Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

101–110 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#101

Earlier quoted context omitted.

Funny, I don't really care China spying on me as much since they just don't have any handles that would be relevant. Your own government spying on you is much more dangerous. And since I don't have influence on policies of China, I can at least hold domestic politicians that strive for more surveillance accountable. At least theoretically. History shows that government isn't your friend at all. The US might be a rare…

As a US citizen and resident I would far more prefer to have to contend with the US Govt than the CCP on this matter. At least in the US there is some legal procedure, accountability and civil society culture around limiting govt power. With the CCP there is none of that, neither for Chinese citizens nor foreigners. It’s clear that the CCP is assembling a database of information on everyone in the developed world, no…

> At least in the US there is some legal procedure, accountability and civil society culture around limiting govt power.

No: go read about National Security Letters.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#102

Earlier quoted context omitted.

I'm not sure that makes sense. The US could compel the devs to compromise their product but not keep them from issuing a cryptic statement and stopping work on the product?

It doesn't make sense for two reasons to me. For one, the government can't compel you to do work. That's slavery. Also, it's open source software. TrueCrypt going down didn't change the security landscape at all.

The government can. For example, take how the police will turn individuals into informants by getting them on trumped up drug charges and then offering them a deal if they work for the government, including engaging in acts that put them at risk of being killed.

https://en.wikipedia.org/wiki/Murder_of_Rachel_Hoffman

The end result is "Work for us or go to prison."

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#103
post #43

Earlier quoted context omitted.

Well, yes, but for third parties like the UK it makes it much more explicit that the choice is between the system that might be compromised by Huawei and the system that might be compromised by the US. Except the UK has its own little joint venture of security inspection of Huawei systems ...

please expand..

New account, 1 post.. I woulnd't answer "OBFUSCATED"'s question.. seems like he's already picked where to dig the ditch for the commenter. GCHQ? Something nastier?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#104

Earlier quoted context omitted.

I'm not sure that makes sense. The US could compel the devs to compromise their product but not keep them from issuing a cryptic statement and stopping work on the product?

It doesn't make sense for two reasons to me. For one, the government can't compel you to do work. That's slavery. Also, it's open source software. TrueCrypt going down didn't change the security landscape at all.

> For one, the government can't compel you to do work. That's slavery.

Slavery's perfectly legal. The 13th Amendment:

"Neither slavery nor involuntary servitude, except as a punishment for crime whereof the party shall have been duly convicted, shall exist within the United States, or any place subject to their jurisdiction."

https://en.wikipedia.org/wiki/Penal_labor_in_the_United_Stat...

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#105

What a treat to read a well written piece based on decent research. It's a long read but well worth your time. Kudo's to the journalists who helped uncover it. And the 'coup of the century' is far from clickbait, it's definitionally warranted for what the CIA and BND did here. It's a little ironic as well, especially since the US is so keen on blocking Huawei over espionage concerns.

No, this is not original research, this isn't being uncovered now, and I'm not sure why this is being republished now in 2020.

There have been detailed leaks since 1995 on cryptome.org and crypto mailing lists about CryptoAG, including details about the message format and the bits used to leak parts of the key (16 bit leak, IIRC).

The CryptoAG story has tainted all Swiss-based crypto/security firms since 1994.

[1] https://www.cryptomuseum.com/people/hans_buehler.htm

[2] Verschlüsselt, Der Fall Hans Bühler, ISBN 3-85932-141-2. 1994 - Book written by former CryptoAG employee Hans Buehler (1994).

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#106

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

Funny, I don't really care China spying on me as much since they just don't have any handles that would be relevant. Your own government spying on you is much more dangerous. And since I don't have influence on policies of China, I can at least hold domestic politicians that strive for more surveillance accountable. At least theoretically. History shows that government isn't your friend at all. The US might be a rare…

Yes, you may not care if you are spied on, as I do not. But do you care if our Congresspeople are spied on by China? I sure as heck do.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#107
post #17
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

I'm pretty sure the US government is why the TrueCrypt devs stopped all work. They got hit with a national security letter (NSL) or heavily leaned on and pressured to stop making their product so awesome and un-breakable.

Why then aren't they able to do the same with LUKS, dm-crypt, cryfs, bitlocker etc?

Does that mean they are only available because the 3 letter agencies can hack them?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#108
My new startup focuses on human nervous system faraday cages embedded into next generation fashion technology. This tech covers your entire body, keeping you safe from remote scans, and includes realistic facial and body disguises. For your safety, our tech constantly scans your thought patterns and memories and keeps them safe with a static filled triple scrambled encryption method, and encodes them into specially placed augmented cellular technology at undisclosed locations in the body.

For funding, please visit https://CE.YA/

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#109
post #87

Earlier quoted context omitted.

I don't even understand the theory underneath this supposed conspiracy, since full-disk encryption is utterly mainstream at this point. I also don't need to get too deep into what I don't like about TrueCrypt; use it if you like it. The problem is with the model of full-disk encryption; outside of phones with deeply integrated hardware designs that support it, FDE is the least powerful form of encryption we use. It w…

Again: why do you use such belittling words like "conspiracy theory"? We know that the services interfere. We know that they interfered with vendors of cryptography products. And we know that National Security Letters exist, as do other – legal – means to pressure such vendors. There is no conspiracy needed for them to try to pressure someone by, say, threatening them with denial of a entry visa. Or they could have s…

> what would they have done if the suspect hadn't used his laptop in a public place?

Screw open his laptop when it's turned off and he's away from home, install a keylogger into the bios. Put a camera onto the shelf to film which keys he types to log in. If he puts a blanket over his head: solely rely on the sound each key makes. Hack his computer remotely using one of the government owned 0days and dump the keys. Use side channels to attain the password via the power outlet in the neighbouring house.

They had countless ways and they chose the one that revealed the least about their capabilities.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#110
Would be cool if the Agency did relatively more of this kind of thing and relatively less of, for example, paying psychotic Afghan pedophile warlords hundreds of millions of dollars for reneged-upon power sharing agreements and HUMINT of dubious value.
Post reply on HN