Earlier quoted context omitted.
I guess funding was not a big issue for the CIA...
They are still flush with cash from decades of running cocaine.
New German law would force ISPs to allow secret service to install trojans
101–110 of 245 posts
Re: New German law would force ISPs to allow secret service to install trojans
#102Pretty shocking in a state that has such strict privacy laws. Not sure how the two can come from the same mouth, and even be in public view. My understanding is that the privacy restrictions are largely the result of half the country having lived under the Statsi, and thus being extremely weary of government eyes. Here it’s out in the open!
If viewed from the different perspective of government intrusion on tech, it can appear less shocking. A government encouraged by its citizenry to use its leverage over tech companies will continue to do so, and not always in the same ways.
Re: New German law would force ISPs to allow secret service to install trojans
#103Earlier quoted context omitted.
I think you can collect a lot of good data for law enforcement purposes by tapping datacenter networks. Remember the NSA's "SSL added and removed here :-)" slide? Raise your hand if you use TLS between your database server and your web frontend. Keep your hand up if you rotated that certificate in the last month. Keep your hand up if you know whether your database's certificate has been tampered with. (i.e. do you ch…
Yeah, but Germany's intelligence services aren't the NSA, neither regarding technical ability, nor regarding the lack of mission constraints. I'm sure they'd love to get their hands on DE-CIX as a whole, but they won't unless somebody with a US passport sits in on the meeting - and if they have that person, they don't need German laws. I believe that these changes target ISPs and providers like mailbox.org, posteo et…
Re: New German law would force ISPs to allow secret service to install trojans
#104VPN service providers can expect a pretty good future for them (not only with this, but also the new EU copyright guidelines).
Re: New German law would force ISPs to allow secret service to install trojans
#105Earlier quoted context omitted.
Presumably, Germany would have little trouble compelling at least one root CA to sign any TLS certificates they wanted. Just a cursory search shows that Google Chrome, on Linux, trusts, e.g. > CN = D-TRUST Root CA 3 2013 > O = D-Trust GmbH > C = DE There is certificate transparency and pinning and so on, and they would be caught (probably, maybe) if they abused this carelessly and at scale, but in practice, for a sma…
Google, Mozilla, et al. should make a commitment to revoke the trust of any CA that is found to partake in behavior like that. Even retroactive revocation of existing certificates shouldn't be off the table if the offense is egregious enough. It's actually pretty scary seeing just how many CAs are in the list of trusted CAs on any given device. While no government is beyond reproach, I do wish there were a way for me…
Re: New German law would force ISPs to allow secret service to install trojans
#106Earlier quoted context omitted.
Presumably, Germany would have little trouble compelling at least one root CA to sign any TLS certificates they wanted. Just a cursory search shows that Google Chrome, on Linux, trusts, e.g. > CN = D-TRUST Root CA 3 2013 > O = D-Trust GmbH > C = DE There is certificate transparency and pinning and so on, and they would be caught (probably, maybe) if they abused this carelessly and at scale, but in practice, for a sma…
Well. That is the reason for Certificate Pinning. And these days there is no excuse to not enable it server-side. Helped me detect some MITM-Interceptions. Not that the content was malicious (OpenDNS just rerouted my requests to a "This site is blocked page", but the certificate was signed by Cisco, and thus valid. Certificate Pinning still picked it up. Little hint: It was an Archlinux-site.).
Or is cert pinning something different than HPKP?
- [1]: https://security.stackexchange.com/questions/213410/did-goog...
Re: New German law would force ISPs to allow secret service to install trojans
#107FYI: pervasive mass internet surveillance by the US military with the active cooperation of large US telcos AT&T, Verizon, and others already enables this capability in the US and much of the rest of the world. The surveillance allows them to read the TCP sequence numbers or DNS query IDs, and then spoof valid response packets. It’s called QUANTUMINSERT. https://blog.fox-it.com/2015/04/20/deep-dive-into-quantum-in...
Is this relevant since nearly everything is https these days?
NSA would be very bad at their job indeed if they couldn’t issue valid TLS certificates for any domain to themselves.
Re: New German law would force ISPs to allow secret service to install trojans
#108What does "trojans at ISPs" even mean? TLS works end-to-end and ISPs can do absolutely nothing to see the plaintext. It's unless the CAs at users-side are manually replaced with fake ones nothing can be done. I've never used Windows since I was a kid but I am sure this is pretty much impossible on Linux for example since adding CAs require root privilege.
Presumably, Germany would have little trouble compelling at least one root CA to sign any TLS certificates they wanted. Just a cursory search shows that Google Chrome, on Linux, trusts, e.g. > CN = D-TRUST Root CA 3 2013 > O = D-Trust GmbH > C = DE There is certificate transparency and pinning and so on, and they would be caught (probably, maybe) if they abused this carelessly and at scale, but in practice, for a sma…
Re: New German law would force ISPs to allow secret service to install trojans
#109Germany, the US, and Mexico all in the same week? The oligarchs are getting worried, it would seem.
Re: New German law would force ISPs to allow secret service to install trojans
#110Earlier quoted context omitted.
>Pretty shocking in a state that has such strict privacy laws. Not sure how the two can come from the same mouth, and even be in public view. Because they're not necessarily contradictory. This doesn't just give secret services a blank cheque to spy on everyone, it just provides intelligence agencies with a tool. I'm German and I don't object in principle to the fact that intelligence, under supervision of the govern…
The scary stuff about the current development is, that we get flooded with arguments about hardcore criminals, but if you look at the actual changes to the laws, such restrictions are not made, instead these extreme measures are allowed for petty reasons and some politicians will still keep pushing for even more totalitarianism. These siloviki want mass surveillance comparable to what Chinas Ministry of State Securit…
I totally get the appeal of that argument, but it completely breaks down once I ask myself how much that autocratic bogeyman regime, once it got into power, would feel bound by privacy protections put in place by their predecessors.