Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

251–260 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#251

Earlier quoted context omitted.

"The majority of Android devices" is a very wide net to cast.

Qualcomm alone covers 40%, and they're arguably the most likely to correctly implement their MMU (nevermind they've seen quite a few vulnerabilities in their MMU implementations over the years..) Meditek uses a similar architecture, and I sure as hell don't trust their MMU. Outside of Apple, Librem and Pine are just about the only way you're getting a USB attached baseband. edit - Here's a Mediatek Baseband->AP PoC e…

https://googleprojectzero.blogspot.com/2017/10/over-air-vol-...

Even Apple's IOMMU has had vulnerabilities allowing for full memory access from the WiFi modem.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#252

Earlier quoted context omitted.

That thought is one reason why I've always questioned this advice: "Don't roll your own encryption." I've always understood the arguments for it but that the advice is so widespread seemed a little counter intuitive. It always seemed, to me at least, that having millions of encryption algorithms out there would be inherently more secure than a lot of people standardized on one because the risk to any one would be so…

I agree with the sentiment. The common argument against rolling out your own encryption just baffles me. Because there are plenty of ways to roll out your own encryption safely and in such a way that drastically eliminates the possibility of getting broken. Following is just a few ideas easily implemented even by a mediocre engineer. For the easiest, you can just apply multiple encryption algorithms in succession (of…

This isn't really "roll your own". This is "run with non-standard parameters". This is a much smaller footgun, though you can really screw this up.

World experts in practical crypto regularly ship implementations that have serious errors that remain undetected by other world experts for years. This shit is hard.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#254
post #249

Earlier quoted context omitted.

it was not his opinion; he mentioned in an interview that when analysts would try to pass along pgp-encrypted messages for cryptanalysis they would be rebuffed, as an example to demonstrate that there is properly-implemented strong cryptography resists scrutiny by nsa. here is documentation: https://twitter.com/Snowden/status/878686842631139334

I read it as the opposite. "No decrypt available for _this_ PGP encrypted message." You don't write an error message that way unless the code has a success case as well.

The NSA has likely harvested and cached thousands of PGP secret keys from passive monitoring of internet links public and private (Google famously failed to use encryption on internal WAN links for a long time), active exploitation of host and workstation systems, and bulk exfiltration of nonpublic data from service providers (think stored records: emails and files).

(Unrelated: As well as TLS long term keys, passwords, hashes, usernames, and any other kind of metadata or secrets that may be useful one day in the future, if nothing more than for dictionary attack prefix/suffix fodder.)

I wouldn’t be surprised if they have some more creative secret key sources too: stolen and glitched smart cards, laptops that disappeared out of targets’ cars, tossed offices via evil maid, dumpster diving, all of it, including some I probably haven’t thought of because I’m a computer nerd and not a military intelligence cloak-and-dagger type.

Put all the recovered secrets into a big ol’ database, because disk is cheap and keys are small. Keep it for all time, Just In Case.

Of course, there is a request system frontending this capability.

There are many PGP messages they can decrypt, simply because they slurped up the specific private keys for those messages at some point, and simply saved every secret key, hash, or password that they ever saw, as a general organizational policy.

That doesn’t mean they have broken PGP.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#255
post #202

Earlier quoted context omitted.

Just watch the "Mission Impossible" franchising. They are obviously dramatized stories but I would not be surprised that the world has been very closed to cease to exist as we know it and the only thing that prevented was that they did their job. Only few people know what they have done, no glory, no prizes, no recognition. What kind of people do that? Heros. Feel free to down vote me. I can only guess but I would no…

There's plenty of memoirs by actual intelligence agents. The world is a lot more boring than films and far more complicated and difficult to pull off serious operations. The serious operations often merely being inside information about other nation states. Not saving the world from bad guys. It's mostly just a long series of super paranoid people chasing each other in circles. And in between plenty of useful informa…

The other amusing thing is that said leaders often ignore all that useful information when making their decisions, because they believe that they know better.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#257
post #220

Earlier quoted context omitted.

I am fine getting rid of the NSA as soon as you can guarantee that Russia and China dismantle their equivalents. Not to mention all the other agencies in the world. Sorry but when you talk of those two in particular, the US is the obvious good guy. Regardless of the terrible shit Trump has done, we would never accept him murdering journalists or critics. That shit happens regularly in Russia and China

It takes a lot of hubris to think that you would ever know for sure if some US three letter agency was killing journalists and critics.

Ummm Trump's biggest critics aren't dropping dead left and right. That is exactly what happens to Putin's critics.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#258
post #243
post #220

Earlier quoted context omitted.

I am fine getting rid of the NSA as soon as you can guarantee that Russia and China dismantle their equivalents. Not to mention all the other agencies in the world. Sorry but when you talk of those two in particular, the US is the obvious good guy. Regardless of the terrible shit Trump has done, we would never accept him murdering journalists or critics. That shit happens regularly in Russia and China

> Regardless of the terrible shit Trump has done, we would never accept him murdering journalists or critics There is strong evidence that Turkish intelligence intercepted the telephone call between Trump's son-in-law Jared Kushner and Bin Salman green-lighting the killing of Jamal Khashoggi, and used it as leverage to force the US drawdown in Syria. Turkish state media was the source of the audio recording of the mu…

So you are saying the US killed Khashoggi.

Of course you don't mean that. What you mean is that the US didn't intervene.

Yes, I am certain the world that hates the US would have loved the US intervening in Saudi Arabia's affairs.

Whether the US gov't knew Saudi was going to do it or not is different than the US gov't pulling the trigger.

Can you name the Trump, Obama, or Bush vocal american citizen critics that have been killed by the government? Because it sure is easy to find the ones Putin has murdered

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#259

Earlier quoted context omitted.

I love privacy 'n' stuff, for sure. But relative to the risk of global nuclear war, and the certainty of global climate disruption, I couldn't care less about the NSA and its adversaries. And hey, maybe all that spying reduces the risk of overt war.

Why do you believe NSA spying decreases the risk of nuclear war, or helps stave off climate change? Also, it's not that we "love privacy", it's that we dislike oppression. And believe you me - most people in my part of the world know very well how the US is oppressing them through military and intelligence means. We don't want to live under the US' boot, and the NSA is part of that boot.

I didn't say anything about spying staving off climate change. That's pretty much a done deal, at least to the extent of destroying our current civilization. We've been in free fall to that, for at least a decade.

And about nuclear war. Although I'm not expert, it seems pretty obvious that uncertainty increases the risk of war.

Sure, I hate oppression. And I'm not into oppressing others.

But the problem is all the assholes who are driven to oppress others. If I could snap my fingers, and have them all die instantly, I would. But that just ain't gonna happen.

And indeed, it's arguable that they've been selected for, since the development of agriculture and animal husbandry. I got that from Morgan's Black Man.

So anyway, I just do what I can for myself and those close to me, and what I can to help others. I don't focus so much on changing the system. Given how people are, it seems kinda pointless.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#260
post #230

Earlier quoted context omitted.

>Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network Makes me wonder what we've done using the fact US companies (ex: Cisco) control large swathes of the internet's infrastructure.

> US companies (ex: Cisco) control large swathes of the internet's infrastructure. Wouldn't China/Russia make some noise if they had proof the Cisco was hiding something in their infra?

I thought the whole point of such things is it's near impossible to prove?

Also complaining means you reveal what you know, which helps narrow what you don't know.

Post reply on HN