Live data from Hacker News

The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

firstlook.org

171–180 of 200 posts

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#171

Earlier quoted context omitted.

Generally, intelligence cannot operate openly, even under a strict set of guidelines. Can this claim be substantiated with evidence?

No. Otherwise police departments would be unable to do anything and would cease to exist. Police operations vary in secrecy but even the most secret eventually stop being so, as there is a need to actually prosecute. The idea that "spys gonna spy" is one we need to start collectively challenging. Why do we need these organisations at all? If NSA/GCHQ were wound up and their technical specialists re-allocated 80% to d…

Have you examined your proposal for drawbacks?

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#172
post #38

Personally, my biggest takeaway is that anything centralized is compromised, period. Any centralized system is such a juicy target that the NSA will compromise it. The only way to avoid dragnet issues is to decentralize and force the NSA to expend resources at the edges. This doesn't means that you can make an individual target secure. The NSA can always outspend you. But you can prevent the NSA from easily just vacu…

Agreed. I still wait to learn that AWS is compromised on a huge scale too. No words yet - mark this post and let's see and wait.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#173

Earlier quoted context omitted.

I can confirm this. In many cases these keys are exchanged over email with simple DES encryption and a key known to everybody in the business (pretty obvious key BTW). It really boils down to the security procedures in place between the SIM manufacturer and Mobile Network Operators.

I want to chime in to offer the counter. I used to work for Gemalto. I'm not exactly sure which keys you are talking about, but when I was there Gemalto's standard practice for the transfer of the keys mentioned in the article--individual SIM embedded keys--was to use AllynisConnect (which I only mention because it's easily found on Google) to facilitate the transfer of individual SIM keys to the customer. Obviously…

https://allynisconnect1.gemalto.com/jsp/tp_logon.jsp

Great - on the open net. No 2FA visible in the first peek.

Way to fuck your customers customers privacy.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#174
post #52
post #39

Earlier quoted context omitted.

Sometimes denying data to others is as good as advertising that someone else got there first. So you might want to leave the treasure trove in place so that nobody else figures out you have it. Intelligence is wheels within wheels within wheels...

Good point. However, it might be possible to deny adversaries without alerting them to the fact that they were denied in the first place.

Depends how advanced the adversary is. It also depends on if you want to deny them, because you might learn something by watching what they do. Or you might feed them false data and see what happens.

Aren't mind games fun?

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#177
One key thing that stood out to me was this:

> [GCHQ operatives] noted that the use of PGP could mean the contents were potentially valuable.

This good reminder that encrypting everything is important for security. Only encrypting valuable or sensitive information provides information to an attacker on where they should focus their efforts.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#178

Earlier quoted context omitted.

So they just decided to declassify or screw up all the intelligence operations that did just that to give them selves a bad rep?

I am not concerned about that. It is bad practice to damage security for all because of few. This is all I am saying. It seems like a pretty bad idea to me.

Damage security? They didn't damage the security of the products because of this, if anything you should take of is just how easily these products can be compromised in such manner.

All the NSA did is to steal keys which they can then use to interdict cellular communications, it's not like they put in a weakness by design and then exploited it (which they might have done in other operations but that's a completely different story).

This thing is no different than the digital signatures on the driver used by Stuxnet ("oddly enough" both companies which were compromised were in the same industrial park just a across of a shared parking lot from each other ;)).

Sadly this level of operation is plausible to be committed not only by private intelligence agencies (which we had too many off already) but by crime organizations as well. I've seen case of corporate espionage which were more complex than this one.

Instead of huffing and puffing at the NSA the proper lesson to learn from this is that cellphone carriers should stop relying on SIM card manufacturers in China and India for their encryption.

Heck if the NSA can interdict equipment in transit to tamper with it, how hard would you think does the Chinese intelligence service has to work to go down the street and just demand the keys straight from the source?

It's about a good damn time that people start asking questions on who has access to the private keys which are used in so many day to day operations from the keys used to authenticate your cable modem to the keys in the card reader you swiped your card trough at your local coffee shop. The answer to this should force quite a few people to live in a hunting lodge in Montana for sure.

I in fact would be very surprised to find a single mass used commercial cryptosystem which is actually secure. Because which each and everyone of those the keys to the castle end up being in the hands of the lowest paid employees out there and business practices will always force availability and serviceability over security.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#179

Earlier quoted context omitted.

But if you've been following the Firstlook disclosures, and the response to it from different governments, you'll notice that they don't really want to hold anyone accountable - likely, they are all on it some way or another. Ireland rushed to retroactively OK british spying. Germany ignored it (with some theatrical "I'm insulted" remarks from Merkel, but no real action). The assumption that any government out there…

Germany's investigation found that it likely didn't happen and that the documents saying it did were possibly forgeries. http://mobile.reuters.com/article/idUSKBN0JP1QG20141211?irpc... > "the document presented in public as proof of an actual tapping of the mobile phone is not an authentic surveillance order by the NSA. It does not come from the NSA database. > "There is no proof at the moment which could lead to cha…

Did you RTFA?

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#180
Interestingly this is about Gemalto, a company with a remarkable history.

Remember times when the USofA wasn't adopting the smart card technology ? Well it had something to do with this chip technology (crypto) being a foreign technology which coincidently was the propriety of the French company Gemplus.

At the turn of the millenium an US investment funds (Texas Pacific Group) managed to find its way in Gemplus capital after a couple denials, which is the start what is known in France as l'affaire Gemplus. To summarize instead of helping to conquer the US market, TPG used its power to change the board of director (and choose Alex Mandl as the head), initiated rounds of layoff and moved the R&D to the US to take control of the sought after technology.

The whole thing is shown to be an operation of the C.I.A. through In-Q-Tel to take control of the chip card technology and possibly insert backdoors before exporting. Slow to react, it takes several years for the french government to create its own version of In-Q-Tel called "Fonds Stratégique d'Investissement" and try to reclaim Gemplus, now Gemalto, by becoming the majority stakeholder with 8% of shares in 2009, a move that happens too late and TPG having gotten what they wanted sells its share a year later.

Post reply on HN