Live data from Hacker News

The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

firstlook.org

101–110 of 200 posts

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#101

"TOP-SECRET GCHQ documents reveal that the intelligence agencies accessed the email and Facebook accounts of engineers and other employees of major telecom corporations and SIM card manufacturers in an effort to secretly obtain information that could give them access to millions of encryption keys. They did this by utilizing the NSA’s X-KEYSCORE program, which allowed them access to private emails hosted by the SIM c…

As other people have stated here, security is a justified means to an end to those who practice it.

I cringe a little bit whenever someone starts on the "first they came for..." monologue. Not because it isn't true, but because it first was used talking about the Jews in WWII Germany. You're effectively playing the Hitler card in a debate that isn't about Hitler.

The US was built in part by this type of security. Chances are things would be very different here if the security professionals over the years made decisions based on moral qualms.

I am playing the devils advocate, but when you look at the senate, it's hard to actually point a finger at the intelligence agencies. This is the world we have made, fear mongering hardly fits into this argument, and certainly adds nothing of substance.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#102
post #84
post #77

Earlier quoted context omitted.

Manual baseband isolation via mobile hotspot and nexus 7, does the trick for now

Until the AMSS in the hotspot is compromised and used to attack your Android device via wifi. This applies to mobile hotspots built around Qualcomm baseband/application processors, in other cases you would have to exploit the main CPU first.

Well, at least that requires two exploits/backdoors, instead of one.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#103

At some point, people have to begin to realize that this has progressed past "looking for terrorists." Statists are gonna state, I guess.

The article specifically cites the mobile phone networks of Iran, Yemen, Afghanistan, and Somalia as targets. One is a state sponsor of terrorism, the other three are places where the US is actively fighting terrorism.

You conveniently left out Iceland, from the very same sentence that is the source of what you listed. As far as I know, Iceland is innocent of terrorism accusations from the US. (OK, benefit of the doubt: maybe The Intercept added Iceland to the article later, or you genuinely didn't see it.)

Anyway, you really think the "bad countries" you named from a 5-year-old document are an exhaustive list of what they've got today? You think the agencies won't scoop up any other countries' keys, including the United States', just in case their metadata graphs later suggest sleeper agents in "the good countries"?

I'm too ticked to make a good argument about morality or lack thereof right now, so I'll just leave it here. They hacked and surveilled non-terrorists to get the keys, and got the keys of at least one "non-terrorist country" (Iceland), so no, I don't find your argument convincing, and I think the parent post's point stands.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#105

Earlier quoted context omitted.

The article specifically cites the mobile phone networks of Iran, Yemen, Afghanistan, and Somalia as targets. One is a state sponsor of terrorism, the other three are places where the US is actively fighting terrorism.

You conveniently left out Iceland, from the very same sentence that is the source of what you listed. As far as I know, Iceland is innocent of terrorism accusations from the US. (OK, benefit of the doubt: maybe The Intercept added Iceland to the article later, or you genuinely didn't see it.) Anyway, you really think the "bad countries" you named from a 5-year-old document are an exhaustive list of what they've got t…

From the Intercept article its not clear why this type of data was collected from an Icelandic carrier. The linked graph appears to show 100 IMSI's from Iceland, as opposed to 100,000 from Somalia* and tens of thousands from Afghanistan. It's possible that the Iceland data was acquired incidentally because it happened to come from the same sources that were sending data on more interesting countries. It's possible that there's something of value to be learned in Iceland. I don't know. The Intercept gives us very little context as to the actual products that the intelligence agencies produce. [Edit: Page 11 of this document indicates that the acquisition of keys from Iceland and Tajikistan was unexpected and that those countries were not targeted: https://firstlook.org/theintercept/document/2015/02/19/pcs-h...]

I don't dispute the fact that the US government has intelligence-gathering priorities that don't involve terrorism. I would argue that at least one reason terrorism is discussed is that there are diplomatic consequences to saying one spies on foreign governments. I also agree with the more cynical view, that terrorism is cited as a rationale because terrorism is scary and something opposed by everyone the US is trying to convince.

I believe very strongly that the world would be a lot safer if the US government knew certain things like the intentions of the Russian leadership and the capabilities of the Russian armed forces. Or the state of the Iranian nuclear program and that country's negotiating position. Or what exactly is happening on the ground in the midst of all the chaos in Libya or Syria or Yemen.

The answers to these questions will determine the fate of entire regions of the world.

*A subsequent document puts a later figure for Somalia at 300,000.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#106

Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…

Indeed,

It is gradually recursing backward to "invasive targeting of completely innocent and ordinary people simply as a means to get access more innocent and ordinary people in order to ...etc"

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#107
post #39

Earlier quoted context omitted.

Sometimes denying data to others is as good as advertising that someone else got there first. So you might want to leave the treasure trove in place so that nobody else figures out you have it. Intelligence is wheels within wheels within wheels...

and the inverse is that there can be good intel gleaned by watching who else is trying to get in.

And you can learn a lot by letting them in and seeing what they look for.

Emphasis on can, of course.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#109
post #58

Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…

I wonder how many years with of jail time Aaron Schwartz's prosecutors would be talking about if this'd been done by a mouthy kid instead of the NSA? I wonder which non-US country, where the NSA's actions aren't made "legal" by secret FISA courts or acts of (US) Congress, will be the first to start throwing that kind of legal threat at NSA staff responsible for this?

What do you think spying is? By definition it is illegal. Other countries won't do anything but cry a bit because their hands aren't much cleaner.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#110
post #101

"TOP-SECRET GCHQ documents reveal that the intelligence agencies accessed the email and Facebook accounts of engineers and other employees of major telecom corporations and SIM card manufacturers in an effort to secretly obtain information that could give them access to millions of encryption keys. They did this by utilizing the NSA’s X-KEYSCORE program, which allowed them access to private emails hosted by the SIM c…

As other people have stated here, security is a justified means to an end to those who practice it. I cringe a little bit whenever someone starts on the "first they came for..." monologue. Not because it isn't true, but because it first was used talking about the Jews in WWII Germany. You're effectively playing the Hitler card in a debate that isn't about Hitler. The US was built in part by this type of security. Cha…

I understand why that might make you uncomfortable, and I do hesitate to make such comparisons. But, you know who cringes when they hear about the surveillance apparatus that we are building in the Five Eyes countries? Germans.
Post reply on HN