had agreed to pay So the FBI built a 8 figure ARR hardware business...

Funny but that is exactly where my brain went too, it was like "Wow, that is some serious market validation."

Of course, but there would be similar market validation for being able to hold up a bank without ever being recognized or to be able to steal money from bank accounts anonymously.

That 'market' is called crime, and obviously criminals will be more than happy to fork over money for tools that help them to commit crimes without being arrested. In reality though, that market doesn't exist because if you or I would address that market we'd be hit hard by the authorities, and for good reason.

Re: ‘Every message was copied to the police’

#122
post #120

Every time I read about police investigation techniques that justify the use of mass-surveillance, deception, and entrapment, I grow closer to fully rejecting the legitimacy of criminal law and criminal justice. The less legitimacy I assign to criminal law and criminal justice, the more infuriating it is that the budgets of law enforcement agencies grow ever more inflated to do ridiculous schemes like this to enforce…

Have you ever hung out with a cokehead?

Re: ‘Every message was copied to the police’

#123

Earlier quoted context omitted.

And if I place a call for someone on good-faith belief that they need assistance?

I don't get where your point is leading or coming from.

Let's back up a bit here.

What specifically in this comment would you penalise?

https://news.ycombinator.com/item?id=28620403

And how would you address the issue of people being good sams --- making calls on behalf of someone else when they ask, in good faith.

See for example RMS:

When I need to call someone, I ask someone nearby to let me make a call. If I use someone else's cell phone, that doesn't give Big Brother any information about me.

https://stallman.org/rms-lifestyle.html

Re: ‘Every message was copied to the police’

#124

Earlier quoted context omitted.

I wonder how useful The Solitare Encryption Algorithm would be here - https://www.schneier.com/academic/solitaire/

Solitaire is very broken as an encryption scheme. You should not use it for communication that requires more than LARP security. If you need to encrypt a message manually, LC4 is a better algorithm, but still not acceptable for real world use. The good old one time pad may be most effective.

I don't remember reading it was broken per say, just that there are some issues, and weak keys. The only work I know of analyzing Solitare is [0]. And they propose some fixes to make it more resilient. OTP is by far the easiest and most reliable pencil and paper crypto algorithm though.

[0]: https://arxiv.org/abs/1909.06300

Re: ‘Every message was copied to the police’

#125
post #120

Every time I read about police investigation techniques that justify the use of mass-surveillance, deception, and entrapment, I grow closer to fully rejecting the legitimacy of criminal law and criminal justice. The less legitimacy I assign to criminal law and criminal justice, the more infuriating it is that the budgets of law enforcement agencies grow ever more inflated to do ridiculous schemes like this to enforce…

Have you ever hung out with a cokehead?

Sure. I've met multiple cocaine users

Re: ‘Every message was copied to the police’

#126
post #48

Earlier quoted context omitted.

I also wonder why there's such a pushback against one-time-pads. The common critiques don't seem to be any greater of a risk than the holes we've already encountered (e.g. heartbleed). I think I remember a scifi story that mentioned some character who worked in the one-time-pad shipping business. I guess a spacecraft full of data storage can hold enough random data to last for a long time. Seems like we should at lea…

Unless you’re using a true random number generator that works on a mechanical/electrical process a lot of encryption algorithms are various ways of creating a one-time pad. And they save a lot on space which used to be precious. With a single key much smaller than a megabyte I can encrypt essentially endlessly where for the normal OTP process I need as much random data as there is data to be encrypted which gets unwi…

> Unless you’re using a true random number generator that works on a mechanical/electrical process…

…you're not using a one-time pad. OTP requires the pad to be truly random: at least one bit of unique, never-used-elsewhere entropy for every bit in the message. Merely XORing some plaintext with a pseudo-random stream based on a smaller seed, which as you say is the basis for various other encryption algorithms, is not a one-time pad.

The real problem with OTP is key distribution: You need to share pads with everyone you might want to communicate with, one pad per sender/receiver pair, and those pads need to be at least as large as all the message you'll eventually want to exchange. There is no OTP equivalent to public-key cryptography where you only need one private/public keypair per recipient.

Re: ‘Every message was copied to the police’

#127

Earlier quoted context omitted.

Vendor-based scams are what this thread and this article is about. The root quoted that An0m was a 'trick' that couldn't be repeated again. My point is that legitimate businesses would have never had to worry about such tricks, being scammed by a vendor like this is a problem unique to illegal businesses.

OK, I see what you're saying. Though I think there are actually at least two discussions being had here, apparently talking past one another: One, that a vendor which promises some service but fails to deliver on it, as An0m did here, would be subject to civil claims for fraud or false representation. This seems to be your general argument. Another is that any given business has concerns over surveillance and privac…

That's fair. But I still don't think the situation translates; businesses have significantly more options for mitigation and less downside risk. They're likely not going to prison if they have a data leak, and they have access to good information and the world's most reputable vendors for solutions to those problems.

Outside of exceptionally high risk (or exceptionally low revenue) businesses , I don't think many are going to choose to go back to paper. Although, we may see more systems being air-gapped, virtualized, or using other forms of isolation. The types of enterprises that could afford the labor cost of using paper can also afford the price tag on digital solutions that do a good job of mitigating those risks. Most breaches, ransomware attacks, etc are things that could have been prevented. Rarely do incident response crews say "this company couldn't have done anything to prevent this"

Additionally, legitimate businesses have customers that will demand that they use digital solutions. Criminals dealing with other criminals might be willing to use paper to mitigate risks. Customers of established B2B or B2C companies will not.

Re: ‘Every message was copied to the police’

#128

Earlier quoted context omitted.

Funny but that is exactly where my brain went too, it was like "Wow, that is some serious market validation."

Of course, but there would be similar market validation for being able to hold up a bank without ever being recognized or to be able to steal money from bank accounts anonymously. That 'market' is called crime, and obviously criminals will be more than happy to fork over money for tools that help them to commit crimes without being arrested. In reality though, that market doesn't exist because if you or I would addre…

As far as I can tell, An0m has the same marketing pitch as Purism.

Re: ‘Every message was copied to the police’

#129

One of the earlier items posted on this investigation highlights what's an increasing concern of mine as regards the investigation: That the methods used are illegal in the US by virtue of the 4th Amendment protections on search and privacy: FBI agents were not allowed to download or read any messages sent from AN0M accounts in the United States because of privacy laws. President of the NSW Council of Civil Liberties…

[deleted]

Re: ‘Every message was copied to the police’

#130

Earlier quoted context omitted.

I don't get where your point is leading or coming from.

Let's back up a bit here. What specifically in this comment would you penalise? https://news.ycombinator.com/item?id=28620403 And how would you address the issue of people being good sams --- making calls on behalf of someone else when they ask, in good faith. See for example RMS: When I need to call someone, I ask someone nearby to let me make a call. If I use someone else's cell phone, that doesn't give Big Brother…

> What specifically in this comment would you penalise?

One comment up from that I said:

> The easier way to attack this is by instituting a know your customer law for phone systems including prepaid SIMs, combined with accomplice charges for anyone who's SIM is used in connection with criminal acts.

~~~~~~~~~~~~~~~~

> And how would you address the issue of people being good sams --- making calls on behalf of someone else when they ask, in good faith.

Prosecutorial discretion.

And to be clear I'm not pushing for these laws; I think they're awful. I just see it as a clear direction that .gov is going to go if they feel the need to that's easier than maintaining zero days for general law enforcement. The ability to actually tie phones to personal identity in a way good enough for a court room.

Post reply on HN