Live data from Hacker News

The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

firstlook.org

131–140 of 200 posts

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#131
post #122

Nothing new. At this point nobody should consider any closed source encryption like something even nearly trustworthy.

That has very little to do with this particular attack. The NSA did not attack the proprietary code, which uses standard, open, and publicly-known and documented cryptographic operations, by the way. They compromised the key custodians. While I agree in principle about open source, using purely open-source software would not have provided any defence here.

> While I agree in principle about open source, using purely open-source software would not have provided any defence here.

In open source software / hardware there wouldn't be "master key" that can't be changed and that have to be used by telecom's. Yeah of course no doubt NSA may penetrate in network of every of them, but it's would be a lot more costly.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#132
post #85

Earlier quoted context omitted.

When you hold the Poisoned Chalice of Power you get to decide who is legally justified and who isn't. "Morals" doesn't even factor into things....unfortunately.

Only in a limited way though, the NSA can decide (or at least exert considerable influence over) what's legal in the US - but criminal actions in, say, The Netherlands or any other (non five eyes) country, cannot be "justified" or "excused" legally by another except those countries. I guess a _lot_ of what goes in in state sponsored espionage happens outside the civilian legal system - at least in "major" countries -…

But how do you identify an anonymous NSA hacker?

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#133
post #4

This is yet another good argument for TextSecure and RedPhone, which don't depend on the SIM card encryption. https://whispersystems.org/

It's unfortunate that the free Linphone for iOS crashes since the last update... it offers standard ZRTP calls for iOS.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#134
post #129
post #89

Earlier quoted context omitted.

It's also likely or possible that other disclosures are labeled under Snowden in order not to compromise or reveal the existence of a new source.

In fact, Bruce Schneier believes there's another, unknown NSA leaker besides Snowden: https://www.schneier.com/blog/archives/2014/08/the_us_intell...

It was already confirmed in the documentary CITIZENFOUR

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#135
Since the US and British governments operate on the premise of invading the privacy of all citizens without warrant in order to prevent a handful of bad apples, should other countries consider a temporary blanket ban on all US citizens from visiting to their countries in order to make a point?

I know that only 4% of US citizens have passports, and most countries rely on US trade, but still it would certainly send a message?

Simplistic I know but somehow we need to voice our dissatisfaction with the way things are headed. Foreign citizens can't change US policy, only US citizens can vote out their corrupted system.

The privacy of non-US citizens is considered as fair game. We have no comeback presently.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#136
post #72

Earlier quoted context omitted.

Intelligence is the dirty-but-necessary stuff that makes it possible to accurately guide diplomacy, economic policy, trade, and military action to achieve the desired goals of a nation-state for a minimum of cost. It includes internal security. Generally, intelligence cannot operate openly, even under a strict set of guidelines. Further, there will always be situations where efficacy runs into guidelines and somethin…

Generally, intelligence cannot operate openly, even under a strict set of guidelines. Can this claim be substantiated with evidence?

No. Otherwise police departments would be unable to do anything and would cease to exist. Police operations vary in secrecy but even the most secret eventually stop being so, as there is a need to actually prosecute.

The idea that "spys gonna spy" is one we need to start collectively challenging. Why do we need these organisations at all? If NSA/GCHQ were wound up and their technical specialists re-allocated 80% to domestic law enforcement for computer forensics purposes, and 20% to a new dedicated counter-intel-only organisation, would the sky fall? I doubt it.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#137

Earlier quoted context omitted.

Just as important, if you're an engineer, developer, or mathematician who works for the NSA or a similar agency, you need to take a long look in the mirror and ask yourself if this is really what you wanted to do when you grew up.

What, work with some of the smartest people on the planet with a near-infinite budget solving the biggest big data problems out there whilst defending your country from turrists? Sign me up!

The smartest people on the planet are not working at the NSA. Most of what they're doing is just plain old data aggregation and analysis, with a side helping of large scale but ordinary hacking. The type that lots of teenagers have done.

From a technical perspective, the sort of research going on at Google (deep neural nets, etc) is in a whole other intellectual league.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#138

"TOP-SECRET GCHQ documents reveal that the intelligence agencies accessed the email and Facebook accounts of engineers and other employees of major telecom corporations and SIM card manufacturers in an effort to secretly obtain information that could give them access to millions of encryption keys. They did this by utilizing the NSA’s X-KEYSCORE program, which allowed them access to private emails hosted by the SIM c…

"They did this by utilizing the NSA’s X-KEYSCORE program, which allowed them access to private emails hosted by the SIM card and mobile companies’ servers, as well as those of major tech corporations, including Yahoo and Google." This is not supported by any of the leaked documents. GCHQ certainly had full access to Gemalto's email servers, and several documents refer to information retrieved from there. There is not…

XKEYSCORE holds metadata, it seems. One document that explicitly stated they knew the Thailand employee was emailing PGP encrypted files because of data they retrieved from XKEYSCORE. He then became a target as a result.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#139
post #101

"TOP-SECRET GCHQ documents reveal that the intelligence agencies accessed the email and Facebook accounts of engineers and other employees of major telecom corporations and SIM card manufacturers in an effort to secretly obtain information that could give them access to millions of encryption keys. They did this by utilizing the NSA’s X-KEYSCORE program, which allowed them access to private emails hosted by the SIM c…

As other people have stated here, security is a justified means to an end to those who practice it. I cringe a little bit whenever someone starts on the "first they came for..." monologue. Not because it isn't true, but because it first was used talking about the Jews in WWII Germany. You're effectively playing the Hitler card in a debate that isn't about Hitler. The US was built in part by this type of security. Cha…

What kicked off this whole thing was Clapper lying to the elected representative about what the NSA was doing. That was the trigger event that caused Snowden to finally leak his cache. So I don't think you can totally blame Congress or the Senate, even though they surely have deep problems.

The US was not built by this type of security. What the NSA is doing only became possible quite recently. It's just in a whole other world to what was previously imaginable.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#140
post #4

This is yet another good argument for TextSecure and RedPhone, which don't depend on the SIM card encryption. https://whispersystems.org/

While certainly a step in the right direction, the lack of an open baseband remains a huge problem, even with TextSecure. Any smartphone has a whole separate OS running, with access to the system bus and memory, that we generally have zero visibility into. There could be exploitable bugs, there could be actual backdoors, and we just have no idea. If you truly want to secure data, you need to use an airgapped system w…

Modern basebands are sandboxed, from what I understand. Partly because phones kept getting unlocked through exploiting baseband bugs and that messes with carrier subsidies.
Post reply on HN