Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

141–150 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#141
post #90
post #87

Earlier quoted context omitted.

I don't even understand the theory underneath this supposed conspiracy, since full-disk encryption is utterly mainstream at this point. I also don't need to get too deep into what I don't like about TrueCrypt; use it if you like it. The problem is with the model of full-disk encryption; outside of phones with deeply integrated hardware designs that support it, FDE is the least powerful form of encryption we use. It w…

AIUI it was a speedbump for Ulbricht; didn't they need to ambush him in a library in order to ensure they had access to his laptop's contents? (I mean, sure, it didn't protect him in the end. But it was a speedbump.)

ambush him in a library

Someone started talking to him while someone else snagged his laptop - a thing you and a friend can do to more or less anyone. It's not like people rappelled down from helicopters with guns drawn.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#142

It has been known for a pretty long time that the Crypto AG is affiliated with or controlled by intelligence services. It was also always firmly in the "security through obscurity of our own cipher designs" department. Their C-52 (52 as in "1952") cipher machines were designed to enable decryption by Western intelligence. > Le Temps has argued that Crypto AG had been actively working with the British, US and West Ger…

This thread needs to be at the top of the heap. I've read the WaPo article and it would be interesting to know exactly what's newly being revealed in it.

They have a little bit at the top claiming that it's newsworthy because they had access to a complete internal history which is rarely declassified. Okay. I'll buy that. And at the end, they mention a good article from the Baltimore Sun that is MORE THAN 20 YEARS OLD! But that's at the end.

Along the way, I wouldn't blame any reader for assuming that this is entirely new information.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#143
post #136

Earlier quoted context omitted.

From the TrueCrypt webpage: http://truecrypt.sourceforge.net/ > WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues The fact that they use awkward wording that contains words whose first letters that start with NSA (not secure as) is pretty suggestive that you are right.

No the actual message is "Using TrueCrypt" -> UTC -> Coordinated Universal Time. The real culprit are the time thieves as explained in the book "Momo and the Time Thieves". Your mind will see what it wants.

It's plausible to think that that message constitutes a warrant canary [0].

[0] https://en.wikipedia.org/wiki/Warrant_canary

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#144
post #105

What a treat to read a well written piece based on decent research. It's a long read but well worth your time. Kudo's to the journalists who helped uncover it. And the 'coup of the century' is far from clickbait, it's definitionally warranted for what the CIA and BND did here. It's a little ironic as well, especially since the US is so keen on blocking Huawei over espionage concerns.

No, this is not original research, this isn't being uncovered now, and I'm not sure why this is being republished now in 2020. There have been detailed leaks since 1995 on cryptome.org and crypto mailing lists about CryptoAG, including details about the message format and the bits used to leak parts of the key (16 bit leak, IIRC). The CryptoAG story has tainted all Swiss-based crypto/security firms since 1994. [1] ht…

Exactly. The piece does give a hat tip to the good article written by their rival, the Baltimore SUN, more than 20 years ago. But that's buried near the bottom.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#145
post #77

Earlier quoted context omitted.

I mean, Paul LeRoux is associated with it and he's been mythologized already himself

To be clear, "associated" means absolutely nothing at all here. Zero proof or anything close.

He's not linked beyond reasonable doubt to TrueCrypt, but IIRC

- there is clear evidence linking him to some earlier cryptographic software

-and someone (the journalist who wrote the story?) tried to say that it was a precursor to TrueCrypt.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#146

Earlier quoted context omitted.

Your cellular phone modem is both remotely programmable and has full root memory access 24/7. Let that sink in a bit.

Your "cellular phone" does not in fact have "full root memory access 24/7". In modern phone designs, the baseband is a USB peripheral. The notion that the closed, secret baseband is a DMA backdoor into AP memory is a message board meme, not engineering reality.

That may be true of Apple, and is true of the PinePhone and Librem, but for the majority of Android devices, that's blatantly false.

On Qualcomm chipsets in particular heavily utilize shared memory for baseband to application processor communication.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#147
post #128

Earlier quoted context omitted.

That thought is one reason why I've always questioned this advice: "Don't roll your own encryption." I've always understood the arguments for it but that the advice is so widespread seemed a little counter intuitive. It always seemed, to me at least, that having millions of encryption algorithms out there would be inherently more secure than a lot of people standardized on one because the risk to any one would be so…

The "don't roll your own" argument isn't against having lots of encryption algorithms, though. It's because it's nearly impossible for a nonspecialist to implement tools that other specialists can't fairly easily recognize as broken and exploit (whether cryptologically broken or due to side-channel exploits).

> other specialists can't fairly easily recognize as broken and exploit

Is there any supporting evidence for this claim? If I took an AES library and changed the order of some inner loop wouldn't it require extensive statistical analysis to notice the difference? Which means instead of throwing a bunch of compute at decrypting me, along with the masses 10 years from now, you would need to get a specialist to specifically target me and spend considerable time.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#148

Earlier quoted context omitted.

This thread needs to be at the top of the heap. I've read the WaPo article and it would be interesting to know exactly what's newly being revealed in it.

They have a little bit at the top claiming that it's newsworthy because they had access to a complete internal history which is rarely declassified. Okay. I'll buy that. And at the end, they mention a good article from the Baltimore Sun that is MORE THAN 20 YEARS OLD! But that's at the end. Along the way, I wouldn't blame any reader for assuming that this is entirely new information.

The main (new) thing is that it was 100% CIA and German Intelligence owned, followed by 100% CIA owned. Not sure exactly how big of deal that really is...

(Edit: other than being a longtime profit center for CIA slush money.)

It's all a bit fishy, especially since it's admittedly sourced from within the agency. A lot depends on if it was an approved leak or not. With the divestment in 2018, and no other really new information, I would suspect sanctioned leak, as there was nothing to lose.

The question is what was gained by whom? And why the timing? There's nothing in the story that's pressing topical information.

Between the Amazon government cloud contract lawsuit, and being 1 week post impeachment, there's quite a few opposing angles that would all seem plausible. Wapo reward for some Agency cooperation maybe? Rabbit holes in every direction.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#149
post #112

Earlier quoted context omitted.

Putting my tinfoil hat on, after reading the Snowden disclosures I'm convinced that they do have limited means of attacking encrypted communication but they would rather rely on these (expendable) means. Once they lose their crypto vulnerabilities it will force them to be even more overt.

The key difference is that decrypting something would likely need to be targeted and on a case-by-case basis, as it would take specialized work, as opposed to these sorts of attacks (much like tapping all of the pipes which transit data underseas or elsewhere, which still goes on in every country or working directly with the ISPs and mobile operators which happens in most countries) which allows mass dragnet surveill…

> I think most of us would be fine with the NSA doing what they do if it was targeted

You think wrong. That fact that there are opposing world states engaging in this nefarious, oppressive, terrible acts and they're not all aligned doesn't legitimize any of these states' activities.

The NSA should essentially be shut down, or cut down to a small agency operating in public with a much more limited mandate. And no secret FISA courts all of that spy-movie crap. That should just stop, period.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#150

Earlier quoted context omitted.

Your "cellular phone" does not in fact have "full root memory access 24/7". In modern phone designs, the baseband is a USB peripheral. The notion that the closed, secret baseband is a DMA backdoor into AP memory is a message board meme, not engineering reality.

That may be true of Apple, and is true of the PinePhone and Librem, but for the majority of Android devices, that's blatantly false. On Qualcomm chipsets in particular heavily utilize shared memory for baseband to application processor communication.

"The majority of Android devices" is a very wide net to cast.
Post reply on HN