Live data from Hacker News

A Saudi Arabia Telecom's Surveillance Pitch

thoughtcrime.org

31–40 of 115 posts

Re: A Saudi Arabia Telecom's Surveillance Pitch

#31
post #6
post #4

Earlier quoted context omitted.

Nobody trusts CAs. There is a lot of work being done on layering more trustworthy authentication features on top of the TLS CA system, one good one being TACK: http://tack.io/draft.html The problem with simply abandoning CAs is that it creates a situation in which it's even easier for government sponsored agencies to mass-intercept traffic, at least for a window of time (probably several years), and all that window b…

> Nobody trusts CAs. No. The problem is that pretty much everyone trusts them, at this point in time. That was Peter's point. Sure, there are researchers and engineers who rightfully don't trust CAs. But we don't really matter. The users, the consumers, the parents, the grandparents, the activists do.

What about a crowd-sourced decentralized list of known bad-CAs or certificates known to be used by Government security services? At the very worst, it will raise some warnings and let the user think twice before connecting to that service (which may or may not be annoying), but at best it would shield users from surveillance?

Re: A Saudi Arabia Telecom's Surveillance Pitch

#32

I'm very curious what aspect of Twitter's TLS code makes hard to intercept whereas other websites can be easily intercepted? I'm also very curious about how they intercepted Whatsapp. Does it do something stupid like eval'ing code received over regular HTTP? Quoting the paragraph, in case my paraphrasing is inaccurate: "What’s depressing is that I could have easily helped them intercept basically all of the traffic t…

They pin the TLS certificate: to successfully create a connection to Twitter, their mobile apps will check not only the validity of the certificate the server presents, but also a hardcoded digest of the correct certificate, so that a "valid" certificate for Twitter from a CA Twitter has no relationship with will be rejected.

Re: A Saudi Arabia Telecom's Surveillance Pitch

#34
post #2

This stuff happens more than anyone in infosec wants to admit; it's (ironically) what got me into professional software security to begin with, after being upset by what a commercial network monitoring tool would have allowed us to do to our customers at an ISP I helped run. It's especially funny to see a government sponsored telecom reaching out to Moxie Marlinspike. Also: this isn't like that time a random Microsof…

Like Moxie says, money buys technology, and they will eventually find someone to rig up a workable solution for what they're trying to do.

Governments are in a unique position here. They can always just move up the stack. Can't break the crypto? That's fine. They can just require the mobile phone companies to sell phones with spyware already included.

Re: A Saudi Arabia Telecom's Surveillance Pitch

#37
post #34
post #2

This stuff happens more than anyone in infosec wants to admit; it's (ironically) what got me into professional software security to begin with, after being upset by what a commercial network monitoring tool would have allowed us to do to our customers at an ISP I helped run. It's especially funny to see a government sponsored telecom reaching out to Moxie Marlinspike. Also: this isn't like that time a random Microsof…

Like Moxie says, money buys technology, and they will eventually find someone to rig up a workable solution for what they're trying to do. Governments are in a unique position here. They can always just move up the stack. Can't break the crypto? That's fine. They can just require the mobile phone companies to sell phones with spyware already included.

That problem is, I think, a showstopper for "anti-circumvention" tools like whatever- the- next- generation- of - Tor will be. Dictatorships have little to lose by backdooring or rootkitting devices; they'll laugh off any outrage stirred up by the discovery of these methods.

But the economics flip around in Europe, Japan, the US, &c: governments there do have something to lose by surreptitiously backdooring huge numbers of devices, and the odds are good that any efforts to do so will be detected (the state of the art for reverse engineering now includes decapsulation and imaging of electronics packages).

Re: A Saudi Arabia Telecom's Surveillance Pitch

#39
post #6

Earlier quoted context omitted.

> Nobody trusts CAs. No. The problem is that pretty much everyone trusts them, at this point in time. That was Peter's point. Sure, there are researchers and engineers who rightfully don't trust CAs. But we don't really matter. The users, the consumers, the parents, the grandparents, the activists do.

What about a crowd-sourced decentralized list of known bad-CAs or certificates known to be used by Government security services? At the very worst, it will raise some warnings and let the user think twice before connecting to that service (which may or may not be annoying), but at best it would shield users from surveillance?

The government and corporations (and thus defense contractors) are experts at manipulating crowdsourcing for their own ends. I sure as hell wouldn't trust crowdsourcing.

Re: A Saudi Arabia Telecom's Surveillance Pitch

#40
post #14

I suddenly had a realization why someday in the future everyone is going to want their own personal satellite. Government interception/manipulation (or any other party) would become rather difficult.

Until hunter-seeker satellites intercept other people's micro satellites and destroy them, or worse 'wiretap' into their internal computers without their knowledge.
Post reply on HN