Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

241–250 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#242

Earlier quoted context omitted.

They have a little bit at the top claiming that it's newsworthy because they had access to a complete internal history which is rarely declassified. Okay. I'll buy that. And at the end, they mention a good article from the Baltimore Sun that is MORE THAN 20 YEARS OLD! But that's at the end. Along the way, I wouldn't blame any reader for assuming that this is entirely new information.

The main (new) thing is that it was 100% CIA and German Intelligence owned, followed by 100% CIA owned. Not sure exactly how big of deal that really is... (Edit: other than being a longtime profit center for CIA slush money.) It's all a bit fishy, especially since it's admittedly sourced from within the agency. A lot depends on if it was an approved leak or not. With the divestment in 2018, and no other really new in…

I'm guessing it's a sanctioned leak because they want the world to understand the danger with Huawei. Now that others are playing the same game, they need to stop it!

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#243
post #220

Earlier quoted context omitted.

I'm sure that's what you would have told me 300 years ago if I claimed we should abolish monarchy and hereditary rule...

I am fine getting rid of the NSA as soon as you can guarantee that Russia and China dismantle their equivalents. Not to mention all the other agencies in the world. Sorry but when you talk of those two in particular, the US is the obvious good guy. Regardless of the terrible shit Trump has done, we would never accept him murdering journalists or critics. That shit happens regularly in Russia and China

> Regardless of the terrible shit Trump has done, we would never accept him murdering journalists or critics

There is strong evidence that Turkish intelligence intercepted the telephone call between Trump's son-in-law Jared Kushner and Bin Salman green-lighting the killing of Jamal Khashoggi, and used it as leverage to force the US drawdown in Syria. Turkish state media was the source of the audio recording of the murder inside the embassy, so it is not unreasonable to believe they have sufficient espionage capabilities against the Saudis to have phone recordings as well.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#245
post #220

Earlier quoted context omitted.

I'm sure that's what you would have told me 300 years ago if I claimed we should abolish monarchy and hereditary rule...

I am fine getting rid of the NSA as soon as you can guarantee that Russia and China dismantle their equivalents. Not to mention all the other agencies in the world. Sorry but when you talk of those two in particular, the US is the obvious good guy. Regardless of the terrible shit Trump has done, we would never accept him murdering journalists or critics. That shit happens regularly in Russia and China

It takes a lot of hubris to think that you would ever know for sure if some US three letter agency was killing journalists and critics.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#246

Earlier quoted context omitted.

That thought is one reason why I've always questioned this advice: "Don't roll your own encryption." I've always understood the arguments for it but that the advice is so widespread seemed a little counter intuitive. It always seemed, to me at least, that having millions of encryption algorithms out there would be inherently more secure than a lot of people standardized on one because the risk to any one would be so…

I agree with the sentiment. The common argument against rolling out your own encryption just baffles me. Because there are plenty of ways to roll out your own encryption safely and in such a way that drastically eliminates the possibility of getting broken. Following is just a few ideas easily implemented even by a mediocre engineer. For the easiest, you can just apply multiple encryption algorithms in succession (of…

To support both sides on this one, you could roll your own crypto on top of a third party crypto like AES. That way you get the benefits of both: You have the tried and true AES backing you up if your custom crypto is cracked, and you get security and obfuscation benefits from rolling your own crypto.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#247

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

Funny, I don't really care China spying on me as much since they just don't have any handles that would be relevant. Your own government spying on you is much more dangerous. And since I don't have influence on policies of China, I can at least hold domestic politicians that strive for more surveillance accountable. At least theoretically. History shows that government isn't your friend at all. The US might be a rare…

> Funny, I don't really care China spying on me as much since they just don't have any handles that would be relevant.

This is an incredibly foolish line of reasoning. Compromising the trust and sovereignty of individuals in the U.S. is an extreme risk, and it can come for anyone. The U.S. government at least will tend not to try undermining the U.S. economy except through specific policy initiatives; the Chinese government has a permanent interest in controlling the U.S. economy, and holding the threat of compromise over our heads.

No government is your friend, but there's really no comparing the abusiveness of the CCP, both at home and abroad, to the U.S. equivalent, and I'm honestly shocked that I ever have to remind people in the west of this.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#248

Earlier quoted context omitted.

How on Earth would he know? He's not a cryptographer. Much of what we've learned from the Snowden disclosures has been through experts granted access to the SCIF that houses the documents he exfiltrated. He didn't carefully review those documents before collecting them. I think it's really difficult to come to any kind of firm conclusion about what NSA can and can't break, even with a background in the material. I te…

> How on Earth would he know? I'm sure he said "to my knowledge" or something to that effect. That is, at least for at least relatively far into the circles of confidence, people did not know about encryption being broken algorithmicly or PGP broken in practice.

Which might also be a false-flag to encourage the use of PGP.

Russia has world class cryptographers too, and may have beaten the NSA to the punch. Snowden is after all currently living under FSB protection, which I doubt came for free. Someone willing to sell out their country would likely sell out its people too.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#249

Earlier quoted context omitted.

How on Earth would he know? He's not a cryptographer. Much of what we've learned from the Snowden disclosures has been through experts granted access to the SCIF that houses the documents he exfiltrated. He didn't carefully review those documents before collecting them. I think it's really difficult to come to any kind of firm conclusion about what NSA can and can't break, even with a background in the material. I te…

it was not his opinion; he mentioned in an interview that when analysts would try to pass along pgp-encrypted messages for cryptanalysis they would be rebuffed, as an example to demonstrate that there is properly-implemented strong cryptography resists scrutiny by nsa. here is documentation: https://twitter.com/Snowden/status/878686842631139334

I read it as the opposite.

"No decrypt available for _this_ PGP encrypted message."

You don't write an error message that way unless the code has a success case as well.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#250
post #222

Earlier quoted context omitted.

And for 2 years of boring paranoia there may be 2 days that save the day. I would expect that people that speak up are mostly dissatisfied and frustrated people. And for opacity, one part of the org will likely not know about what is going on on the other side. A big selection bias. But who knows...

I mean, sure, if you want to believe in superheroes, that's fine. But heroics typically have an opportunity to exist due to extreme events. Those, in turn, mostly happen due to massive screwups or deliberate large destructive events. Occasionally, accidents, but that's not what you're talking about. If you want insight as to why heroic interventions are a sign of failure, talk to your IT department and then scale tha…

I completely agree that the need of superheroic actions may arise by the result of self inflicted pains and it is usually the case in big corps.

At the same time, other heroic efforts may also require hard work to keep up with the competition or to clean up someone's mess.

That seems one of the reason they monitor what is going on and are vigilant: so they are more likely successful at preventing problems before they araise or become too big. Are not those the problems that require superheroic measures?

Post reply on HN