Earlier quoted context omitted.
When I re-read the parent's post I thought to myself "of course he is being sarcastic!" But then I saw your post and it made me think. And I believe you are onto something here. I mean, sure, probably tapping one phone is much easier physically, just connect the wires and you're done. However the point you bring is game-changer. In ye' olden days spooks were interested in certain persons only, but now it seems that w…
Somebody told me that post-Snowden, the NSA started processing some high-value internal paperwork with fancy typewriters to prevent signals intelligence attacks. Apparently the typewriters have little signatures embedded in each letter that are unique per typewriter operator.
The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
51–60 of 200 posts
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#52Earlier quoted context omitted.
On that note, I wonder if their compromising of these systems affords the target any sort of immunization from attacks by other actors. It would make sense that NSA/GHCQ wouldn't want their foreign competitors to share in the prize, and it would also be congruent with their interests to not afford competing actors access to such a prize. Then again, this notion is likely far too romantic. The reality is probably clos…
Sometimes denying data to others is as good as advertising that someone else got there first. So you might want to leave the treasure trove in place so that nobody else figures out you have it. Intelligence is wheels within wheels within wheels...
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#53Earlier quoted context omitted.
The old technologies required more effort (somebody had to go physically tap the wire).
You can't tap a cell phone call remotely either - you have to be pretty close to the cell phone. So it's not that different, a bit easier, yes. But you still have to physically go there.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#54Earlier quoted context omitted.
Sure. Lets suppose it actually was a valid defense. But what does that have to do with going through the Facebook and personal email of individual employees to know who to target. That was done up close, in personal, by hand. By any definition, those people had their privacy specifically and intentionally violated by actual human analysts.
Intelligence is one of the few rare fields based wholly upon the idea that the ends justify the means. There are no easy answers there.
If we judge the means by the ends, I do not believe that their end provides sufficient justification for their means. They appear to believe otherwise, however they fail to offer any evidence for their perspective; as an American, I am feeling ever more alienated from the organizations which were theoretically founded for our benefit.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#55Earlier quoted context omitted.
I can confirm this. In many cases these keys are exchanged over email with simple DES encryption and a key known to everybody in the business (pretty obvious key BTW). It really boils down to the security procedures in place between the SIM manufacturer and Mobile Network Operators.
I want to chime in to offer the counter. I used to work for Gemalto. I'm not exactly sure which keys you are talking about, but when I was there Gemalto's standard practice for the transfer of the keys mentioned in the article--individual SIM embedded keys--was to use AllynisConnect (which I only mention because it's easily found on Google) to facilitate the transfer of individual SIM keys to the customer. Obviously…
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#56Earlier quoted context omitted.
Intelligence is one of the few rare fields based wholly upon the idea that the ends justify the means. There are no easy answers there.
The end in this case being the ability to decrypt cellphone traffic. And what will that capacity be used for? Spying on foreign nations? Halting nonexistent terrorist plots? Further secret surveillance of American citizens? If we judge the means by the ends, I do not believe that their end provides sufficient justification for their means. They appear to believe otherwise, however they fail to offer any evidence for…
Did it? Has it? Unknown.
The trouble with intelligence is that it's only effective when done with secrecy and fairly broad latitude to operate. There are few easy answers here.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#57Earlier quoted context omitted.
I want to chime in to offer the counter. I used to work for Gemalto. I'm not exactly sure which keys you are talking about, but when I was there Gemalto's standard practice for the transfer of the keys mentioned in the article--individual SIM embedded keys--was to use AllynisConnect (which I only mention because it's easily found on Google) to facilitate the transfer of individual SIM keys to the customer. Obviously…
In many cases you have specific procedures in place for security-conscious MNOs, but some of these procedures are such a pain that you inevitably end up finding workarounds to get the business going, e.g. email or USB tokens between various people who are not supposed to have those keys. Of course security officers and other officials are not aware of this. Dig through any sales mailbox and you will find CSV files (u…
Of course, there are lots of things I didn't have visibility on and it is possible that I am overly optimistic.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#58Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…
I wonder which non-US country, where the NSA's actions aren't made "legal" by secret FISA courts or acts of (US) Congress, will be the first to start throwing that kind of legal threat at NSA staff responsible for this?
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#59Earlier quoted context omitted.
The old technologies required more effort (somebody had to go physically tap the wire).
You can't tap a cell phone call remotely either - you have to be pretty close to the cell phone. So it's not that different, a bit easier, yes. But you still have to physically go there.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#60This is exactly why Intel's upcoming SGX worries me greatly, too. NSA could get the "key" to all SGX machines and therefore to all applications using SGX to secure themselves properly (ironically enough) [1]. Intel really needs to figure out how to protect the SGX system against such a key robbery, and not by promising to only give access to a couple of employees in the whole company who know a very special hand-shak…
But yes, any situation like this where you cannot be trusted means a hacker can gain a higher level of trust than you if they break the security.