Live data from Hacker News

The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

firstlook.org

51–60 of 200 posts

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#51
post #46
post #35

Earlier quoted context omitted.

When I re-read the parent's post I thought to myself "of course he is being sarcastic!" But then I saw your post and it made me think. And I believe you are onto something here. I mean, sure, probably tapping one phone is much easier physically, just connect the wires and you're done. However the point you bring is game-changer. In ye' olden days spooks were interested in certain persons only, but now it seems that w…

Somebody told me that post-Snowden, the NSA started processing some high-value internal paperwork with fancy typewriters to prevent signals intelligence attacks. Apparently the typewriters have little signatures embedded in each letter that are unique per typewriter operator.

Every typewriter has a unique signature as has every other polygraphic machine (fax, printer, copier). This was a case always, after Media burglary (in the '70!) FBI was collecting Xerox copier printouts to identify where the burglars reproduced the stolen files.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#52
post #39
post #32

Earlier quoted context omitted.

On that note, I wonder if their compromising of these systems affords the target any sort of immunization from attacks by other actors. It would make sense that NSA/GHCQ wouldn't want their foreign competitors to share in the prize, and it would also be congruent with their interests to not afford competing actors access to such a prize. Then again, this notion is likely far too romantic. The reality is probably clos…

Sometimes denying data to others is as good as advertising that someone else got there first. So you might want to leave the treasure trove in place so that nobody else figures out you have it. Intelligence is wheels within wheels within wheels...

Good point. However, it might be possible to deny adversaries without alerting them to the fact that they were denied in the first place.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#53
post #34
post #31

Earlier quoted context omitted.

The old technologies required more effort (somebody had to go physically tap the wire).

You can't tap a cell phone call remotely either - you have to be pretty close to the cell phone. So it's not that different, a bit easier, yes. But you still have to physically go there.

So little you know... ;)

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#54
post #41

Earlier quoted context omitted.

Sure. Lets suppose it actually was a valid defense. But what does that have to do with going through the Facebook and personal email of individual employees to know who to target. That was done up close, in personal, by hand. By any definition, those people had their privacy specifically and intentionally violated by actual human analysts.

Intelligence is one of the few rare fields based wholly upon the idea that the ends justify the means. There are no easy answers there.

The end in this case being the ability to decrypt cellphone traffic. And what will that capacity be used for? Spying on foreign nations? Halting nonexistent terrorist plots? Further secret surveillance of American citizens?

If we judge the means by the ends, I do not believe that their end provides sufficient justification for their means. They appear to believe otherwise, however they fail to offer any evidence for their perspective; as an American, I am feeling ever more alienated from the organizations which were theoretically founded for our benefit.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#55

Earlier quoted context omitted.

I can confirm this. In many cases these keys are exchanged over email with simple DES encryption and a key known to everybody in the business (pretty obvious key BTW). It really boils down to the security procedures in place between the SIM manufacturer and Mobile Network Operators.

I want to chime in to offer the counter. I used to work for Gemalto. I'm not exactly sure which keys you are talking about, but when I was there Gemalto's standard practice for the transfer of the keys mentioned in the article--individual SIM embedded keys--was to use AllynisConnect (which I only mention because it's easily found on Google) to facilitate the transfer of individual SIM keys to the customer. Obviously…

In many cases you have specific procedures in place for security-conscious MNOs, but some of these procedures are such a pain that you inevitably end up finding workarounds to get the business going, e.g. email or USB tokens between various people who are not supposed to have those keys. Of course security officers and other officials are not aware of this. Dig through any sales mailbox and you will find CSV files (usually called output files) containing Ki encrypted with simple DES. I let you ask around to learn which DES key is most often used. Disclaimer: this is not specific to Gemalto.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#56
post #41

Earlier quoted context omitted.

Intelligence is one of the few rare fields based wholly upon the idea that the ends justify the means. There are no easy answers there.

The end in this case being the ability to decrypt cellphone traffic. And what will that capacity be used for? Spying on foreign nations? Halting nonexistent terrorist plots? Further secret surveillance of American citizens? If we judge the means by the ends, I do not believe that their end provides sufficient justification for their means. They appear to believe otherwise, however they fail to offer any evidence for…

Decrypting cellphone traffic is also a means. It's a means towards information and human connections and so on. That's the sort of stuff that can make or break an operation.

Did it? Has it? Unknown.

The trouble with intelligence is that it's only effective when done with secrecy and fairly broad latitude to operate. There are few easy answers here.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#57

Earlier quoted context omitted.

I want to chime in to offer the counter. I used to work for Gemalto. I'm not exactly sure which keys you are talking about, but when I was there Gemalto's standard practice for the transfer of the keys mentioned in the article--individual SIM embedded keys--was to use AllynisConnect (which I only mention because it's easily found on Google) to facilitate the transfer of individual SIM keys to the customer. Obviously…

In many cases you have specific procedures in place for security-conscious MNOs, but some of these procedures are such a pain that you inevitably end up finding workarounds to get the business going, e.g. email or USB tokens between various people who are not supposed to have those keys. Of course security officers and other officials are not aware of this. Dig through any sales mailbox and you will find CSV files (u…

Unfortunately that is very possible, and of course I can't speak for other companies. I will say that Gemalto has internal access protection for these and other information.

Of course, there are lots of things I didn't have visibility on and it is possible that I am overly optimistic.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#58

Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…

I wonder how many years with of jail time Aaron Schwartz's prosecutors would be talking about if this'd been done by a mouthy kid instead of the NSA?

I wonder which non-US country, where the NSA's actions aren't made "legal" by secret FISA courts or acts of (US) Congress, will be the first to start throwing that kind of legal threat at NSA staff responsible for this?

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#59
post #34
post #31

Earlier quoted context omitted.

The old technologies required more effort (somebody had to go physically tap the wire).

You can't tap a cell phone call remotely either - you have to be pretty close to the cell phone. So it's not that different, a bit easier, yes. But you still have to physically go there.

Not if you have access to the carrier's internal network...

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#60

This is exactly why Intel's upcoming SGX worries me greatly, too. NSA could get the "key" to all SGX machines and therefore to all applications using SGX to secure themselves properly (ironically enough) [1]. Intel really needs to figure out how to protect the SGX system against such a key robbery, and not by promising to only give access to a couple of employees in the whole company who know a very special hand-shak…

You mistake the point of SGX. The point of is a reincarnation of treacherous computing. Intel SGX requires remote attestation. This means that YOU, the owner of the device, is not trusted. To have 3rd party keys would mean they would have to trust you. With trust in you, how could it be marketed to the copyright owners? The answer is that it cannot. The point of Intel SGX is to deny ownership of the device to its owner.

But yes, any situation like this where you cannot be trusted means a hacker can gain a higher level of trust than you if they break the security.

Post reply on HN