Live data from Hacker News

The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

firstlook.org

121–130 of 200 posts

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#121
post #47

Earlier quoted context omitted.

"Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people" Nothing new here - as the Belgacom hack has shown already.

I don't remember the reporting on the Belgacom hack mentioning that they were casually querying X-KEYSCORE as they reportedly did here to identify potential targets.

See the comment below in this subthread. You are right, no mentioning of XKEYSCORE but they pretty much owned their whole mail server(s).

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#123

Earlier quoted context omitted.

While certainly a step in the right direction, the lack of an open baseband remains a huge problem, even with TextSecure. Any smartphone has a whole separate OS running, with access to the system bus and memory, that we generally have zero visibility into. There could be exploitable bugs, there could be actual backdoors, and we just have no idea. If you truly want to secure data, you need to use an airgapped system w…

That should be a solvable problem, aren't there tons of operating systems professors and electrical engineers around in Europe that could in principle develop an open baseband chip and operating system? Germany and France should have an interest that their communication can't be trivially backdoored by the NSA.

Main issue is there really no specifications available on many things. Also it's will be nearly impossible to pass certification so no real manufacturer would use it.

If you want more details you may check OsmocomBB site and IRC.

> Germany and France should have an interest that their communication can't be trivially backdoored by the NSA.

Nobody saying that governments don't have trusted hardware with only their own backdoors. In almost every country manufacturer have to provide source code and specs in order to pass certification so gov does have everything needed.

Though it's not help anybody else as it's will never be open.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#124
post #72

Earlier quoted context omitted.

Can you please provide your definition of intelligence? I would argue that theoretically , a government (or other entity) could use intelligence but use it within a set of moral and/or ethical guidelines that uses a system of checks and balances.

Intelligence is the dirty-but-necessary stuff that makes it possible to accurately guide diplomacy, economic policy, trade, and military action to achieve the desired goals of a nation-state for a minimum of cost. It includes internal security. Generally, intelligence cannot operate openly, even under a strict set of guidelines. Further, there will always be situations where efficacy runs into guidelines and somethin…

Would you be willing to violate the privacy of one person to prevent an attack that would kill five thousand?

Why don't we skip the suggestive "thought experiments" and look at some facts instead.

A grand total of 3467 people in the USA have been killed by terror attacks since 1970[1].

In the same timeframe 2091 americans were killed by lightning strike[2] and roughly 102.000.000 died of old age.

Please explain how these numbers justify the NSA's yearly budget of $75 billion dollars, and their documented, ongoing violation of millions of people's privacy.

[1] http://www.start.umd.edu/gtd/search/Results.aspx?chart=fatal...

[2] http://en.wikipedia.org/wiki/Lightning_strike#Epidemiology

[3] http://money.cnn.com/2013/06/07/news/economy/nsa-surveillanc...

[4] https://firstlook.org/theintercept/2014/08/25/icreach-nsa-ci...

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#125

"TOP-SECRET GCHQ documents reveal that the intelligence agencies accessed the email and Facebook accounts of engineers and other employees of major telecom corporations and SIM card manufacturers in an effort to secretly obtain information that could give them access to millions of encryption keys. They did this by utilizing the NSA’s X-KEYSCORE program, which allowed them access to private emails hosted by the SIM c…

"They did this by utilizing the NSA’s X-KEYSCORE program, which allowed them access to private emails hosted by the SIM card and mobile companies’ servers, as well as those of major tech corporations, including Yahoo and Google."

This is not supported by any of the leaked documents. GCHQ certainly had full access to Gemalto's email servers, and several documents refer to information retrieved from there. There is nothing to show that data was ingested into XKEYSCORE and absolutely nothing to show that the employees' personal emails were in XKEYSCORE.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#126
post #122

Nothing new. At this point nobody should consider any closed source encryption like something even nearly trustworthy.

That has very little to do with this particular attack. The NSA did not attack the proprietary code, which uses standard, open, and publicly-known and documented cryptographic operations, by the way. They compromised the key custodians.

While I agree in principle about open source, using purely open-source software would not have provided any defence here.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#127

"TOP-SECRET GCHQ documents reveal that the intelligence agencies accessed the email and Facebook accounts of engineers and other employees of major telecom corporations and SIM card manufacturers in an effort to secretly obtain information that could give them access to millions of encryption keys. They did this by utilizing the NSA’s X-KEYSCORE program, which allowed them access to private emails hosted by the SIM c…

Just as important, if you're an engineer, developer, or mathematician who works for the NSA or a similar agency, you need to take a long look in the mirror and ask yourself if this is really what you wanted to do when you grew up.

What, work with some of the smartest people on the planet with a near-infinite budget solving the biggest big data problems out there whilst defending your country from turrists? Sign me up!

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#128

Earlier quoted context omitted.

You conveniently left out Iceland, from the very same sentence that is the source of what you listed. As far as I know, Iceland is innocent of terrorism accusations from the US. (OK, benefit of the doubt: maybe The Intercept added Iceland to the article later, or you genuinely didn't see it.) Anyway, you really think the "bad countries" you named from a 5-year-old document are an exhaustive list of what they've got t…

From the Intercept article its not clear why this type of data was collected from an Icelandic carrier. The linked graph appears to show 100 IMSI's from Iceland, as opposed to 100,000 from Somalia* and tens of thousands from Afghanistan. It's possible that the Iceland data was acquired incidentally because it happened to come from the same sources that were sending data on more interesting countries. It's possible th…

In the interest of the fuller picture, thanks for noting that Iceland and Tajikistan were incidental. I don't know that we have a definitive answer from these docs on whether those keys were even saved. Even if not, it's unsettling that an "automated process" turns up keys "not on the list of interest." The article even says the "system failed to produce results against Pakistani networks, denoted as “priority targets” in the document."

I don't know how far I'd be willing to go to effect a hypothetical, unknown increase in safety and control. I do know that the US government and its allies are destroying the reputations of innocent companies, the peace of mind of hundreds of Gemalto/network employees who will now be wondering if they were personally hacked and to what extent, and the human rights of privacy of hundreds of thousands of people who use SIM cards. Is it worth it? I guess we'll never know, and I don't think the spies can truly say either.

Maybe some of that falls on leakers' shoulders too, but in any case it's not very confidence-inspiring that lowly people like Manning and Snowden were able to steal what they did.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#129
post #89

How is snowden still producing high-level stuff like this? Did he really steal info on that many headline-worthy stories all in one go, or does he have fresh sources? Sometimes this feels like another instance of what I call the "weird al phenomenon", where any person who hears a silly parody of a pop song attributes it to weird al, because "wait, you're telling me there are other song parody writers?"

It's also likely or possible that other disclosures are labeled under Snowden in order not to compromise or reveal the existence of a new source.

In fact, Bruce Schneier believes there's another, unknown NSA leaker besides Snowden: https://www.schneier.com/blog/archives/2014/08/the_us_intell...
Post reply on HN