Live data from Hacker News

The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

firstlook.org

91–100 of 200 posts

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#91

Earlier quoted context omitted.

No they didn't. There are intelligence operation that you haven't heard of, and this is not an accident. Just because NSA is using brute force and does not care about the collateral damage it does not mean that all of the secret agencies should do the same or doing the same.

So they just decided to declassify or screw up all the intelligence operations that did just that to give them selves a bad rep?

I am not concerned about that. It is bad practice to damage security for all because of few. This is all I am saying. It seems like a pretty bad idea to me.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#92
post #35

Earlier quoted context omitted.

When I re-read the parent's post I thought to myself "of course he is being sarcastic!" But then I saw your post and it made me think. And I believe you are onto something here. I mean, sure, probably tapping one phone is much easier physically, just connect the wires and you're done. However the point you bring is game-changer. In ye' olden days spooks were interested in certain persons only, but now it seems that w…

Except more and more, calls are going over VoIP, which is essentially never encrypted. Even calls from one landline to another, even to a neighbor, might end up on VoIP. And in any given call, there are probably multiple resellers. Each with full capability to intercept, redirect, modify, etc. any call. And tech support is often given access to capture any call, as a troubleshooting measure. Even companies like AT&T,…

That depends on what network you're using. If you're using a landline from the incumbent local exchange carrier, the probability of a local call going over voip is effectively almost zero. Likewise, for long distance carriers, AT&T, the ex-MCI networks Verizon owns, and the Sprint wireline long distance network (their mobile stuff goes over separate facilities; their long distance network, as well as most of the ex-MCI networks use a platform called the DMS-250, which is very much oriented to non-packet connectivity) generally don't use voip trunks for national traffic. Also, there is no least cost routing operation like on most of the smaller carriers, so there's no need to hit any sort of public network until it reaches the access tandem at your destination, at which point, it definitely isn't exchanged in any sort of IP format.

Internationally, it depends on what carrier they interconnect with and what they want. Generally speaking, I think Verizon will use more IP-based routes (usually to more expensive countries) then the other two.

By contrast, landline service coming from the cable company generally does go over voip, but only within their internal network. For local and inbound calls, it'll still hit some DSx trunks back to the phone network. 1+ long distance traffic, at least on Comcast, is definitely in IP format, and could very well even be hitting the public internet for least cost routing operations.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#93
post #86

How is snowden still producing high-level stuff like this? Did he really steal info on that many headline-worthy stories all in one go, or does he have fresh sources? Sometimes this feels like another instance of what I call the "weird al phenomenon", where any person who hears a silly parody of a pop song attributes it to weird al, because "wait, you're telling me there are other song parody writers?"

It's safe to assume that the vast quantities of documentation he liberated have enough newsworthy material in them to last those with access a very very long time.

Greenwald and Poitras have said this publicly many times. They have years worth of material to report from the cache of files.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#95

"TOP-SECRET GCHQ documents reveal that the intelligence agencies accessed the email and Facebook accounts of engineers and other employees of major telecom corporations and SIM card manufacturers in an effort to secretly obtain information that could give them access to millions of encryption keys. They did this by utilizing the NSA’s X-KEYSCORE program, which allowed them access to private emails hosted by the SIM c…

This should be the top comment.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#96
One notable line:

"GCHQ operatives identified key individuals and their positions within Gemalto and then dug into their emails. In one instance, GCHQ zeroed in on a Gemalto employee in Thailand who they observed sending PGP-encrypted files, noting that if GCHQ wanted to expand its Gemalto operations, “he would certainly be a good place to start.”"

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#98
post #56

Earlier quoted context omitted.

Decrypting cellphone traffic is also a means. It's a means towards information and human connections and so on. That's the sort of stuff that can make or break an operation. Did it? Has it? Unknown. The trouble with intelligence is that it's only effective when done with secrecy and fairly broad latitude to operate. There are few easy answers here.

A fairly broad latitude? If the ends justify the means and yet the ends themselves are kept completely hidden, then the latitude, as you put it, is completely unconstrained. An intelligence agency operating under those principles can literally do anything claiming that it is for the greater good. In short, it sounds like you are advocating for an agency which can take arbitrary extralegal action at its own discretion…

You misread me. I am not advocating for anything. I am commenting on the constraints and issues of the problem space.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#99

"TOP-SECRET GCHQ documents reveal that the intelligence agencies accessed the email and Facebook accounts of engineers and other employees of major telecom corporations and SIM card manufacturers in an effort to secretly obtain information that could give them access to millions of encryption keys. They did this by utilizing the NSA’s X-KEYSCORE program, which allowed them access to private emails hosted by the SIM c…

Just as important, if you're an engineer, developer, or mathematician who works for the NSA or a similar agency, you need to take a long look in the mirror and ask yourself if this is really what you wanted to do when you grew up.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#100
post #39
post #32

Earlier quoted context omitted.

On that note, I wonder if their compromising of these systems affords the target any sort of immunization from attacks by other actors. It would make sense that NSA/GHCQ wouldn't want their foreign competitors to share in the prize, and it would also be congruent with their interests to not afford competing actors access to such a prize. Then again, this notion is likely far too romantic. The reality is probably clos…

Sometimes denying data to others is as good as advertising that someone else got there first. So you might want to leave the treasure trove in place so that nobody else figures out you have it. Intelligence is wheels within wheels within wheels...

and the inverse is that there can be good intel gleaned by watching who else is trying to get in.
Post reply on HN