Live data from Hacker News

Core Secrets: NSA Saboteurs in China and Germany

firstlook.org

121–130 of 130 posts

Re: Core Secrets: NSA Saboteurs in China and Germany

#121
post #116

Earlier quoted context omitted.

All large corporations weaken encryption for the government. Some articles. If you want more, I'm sure I can dig up a few. https://en.wikipedia.org/wiki/Communications_Assistance_for_... http://www.foia.cia.gov/sites/default/files/DOC_0006231614.p...

> All large corporations weaken encryption for the government This is simply false. It is untrue to claim that all U.S. companies have somehow "weakened" encryption or inserted backdoors in their products for the Feds. I normally wouldn't waste my time correcting conspiracy theories, but sometimes it's necessary to stop the more credulous from believing them. Yes, the NSA has boasted of having a surveillance "partner…

It's funny you call it a conspiracy theory. There's no conspiracy. And it is not a theory. The NSA currently requires companies (like Microsoft, Apple) to provide encryption keys corresponding to devices where pertinent. If you look at Bush era legislation most of the pen register, tap-and-trace laws and rulings were precisely pulling existing laws for telecommunication onto the domain of the internet by arguing technical equivalence. It is also true today that essentially all telecommunications are done over digital lines.

Finally Apple isn't a "web company", nor is Microsoft or the majority of 'large corporations'.

> "...unless the encryption was provided by the carrier and the carrier possesses the information necessary to decrypt the communication"

I don't think I need to say very much here.

Regarding Apple's encryption there's lots of good information about how very little it actually does and can do. There was also a hacker news thread with yours truly. https://news.ycombinator.com/item?id=8389365

Regarding the 'antiquated' FOIA doc - you can export strong crypto but you backdoor it, keep the keys, or provide other ways to access the data. Blackberry's entire business model was secure communications and look where they are today. RSA is now in a similar boat.

"Weaken encryption" does not mean 'lower the bit security under the standard attacker model' here. In this case it means 'subvert encryption through design or implementation flaws, key repositories, controlled PRNGs, side channel access or designed-in systems level access to the data'. "Weaken encryption" doesn't mean "choose smaller key sizes", it means "make the fact that something is encrypted a weak guarantee of security and privacy."

> But the Silicon Valley companies that we know and more-or-less love have done the opposite

Image management, nothing more. Why the public showdown? That doesn't make any sense at all. No sir, I'm certain that corporations would like to provide security and privacy for their customers. And they do. But not against federal law enforcement. There are no new laws that need passing right now. The machinery is there and we've witnessed it in action multiple times. There is no David and Goliath story here, no heroes to be heralded. It's romantic, alright. I wish it were realistic.

Google (and others, that we are supposed to love) fought several battles that made it to the highest levels of court in the United States but lost. They were then forced to comply. The United States used extreme financial leverage to get QWest to comply (and when they still wouldn't, let/forced them to go bankrupt).

What's changed since then? Where there some new Supreme or Circuit Court decisions that have depreciated the former?

Re: Core Secrets: NSA Saboteurs in China and Germany

#122

Earlier quoted context omitted.

> It seems you've decided Nah that's not what I think or believe. I'm trying to explain broader context. The US is not hacking in a vacuum. It has to make strategic decisions. We can arm chair the US strategic command all we want. There seems to be a presumption that the US is doing these things 'just because'. What I believe is that the US is making decisions based on incentives, costs, benefits and other tradeoffs.…

Presumably, I could better my negotiation position on pretty much any deal by spying or sabotaging the other party. Say I am negotiating a salary offer from a company, having access to the CEO email and that of other key decision makers (even just the prospective team and the HR reps) would presumably give me information I can use to secure a higher comp package, no? Without disrupting their operations in general, if…

These are all really good questions and I don't have answers other than to say there's a 'prisoner's dilemma'/'tragedy at the commons'/'cold war' situation. If you do no espionage and no sabotage, even though it is a higher moral ground, you don't exist for very long as a country.

So it's damned if you do and damned if you don't.

Re: Core Secrets: NSA Saboteurs in China and Germany

#123
post #104

Earlier quoted context omitted.

> ... Germany and others have hacked into us. Could you elaborate? As far as I know, Germany has some kind of agreement to not spy on the US.

Found the reference to Israel/France, looking for Germany references. http://hbpub.vo.llnwd.net/o16/video/olmk/holt/greenwald/NoPl... (pg 40/125) Why the downvote here? The comment contributes to the conversation...

This PDF does not appear to have searchable text.

Could you provide direct citations or quotes of allied countries infiltrating our government or private infrastructure? Excluding Israel, because they have the same mindset as the NSA/CIA (in which case I also don't take issue with us hacking Israel).

Re: Core Secrets: NSA Saboteurs in China and Germany

#124
post #116

Earlier quoted context omitted.

> All large corporations weaken encryption for the government This is simply false. It is untrue to claim that all U.S. companies have somehow "weakened" encryption or inserted backdoors in their products for the Feds. I normally wouldn't waste my time correcting conspiracy theories, but sometimes it's necessary to stop the more credulous from believing them. Yes, the NSA has boasted of having a surveillance "partner…

It's funny you call it a conspiracy theory. There's no conspiracy. And it is not a theory. The NSA currently requires companies (like Microsoft, Apple) to provide encryption keys corresponding to devices where pertinent. If you look at Bush era legislation most of the pen register, tap-and-trace laws and rulings were precisely pulling existing laws for telecommunication onto the domain of the internet by arguing tech…

>NSA currently requires companies (like Microsoft, Apple) to provide encryption keys corresponding to devices

Link, please?

Re: Core Secrets: NSA Saboteurs in China and Germany

#125
post #124

Earlier quoted context omitted.

It's funny you call it a conspiracy theory. There's no conspiracy. And it is not a theory. The NSA currently requires companies (like Microsoft, Apple) to provide encryption keys corresponding to devices where pertinent. If you look at Bush era legislation most of the pen register, tap-and-trace laws and rulings were precisely pulling existing laws for telecommunication onto the domain of the internet by arguing tech…

>NSA currently requires companies (like Microsoft, Apple) to provide encryption keys corresponding to devices Link, please?

"They can promise strong encryption. They just need to figure out how they can provide us plain text." - FBI General Counsel Valerie Caproni, September 27, 2010

Didn't we already chat about key escrow requirements, CALEA, etc?

The Clinton Administration's big thing was key escrow. Clipper, of course, and as that policy failed the administration moved control of encryption from Military/Exports and Munitions to the Department of Commerce under the agreement that key escrow systems would be put in place where weak cryptography had been previously. Major companies (including RSA, IBM, Apple, Sun, HP, AOL, others) collaboratively drafted industry standard key escrow systems (aside: crypto key escrow patents are a fun things to look up on patent searches).

Additional pressure was exerted of course because the United States had seen a very strong rise in geopolitical espionage and sabotage and strong crypto was becoming a problem for the NSA.

That's where things were at the end of the Clinton Administration. During Bush's administration we saw nothing but an expansion of powers and budgets for intelligence agencies and reclassification of laws applying to other media (for tap and trace/pen register) to the internet (although CALEA already applies to broadband internet) and to computers, 'computer systems and networks' and electronic equipment. Bush (and Clinton before him) warned of rising international cyberwarfare, but couldn't get the populace concerned about it. Anyway, you do NOT see a reversal on escrow requirements during the Bush or the Obama administration - rather you see an expansion of escrow and an expansion of hardware, software and standard backdoors as well as the leaks from Snowden.

There are a number of ways that escrow is done (we're ignoring backdoors right now). The TPM is one novel way that keys are stored in a way that gives access for law enforcement. TPMs are in essentially every computer, 'spooks' showed up at the standardization meetings for the chip, Germany announced they provided backdoor access during diplomatic troubles (and have since 'rescinded the announcement' whatever that means), China blocks all electronics with TPM chips coming from the United States (and allies) and after a bunch of international and technical/commercial problems the TPM 2.0 spec (again attended by Five Eyes spooks) it was for the most part abandoned. And honestly, does a low end consumer device ($650 laptop or $300 phone) require a self destructing chip that can't be examined using standard equipment or at room temperature? The TPM also almost always resides on the low pin count bus (the spec does not specify where it needs to sit), which gives it DMA (TPMs do NOT need DMA).

Or check out Microsoft's Cryptographic Service Provider (CSPs). This is where you store, provision, can generate, access, and utilize your keys in a Microsoft system. It's also famous for being where the NSAKEY gave access. Microsoft will tell you that it keeps your keys secured, but it is well known to any pentester that access to admin on a box can dump all of the keys, including those that are so-called 'marked non-exportable'. From what I can tell by the public MSDN articles on the subject contents of the CSPs can be controlled via group policies, and interops with other management systems.

This isn't to mention that bitlocker keys are automatically synchronized with Skydrive (Onedrive) accounts and that Onedrive was onboarded to PRISM for NSA access. Well, that's only if you have a Microsoft Account. Oh, one is automatically made for you and you're essentially required to sign up for an account to use any new Microsoft OS.

Well, that and bitlocker keys are also backed up inside of organizations to Active Directory (i.e. don't 'domain join' your personal computer).

Anyway.

Check the flurry of Apple news items recently. The narrative would like to use that as some sort of David vs. Goliath story of the good guy capitalist protecting his consumer. But check the details. The addition of encryption is not new. What's new is that they are publicly claiming that with this encryption system they will not have access to the private keys, and so can not comply with requests. Now we don't have to believe them (I don't), but we do have to acknowledge that -not having a facility for escrow- is their 'dangerous game'. Encryption is not a 'dangerous game'. Not providing escrow is.

Re: Core Secrets: NSA Saboteurs in China and Germany

#126
post #124

Earlier quoted context omitted.

>NSA currently requires companies (like Microsoft, Apple) to provide encryption keys corresponding to devices Link, please?

"They can promise strong encryption. They just need to figure out how they can provide us plain text." - FBI General Counsel Valerie Caproni, September 27, 2010 Didn't we already chat about key escrow requirements, CALEA, etc? The Clinton Administration's big thing was key escrow. Clipper, of course, and as that policy failed the administration moved control of encryption from Military/Exports and Munitions to the De…

Thanks for your reply. I'm aware of what the FBI was asking for (Val Caproni is no longer there, FYI) four years ago. My reporting before I founded recent.io was the first to disclose some elements of the bureau's demands and strategy, in fact.

You're right that it's unreasonable to place blind trust in a closed encryption system, even Apple's, that we're unable to review or audit. Even if their intentions are pure, it could be poorly implemented.

But my point is simply this: there is no U.S. law mandating key escrow for Apple, Google, Microsoft, etc. One was proposed in the 1990s. It didn't pass. One was proposed in the Going Dark era 4-5 years ago. It didn't pass. One is being quasi-proposed now. It hasn't passed.

I actually think I'll agree with you on a lot of issues based on your post above -- but it is nevertheless a conspiracy theory to claim that Silicon Valley companies somehow engage in key escrow for the NSA or that there is a legal requirement for them to do so. As I said before, if you claim otherwise, URL, please.

>NSA currently requires companies (like Microsoft, Apple) to provide encryption keys corresponding to devices

PS: ^^^ I'm still waiting for the link that backs up this claim too.

Re: Core Secrets: NSA Saboteurs in China and Germany

#127
post #126

Earlier quoted context omitted.

"They can promise strong encryption. They just need to figure out how they can provide us plain text." - FBI General Counsel Valerie Caproni, September 27, 2010 Didn't we already chat about key escrow requirements, CALEA, etc? The Clinton Administration's big thing was key escrow. Clipper, of course, and as that policy failed the administration moved control of encryption from Military/Exports and Munitions to the De…

Thanks for your reply. I'm aware of what the FBI was asking for (Val Caproni is no longer there, FYI) four years ago. My reporting before I founded recent.io was the first to disclose some elements of the bureau's demands and strategy, in fact. You're right that it's unreasonable to place blind trust in a closed encryption system, even Apple's, that we're unable to review or audit. Even if their intentions are pure,…

AFAIK there is no explicit law requiring every company that sells cryptography (in the general case, i.e. not as a service provider) to provide key escrow.

However, this is not to discount law in praxis, how CALEA is interpreted and enforced, the history of key escrow, current technology considerations, known and suspected escrow mechanisms, and pressures exerted by federal law enforcement (e.g. the removal of effective crypto from Skype when it captured its market), and how all of this hangs together.

My (reasonably, educated and technically informed :p) suspicion is that companies at a certain size, federal agents will come to your company and make demands for data, which you must comply with and slowly as you are compelled by law to give keys and data on a regular basis it becomes the best thing for your business to install automatic escrow mechanisms.

It is my assertion that law enforcement interprets laws that read as "...unless the encryption was provided by the carrier and the carrier possesses the information necessary to decrypt the communication" as enough to force companies to create escrow mechanisms.

I would argue some of this story played out very publicly with Google. Another great example here would be the NSL of Lavabit - how they asked for far more than was legally obligated and the forcefulness and non-public nature of the demands made it impossible to put forward a reasonable defense.

To summarize it is apparent to me that the difference in our perspectives is whether a specific law (another being proposed again now, as you point out) is required in the current climate of practice of law, along with the leverage and the compliance requirements that exist inside it, for key escrow to be 'required of companies'.

I come down on the side of 'no'. I believe they have what they need now to get escrow.

Maybe this Apple and Google thing will clarify it. But somehow I doubt it. Prediction: no explicit law on key escrow will be passed (it would be entirely too harmful for US exports) but it will continue to be practiced.

Re: Core Secrets: NSA Saboteurs in China and Germany

#128
post #126

Earlier quoted context omitted.

Thanks for your reply. I'm aware of what the FBI was asking for (Val Caproni is no longer there, FYI) four years ago. My reporting before I founded recent.io was the first to disclose some elements of the bureau's demands and strategy, in fact. You're right that it's unreasonable to place blind trust in a closed encryption system, even Apple's, that we're unable to review or audit. Even if their intentions are pure,…

AFAIK there is no explicit law requiring every company that sells cryptography (in the general case, i.e. not as a service provider) to provide key escrow. However, this is not to discount law in praxis, how CALEA is interpreted and enforced, the history of key escrow, current technology considerations, known and suspected escrow mechanisms, and pressures exerted by federal law enforcement (e.g. the removal of effect…

Here are some interesting links.

HP obtained a patented backdoor system in 2008 (filed mid 2000 and approved around the start of 2001).

https://www.google.com/patents/EP1059578A2

Certicom (the same company DUAL_EC was filed under) has a new key escrow system patented.

https://www.google.com/patents/EP2637350A2

Key escrow system filed in 2004 and published in 2011:

https://www.google.com/patents/US8015597

2008-2012 stateless key escrow patent:

https://www.google.com/patents/US8315395

"Automatic recovery of TPM keys" - Lenovo

https://www.google.com/patents/US8290164

Oops, here's a Microsoft "cloud storage" key escrow system from 2011-2012.

"Some of the files stored on the network server may be sensitive or confidential. The user may wish to restrict access to those files. The files may then be encrypted or otherwise protected with a password or other key. The user may not trust the network server to store the key, and may thus desire to retain sole possession of the key. Such users, however, often lose (or forget) their passwords or keys. Moreover, other third party users may legitimately require access to the stored, encrypted files."

"FIG. 3 illustrates a flowchart of an example method for providing third party data access to a user's encrypted data according to a predefined policy."

"In some cases, however, while the data storage system is not able to decrypt the user's data, it may be necessary for an outside entity (e.g. a governmental entity) to access the user's data."

"In cases where the encrypted data is a cryptographic key, that key may be stored as a plurality of shares. The shares are mathematical transformations of the user's private key, and each share is provided to one of the verified third parties. Each verified third party publishes his or her own public keys, and encrypts his or her share of the encrypted key using their published public key. The verified third party shares encrypted according to the third partys' public keys are then stored in the data storage system. Because the shares are encrypted according to the verified third parties' public/private key pair, the data storage system is prevented from accessing the encrypted shares, and is further prevented from accessing the user's data."

"In some cases, the user's data may comprise, at least in part, a cryptographic key. The user's data, including the key, may be stored in multiple different shares."

Encrypted data AND keys!

The patent examiner cited "The Risks of Key Recovery, Key Escrow, and Trusted Third-Party Encryption" when doing his examination.

https://www.google.com/patents/US20120321086

http://academiccommons.columbia.edu/catalog/ac:127127

Some Raytheon for good measure. A bit older, but certainly Bush era.

https://www.google.com/patents/US7269261

Motorola [1]. Certicom [2]. Honeywell [3]. Motorola [4]. Deutsche Telekom Ag [5]. IBM [6]. Apple [7]. ‎Fujitsu [8]. Red hat [9]. F-Secure [10]. Sony [11]. Seagate [12]. Dell [13]. Sprint [14]. Nokia [15]. Gemalto [16]. Intel [17]. Samsung [18]. Symantec [19]. Sun Microsystems [20]. Toshiba [21]. Cinea [22]. General Dynamics [23]. Citicorp [24]. Siemens [25]. Ericsson [26]. VMWare [27]. Facebook [28]. HP [29]. Cisco [30]. Liquid Machines [31]. GIC [32]. Microsoft [33]. Novell [34].

And of course the US patent system has a classification for key escrow systems: 380/286.

http://www.uspto.gov/web/patents/classification/uspc380/defs...

[1] https://www.google.com/patents/US7116786

[2] https://www.google.com/patents/US8688998

[3] https://www.google.com/patents/US20070140496

[4] https://www.google.com/patents/US5241597

[5] https://www.google.com/patents/US7162037

[6] https://www.google.com/patents/US8195959 & https://www.google.com/patents/US7856664 & https://www.google.com/patents/US7873170

[7] https://www.google.com/patents/US20090319769

[8] https://www.google.com/patents/US6754349 & https://www.google.com/patents/US8055911 & https://www.google.com/patents/US7752318

[9] https://www.google.com/patents/US8144876 & https://www.google.com/patents/US8494169 & https://www.google.com/patents/US20070280483

[10] https://www.google.com/patents/US8824682

[11] https://www.google.com/patents/US7672458

[12] https://www.google.com/patents/US7899186

[13] https://www.google.com/patents/US20090080663

[14] https://www.google.com/patents/US7869602

[15] https://www.google.com/patents/US8107623

[16] https://www.google.com/patents/US8074076

[17] https://www.google.com/patents/US6950523

[18] https://www.google.com/patents/US8315386 & https://www.google.com/patents/US20070172069 & https://www.google.com/patents/US7492895

[19] https://www.google.com/patents/US8397281

[20] https://www.google.com/patents/US7050589 & https://www.google.com/patents/US7660423 & https://www.google.com/patents/US20100142713

[21] https://www.google.com/patents/US8099609

[22] https://www.google.com/patents/US7277544

[23] https://www.google.com/patents/US20070195960

[24] https://www.google.com/patents/US6970836

[25] https://www.google.com/patents/US7313697

[26] https://www.google.com/patents/US20080152151

[27] https://www.google.com/patents/US8234518

[28] https://www.google.com/patents/US8490166

[29] https://www.google.com/patents/US6577735

[30] https://www.google.com/patents/US8631227

[31] https://www.google.com/patents/US7796760

[32] https://www.google.com/patents/US20040052380

[33] https://www.google.com/patents/US20070003065

[34] https://www.google.com/patents/US8098828

Re: Core Secrets: NSA Saboteurs in China and Germany

#129

Earlier quoted context omitted.

AFAIK there is no explicit law requiring every company that sells cryptography (in the general case, i.e. not as a service provider) to provide key escrow. However, this is not to discount law in praxis, how CALEA is interpreted and enforced, the history of key escrow, current technology considerations, known and suspected escrow mechanisms, and pressures exerted by federal law enforcement (e.g. the removal of effect…

Here are some interesting links. HP obtained a patented backdoor system in 2008 (filed mid 2000 and approved around the start of 2001). https://www.google.com/patents/EP1059578A2 Certicom (the same company DUAL_EC was filed under) has a new key escrow system patented. https://www.google.com/patents/EP2637350A2 Key escrow system filed in 2004 and published in 2011: https://www.google.com/patents/US8015597 2008-2012 st…

I have lost the ability to edit this post. I wanted to share some more information. All of these patents contains key escrow capabilities, which is defined by the US patent system as "Subject matter wherein the key is deposited or retrieved to or from a third party."

There are circumstances where this is not being used to give access to law enforcement, or the patent would not make sense in that context.

This is a last defense argument. Certainly it is the case for some escrow systems, and (especially with the patentese) are difficult to decipher.

But others are clear as day: "In order to receive the information, law enforcement may submit a request to each of the entities identifying the communication session and their basis for authorization."

Only some of the documents provided above have been read through by yours truly. They constitute only a minor fraction of patents by a minor fractions of companies in the US patent system.

Verisign? [1]

[1] https://www.google.com/patents/US6931133

Re: Core Secrets: NSA Saboteurs in China and Germany

#130

Earlier quoted context omitted.

Presumably, I could better my negotiation position on pretty much any deal by spying or sabotaging the other party. Say I am negotiating a salary offer from a company, having access to the CEO email and that of other key decision makers (even just the prospective team and the HR reps) would presumably give me information I can use to secure a higher comp package, no? Without disrupting their operations in general, if…

These are all really good questions and I don't have answers other than to say there's a 'prisoner's dilemma'/'tragedy at the commons'/'cold war' situation. If you do no espionage and no sabotage, even though it is a higher moral ground, you don't exist for very long as a country. So it's damned if you do and damned if you don't.

Except I suspect many countries actually do without effective espionage or sabotage, if only because they lack the capability.

I guess you can argue that many of these countries rely on allies who perform espionage and sabotage, thus benefiting from those activities despite not doing them themselves. But that still means that closely-aligned countries can survive without spying on each other. I might not have all the facts, but it seems unlikely that Germany or Brazil would be considered an existential threat to the US in the foreseeable future, so why spy on those countries? Slight economic advantages don't seem to justify the breach of ethics.

I guess I can see what you are saying and I don't think we can have a world without spying any time soon. But that doesn't mean all international spying is justified.

Post reply on HN