Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

161–170 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#161

Earlier quoted context omitted.

Again: why do you use such belittling words like "conspiracy theory"? We know that the services interfere. We know that they interfered with vendors of cryptography products. And we know that National Security Letters exist, as do other – legal – means to pressure such vendors. There is no conspiracy needed for them to try to pressure someone by, say, threatening them with denial of a entry visa. Or they could have s…

We in fact do not know that NSLs of the form suggested in the root comment exist. Such an NSL, requiring developers to stop work on a project, would in fact be unprecedented. It is, in fact, a conspiracy theory. In reality, the exact opposite thing occurs: the USG-backed Broadcast Board of Governors actively funds cryptographic privacy technology, both through direct grants to projects and, to head off other conspira…

Pretty sure you misinterpreted that comment. It's not suggesting that they pressured the devs to stop work, it says they were pressured to stop making it so awesome. The inference being that they were pressured to weaken the product and they walked away instead.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#162

Earlier quoted context omitted.

There's nothing ironic, weird, or surprising about the US wanting to stop other countries from doing to them what they do to other countries. It's hypocritical in some sense, mostly because the US tries to project itself as the good guys, but it's just basic international relations. That's how every country has always operated and will always operate.

Right, the decision to avoid huawei is totally justified, but the hypocrisy is something to behold. Even here on HN, where people supposedly shouldn't be falling for propaganda so easily, there is a lot of indignation when e.g. the Chinese are caught doing something shady. If someone then points out that this is in some sense normal and US agencies are doing the same or worse stuff it is instantly dismissed as whatab…

Even if something is "in some sense normal" it is still completely unacceptable.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#163
post #112

Earlier quoted context omitted.

The key difference is that decrypting something would likely need to be targeted and on a case-by-case basis, as it would take specialized work, as opposed to these sorts of attacks (much like tapping all of the pipes which transit data underseas or elsewhere, which still goes on in every country or working directly with the ISPs and mobile operators which happens in most countries) which allows mass dragnet surveill…

> I think most of us would be fine with the NSA doing what they do if it was targeted You think wrong. That fact that there are opposing world states engaging in this nefarious, oppressive, terrible acts and they're not all aligned doesn't legitimize any of these states' activities. The NSA should essentially be shut down, or cut down to a small agency operating in public with a much more limited mandate. And no secr…

You do realize there is a world that exists beyond your idealism and naivete?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#164
post #109

Earlier quoted context omitted.

Again: why do you use such belittling words like "conspiracy theory"? We know that the services interfere. We know that they interfered with vendors of cryptography products. And we know that National Security Letters exist, as do other – legal – means to pressure such vendors. There is no conspiracy needed for them to try to pressure someone by, say, threatening them with denial of a entry visa. Or they could have s…

> what would they have done if the suspect hadn't used his laptop in a public place? Screw open his laptop when it's turned off and he's away from home, install a keylogger into the bios. Put a camera onto the shelf to film which keys he types to log in. If he puts a blanket over his head: solely rely on the sound each key makes. Hack his computer remotely using one of the government owned 0days and dump the keys. Us…

While what you are saying is possible technically, assuming any and all investigators in the US can tap into such capabilities is just FUD.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#165

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

> Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others.

Exactly. Huawei even kinda smells the same. From the OP:

> As Widman settled in, the secret partners adopted a set of principles for rigged algorithms, according to the BND history. They had to be “undetectable by usual statistical tests” and, if discovered, be “easily masked as implementation or human errors.”

> In other words, when cornered, Crypto executives would blame sloppy employees or clueless users.

https://www.theregister.co.uk/2019/03/28/hcsec_huawei_oversi...:

> Huawei savaged by Brit code review board over pisspoor dev practices

> "The work of HCSEC [Huawei Cyber Security Evaluation Centre]… reveals serious and systematic defects in Huawei's software engineering and cyber security competence," said the HCSEC oversight board in its annual report, published this morning.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#166

Earlier quoted context omitted.

please expand..

New account, 1 post.. I woulnd't answer "OBFUSCATED"'s question.. seems like he's already picked where to dig the ditch for the commenter. GCHQ? Something nastier?

Guess again, actually this is the first time I had reason to register despite reading for a long time.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#167
post #141
post #90

Earlier quoted context omitted.

AIUI it was a speedbump for Ulbricht; didn't they need to ambush him in a library in order to ensure they had access to his laptop's contents? (I mean, sure, it didn't protect him in the end. But it was a speedbump.)

ambush him in a library Someone started talking to him while someone else snagged his laptop - a thing you and a friend can do to more or less anyone. It's not like people rappelled down from helicopters with guns drawn.

They developed USBKill right after to prevent against stuff like this. That said, I'm sure the FBI knows about that now as well and would avoid sticking USBs into computers they want to target randomly.

But, there are also other tools out there.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#168

Earlier quoted context omitted.

I'm not sure that makes sense. The US could compel the devs to compromise their product but not keep them from issuing a cryptic statement and stopping work on the product?

It doesn't make sense for two reasons to me. For one, the government can't compel you to do work. That's slavery. Also, it's open source software. TrueCrypt going down didn't change the security landscape at all.

Like the government (of any given state) can't rendition you or assassinate you if they deem it necessary for national security reasons?

I think under the right conditions, a good many state intelligence services would not let the letter of the law get in their way. I just don't think the particular scenario above makes sense.

What makes sense:

-devs discovered some vulnerability but were persuaded that disclosing it would endanger important operations in progress. They were not coerced but reached a compromise with (agency).

-Devs were told, in no uncertain terms, that they need to discourage use of Truecrypt. Seems kind of low-impact, so probably not the case.

- Truecrypt was an (agency) project all along, and the faction arguing for universal access to strong cryptography finally lost out. The cat being out of the bag, and given the difficulty of introducing new vulnerabilities into an open-source tool used by the professionally paranoid, the best option was to try to discredit Truecrypt to the extent possible.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#169

Earlier quoted context omitted.

We in fact do not know that NSLs of the form suggested in the root comment exist. Such an NSL, requiring developers to stop work on a project, would in fact be unprecedented. It is, in fact, a conspiracy theory. In reality, the exact opposite thing occurs: the USG-backed Broadcast Board of Governors actively funds cryptographic privacy technology, both through direct grants to projects and, to head off other conspira…

Pretty sure you misinterpreted that comment. It's not suggesting that they pressured the devs to stop work, it says they were pressured to stop making it so awesome. The inference being that they were pressured to weaken the product and they walked away instead.

An NSL to that effect would also be unprecedented. There is no evidence that anything like that has ever happened.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#170

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

Funny, I don't really care China spying on me as much since they just don't have any handles that would be relevant. Your own government spying on you is much more dangerous. And since I don't have influence on policies of China, I can at least hold domestic politicians that strive for more surveillance accountable. At least theoretically. History shows that government isn't your friend at all. The US might be a rare…

> Your own government spying on you is much more dangerous.

That really depends on the government, and how heavily they rely on domestic surveillance as an instrument of political control. It also depends on the geopolitical and diplomatic situation, and the risks that stem from that.

In China for instance, domestic surveillance is a clear threat any of its citizens that choose to be dissidents and advocate for change. For instance, I have friends there who are very angry about the coronavirus situation, but have to be careful about what they say and how they say it to avoid risking government attention. Even with an extremely dark and cynical view of the US government, that kind of threat is far less for US citizens.

Foreign spying can be dangerous to you, personally, but usually in a more indirect and collective way [1]. The most obvious example of this is war. If your country loses one to a more brutal and oppressive adversary, you'll likely find yourself is a worse, if not outright bad, position. On a smaller and more mundane scale, foreign industrial espionage could put you out of a job.

[1] You may be a target of foreign direct spying if you're friend of a dissident, a government employee, a government official, or have access to valuable technology or trade secrets, etc.

Post reply on HN