Live data from Hacker News

The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

firstlook.org

71–80 of 200 posts

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#71
post #38

Personally, my biggest takeaway is that anything centralized is compromised, period. Any centralized system is such a juicy target that the NSA will compromise it. The only way to avoid dragnet issues is to decentralize and force the NSA to expend resources at the edges. This doesn't means that you can make an individual target secure. The NSA can always outspend you. But you can prevent the NSA from easily just vacu…

Yet you still have carefully to cloak yourself, otherwise you will bring more attention to yourself.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#72
post #41

Earlier quoted context omitted.

Intelligence is one of the few rare fields based wholly upon the idea that the ends justify the means. There are no easy answers there.

Can you please provide your definition of intelligence? I would argue that theoretically , a government (or other entity) could use intelligence but use it within a set of moral and/or ethical guidelines that uses a system of checks and balances.

Intelligence is the dirty-but-necessary stuff that makes it possible to accurately guide diplomacy, economic policy, trade, and military action to achieve the desired goals of a nation-state for a minimum of cost. It includes internal security.

Generally, intelligence cannot operate openly, even under a strict set of guidelines. Further, there will always be situations where efficacy runs into guidelines and something has to give. Would you be willing to violate the privacy of one person to prevent an attack that would kill five thousand? How about a dozen people's privacy? A hundred? A thousand? A million?

As I understand it, those aren't purely theoretical questions in the world of intelligence.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#73
post #58

Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…

I wonder how many years with of jail time Aaron Schwartz's prosecutors would be talking about if this'd been done by a mouthy kid instead of the NSA? I wonder which non-US country, where the NSA's actions aren't made "legal" by secret FISA courts or acts of (US) Congress, will be the first to start throwing that kind of legal threat at NSA staff responsible for this?

When you hold the Poisoned Chalice of Power you get to decide who is legally justified and who isn't. "Morals" doesn't even factor into things....unfortunately.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#74
post #4

This is yet another good argument for TextSecure and RedPhone, which don't depend on the SIM card encryption. https://whispersystems.org/

While certainly a step in the right direction, the lack of an open baseband remains a huge problem, even with TextSecure. Any smartphone has a whole separate OS running, with access to the system bus and memory, that we generally have zero visibility into. There could be exploitable bugs, there could be actual backdoors, and we just have no idea. If you truly want to secure data, you need to use an airgapped system w…

That should be a solvable problem, aren't there tons of operating systems professors and electrical engineers around in Europe that could in principle develop an open baseband chip and operating system? Germany and France should have an interest that their communication can't be trivially backdoored by the NSA.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#75

Do they want me to be apathetic about the actions of our government? I'm getting close.

You should read "The Crisis of Democracy", in short yes, you are supposed to be apathetic, the people in power get uncomfortable quickly if you take an interest in what they do.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#76
"TOP-SECRET GCHQ documents reveal that the intelligence agencies accessed the email and Facebook accounts of engineers and other employees of major telecom corporations and SIM card manufacturers in an effort to secretly obtain information that could give them access to millions of encryption keys. They did this by utilizing the NSA’s X-KEYSCORE program, which allowed them access to private emails hosted by the SIM card and mobile companies’ servers, as well as those of major tech corporations, including Yahoo and Google."

First, it came for the terrorists, and I did not speak out, because I was not a terrorist.

Then, it came for the muslims, and I did not speak out, because I was not a muslim.

Then, it came for the Dutch, Belgian, and German engineers, and I did not speak out, because I was not a Dutch, Belgian, or German engineer.

If you're an engineer, developer, sales staff, or pretty much anything else, and you work at a company that has something worth stealing, you should think about how this ends. If they don't come for you first, your personal life is now completely fair game for nation state attackers.

They will stop at nothing, they have limitless budgets, they will attack your private life, they will reflash the firmware in components of your personal devices, and they will stalk you. Even when you did nothing wrong, even when your employer did nothing wrong, even when your social graph is in no way linked to anyone who ever did anything wrong.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#77
post #4

This is yet another good argument for TextSecure and RedPhone, which don't depend on the SIM card encryption. https://whispersystems.org/

While certainly a step in the right direction, the lack of an open baseband remains a huge problem, even with TextSecure. Any smartphone has a whole separate OS running, with access to the system bus and memory, that we generally have zero visibility into. There could be exploitable bugs, there could be actual backdoors, and we just have no idea. If you truly want to secure data, you need to use an airgapped system w…

Manual baseband isolation via mobile hotspot and nexus 7, does the trick for now

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#78
How is snowden still producing high-level stuff like this?

Did he really steal info on that many headline-worthy stories all in one go, or does he have fresh sources?

Sometimes this feels like another instance of what I call the "weird al phenomenon", where any person who hears a silly parody of a pop song attributes it to weird al, because "wait, you're telling me there are other song parody writers?"

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#79

Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…

How do you think the world actually works? Do you think that any other intelligence operation this past century didn't target similar people?

Take a look at the cold war, most of the directly tasked targets of US and Soviet intelligence efforts were "small fish" with the right access, anything from a hotel employee to a secretary or a cook or even your hair dresses.

At least with this NSA thing they don't end up with 2 bullet holes at their back of the head at the bottom of a trash chute.

Spy agencies always have and always will operate in such manner really not sure why people still act in any sort of shock this is the most basic trade craft.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#80
post #66

Earlier quoted context omitted.

I want to chime in to offer the counter. I used to work for Gemalto. I'm not exactly sure which keys you are talking about, but when I was there Gemalto's standard practice for the transfer of the keys mentioned in the article--individual SIM embedded keys--was to use AllynisConnect (which I only mention because it's easily found on Google) to facilitate the transfer of individual SIM keys to the customer. Obviously…

Why does there have to be any key transfer at all? Why are they not generated in a more decentralized manner, at the manufacturer for example? Why are there servers for the NSA to hack where they can exfiltrate the keys in the first place? Information minimization and avoiding single points of failures could have prevented this.

Because that's how you make money before thinking about security. Centralize and cash in.

My understanding is that the root of the SIM cards are always "owned" by the company sourcing them.

Post reply on HN