At this point, we might as well just go back to landlines and fax machines.
Aren't those even easier to wiretap? I believe (maybe I'm wrong here) that the word wiretap comes precisely because people could literally "tap" into the wire and listen everything. Or did I miss the sarcasm?
The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
31–40 of 200 posts
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#32I think its safe to say NSA/GCHQ are not the only ones in the game who have hit this target.
It would make sense that NSA/GHCQ wouldn't want their foreign competitors to share in the prize, and it would also be congruent with their interests to not afford competing actors access to such a prize.
Then again, this notion is likely far too romantic. The reality is probably closer to one where foreign actors have compromised everything just the same.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#33Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…
"Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people" Nothing new here - as the Belgacom hack has shown already.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#34Earlier quoted context omitted.
Aren't those even easier to wiretap? I believe (maybe I'm wrong here) that the word wiretap comes precisely because people could literally "tap" into the wire and listen everything. Or did I miss the sarcasm?
The old technologies required more effort (somebody had to go physically tap the wire).
So it's not that different, a bit easier, yes. But you still have to physically go there.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#35Earlier quoted context omitted.
Aren't those even easier to wiretap? I believe (maybe I'm wrong here) that the word wiretap comes precisely because people could literally "tap" into the wire and listen everything. Or did I miss the sarcasm?
The old technologies required more effort (somebody had to go physically tap the wire).
But then I saw your post and it made me think. And I believe you are onto something here.
I mean, sure, probably tapping one phone is much easier physically, just connect the wires and you're done. However the point you bring is game-changer.
In ye' olden days spooks were interested in certain persons only, but now it seems that we are all fair game, and so the "easy" way of wiretapping becomes incredibly hard when you want to spy on everyone.
It's basically an scalability problem then. Never saw it that way.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#36Earlier quoted context omitted.
"Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people" Nothing new here - as the Belgacom hack has shown already.
So I may have missed the details. I thought we knew they hacked Belgacom, but no one mentioned going through employee's personal email and social networks (though in light of this, we can assume they did). If they did mention it and I missed it, sure, nothing new. But the same entire thing then just applies to that instance too.
https://firstlook.org/theintercept/2014/12/13/belgacom-hack-...
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#37Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…
It's worth remembering that some tools are only useful with lots of data about innocent people. Some forms of network analysis fall into this category, I believe.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#38Any centralized system is such a juicy target that the NSA will compromise it. The only way to avoid dragnet issues is to decentralize and force the NSA to expend resources at the edges.
This doesn't means that you can make an individual target secure. The NSA can always outspend you. But you can prevent the NSA from easily just vacuuming up everybody cheaply.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#39I think its safe to say NSA/GCHQ are not the only ones in the game who have hit this target.
On that note, I wonder if their compromising of these systems affords the target any sort of immunization from attacks by other actors. It would make sense that NSA/GHCQ wouldn't want their foreign competitors to share in the prize, and it would also be congruent with their interests to not afford competing actors access to such a prize. Then again, this notion is likely far too romantic. The reality is probably clos…
Intelligence is wheels within wheels within wheels...
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#40Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…
Preface: this is not a defense. It's worth remembering that some tools are only useful with lots of data about innocent people. Some forms of network analysis fall into this category, I believe.
Lets suppose it actually was a valid defense. But what does that have to do with going through the Facebook and personal email of individual employees to know who to target. That was done up close, in personal, by hand. By any definition, those people had their privacy specifically and intentionally violated by actual human analysts.