Live data from Hacker News

The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

firstlook.org

141–150 of 200 posts

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#141
post #131

Earlier quoted context omitted.

That has very little to do with this particular attack. The NSA did not attack the proprietary code, which uses standard, open, and publicly-known and documented cryptographic operations, by the way. They compromised the key custodians. While I agree in principle about open source, using purely open-source software would not have provided any defence here.

> While I agree in principle about open source, using purely open-source software would not have provided any defence here. In open source software / hardware there wouldn't be "master key" that can't be changed and that have to be used by telecom's. Yeah of course no doubt NSA may penetrate in network of every of them, but it's would be a lot more costly.

No, really, this isn't about open source stuff.

Any architecture that requires pre-shared symmetric keys is going to have this problem. The fix is architectural, not open sourcing stuff. From what I understand LTE is significantly better.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#142

This is exactly why Intel's upcoming SGX worries me greatly, too. NSA could get the "key" to all SGX machines and therefore to all applications using SGX to secure themselves properly (ironically enough) [1]. Intel really needs to figure out how to protect the SGX system against such a key robbery, and not by promising to only give access to a couple of employees in the whole company who know a very special hand-shak…

You mistake the point of SGX. The point of is a reincarnation of treacherous computing. Intel SGX requires remote attestation. This means that YOU, the owner of the device, is not trusted. To have 3rd party keys would mean they would have to trust you. With trust in you, how could it be marketed to the copyright owners? The answer is that it cannot. The point of Intel SGX is to deny ownership of the device to its own…

SGX does not require remote attestation. Just like all prior TC platforms, it offers remote attestation but there is no requirement that it be used.

By the way, very frequently the owner of a computer is not in fact trustworthy. Situations where that occurs crop up all the time in security engineering.

For example a big use of TC is making Bitcoin wallets that are secure against malware. There are other uses too, like safe outsourcing of private data storage/computation to the cloud.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#145

Earlier quoted context omitted.

What, work with some of the smartest people on the planet with a near-infinite budget solving the biggest big data problems out there whilst defending your country from turrists? Sign me up!

The smartest people on the planet are not working at the NSA. Most of what they're doing is just plain old data aggregation and analysis, with a side helping of large scale but ordinary hacking. The type that lots of teenagers have done. From a technical perspective, the sort of research going on at Google (deep neural nets, etc) is in a whole other intellectual league.

Conspiracy theories aside, couldn't the NSA just draft Google?

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#147
It doesn't justify the NSA/GCHQ's actions but the fact these keys could be stolen like that mostly means mobile communications were never really secure in the first place.

I am every day more appalled by the scale of the data breaches we learn about every week.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#148

Earlier quoted context omitted.

You mistake the point of SGX. The point of is a reincarnation of treacherous computing. Intel SGX requires remote attestation. This means that YOU, the owner of the device, is not trusted. To have 3rd party keys would mean they would have to trust you. With trust in you, how could it be marketed to the copyright owners? The answer is that it cannot. The point of Intel SGX is to deny ownership of the device to its own…

SGX does not require remote attestation. Just like all prior TC platforms, it offers remote attestation but there is no requirement that it be used. By the way, very frequently the owner of a computer is not in fact trustworthy. Situations where that occurs crop up all the time in security engineering. For example a big use of TC is making Bitcoin wallets that are secure against malware. There are other uses too, lik…

Yup, cloud is a major motivation for SGX (see e.g. https://www.usenix.org/system/files/conference/osdi14/osdi14... for an example of how it might be put to use). I think it is good idea for making it more difficult for malicious insiders to mount an attack, but any claims of it protecting you from the NSA are laughable given Intel will probably hand over keys to them anyway.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#149
post #134
post #129

Earlier quoted context omitted.

In fact, Bruce Schneier believes there's another, unknown NSA leaker besides Snowden: https://www.schneier.com/blog/archives/2014/08/the_us_intell...

It was already confirmed in the documentary CITIZENFOUR

That's the third leaker, not the second one.

1. Snowden

2. Unknown NSA leaker

3. Unknown National Counterterrorism Center (NCTC) leaker

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#150
post #4

This is yet another good argument for TextSecure and RedPhone, which don't depend on the SIM card encryption. https://whispersystems.org/

While certainly a step in the right direction, the lack of an open baseband remains a huge problem, even with TextSecure. Any smartphone has a whole separate OS running, with access to the system bus and memory, that we generally have zero visibility into. There could be exploitable bugs, there could be actual backdoors, and we just have no idea. If you truly want to secure data, you need to use an airgapped system w…

Indeed. Samsung baseband was found to have a backdoor to read files in the phone.

https://www.fsf.org/blogs/community/replicant-developers-fin...

Post reply on HN