Live data from Hacker News

‘Every message was copied to the police’

theguardian.com

181–190 of 193 posts

Re: ‘Every message was copied to the police’

#181

Earlier quoted context omitted.

From the article: Soldiers seized 167 antennas, more than 150 repeaters and thousands of cellphones and radios that operated on the system. It sounds like it had both radio and cell bands if phones were able to use it.

There exist very fancy radios that look somewhat like GSM-alike cell phones, if I'm not mistaken.

there are also cheap vhf/uhf handheld radios from china which integrate a basic 2G GSM radio, SIM card slot, and can talk to common euro/asian 3GPP radio bands.

Re: ‘Every message was copied to the police’

#182
post #163

Earlier quoted context omitted.

> Unless you’re using a true random number generator that works on a mechanical/electrical process… …you're not using a one-time pad. OTP requires the pad to be truly random: at least one bit of unique, never-used-elsewhere entropy for every bit in the message. Merely XORing some plaintext with a pseudo-random stream based on a smaller seed, which as you say is the basis for various other encryption algorithms, is no…

That's what I was saying a true OTP is a cumbersome version of stream cyphers that trades some improvement in security for a huge increase in fragility and difficulty of use and distribution.

The OTP algorithm can be seen as a form of stream cipher (where the key is the stream), but what you actually said was "a lot of encryption algorithms are various ways of creating a one-time pad". This is false since a one-time pad must be truly random and the stream produced by the other algorithms is only pseudo-random; you can't "create" a one-time pad using a pseudo-random number generator. This is a qualitative difference in security because a pseudo-random stream is subject to brute-force searches to locate the seed which decodes the ciphertext to a meaningful message (the number of possible seeds is much smaller than the number of possible messages, so you can generally determine when you've found the right key) whereas with a properly implemented OTP for any message of size equal to or smaller than the ciphertext there exists a key which will decode the ciphertext into that message (possibly with some padding), so brute-force search is impossible.

I wouldn't call OTP "fragile" or "hard to use", but you're correct about the key distribution difficulties.

Re: ‘Every message was copied to the police’

#183

Earlier quoted context omitted.

This is a long feature piece. It's journalism. If you want the simple facts, the story has been reported plenty of other places. You can get the CliffsNotes on Twitter.

> This is a long feature piece. It's journalism The style you are calling «journalism», others call "entertainment". The article does provide information, but the idea implied in the opening, of "bringing you somewhere" (as if fiction), clashes with the supposed intention of inform and comment (the «lightly pattering rain» is irrelevant to the story). If a journal is intended for recording idle remarks, its purpose m…

For comparison:

> Chiba (千葉市, Chiba-shi, Japanese: [tɕiꜜba]) is the capital city of Chiba Prefecture, Japan. It sits about 40 kilometres (25 mi) East of the centre of Tokyo on Tokyo Bay.[1] The city became a government-designated city in 1992. In June 2019, its population was 979,768, with a population density of 3,605 people per km2. The city has an area of 271.77 square kilometres (104.93 sq mi).

The sky above the port was the color of television, tuned to a dead channel.

"It's not like I'm using", Case heard someone say, as he shouldered his way through the crowd around the door of the Chat. "It's like my body's developed this massive drug deficiency". It was a Sprawl voice and a Sprawl joke. The Chatsubo was a bar for professional expatriates; you could drink there for a week and never hear two words in Japanese. [...]

Pseudo-W.Gibson

Re: ‘Every message was copied to the police’

#184
post #92
post #45

Earlier quoted context omitted.

IF you want to send arbitrary data. Usually people don't need that. For something like coke smuggling you just need to know its on the way, get ready. So the OTP could be something as lame as "if you get a phone call from some rando who says 'Taste the Feeling'" then the next boat is full of coke, or if not, then the next boat is not full of coke". Actually terrible idea as taste the feeling was a coke company slogan…

Most criminal activity involves communicating arbitrary data. Communicating that a drug boat is coming across a border is a tiny fraction of the communication in a criminal organization. In the scenario you described, planning out the communication protocol itself is an example of communicating arbitrary data... That needs to happen, at every physical hand-off point.

Interestingly, no.

I had recently finished reading both books by Robert Mason, who started out flying helicopters for the Army in Vietnam and ended up smuggling literal tons of weed and got caught and did federal time. Pretty interesting autobiography. Anyway my comments fit pretty well with his description contained in his second book.

Mr Mason got caught by bad luck. There will always be small timers who do things small timer style who get caught by being verbose and oversharing, and to catch those we'll have "encrypted" smartphones.

Re: ‘Every message was copied to the police’

#185

> Either because of a lack of technical knowhow, or fear for his safety, Ramos refused, and pleaded guilty to running a criminal enterprise, a charge for which he was sentenced to nine years in prison Wait a second, why would he have to go to prison? If all he did was selling phones, what charges could there possibly be? I'm also missing a third option that he refused to cooperate "for idiological reasons".

If you knowingly work with and for criminals congrats you're committing a crime too basically anywhere. A LocalBitcoins guy I knew briefly got charged (on top of the usual illegal money tranmission charges) a bit back for selling coins to an undercover after they implied the money came from selling cocaine.

Re: ‘Every message was copied to the police’

#186

This just goes to show that you can't trust any messaging app or phone to be "secure". Imagine if there was a small handheld device that you could type messages into (along with a secret phrase or a private key), and it would spit out a string of encrypted text that could be entered into ANY messaging app (or even published publicly on a billboard if you wanted). You could even encode the encrypted text as a scannabl…

If we're being paranoid that separate device could also be compromised so that the messages could be decrypted with another key other than the main key(s) used by either party.

Re: ‘Every message was copied to the police’

#187

FBI? I though FBI was supposed to only work on US soil? And were they listening to any messages from American citizens? Because that works appear to be unconstitutional.

Sounds like the FBI sold the phones and the Aussies did the reading. It's the same trick that was revealed a decade ago, US agencies can't read American messages but foreign agencies can so they share info on anything interesting the other partners couldn't legally find out themselves.

> Every single message sent on the app since its launch in 2018 – 19.37m of them – had been collected, and many of them read by the Australian federal police (AFP) who, together with the FBI, had conceived, built, marketed and sold the devices

Re: ‘Every message was copied to the police’

#188

It is a fascinating case, but apart from the technical aspect of it.. how is that not entrapment? FBI effectively created a tool explicitly designed for criminal element and 'marketed' as such. I would ask about legality, but I am worried its in a very, very grey area.

This isn't entrapment. Entrapment is when the government forces you to commit a crime not when the government provides all the tools required to commit a crime without any coercion. Unless you can show you were pressured/forced to do the crime by the government it's assumed you would have done it the same if the situation arose without the government being the other party, because you already did and presumably you didn't know they were cops.

Re: ‘Every message was copied to the police’

#189
post #170

What if I were to make encrypted phones and software for high net worth individuals and celebrities?

That's fine but you'll eventually have undercovers (or less discrete criminals) who'll lets 'slip' that they're using your phones to do crimes at which point if you don't refuse to sell to them you're a criminal too in most of the world.

Re: ‘Every message was copied to the police’

#190

Earlier quoted context omitted.

As far as I can tell, An0m has the same marketing pitch as Purism.

... or the "Freedom phone"

You should be able to have the american flag being waved or tastefully fluttering in the breeze in the background of your comment.
Post reply on HN