Live data from Hacker News

A Saudi Arabia Telecom's Surveillance Pitch

thoughtcrime.org

71–80 of 115 posts

Re: A Saudi Arabia Telecom's Surveillance Pitch

#71
post #15
post #7

> TextSecure and RedPhone could serve as appropriate secure replacements sadly those are only available for Android.

...and, under these sorts of regimes, will likely get blocked should they gain any sort of real traction anyway. (Moxie's post is clear that they want to intercept, and block what they can't.) Without jailbreaking or a dev cert, you can't ensure that an app you install from the App Store on iOS isn't backdoored anyway. I'm an iOS devotee but even I'm going to buy a second phone specifically to support sideloading of…

With Android all you have to do is tick a checkbox to install apps that are not from the market, you don't need to root it and you don't need a special certificate.

Oh and if you want a dev user, it is a one time fee of 20 usd (or was, when I got mine).

Re: A Saudi Arabia Telecom's Surveillance Pitch

#72
We all supposedly know how totalitarian Saudi Arabia is compared to the free United States, so giving Saudi Arabia eaves dropping and decryption tools is something we all obviously dislike. But we are all bathing in American propaganda, so many people, like those "patriotic hackers", support the Feds having the same power that Saudi Arabia is seeking. In fact, the US government is doing much more sophisticated eavesdropping of all our communications and storing it for later perusal. And they use the same "terrorism" justification as the dictators. And what is a terrorist? Whoever they say is a terrorist. Which can include anyone advancing any political ideology that is frowned upon by the bipartisan "washington consensus" of what is acceptable debate. From libertarians to environmentalists to any kind of anti-authoritarian that doesn't serve the interests of the establishment.

Re: A Saudi Arabia Telecom's Surveillance Pitch

#73
post #2

This stuff happens more than anyone in infosec wants to admit; it's (ironically) what got me into professional software security to begin with, after being upset by what a commercial network monitoring tool would have allowed us to do to our customers at an ISP I helped run. It's especially funny to see a government sponsored telecom reaching out to Moxie Marlinspike. Also: this isn't like that time a random Microsof…

> money buys technology I don't think it matters. He quickly noticed that the problem is cultural, that >> I’d much rather think about the question of exploit sales in terms of who we welcome to our conferences, who we choose to associate with, and who we choose to exclude, than in terms of legal regulations. I think the contextual shift we’ve seen over the past few years requires that we think critically about what’…

It'll change plenty if we do. Oppressive regimes are taken down by conspiracies and secret communication. If they eliminate this ability to associate, with our assistance, there will never be any space for revolution, or even reform.

This logic reeks of the law of averages: "I might as well swim over Niagara Falls because I could die any day, even from crossing the street. If I die today, it was just my day to die."

Of course, I have less of a reply to "Even if I don't sell it to them, someone will." The middle class finds it very easy to rationalize behavior that will keep the consumption flowing.

Re: A Saudi Arabia Telecom's Surveillance Pitch

#74
post #69
post #32

Earlier quoted context omitted.

They pin the TLS certificate: to successfully create a connection to Twitter, their mobile apps will check not only the validity of the certificate the server presents, but also a hardcoded digest of the correct certificate, so that a "valid" certificate for Twitter from a CA Twitter has no relationship with will be rejected.

Wouldn't that break when they need to update the certificate, due to expiration?

Yes and that's kind of the point.

It's like Firmware in VoIP, although VoIP implementations leave something to be desired. In essence they're doing something similar to a checksum on the certificate such that any change to the certificate causes the transaction to fail.

You would have to hard code the new dates in.

Re: A Saudi Arabia Telecom's Surveillance Pitch

#76
post #24

Earlier quoted context omitted.

In this case I was mostly referring to the inclusion of certificate pinning (ex: https://github.com/moxie0/AndroidPinning ) in the mobile apps, which would theoretically prevent them from using a UAE or Saudi controlled CA to do the interception. In addition to iOS and Android, we also refused to compromise with low-end platforms like MediaTek, and made sure those clients were also all-TLS and that they employed cert…

If you really want the world to be a more secure place, can I please ask that you relicense the AndroidPinning code as BSD or something less viral than GPLv3? I don't see Instagram, Facebook, etc. using that code to secure their apps, they won't license their Android clients as GPLv3 just to use the Android pinning library. While it is easy enough to re-create your code (though I have not looked at it), given that we…

> I don't see Instagram, Facebook, etc. using that code to secure their apps, they won't license their Android clients as GPLv3

They might license the code under a non-exclusive license with different terms. I.e. the copyright holder is free to license the same source code under various licenses.

So, e.g. I could license some code to the community under GPL, but I could also license it closed-source to a corp for a fee.

Re: A Saudi Arabia Telecom's Surveillance Pitch

#77
post #63

Earlier quoted context omitted.

If he hadn't taken the time to publish this code, you wouldn't have even known to try to zing him for using the "wrong" license. Perhaps the most rational solution for people like Moxie would simply be to never publish their code, and simply continue to write forcefully and effectively about technical controls and privacy. Then they wouldn't have to jump through silly hoops to prove whether they "really want the worl…

You don't have to be such an ass. I asked nicely enough. I fully acknowledge Moxie is better at security than I ever will even dream of being. I just hoped he might see the value in releasing it under a more-amicable license. I don't have the numbers, but more-liberal licenses are by a wide margin the choice for open-source crypto. I'm not speaking from the armchair, I've released open-source code under BSD/MIT mysel…

There's more value in forcing vendors to work with Free Software licenses than in compromising the ideals of open source to allow vendors to benefit without contributing back.

You should be asking yourself how you can change your project so that GPL3 licensed code will be acceptable, rather than asking others to relicense their code.

Re: A Saudi Arabia Telecom's Surveillance Pitch

#78
post #72

We all supposedly know how totalitarian Saudi Arabia is compared to the free United States, so giving Saudi Arabia eaves dropping and decryption tools is something we all obviously dislike. But we are all bathing in American propaganda, so many people, like those "patriotic hackers", support the Feds having the same power that Saudi Arabia is seeking. In fact, the US government is doing much more sophisticated eavesd…

  ...so many people, like those "patriotic hackers", support the Feds having the same power that Saudi Arabia is seeking
They do? I'm not sure I can name a single hacker that wants the US, or any other govt, to have the same power.

Re: A Saudi Arabia Telecom's Surveillance Pitch

#79
post #45
post #42

Earlier quoted context omitted.

The US government is a special case again. Since most of the companies mentioned here are headquartered in the US, the US government can resort to the no-tech solution of just asking for the data and presenting a subpoena (or so was my experience working for a large US telecom carrier).

The difference is that a subpoena doesn't decrypt an EDH TLS session.

But it does decrypt the data at rest.

Re: A Saudi Arabia Telecom's Surveillance Pitch

#80
post #72

We all supposedly know how totalitarian Saudi Arabia is compared to the free United States, so giving Saudi Arabia eaves dropping and decryption tools is something we all obviously dislike. But we are all bathing in American propaganda, so many people, like those "patriotic hackers", support the Feds having the same power that Saudi Arabia is seeking. In fact, the US government is doing much more sophisticated eavesd…

...so many people, like those "patriotic hackers", support the Feds having the same power that Saudi Arabia is seeking They do? I'm not sure I can name a single hacker that wants the US, or any other govt, to have the same power.

Here's the link from TFA: http://erratasec.blogspot.de/2012/08/who-will-fight-for-me.h...
Post reply on HN