Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

221–230 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#221

Earlier quoted context omitted.

who else is it for?

So that's a "yes"? Presumably you think, similarly, that if NSA, say, breaks all elliptic curve discrete log crypto, a random analyst inside NSA will be able to submit a ticket and break random crypto? No, I don't think that's how it works. A class break in a core cryptography primitive or even a major break in a particular crypto format would be one of the most closely protected SIGINT secrets in the country; the nu…

agee was a mere case officer and knew about minerva, wrote about it in the book he published in the 70s. snowden had access to documentation for dozens or hundreds of projects, many of which were much more damaging to leak (eg technical details for xkeyscore) than a pgp attack. nsa breaks things so their analysts can decrypt intelligence. it's not much use if your people can't use it.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#222
post #202

Earlier quoted context omitted.

There's plenty of memoirs by actual intelligence agents. The world is a lot more boring than films and far more complicated and difficult to pull off serious operations. The serious operations often merely being inside information about other nation states. Not saving the world from bad guys. It's mostly just a long series of super paranoid people chasing each other in circles. And in between plenty of useful informa…

And for 2 years of boring paranoia there may be 2 days that save the day. I would expect that people that speak up are mostly dissatisfied and frustrated people. And for opacity, one part of the org will likely not know about what is going on on the other side. A big selection bias. But who knows...

I mean, sure, if you want to believe in superheroes, that's fine. But heroics typically have an opportunity to exist due to extreme events. Those, in turn, mostly happen due to massive screwups or deliberate large destructive events. Occasionally, accidents, but that's not what you're talking about.

If you want insight as to why heroic interventions are a sign of failure, talk to your IT department and then scale that up to nation states.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#223

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

>Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network

Makes me wonder what we've done using the fact US companies (ex: Cisco) control large swathes of the internet's infrastructure.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#224

Earlier quoted context omitted.

I'm sure they were pressured, but the USG has deep pockets if they wanted someone to stop doing something they just throw a few million at them and call it done, there's far less chance of PR blowback then. Even just reading this article should show you that they kill you with kindness when they want to keep things hush-hush. If someone is developing a free tool, and are offered a retirement-tier payoff to stop, they…

If an average person got a huge windfall, that would raise a lot of attention, and people would wonder how they got the money. Police use sudden unexplained riches as a way to watch out for criminal activity, and everyone who knew the receiver of the windfall would ask questions. Between $10M and the other option, it may be easier to kill them with killing.

Agencies routinely set up fake businesses for cover, with the cooperation of insiders at big names (e.g. Dell). So you set up a fake SaaS, have your big name client buy the big thing 25k / CPU x however many you need to reach payout, done. All legitimized by a fancy public stock name.

If things really get too hot, it's easy to send a letter to any country's IRS via their local intell agency.

You'd be surprised how simple it is to close files in this world. I'd suggest reading Snowden's autobiography, Permanent Record. Very eye-opening and a great read.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#225
post #219

Earlier quoted context omitted.

snowden explicitly said pgp was safe

He said that, from his vantage point, analysts at BAH didn't have access to capabilities to break PGP emails. To be sure, that's an important fact. And it does mean that PGP (and for that matter, similar cryptosystems with robust implementations) create a palpable and useful protection against this kind of analysis. But in the event that the NSA (or other agencies engaged in signals intelligence) have an attack wholl…

that's a fair distinction

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#226
post #128

Earlier quoted context omitted.

The "don't roll your own" argument isn't against having lots of encryption algorithms, though. It's because it's nearly impossible for a nonspecialist to implement tools that other specialists can't fairly easily recognize as broken and exploit (whether cryptologically broken or due to side-channel exploits).

> other specialists can't fairly easily recognize as broken and exploit Is there any supporting evidence for this claim? If I took an AES library and changed the order of some inner loop wouldn't it require extensive statistical analysis to notice the difference? Which means instead of throwing a bunch of compute at decrypting me, along with the masses 10 years from now, you would need to get a specialist to specific…

Maybe it would be safe, but there would be a decent chance you would accidentally mess up sometime simple and makee the algorithm trivial to decrypt. How do I know? I've experimented with variants of hash functions and seen that happen.

IIRC Groestl if you switch the inputs between the P and Q functions you'll introduce fixed points ino Groestl. Or take your example of AES, if you changed AES such that the loop which ran shift rows and increase it to run four times, you'd massively damage diffusion and probably have a trivially breakable block cipher. Modern cryptographic primitives are very carefully built, minor changes can be disastrous.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#227
post #22

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

It wouldn't be so bad with ubiquitous end to end encryption though right? If everything was encrypted in transit it wouldn't really matter if Huawei (and by extension the supposition goes the Chinese government) because they'd just see noise. Guess they would also be able to do location tracking though and that's not so easily solved.

There is also the risk of disrupting network operations at some unfortunate time, especially since these new networks are thought to be dominated by machine-to-machine communications.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#228
post #84

Earlier quoted context omitted.

Wow. In a different timeline I'd dismiss that as tinfoil hat time, but in this one it seems spot on.

> tinfoil hat time This trope needs to die already.

What would you suggest instead? It's a good way to convey unfounded paranoia or to acknowledge that what you're saying sounds like a conspiracy theory.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#230

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

>Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network Makes me wonder what we've done using the fact US companies (ex: Cisco) control large swathes of the internet's infrastructure.

> US companies (ex: Cisco) control large swathes of the internet's infrastructure.

Wouldn't China/Russia make some noise if they had proof the Cisco was hiding something in their infra?

Post reply on HN