Live data from Hacker News

The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

firstlook.org

161–170 of 200 posts

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#162
What is problematic here is that the legitimacy of almost all information exchanged in a digital form has been lost almost entirely. How much longer must we presume ignorance in what is really happening? How much longer will the innocent be bullied through technological and psychological means to promote the interests of the current national security apparatus with interests entirely different than the rest of America/World? What happened to Aaron Swartz is only a taste of what is happening to the rest of us who believe these types of activities are unethical and a violation of constitutional law. Do we honestly believe that this isn't being used for insider trading, to capture sensitive medical information, and steal other trade secrets that should be protected by law? Wake up America. We need to stand up against this digital tyranny.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#163

Earlier quoted context omitted.

It has been my assumption that Facebook's and Google's core network and security teams are each a large crowd of embedded spies working for various intelligence agencies. Think about it: You're a NSA/Mossad/MI5 NetOps operative. You can have access to a lot of information without risking your life, get paid by your agency AND google/facebook. What's not to like?

Wouldn't work well. Way too many of these companies key employees are not US citizens and many aren't in the USA at all. Google, for example, has a large security team in Switzerland, with quite a few German and British employees. The NSA sees itself as a military organisation, it is bound by military rules.

Why would that matter? Intelligence agencies have turned foreign nationals before. And in the case of a US/British cross-over, those intelligence agencies have intelligence sharing agreements.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#164
I always wondered if HSMs are at risk to be compromised at the core (read: the manufacturer) such as those frome SafeNet (in use e.g. with Box.com on their enterprise external HSM plan).

And guess what, Gemalto merged with SafeNet the other day.

http://www.safenet-inc.com/SafeNet-Gemalto-Merger/

Everything is compromised. Everything!

References:

https://www.box.com/blog/breaking-the-last-barrier-to-cloud-...

http://www.safenet-inc.com/data-encryption/hardware-security...

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#166
post #151

Earlier quoted context omitted.

Conspiracy theories aside, couldn't the NSA just draft Google?

I'd be stunned if they didn't have employees embedded at Google and other major technology firms.

They do. In fact, there goal is to find fresh college grads who are just good enough to potentially get hired in these firms then send them into the firms as spies.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#167

"TOP-SECRET GCHQ documents reveal that the intelligence agencies accessed the email and Facebook accounts of engineers and other employees of major telecom corporations and SIM card manufacturers in an effort to secretly obtain information that could give them access to millions of encryption keys. They did this by utilizing the NSA’s X-KEYSCORE program, which allowed them access to private emails hosted by the SIM c…

They are already targeting me with a vast array of unconstitutional practices... and I'm just someone who is studying medicine and engineering...

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#168

Earlier quoted context omitted.

It has been my assumption that Facebook's and Google's core network and security teams are each a large crowd of embedded spies working for various intelligence agencies. Think about it: You're a NSA/Mossad/MI5 NetOps operative. You can have access to a lot of information without risking your life, get paid by your agency AND google/facebook. What's not to like?

Wouldn't work well. Way too many of these companies key employees are not US citizens and many aren't in the USA at all. Google, for example, has a large security team in Switzerland, with quite a few German and British employees. The NSA sees itself as a military organisation, it is bound by military rules.

> The NSA sees itself as a military organisation, it is bound by military rules.

What rules would that be? In the military, actively seeking (and using) information you have no right/classification to see is a serious offence. According to articles I've read, not a single NSA employee was disciplined for e.g. spying on their SOs or Exs.

Also: If the NSA doesn't have Swiss and German citizens working for it, it's not a very good intelligence agency. And we know for a fact that it is, at least as far as reach is concerned.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#169

"TOP-SECRET GCHQ documents reveal that the intelligence agencies accessed the email and Facebook accounts of engineers and other employees of major telecom corporations and SIM card manufacturers in an effort to secretly obtain information that could give them access to millions of encryption keys. They did this by utilizing the NSA’s X-KEYSCORE program, which allowed them access to private emails hosted by the SIM c…

Just as important, if you're an engineer, developer, or mathematician who works for the NSA or a similar agency, you need to take a long look in the mirror and ask yourself if this is really what you wanted to do when you grew up.

"Just as important, if you're an engineer, developer, or mathematician who works for the NSA or a similar agency, you need to take a long look in the mirror and ask yourself if this is really what you wanted to do when you grew up."

No, don't look in the mirror, waste of time. Walk away from your job.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#170

Earlier quoted context omitted.

"They did this by utilizing the NSA’s X-KEYSCORE program, which allowed them access to private emails hosted by the SIM card and mobile companies’ servers, as well as those of major tech corporations, including Yahoo and Google." This is not supported by any of the leaked documents. GCHQ certainly had full access to Gemalto's email servers, and several documents refer to information retrieved from there. There is not…

XKEYSCORE holds metadata, it seems. One document that explicitly stated they knew the Thailand employee was emailing PGP encrypted files because of data they retrieved from XKEYSCORE. He then became a target as a result.

Op sounds like a shill. Seen that before in other related threads...
Post reply on HN