Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

231–240 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#231
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

Putting my tinfoil hat on, after reading the Snowden disclosures I'm convinced that they do have limited means of attacking encrypted communication but they would rather rely on these (expendable) means. Once they lose their crypto vulnerabilities it will force them to be even more overt.

SNEAKERNETWORK (an humble submission to cure some crypto ills)

It's time to resurrect the one time pad (not referring here to 2 factor authentication (2FA), I should hope to include 2FA FIDO in a Sneakernetwork standard), but rather the process of generating random data, shared between only two people, for the purpose of the most primitive of systems of encrypted communication. Simplest, but most secure(!!!)

There is a lot of research in this area, and each issue can be addressed (for example, the risk of reuse can be solved in various ways).

What we need is a way to "sneakernetwork" our otp random data to our friends. Like a business card, only where it's a mutual otp between these friends. For most people, 99% of important communications could be handled this way, through only a single contact. Certainly one could easily text for life with a single SDHC card of otp. And an SSD could handle phonecalls. A lifetime of video calls (again, between the two parties) aren't out of reach either.

What we also need is a networking protocol that supports forwarding through the web of trust messages to parties known only at the fringes of one's social network. For example, connections of the 1st degree are sneakernetworked contacts. Like you visit your mother, you share an otp blob. Now, even if your mother is in another country you can never visit, you can always talk to her about politics or religion without any worries about oppressive authorities. But out from there, anyone who is in your mother's 1st degree network can be added to your own 2nd degree network, depending upon her permissions. This kind of p2p interworking.

Before you object that "real" encryption is also needed, I agree, "real" encryption in addition to otp (it needs to be throughout a well-designed sneakernetwork system). But otp is superior, and, if you have to choose, choose otp.

There is no reason why the security of assymmetric encryption should matter to ordinary (or the majority of extraordinary) people.

It might be different for you, but 100% of the people I've had important conversations with have been friends I know from life, family, which I unsurprisingly know from life, and financial institutions of various kinds, which have offices for physical contact.

And I know the very thought of otp makes some people ill. It reminds one of hack jobs. Yet there it is, as factual, the best encryption, perfectly suited to normal people, and with data capacities at the level where it's beyond practical. What we lack is adequate paranoia and vision in the tech community.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#232

Earlier quoted context omitted.

> I think most of us would be fine with the NSA doing what they do if it was targeted You think wrong. That fact that there are opposing world states engaging in this nefarious, oppressive, terrible acts and they're not all aligned doesn't legitimize any of these states' activities. The NSA should essentially be shut down, or cut down to a small agency operating in public with a much more limited mandate. And no secr…

I love privacy 'n' stuff, for sure. But relative to the risk of global nuclear war, and the certainty of global climate disruption, I couldn't care less about the NSA and its adversaries. And hey, maybe all that spying reduces the risk of overt war.

Okay, but these big picture perspectives don't materialize in a vacuum. It's not just this binary do-or-die nuclear deterrence that such a mindset acquiesces to.

The rubber meets the road, and real names are drawn from a hat somewhere along the line. After we shoo away that pesky threat of hypersonic implosion triggered plutonium cores raining down upon our heads, the sun rises on a new day, and we have to put on coffee and make breakfast.

And some people ride in limousines from hotels for brunch, and some people ride the bus to a fast food job at the ass crack of dawn.

And you can bet that whomsoever holds the keys to these cryptosystems that serve as nuclear-proof umbrellas keeping our heads dry from the oh-so-inevitable megatons of explosive fire, they'll never drive a garbage truck, they're kids won't have to worry about flunking out of college, and none of them will ever get cold in the winter, unless they want to on their holiday ski trip.

And it's no accident, the way such things work.

So, maybe this whole nuclear war thing? Maybe it's always been a big shakedown.

Maybe, sometimes you buy a gun with the full knowledge that keeping it clean, safe and ready for reliable use is going to book your Sundays solid from now on, and whoops, the cost of gun ownership, it just so happens, is never attending Sunday mass again.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#233
post #222

Earlier quoted context omitted.

And for 2 years of boring paranoia there may be 2 days that save the day. I would expect that people that speak up are mostly dissatisfied and frustrated people. And for opacity, one part of the org will likely not know about what is going on on the other side. A big selection bias. But who knows...

I mean, sure, if you want to believe in superheroes, that's fine. But heroics typically have an opportunity to exist due to extreme events. Those, in turn, mostly happen due to massive screwups or deliberate large destructive events. Occasionally, accidents, but that's not what you're talking about. If you want insight as to why heroic interventions are a sign of failure, talk to your IT department and then scale tha…

Wow! I have never seen it stated that well. I always said this one team got hero status for saving a contract that was horribly underbid in schedule and budget, so they proceeded to underbid contracts to recreate the success. If we treated heroics as a red flag we would all be better off.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#234

Earlier quoted context omitted.

Just watch the "Mission Impossible" franchising. They are obviously dramatized stories but I would not be surprised that the world has been very closed to cease to exist as we know it and the only thing that prevented was that they did their job. Only few people know what they have done, no glory, no prizes, no recognition. What kind of people do that? Heros. Feel free to down vote me. I can only guess but I would no…

The world is far more Mr. Bean than James Bond.

The NSA hires neither, but mathematicians, programmers, electronics engineers. But the secret lives of computers are more dramatic than any movie!

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#235

Earlier quoted context omitted.

It doesn't make sense for two reasons to me. For one, the government can't compel you to do work. That's slavery. Also, it's open source software. TrueCrypt going down didn't change the security landscape at all.

> For one, the government can't compel you to do work. That's slavery. That may be your personal opinion, but legally speaking, it is not true in any sense.

[deleted]

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#236
post #173

Earlier quoted context omitted.

Hmm, nah I don't think people understand that they created NSA. It is them and their neighbor living in quiet area paying taxes where government want to keep them quiet and keep paying. This way of things is giving birth to idealism and naivete. Just like people living in cities are idealistic and naive about life of cattle and poultry. You don't want innocent chicken to be killed, but it is tasty. You don't want inn…

A spy agency is necessary for the USA to compete on the world stage. Though, it's operations should be significantly limited. The CIA is a disaster that needs to be dismantled.

> The CIA is a disaster that needs to be dismantled.

Working for the CIA is like being a sysadmin. The world only knows you exist when you fuck up.

There was a great CCC talk recently that showed how one of the Vault 7 tools wasn't a remote assassination boogieman drone tool like Wikileaks framed it, but actually a control the CIA developed that allowed them to give anti-air weapons to friendlies in Syria and Ukraine with positive access control and strong time/geo scoping to prevent them from being used nefariously.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#237

Earlier quoted context omitted.

I always assumed that this is exactly what happened to Skype and Whatsapp.

I’m in the exact same boat as you. I’m on mobile and lazy to post links, but Whatsapp’s acquisition was carried through a boutique investment bank which had former CIA director George Tenet on its board of directors. Anyway, I found a quick link about the bank [1], it’s called Allen & Co. And also let’s not forget that the precursor of Google Maps was funded with CIA venture capital money. I’m stil curious why and ho…

Also that one of the founders shifted his support to Signal...

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#238

Earlier quoted context omitted.

who else is it for?

So that's a "yes"? Presumably you think, similarly, that if NSA, say, breaks all elliptic curve discrete log crypto, a random analyst inside NSA will be able to submit a ticket and break random crypto? No, I don't think that's how it works. A class break in a core cryptography primitive or even a major break in a particular crypto format would be one of the most closely protected SIGINT secrets in the country; the nu…

To further your point, even Snowden didn’t have access to the documents that tell us precisely what BULLRUN is able to do, or how.

(The speculation is, of course, with reasonable circumstantial support, is that it is a ~$1B program that has brute-forced the most common 1024 DH group in use.)

We simply don’t have the hard data, it is (educated) speculation based on what information we do have.

Even the existence of the program is TS. Its capabilities remain secret, due to the exact system you describe.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#239
There was a documentary about this company and other surveillance topics aired on Swiss TV in last November.

https://www.rts.ch/dossiers/la-suisse-sous-couverture/

It's in French and may not be accessible outside Switzerland but I highly recommend it.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#240

Earlier quoted context omitted.

A spy agency is necessary for the USA to compete on the world stage. Though, it's operations should be significantly limited. The CIA is a disaster that needs to be dismantled.

The conceit of planetary-level politics being a "competition" is - with due respect - propaganda of the imperialist powers, that most of us are being fed and expected to buy into. Don't. In fact, with deepening global threats like climate change and nuclear war ( ), it is becoming clear just how mortally dangerous such perceptions are. So: Stop supporting "competition on the world stage". --- Yes, that is still a thi…

Welp, I'm a doomsday prepper now.
Post reply on HN