Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

181–190 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#181
post #128

Earlier quoted context omitted.

The "don't roll your own" argument isn't against having lots of encryption algorithms, though. It's because it's nearly impossible for a nonspecialist to implement tools that other specialists can't fairly easily recognize as broken and exploit (whether cryptologically broken or due to side-channel exploits).

> other specialists can't fairly easily recognize as broken and exploit Is there any supporting evidence for this claim? If I took an AES library and changed the order of some inner loop wouldn't it require extensive statistical analysis to notice the difference? Which means instead of throwing a bunch of compute at decrypting me, along with the masses 10 years from now, you would need to get a specialist to specific…

There's also a good chance that your change would break some assumptions/guarantees of AES, perhaps fatally (e.g. the result could be that your result only depends on just a few bits of the key).

True, if your threat model is exclusively future untargetted attacks ,your algorithm may be safer,but that is not a commonly accepted threat model I think, even for terrorists or banks.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#182

Earlier quoted context omitted.

> For one, the government can't compel you to do work. That's slavery. That may be your personal opinion, but legally speaking, it is not true in any sense.

It is also the argument that Apple used against the FBI in the San Bernardino case.

I'm just taking issue with the quoted claim at face value, outside of the context. Consider for example, the legality of jury duty, conscription, subpoenas, taxation, traffic stops, etc. Government-compelled actions are common and legal.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#183
post #112

Earlier quoted context omitted.

The key difference is that decrypting something would likely need to be targeted and on a case-by-case basis, as it would take specialized work, as opposed to these sorts of attacks (much like tapping all of the pipes which transit data underseas or elsewhere, which still goes on in every country or working directly with the ISPs and mobile operators which happens in most countries) which allows mass dragnet surveill…

> I think most of us would be fine with the NSA doing what they do if it was targeted You think wrong. That fact that there are opposing world states engaging in this nefarious, oppressive, terrible acts and they're not all aligned doesn't legitimize any of these states' activities. The NSA should essentially be shut down, or cut down to a small agency operating in public with a much more limited mandate. And no secr…

Just watch the "Mission Impossible" franchising. They are obviously dramatized stories but I would not be surprised that the world has been very closed to cease to exist as we know it and the only thing that prevented was that they did their job. Only few people know what they have done, no glory, no prizes, no recognition. What kind of people do that? Heros.

Feel free to down vote me.

I can only guess but I would not be surprised if your very life was saved. Or even if we just look at money, you may have lost a significant amount of what you have in a scam that was avoided.

We do not know what we do not know. But there must be more good than bad in what they do.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#184

Earlier quoted context omitted.

snowden explicitly said pgp was safe

How on Earth would he know? He's not a cryptographer. Much of what we've learned from the Snowden disclosures has been through experts granted access to the SCIF that houses the documents he exfiltrated. He didn't carefully review those documents before collecting them. I think it's really difficult to come to any kind of firm conclusion about what NSA can and can't break, even with a background in the material. I te…

it was not his opinion; he mentioned in an interview that when analysts would try to pass along pgp-encrypted messages for cryptanalysis they would be rebuffed, as an example to demonstrate that there is properly-implemented strong cryptography resists scrutiny by nsa. here is documentation: https://twitter.com/Snowden/status/878686842631139334

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#185
post #109

Earlier quoted context omitted.

> what would they have done if the suspect hadn't used his laptop in a public place? Screw open his laptop when it's turned off and he's away from home, install a keylogger into the bios. Put a camera onto the shelf to film which keys he types to log in. If he puts a blanket over his head: solely rely on the sound each key makes. Hack his computer remotely using one of the government owned 0days and dump the keys. Us…

While what you are saying is possible technically, assuming any and all investigators in the US can tap into such capabilities is just FUD.

Yeah, on the county sheriff level those capabilities are probably not available. However, Ulbricht was target of investigations on a federal level. He was arrested by FBI agents.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#186
post #43
post #28

Earlier quoted context omitted.

The fact that the US has repeatedly succeeded in SIGINT capers like this makes their concern about Huawei kind of un-ironic, right?

Well, yes, but for third parties like the UK it makes it much more explicit that the choice is between the system that might be compromised by Huawei and the system that might be compromised by the US. Except the UK has its own little joint venture of security inspection of Huawei systems ...

Also, the UK is one of the Five Eyes nations, explicitly sharing intelligence data with the US and vice-versa. I'm sure they're not 100%open, but if there is any nation on Earth that would not overly fear US spying and prefer it to Chinese spying, it would be the UK.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#187

Earlier quoted context omitted.

> I think most of us would be fine with the NSA doing what they do if it was targeted You think wrong. That fact that there are opposing world states engaging in this nefarious, oppressive, terrible acts and they're not all aligned doesn't legitimize any of these states' activities. The NSA should essentially be shut down, or cut down to a small agency operating in public with a much more limited mandate. And no secr…

Just watch the "Mission Impossible" franchising. They are obviously dramatized stories but I would not be surprised that the world has been very closed to cease to exist as we know it and the only thing that prevented was that they did their job. Only few people know what they have done, no glory, no prizes, no recognition. What kind of people do that? Heros. Feel free to down vote me. I can only guess but I would no…

The world is far more Mr. Bean than James Bond.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#188

What a treat to read a well written piece based on decent research. It's a long read but well worth your time. Kudo's to the journalists who helped uncover it. And the 'coup of the century' is far from clickbait, it's definitionally warranted for what the CIA and BND did here. It's a little ironic as well, especially since the US is so keen on blocking Huawei over espionage concerns.

>based on decent research The story was handed to him by the Agency, or agents of. The only "research" seems to be calling the names in the story for fact checking, and wapo couldn't even determine if some of them were alive or dead. This story is dangerously close to being nothing but a CIA press release.

Ok, what so you think the purpose is?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#189

Earlier quoted context omitted.

How on Earth would he know? He's not a cryptographer. Much of what we've learned from the Snowden disclosures has been through experts granted access to the SCIF that houses the documents he exfiltrated. He didn't carefully review those documents before collecting them. I think it's really difficult to come to any kind of firm conclusion about what NSA can and can't break, even with a background in the material. I te…

it was not his opinion; he mentioned in an interview that when analysts would try to pass along pgp-encrypted messages for cryptanalysis they would be rebuffed, as an example to demonstrate that there is properly-implemented strong cryptography resists scrutiny by nsa. here is documentation: https://twitter.com/Snowden/status/878686842631139334

Your expectation, then, would have been that if NSA had a cryptological capability unknown to the academic literature, it would have put it "on tap" for analysts to call on at random?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#190

Earlier quoted context omitted.

it was not his opinion; he mentioned in an interview that when analysts would try to pass along pgp-encrypted messages for cryptanalysis they would be rebuffed, as an example to demonstrate that there is properly-implemented strong cryptography resists scrutiny by nsa. here is documentation: https://twitter.com/Snowden/status/878686842631139334

Your expectation, then, would have been that if NSA had a cryptological capability unknown to the academic literature, it would have put it "on tap" for analysts to call on at random?

who else is it for?
Post reply on HN