Earlier quoted context omitted.
That thought is one reason why I've always questioned this advice: "Don't roll your own encryption." I've always understood the arguments for it but that the advice is so widespread seemed a little counter intuitive. It always seemed, to me at least, that having millions of encryption algorithms out there would be inherently more secure than a lot of people standardized on one because the risk to any one would be so…
I agree with the sentiment. The common argument against rolling out your own encryption just baffles me. Because there are plenty of ways to roll out your own encryption safely and in such a way that drastically eliminates the possibility of getting broken. Following is just a few ideas easily implemented even by a mediocre engineer. For the easiest, you can just apply multiple encryption algorithms in succession (of…
How the CIA used Crypto AG encryption devices to spy on countries for decades
171–180 of 353 posts
Re: How the CIA used Crypto AG encryption devices to spy on countries for decades
#172Earlier quoted context omitted.
No the actual message is "Using TrueCrypt" -> UTC -> Coordinated Universal Time. The real culprit are the time thieves as explained in the book "Momo and the Time Thieves". Your mind will see what it wants.
It's plausible to think that that message constitutes a warrant canary [0]. [0] https://en.wikipedia.org/wiki/Warrant_canary
Re: How the CIA used Crypto AG encryption devices to spy on countries for decades
#173Earlier quoted context omitted.
> I think most of us would be fine with the NSA doing what they do if it was targeted You think wrong. That fact that there are opposing world states engaging in this nefarious, oppressive, terrible acts and they're not all aligned doesn't legitimize any of these states' activities. The NSA should essentially be shut down, or cut down to a small agency operating in public with a much more limited mandate. And no secr…
You do realize there is a world that exists beyond your idealism and naivete?
This way of things is giving birth to idealism and naivete. Just like people living in cities are idealistic and naive about life of cattle and poultry.
You don't want innocent chicken to be killed, but it is tasty. You don't want innocent person to be kept in hidden prison, but you feel safer.
They all would like to close down the farms or agencies that deal with bad stuff, but once they will be hungry enough that they will have to kill an animal or will be faced with actual violence, they will change their mind right away. (I bet they will want someone else to deal with such things)
If someone lives comfy life he can be oblivious. But on the other hand that is also beneficial for society because people in first world countries can focus on growing their interests and don't mind that bad stuff.
In the end if I would have to kill chickens for food every day I could not learn software development. So I am grateful I don't have to. I am also grateful that I don't have to deal with criminal people every day, because also I probably would not have time to do software development (most likely I would be dead before my 20th birthday).
Re: How the CIA used Crypto AG encryption devices to spy on countries for decades
#174What a treat to read a well written piece based on decent research. It's a long read but well worth your time. Kudo's to the journalists who helped uncover it. And the 'coup of the century' is far from clickbait, it's definitionally warranted for what the CIA and BND did here. It's a little ironic as well, especially since the US is so keen on blocking Huawei over espionage concerns.
It's not ironic to play a game to win. Saying this is ironic is like saying it was ironic for the US to try to keep the North Koreans/Chinese from winning the Korean War because the US had just won WWII.
Re: How the CIA used Crypto AG encryption devices to spy on countries for decades
#175Earlier quoted context omitted.
We in fact do not know that NSLs of the form suggested in the root comment exist. Such an NSL, requiring developers to stop work on a project, would in fact be unprecedented. It is, in fact, a conspiracy theory. In reality, the exact opposite thing occurs: the USG-backed Broadcast Board of Governors actively funds cryptographic privacy technology, both through direct grants to projects and, to head off other conspira…
Pretty sure you misinterpreted that comment. It's not suggesting that they pressured the devs to stop work, it says they were pressured to stop making it so awesome. The inference being that they were pressured to weaken the product and they walked away instead.
Re: How the CIA used Crypto AG encryption devices to spy on countries for decades
#176Earlier quoted context omitted.
I agree with the sentiment. The common argument against rolling out your own encryption just baffles me. Because there are plenty of ways to roll out your own encryption safely and in such a way that drastically eliminates the possibility of getting broken. Following is just a few ideas easily implemented even by a mediocre engineer. For the easiest, you can just apply multiple encryption algorithms in succession (of…
For downvoters - constructive counterarguments are welcome.
A back door is not a side channel.
Re: How the CIA used Crypto AG encryption devices to spy on countries for decades
#177Earlier quoted context omitted.
> what would they have done if the suspect hadn't used his laptop in a public place? Screw open his laptop when it's turned off and he's away from home, install a keylogger into the bios. Put a camera onto the shelf to film which keys he types to log in. If he puts a blanket over his head: solely rely on the sound each key makes. Hack his computer remotely using one of the government owned 0days and dump the keys. Us…
While what you are saying is possible technically, assuming any and all investigators in the US can tap into such capabilities is just FUD.
FDE's not worthless. Again, I don't think it's even optional; one of your laptops is eventually going to get stolen, and you're going to want the reassurance that at the very least, once it loses power, the thief won't have access to your data (meaning, in effect, that most thieves will never have access to your data). And it's somewhat more powerful on phones, which have integrated designs to make FDE more granular.
But the idea that of all the things the USG could spend energy on, aftermarket FDE software would be their target? It's not very plausible.
Re: How the CIA used Crypto AG encryption devices to spy on countries for decades
#178It has been known for a pretty long time that the Crypto AG is affiliated with or controlled by intelligence services. It was also always firmly in the "security through obscurity of our own cipher designs" department. Their C-52 (52 as in "1952") cipher machines were designed to enable decryption by Western intelligence. > Le Temps has argued that Crypto AG had been actively working with the British, US and West Ger…
I saw this article and that is exactly the first thought that popped up. Second thought was why is Washington Post feigning ignorance of this fact.
The new fact is that the company was co-owned, then fully owned by the CIA.
Re: How the CIA used Crypto AG encryption devices to spy on countries for decades
#179Earlier quoted context omitted.
Pretty sure you misinterpreted that comment. It's not suggesting that they pressured the devs to stop work, it says they were pressured to stop making it so awesome. The inference being that they were pressured to weaken the product and they walked away instead.
Just like lavabit: https://en.wikipedia.org/wiki/Lavabit#Suspension_and_gag_ord...
Re: How the CIA used Crypto AG encryption devices to spy on countries for decades
#180Earlier quoted context omitted.
> For one, the government can't compel you to do work. That's slavery. Slavery's perfectly legal. The 13th Amendment: "Neither slavery nor involuntary servitude, except as a punishment for crime whereof the party shall have been duly convicted , shall exist within the United States, or any place subject to their jurisdiction." https://en.wikipedia.org/wiki/Penal_labor_in_the_United_Stat...
Are you suggesting the TrueCrypt authors had been duly convicted of a crime?
See: Three Felonies a Day