Live data from Hacker News

The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

firstlook.org

81–90 of 200 posts

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#81
post #56

Earlier quoted context omitted.

The end in this case being the ability to decrypt cellphone traffic. And what will that capacity be used for? Spying on foreign nations? Halting nonexistent terrorist plots? Further secret surveillance of American citizens? If we judge the means by the ends, I do not believe that their end provides sufficient justification for their means. They appear to believe otherwise, however they fail to offer any evidence for…

Decrypting cellphone traffic is also a means. It's a means towards information and human connections and so on. That's the sort of stuff that can make or break an operation. Did it? Has it? Unknown. The trouble with intelligence is that it's only effective when done with secrecy and fairly broad latitude to operate. There are few easy answers here.

A fairly broad latitude? If the ends justify the means and yet the ends themselves are kept completely hidden, then the latitude, as you put it, is completely unconstrained. An intelligence agency operating under those principles can literally do anything claiming that it is for the greater good.

In short, it sounds like you are advocating for an agency which can take arbitrary extralegal action at its own discretion, without providing reason or explanation, and without providing any demonstrable benefit to anybody, because it's secret.

Frankly, I find the idea terrifying. I understand that intelligence agencies need some quantity of secrecy and some degree of latitude. Like you have repeatedly stated, there are no easy answers. But that doesn't mean we shouldn't ask the question. What the hell are these people doing, and should we let them continue? What is growing in our intelligence sector -- is it an institution that will be found to have brought the world benefit, like Bletchley Park, or will it be seen to have become a thin facade over a malignant, self-interested organization, potentially culminating in something like a secret police?

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#82

Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…

How do you think the world actually works? Do you think that any other intelligence operation this past century didn't target similar people? Take a look at the cold war, most of the directly tasked targets of US and Soviet intelligence efforts were "small fish" with the right access, anything from a hotel employee to a secretary or a cook or even your hair dresses. At least with this NSA thing they don't end up with…

No they didn't. There are intelligence operation that you haven't heard of, and this is not an accident. Just because NSA is using brute force and does not care about the collateral damage it does not mean that all of the secret agencies should do the same or doing the same.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#83

At some point, people have to begin to realize that this has progressed past "looking for terrorists." Statists are gonna state, I guess.

The article specifically cites the mobile phone networks of Iran, Yemen, Afghanistan, and Somalia as targets. One is a state sponsor of terrorism, the other three are places where the US is actively fighting terrorism.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#84
post #77

Earlier quoted context omitted.

While certainly a step in the right direction, the lack of an open baseband remains a huge problem, even with TextSecure. Any smartphone has a whole separate OS running, with access to the system bus and memory, that we generally have zero visibility into. There could be exploitable bugs, there could be actual backdoors, and we just have no idea. If you truly want to secure data, you need to use an airgapped system w…

Manual baseband isolation via mobile hotspot and nexus 7, does the trick for now

Until the AMSS in the hotspot is compromised and used to attack your Android device via wifi.

This applies to mobile hotspots built around Qualcomm baseband/application processors, in other cases you would have to exploit the main CPU first.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#85
post #58

Earlier quoted context omitted.

I wonder how many years with of jail time Aaron Schwartz's prosecutors would be talking about if this'd been done by a mouthy kid instead of the NSA? I wonder which non-US country, where the NSA's actions aren't made "legal" by secret FISA courts or acts of (US) Congress, will be the first to start throwing that kind of legal threat at NSA staff responsible for this?

When you hold the Poisoned Chalice of Power you get to decide who is legally justified and who isn't. "Morals" doesn't even factor into things....unfortunately.

Only in a limited way though, the NSA can decide (or at least exert considerable influence over) what's legal in the US - but criminal actions in, say, The Netherlands or any other (non five eyes) country, cannot be "justified" or "excused" legally by another except those countries.

I guess a _lot_ of what goes in in state sponsored espionage happens outside the civilian legal system - at least in "major" countries - but surely there's scope for a criminal trial and civil damages case against NSA/GHCQ operatives when their espionage involves widespread network exploitation and privacy violation of corporate networks and staff. Crimes which would _clearly_ be aggressively prosecuted if committed by Anonymous Skript Kiddies or criminal credit card fraud gangs. Why shouldn't NSA agents be held just as accountable in this case by non US legal systems? Sure, root the embassy network and expect to be held diplomatically responsible if you get caught. Private companies and citizens though? Go to jail just like anybody else.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#86

How is snowden still producing high-level stuff like this? Did he really steal info on that many headline-worthy stories all in one go, or does he have fresh sources? Sometimes this feels like another instance of what I call the "weird al phenomenon", where any person who hears a silly parody of a pop song attributes it to weird al, because "wait, you're telling me there are other song parody writers?"

It's safe to assume that the vast quantities of documentation he liberated have enough newsworthy material in them to last those with access a very very long time.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#87

Earlier quoted context omitted.

How do you think the world actually works? Do you think that any other intelligence operation this past century didn't target similar people? Take a look at the cold war, most of the directly tasked targets of US and Soviet intelligence efforts were "small fish" with the right access, anything from a hotel employee to a secretary or a cook or even your hair dresses. At least with this NSA thing they don't end up with…

No they didn't. There are intelligence operation that you haven't heard of, and this is not an accident. Just because NSA is using brute force and does not care about the collateral damage it does not mean that all of the secret agencies should do the same or doing the same.

So they just decided to declassify or screw up all the intelligence operations that did just that to give them selves a bad rep?

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#88
post #35
post #31

Earlier quoted context omitted.

The old technologies required more effort (somebody had to go physically tap the wire).

When I re-read the parent's post I thought to myself "of course he is being sarcastic!" But then I saw your post and it made me think. And I believe you are onto something here. I mean, sure, probably tapping one phone is much easier physically, just connect the wires and you're done. However the point you bring is game-changer. In ye' olden days spooks were interested in certain persons only, but now it seems that w…

Back in the day all you had to do was monitor the microwave and satellite links to get all the long haul communications. You didn't have to expose yourself at all.

Now things are the opposite. It is easier to sweep up a bunch of local stuff in the form of cell phone calls but you need a physical connection to tap fibre..

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#89

How is snowden still producing high-level stuff like this? Did he really steal info on that many headline-worthy stories all in one go, or does he have fresh sources? Sometimes this feels like another instance of what I call the "weird al phenomenon", where any person who hears a silly parody of a pop song attributes it to weird al, because "wait, you're telling me there are other song parody writers?"

It's also likely or possible that other disclosures are labeled under Snowden in order not to compromise or reveal the existence of a new source.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#90
How many silicon valley patriots would support this outrageous attack?

It was one week ago that Obama was arguing that this kind of activity is necessary.

http://www.newyorker.com/business/currency/stanford-obama-ti...

This is not a republican/democrat problem. This is an institutional problem. We need comprehensive reform of both parties and it should be followed by a purging of the existing federal machine.

Post reply on HN