Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

131–140 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#132
post #87

Earlier quoted context omitted.

I don't even understand the theory underneath this supposed conspiracy, since full-disk encryption is utterly mainstream at this point. I also don't need to get too deep into what I don't like about TrueCrypt; use it if you like it. The problem is with the model of full-disk encryption; outside of phones with deeply integrated hardware designs that support it, FDE is the least powerful form of encryption we use. It w…

Again: why do you use such belittling words like "conspiracy theory"? We know that the services interfere. We know that they interfered with vendors of cryptography products. And we know that National Security Letters exist, as do other – legal – means to pressure such vendors. There is no conspiracy needed for them to try to pressure someone by, say, threatening them with denial of a entry visa. Or they could have s…

We in fact do not know that NSLs of the form suggested in the root comment exist. Such an NSL, requiring developers to stop work on a project, would in fact be unprecedented. It is, in fact, a conspiracy theory. In reality, the exact opposite thing occurs: the USG-backed Broadcast Board of Governors actively funds cryptographic privacy technology, both through direct grants to projects and, to head off other conspiracy theories, in much harder-to-subvert grants to 3rd party pentesters to find and report vulnerabilities in those tools.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#133

What a treat to read a well written piece based on decent research. It's a long read but well worth your time. Kudo's to the journalists who helped uncover it. And the 'coup of the century' is far from clickbait, it's definitionally warranted for what the CIA and BND did here. It's a little ironic as well, especially since the US is so keen on blocking Huawei over espionage concerns.

Hypocritical, not ironic. You mean to highlight that the USA does not treat other sovereign states like the USA expects to be treated. There is no ironic contrast between the USA funding Crypto AG and China funding Huawei.

I think it's pretty clear that the US expects to be treated exactly like they've treated other nations.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#134

Earlier quoted context omitted.

Putting my tinfoil hat on, after reading the Snowden disclosures I'm convinced that they do have limited means of attacking encrypted communication but they would rather rely on these (expendable) means. Once they lose their crypto vulnerabilities it will force them to be even more overt.

snowden explicitly said pgp was safe

How on Earth would he know? He's not a cryptographer. Much of what we've learned from the Snowden disclosures has been through experts granted access to the SCIF that houses the documents he exfiltrated. He didn't carefully review those documents before collecting them.

I think it's really difficult to come to any kind of firm conclusion about what NSA can and can't break, even with a background in the material. I tend to doubt NSA has a world-beating RSA class break locked away. But I don't think people should be making decisions based on Snowden's personal technical opinions.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#136
post #17

Earlier quoted context omitted.

I'm pretty sure the US government is why the TrueCrypt devs stopped all work. They got hit with a national security letter (NSL) or heavily leaned on and pressured to stop making their product so awesome and un-breakable.

From the TrueCrypt webpage: http://truecrypt.sourceforge.net/ > WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues The fact that they use awkward wording that contains words whose first letters that start with NSA (not secure as) is pretty suggestive that you are right.

No the actual message is "Using TrueCrypt" -> UTC -> Coordinated Universal Time. The real culprit are the time thieves as explained in the book "Momo and the Time Thieves".

Your mind will see what it wants.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#137
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

Your cellular phone modem is both remotely programmable and has full root memory access 24/7.

Let that sink in a bit.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#138

Earlier quoted context omitted.

Funny, I don't really care China spying on me as much since they just don't have any handles that would be relevant. Your own government spying on you is much more dangerous. And since I don't have influence on policies of China, I can at least hold domestic politicians that strive for more surveillance accountable. At least theoretically. History shows that government isn't your friend at all. The US might be a rare…

Even saying that the US is your friend isn't really true. The Tuskegee syphilis experiment and MKULTRA were only ended in the 70s, Orlando Letelier happened the same decade, as did the discovery of Operation Mockingbird and other Church Committee findings. Every peek we've had into that world since then continues to come up dirty too. Operation SHAMROCK was considered a big deal at the time, but we've since then allo…

Ruby Ridge and Waco siege happened only in the 90s as well. Currently we have killer drones assassinating people without trial, CBP ignoring policies (https://vc.gg/blog/so-its-been-a-while.html), sending agents to scare activists (https://news.ycombinator.com/item?id=6946909), and police blowing up houses of innocents and refusing to compensate them (https://news.ycombinator.com/item?id=21399770).

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#139
post #22

Earlier quoted context omitted.

It wouldn't be so bad with ubiquitous end to end encryption though right? If everything was encrypted in transit it wouldn't really matter if Huawei (and by extension the supposition goes the Chinese government) because they'd just see noise. Guess they would also be able to do location tracking though and that's not so easily solved.

Even end to end encryption often leaves them with metadata [0] [0] https://www.nybooks.com/daily/2014/05/10/we-kill-people-base...

Which is why you'll want to use some open source onion-routed app like Briar, Ricochet, Cwtch, TFC, or Session.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#140
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

Your cellular phone modem is both remotely programmable and has full root memory access 24/7. Let that sink in a bit.

Your "cellular phone" does not in fact have "full root memory access 24/7". In modern phone designs, the baseband is a USB peripheral. The notion that the closed, secret baseband is a DMA backdoor into AP memory is a message board meme, not engineering reality.
Post reply on HN