Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

121–130 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#121

It has been known for a pretty long time that the Crypto AG is affiliated with or controlled by intelligence services. It was also always firmly in the "security through obscurity of our own cipher designs" department. Their C-52 (52 as in "1952") cipher machines were designed to enable decryption by Western intelligence. > Le Temps has argued that Crypto AG had been actively working with the British, US and West Ger…

This thread needs to be at the top of the heap. I've read the WaPo article and it would be interesting to know exactly what's newly being revealed in it.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#122

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

The political squabble over 5G/Huawei is as much about western vendors using fear of China to prevent competition.

Why should Cisco/Juniper/Ericsson/etc compete with Huawei when they can more easily use political pressure to exclude them from the market?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#123
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

Putting my tinfoil hat on, after reading the Snowden disclosures I'm convinced that they do have limited means of attacking encrypted communication but they would rather rely on these (expendable) means. Once they lose their crypto vulnerabilities it will force them to be even more overt.

snowden explicitly said pgp was safe

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#124

My new startup focuses on human nervous system faraday cages embedded into next generation fashion technology. This tech covers your entire body, keeping you safe from remote scans, and includes realistic facial and body disguises. For your safety, our tech constantly scans your thought patterns and memories and keeps them safe with a static filled triple scrambled encryption method, and encodes them into specially p…

I love it!

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#125

Earlier quoted context omitted.

It doesn't make sense for two reasons to me. For one, the government can't compel you to do work. That's slavery. Also, it's open source software. TrueCrypt going down didn't change the security landscape at all.

> For one, the government can't compel you to do work. That's slavery. That may be your personal opinion, but legally speaking, it is not true in any sense.

It is also the argument that Apple used against the FBI in the San Bernardino case.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#126
post #90
post #87

Earlier quoted context omitted.

I don't even understand the theory underneath this supposed conspiracy, since full-disk encryption is utterly mainstream at this point. I also don't need to get too deep into what I don't like about TrueCrypt; use it if you like it. The problem is with the model of full-disk encryption; outside of phones with deeply integrated hardware designs that support it, FDE is the least powerful form of encryption we use. It w…

AIUI it was a speedbump for Ulbricht; didn't they need to ambush him in a library in order to ensure they had access to his laptop's contents? (I mean, sure, it didn't protect him in the end. But it was a speedbump.)

this is true but i wouldnt count on it as evidence either way; fbi would not have nsa tools

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#127
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

That thought is one reason why I've always questioned this advice: "Don't roll your own encryption." I've always understood the arguments for it but that the advice is so widespread seemed a little counter intuitive. It always seemed, to me at least, that having millions of encryption algorithms out there would be inherently more secure than a lot of people standardized on one because the risk to any one would be so…

[deleted]

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#128
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

That thought is one reason why I've always questioned this advice: "Don't roll your own encryption." I've always understood the arguments for it but that the advice is so widespread seemed a little counter intuitive. It always seemed, to me at least, that having millions of encryption algorithms out there would be inherently more secure than a lot of people standardized on one because the risk to any one would be so…

The "don't roll your own" argument isn't against having lots of encryption algorithms, though. It's because it's nearly impossible for a nonspecialist to implement tools that other specialists can't fairly easily recognize as broken and exploit (whether cryptologically broken or due to side-channel exploits).

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#129

It has been known for a pretty long time that the Crypto AG is affiliated with or controlled by intelligence services. It was also always firmly in the "security through obscurity of our own cipher designs" department. Their C-52 (52 as in "1952") cipher machines were designed to enable decryption by Western intelligence. > Le Temps has argued that Crypto AG had been actively working with the British, US and West Ger…

> There were also security breaches that put Crypto under clouds of suspicion. Documents released in the 1970s showed extensive — and incriminating — correspondence between an NSA pioneer and Crypto’s founder. Foreign targets were tipped off by the careless statements of public officials including President Ronald Reagan. And the 1992 arrest of a Crypto salesman in Iran, who did not realize he was selling rigged equipment, triggered a devastating “storm of publicity,” according to the CIA history.

> But the true extent of the company’s relationship with the CIA and its German counterpart was until now never revealed.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#130

What a treat to read a well written piece based on decent research. It's a long read but well worth your time. Kudo's to the journalists who helped uncover it. And the 'coup of the century' is far from clickbait, it's definitionally warranted for what the CIA and BND did here. It's a little ironic as well, especially since the US is so keen on blocking Huawei over espionage concerns.

There's nothing ironic, weird, or surprising about the US wanting to stop other countries from doing to them what they do to other countries. It's hypocritical in some sense, mostly because the US tries to project itself as the good guys, but it's just basic international relations. That's how every country has always operated and will always operate.

Right, the decision to avoid huawei is totally justified, but the hypocrisy is something to behold. Even here on HN, where people supposedly shouldn't be falling for propaganda so easily, there is a lot of indignation when e.g. the Chinese are caught doing something shady. If someone then points out that this is in some sense normal and US agencies are doing the same or worse stuff it is instantly dismissed as whataboutism.
Post reply on HN