Earlier quoted context omitted.
"Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people" Nothing new here - as the Belgacom hack has shown already.
I don't remember the reporting on the Belgacom hack mentioning that they were casually querying X-KEYSCORE as they reportedly did here to identify potential targets.
The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
121–130 of 200 posts
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#122Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#123Earlier quoted context omitted.
While certainly a step in the right direction, the lack of an open baseband remains a huge problem, even with TextSecure. Any smartphone has a whole separate OS running, with access to the system bus and memory, that we generally have zero visibility into. There could be exploitable bugs, there could be actual backdoors, and we just have no idea. If you truly want to secure data, you need to use an airgapped system w…
That should be a solvable problem, aren't there tons of operating systems professors and electrical engineers around in Europe that could in principle develop an open baseband chip and operating system? Germany and France should have an interest that their communication can't be trivially backdoored by the NSA.
If you want more details you may check OsmocomBB site and IRC.
> Germany and France should have an interest that their communication can't be trivially backdoored by the NSA.
Nobody saying that governments don't have trusted hardware with only their own backdoors. In almost every country manufacturer have to provide source code and specs in order to pass certification so gov does have everything needed.
Though it's not help anybody else as it's will never be open.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#124Earlier quoted context omitted.
Can you please provide your definition of intelligence? I would argue that theoretically , a government (or other entity) could use intelligence but use it within a set of moral and/or ethical guidelines that uses a system of checks and balances.
Intelligence is the dirty-but-necessary stuff that makes it possible to accurately guide diplomacy, economic policy, trade, and military action to achieve the desired goals of a nation-state for a minimum of cost. It includes internal security. Generally, intelligence cannot operate openly, even under a strict set of guidelines. Further, there will always be situations where efficacy runs into guidelines and somethin…
Why don't we skip the suggestive "thought experiments" and look at some facts instead.
A grand total of 3467 people in the USA have been killed by terror attacks since 1970[1].
In the same timeframe 2091 americans were killed by lightning strike[2] and roughly 102.000.000 died of old age.
Please explain how these numbers justify the NSA's yearly budget of $75 billion dollars, and their documented, ongoing violation of millions of people's privacy.
[1] http://www.start.umd.edu/gtd/search/Results.aspx?chart=fatal...
[2] http://en.wikipedia.org/wiki/Lightning_strike#Epidemiology
[3] http://money.cnn.com/2013/06/07/news/economy/nsa-surveillanc...
[4] https://firstlook.org/theintercept/2014/08/25/icreach-nsa-ci...
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#125"TOP-SECRET GCHQ documents reveal that the intelligence agencies accessed the email and Facebook accounts of engineers and other employees of major telecom corporations and SIM card manufacturers in an effort to secretly obtain information that could give them access to millions of encryption keys. They did this by utilizing the NSA’s X-KEYSCORE program, which allowed them access to private emails hosted by the SIM c…
This is not supported by any of the leaked documents. GCHQ certainly had full access to Gemalto's email servers, and several documents refer to information retrieved from there. There is nothing to show that data was ingested into XKEYSCORE and absolutely nothing to show that the employees' personal emails were in XKEYSCORE.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#126Nothing new. At this point nobody should consider any closed source encryption like something even nearly trustworthy.
While I agree in principle about open source, using purely open-source software would not have provided any defence here.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#127"TOP-SECRET GCHQ documents reveal that the intelligence agencies accessed the email and Facebook accounts of engineers and other employees of major telecom corporations and SIM card manufacturers in an effort to secretly obtain information that could give them access to millions of encryption keys. They did this by utilizing the NSA’s X-KEYSCORE program, which allowed them access to private emails hosted by the SIM c…
Just as important, if you're an engineer, developer, or mathematician who works for the NSA or a similar agency, you need to take a long look in the mirror and ask yourself if this is really what you wanted to do when you grew up.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#128Earlier quoted context omitted.
You conveniently left out Iceland, from the very same sentence that is the source of what you listed. As far as I know, Iceland is innocent of terrorism accusations from the US. (OK, benefit of the doubt: maybe The Intercept added Iceland to the article later, or you genuinely didn't see it.) Anyway, you really think the "bad countries" you named from a 5-year-old document are an exhaustive list of what they've got t…
From the Intercept article its not clear why this type of data was collected from an Icelandic carrier. The linked graph appears to show 100 IMSI's from Iceland, as opposed to 100,000 from Somalia* and tens of thousands from Afghanistan. It's possible that the Iceland data was acquired incidentally because it happened to come from the same sources that were sending data on more interesting countries. It's possible th…
I don't know how far I'd be willing to go to effect a hypothetical, unknown increase in safety and control. I do know that the US government and its allies are destroying the reputations of innocent companies, the peace of mind of hundreds of Gemalto/network employees who will now be wondering if they were personally hacked and to what extent, and the human rights of privacy of hundreds of thousands of people who use SIM cards. Is it worth it? I guess we'll never know, and I don't think the spies can truly say either.
Maybe some of that falls on leakers' shoulders too, but in any case it's not very confidence-inspiring that lowly people like Manning and Snowden were able to steal what they did.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#129How is snowden still producing high-level stuff like this? Did he really steal info on that many headline-worthy stories all in one go, or does he have fresh sources? Sometimes this feels like another instance of what I call the "weird al phenomenon", where any person who hears a silly parody of a pop song attributes it to weird al, because "wait, you're telling me there are other song parody writers?"
It's also likely or possible that other disclosures are labeled under Snowden in order not to compromise or reveal the existence of a new source.
Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
#130Isn't the NSA breaking US law by hacking into a commercial entity's network?