Live data from Hacker News

The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

firstlook.org

11–20 of 200 posts

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#12
post #6

At this point, we might as well just go back to landlines and fax machines.

Aren't those even easier to wiretap?

I believe (maybe I'm wrong here) that the word wiretap comes precisely because people could literally "tap" into the wire and listen everything.

Or did I miss the sarcasm?

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#14
post #11

[deleted]

There is no shock and surprise. Historically, not all communication has been compromised, because it takes physical effort and risk of detection to open every letter. Secure communication (in the sense of the contemporary normal means of communication) has not been a historically hard-to-get commodity.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#15
Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic because of the potential for abuse. Abuse that we either assumed would happen or already had, but as far as I know there was little direct evidence of.

The absolute lowest bar for surveillance seems to be that a government doesn't use it to intentionally target innocent people/ those not in the game (hell, lets lower it even further to be only people the government themselves believe are innocent).[0]

That potentially allows dragnet collection of data if no one looks at it. It might allow hacking just a company's servers to get access to third party data. It probably allows you to spy on foreign heads of state (even if it's a boneheaded move). But it damn well doesn't allow you to go through the personal communications of people who you know have done nothing wrong and aren't even working for someone who has.

[0] This is precisely the woefully low bar Obama has been espousing : “The bottom line is that people around the world, regardless of their nationality, should know that the United States is not spying on ordinary people who don’t threaten our national security and that we take their privacy concerns into account in our policies and procedures,”

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#16
post #11

[deleted]

The SIM card bit is actually I think a distraction. The real issue should be the means: the NSA/GCHQ intentionally targeted innocent/non government affiliated people's personal email and social networking.

That's different than collecting everyone'ss data and claiming you never look at it unless someone does something to loose their innocence. Orwellian nightmare that that is and probably bullshit, revelations along those lines are not surprising. The systematic targeting of the personal lives of random employees (at least of non-governmental/ non defense industry ones), is new.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#17
post #11

[deleted]

The SIM card bit is actually I think a distraction. The real issue should be the means: the NSA/GCHQ intentionally targeted innocent/non government affiliated people's personal email and social networking. That's different than collecting everyone'ss data and claiming you never look at it unless someone does something to loose their innocence. Orwellian nightmare that that is and probably bullshit, revelations along…

[deleted]

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#19
In 2007 I worked with Gemalto when they ported a Java/PKCS #11 Chip & PIN implementation to the .NET Micro Framework/CAPI for Microsoft, who were using it for challenge/response authN on a remote access project for the UK Ministry of Defence. There was a case study of the project on Microsoft.com, but it seems to no longer be there.

Anyway, this sucks because the Gemalto guys I did this with were to this day among the best vendors I've ever worked with. Really awesome guys, smart, and incredibly willing to share what they knew and did. And it's somewhat ironic that Gemalto are trusted by the UK MoD for sourcing their smart card components in Europe.

So much for keeping it local to avoid hacks.

Post reply on HN