Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

171–180 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#171

Earlier quoted context omitted.

That thought is one reason why I've always questioned this advice: "Don't roll your own encryption." I've always understood the arguments for it but that the advice is so widespread seemed a little counter intuitive. It always seemed, to me at least, that having millions of encryption algorithms out there would be inherently more secure than a lot of people standardized on one because the risk to any one would be so…

I agree with the sentiment. The common argument against rolling out your own encryption just baffles me. Because there are plenty of ways to roll out your own encryption safely and in such a way that drastically eliminates the possibility of getting broken. Following is just a few ideas easily implemented even by a mediocre engineer. For the easiest, you can just apply multiple encryption algorithms in succession (of…

For downvoters - constructive counterarguments are welcome.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#172
post #136

Earlier quoted context omitted.

No the actual message is "Using TrueCrypt" -> UTC -> Coordinated Universal Time. The real culprit are the time thieves as explained in the book "Momo and the Time Thieves". Your mind will see what it wants.

It's plausible to think that that message constitutes a warrant canary [0]. [0] https://en.wikipedia.org/wiki/Warrant_canary

Not mutually exclusive, it's possible the Momo and the time thieves and the NSA are working together - the UTC is NSA, is the combined message

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#173

Earlier quoted context omitted.

> I think most of us would be fine with the NSA doing what they do if it was targeted You think wrong. That fact that there are opposing world states engaging in this nefarious, oppressive, terrible acts and they're not all aligned doesn't legitimize any of these states' activities. The NSA should essentially be shut down, or cut down to a small agency operating in public with a much more limited mandate. And no secr…

You do realize there is a world that exists beyond your idealism and naivete?

Hmm, nah I don't think people understand that they created NSA. It is them and their neighbor living in quiet area paying taxes where government want to keep them quiet and keep paying.

This way of things is giving birth to idealism and naivete. Just like people living in cities are idealistic and naive about life of cattle and poultry.

You don't want innocent chicken to be killed, but it is tasty. You don't want innocent person to be kept in hidden prison, but you feel safer.

They all would like to close down the farms or agencies that deal with bad stuff, but once they will be hungry enough that they will have to kill an animal or will be faced with actual violence, they will change their mind right away. (I bet they will want someone else to deal with such things)

If someone lives comfy life he can be oblivious. But on the other hand that is also beneficial for society because people in first world countries can focus on growing their interests and don't mind that bad stuff.

In the end if I would have to kill chickens for food every day I could not learn software development. So I am grateful I don't have to. I am also grateful that I don't have to deal with criminal people every day, because also I probably would not have time to do software development (most likely I would be dead before my 20th birthday).

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#174

What a treat to read a well written piece based on decent research. It's a long read but well worth your time. Kudo's to the journalists who helped uncover it. And the 'coup of the century' is far from clickbait, it's definitionally warranted for what the CIA and BND did here. It's a little ironic as well, especially since the US is so keen on blocking Huawei over espionage concerns.

> It's a little ironic as well, especially since the US is so keen on blocking Huawei over espionage concerns.

It's not ironic to play a game to win. Saying this is ironic is like saying it was ironic for the US to try to keep the North Koreans/Chinese from winning the Korean War because the US had just won WWII.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#175

Earlier quoted context omitted.

We in fact do not know that NSLs of the form suggested in the root comment exist. Such an NSL, requiring developers to stop work on a project, would in fact be unprecedented. It is, in fact, a conspiracy theory. In reality, the exact opposite thing occurs: the USG-backed Broadcast Board of Governors actively funds cryptographic privacy technology, both through direct grants to projects and, to head off other conspira…

Pretty sure you misinterpreted that comment. It's not suggesting that they pressured the devs to stop work, it says they were pressured to stop making it so awesome. The inference being that they were pressured to weaken the product and they walked away instead.

Just like lavabit: https://en.wikipedia.org/wiki/Lavabit#Suspension_and_gag_ord...

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#176

Earlier quoted context omitted.

I agree with the sentiment. The common argument against rolling out your own encryption just baffles me. Because there are plenty of ways to roll out your own encryption safely and in such a way that drastically eliminates the possibility of getting broken. Following is just a few ideas easily implemented even by a mediocre engineer. For the easiest, you can just apply multiple encryption algorithms in succession (of…

For downvoters - constructive counterarguments are welcome.

Combining standard algorithms doesn't constitute rolling your own crypto. Arguably, even increasing the number of rounds in a standard cipher doesn't, either.

A back door is not a side channel.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#177
post #109

Earlier quoted context omitted.

> what would they have done if the suspect hadn't used his laptop in a public place? Screw open his laptop when it's turned off and he's away from home, install a keylogger into the bios. Put a camera onto the shelf to film which keys he types to log in. If he puts a blanket over his head: solely rely on the sound each key makes. Hack his computer remotely using one of the government owned 0days and dump the keys. Us…

While what you are saying is possible technically, assuming any and all investigators in the US can tap into such capabilities is just FUD.

The biggest problem with FDE is that as long as you're using the encrypted computer, FDE isn't protecting you. It doesn't take technical capabilities to exploit this; you just wait until the target has their laptop open to do the interdiction.

FDE's not worthless. Again, I don't think it's even optional; one of your laptops is eventually going to get stolen, and you're going to want the reassurance that at the very least, once it loses power, the thief won't have access to your data (meaning, in effect, that most thieves will never have access to your data). And it's somewhat more powerful on phones, which have integrated designs to make FDE more granular.

But the idea that of all the things the USG could spend energy on, aftermarket FDE software would be their target? It's not very plausible.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#178

It has been known for a pretty long time that the Crypto AG is affiliated with or controlled by intelligence services. It was also always firmly in the "security through obscurity of our own cipher designs" department. Their C-52 (52 as in "1952") cipher machines were designed to enable decryption by Western intelligence. > Le Temps has argued that Crypto AG had been actively working with the British, US and West Ger…

I saw this article and that is exactly the first thought that popped up. Second thought was why is Washington Post feigning ignorance of this fact.

They didn't, following the arrest in Iran and subsequent release of a Crypto AG salesman in 92, they cite the salesman as talking with news organizations, they also cite a Swiss TV broadcast in 1994 and reports from Baltimore Sun in 1995.

The new fact is that the company was co-owned, then fully owned by the CIA.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#179

Earlier quoted context omitted.

Pretty sure you misinterpreted that comment. It's not suggesting that they pressured the devs to stop work, it says they were pressured to stop making it so awesome. The inference being that they were pressured to weaken the product and they walked away instead.

Just like lavabit: https://en.wikipedia.org/wiki/Lavabit#Suspension_and_gag_ord...

Lavabit was a service that effectively held keys for its users and was compelled to disclose them. If we were discussing whether a vulnerable service was somehow compelled by the USG, I wouldn't argue. I doubt you'd even need an NSL compromise Lavabit; you might even be able to do it with routine civil litigation. Don't ever use things like Lavabit. That's why we talk about "end to end encryption", as opposed to the bad kind of encryption.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#180

Earlier quoted context omitted.

> For one, the government can't compel you to do work. That's slavery. Slavery's perfectly legal. The 13th Amendment: "Neither slavery nor involuntary servitude, except as a punishment for crime whereof the party shall have been duly convicted , shall exist within the United States, or any place subject to their jurisdiction." https://en.wikipedia.org/wiki/Penal_labor_in_the_United_Stat...

Are you suggesting the TrueCrypt authors had been duly convicted of a crime?

He's saying they easily could have been.

See: Three Felonies a Day

Post reply on HN