Live data from Hacker News

Australian Federal Police and FBI nab underworld figures using encrypted app

abc.net.au

251–260 of 361 posts

Re: Australian Federal Police and FBI nab underworld figures using encrypted app

#251

The lesson here is complete trust in modern computing platforms is misplaced and impossible. Your hardware has backdoors, so does your OS, and encryption clients. In addition, popular apps, especially in the US, can always be commandeered by 3-letter agencies. You're only anonymous as long as you're not actively targetted, despite using "secure" apps and stuff like Tor, which media makes it seem are unbreakable.

Not quite. They were using an app developed by the police as a honeypot. Someone else had even discovered this and blogged about it[0]. If they had used email and PGP they likely wouldn't have been caught in this way. 3-letter agencies are not going to use their trump card of backdoored OS or hardware to catch drug runners. [0] https://webcache.googleusercontent.com/search?q=cache:PwQXt6...

If they used email and PGP, they wouldn't have been caught this way...

That is because the usability of PGP is so bad, they wouldn't have any time to actually operate their criminal enterprise.

Also - email, PGP or not, leaks metadata, and the police will happily end your whole criminal career based on metadata.

Re: Australian Federal Police and FBI nab underworld figures using encrypted app

#252
post #182

I've been reading a lot about these "encrypted phones recently". What really shocks me is how in the last years police has been going after operators of such services under the premise that they would help criminals. - Sky ECC (Shutdown, owner is facing criminal charges) - Phantom Secure (Shutdown and owner got 9 years in prison) - Encrochat ("Hacked" by french police) So it seems like those "Encrypted phones" were v…

>imminent mass shooting may prompt interdiction

Pulse night club comes to mind as a counterpoint. A lot of people died to keep an informant happy. I think a more cynical outlook on law enforcement is appropriate.

Re: Australian Federal Police and FBI nab underworld figures using encrypted app

#254
post #210
post #43

The Australian Broadcasting Corporation is covering it in more detail than the Reuters article, including some of the mechanics of how it was pulled off: https://www.abc.net.au/news/2021-06-08/fbi-afp-underworld-cr... Apparently it revolved around duping Hakan Ayik, one of Australia's most wanted drug dealers now operating as an international kingpin from Turkey, to trust the app and recommend it to his associates. I…

Can they actually just pin that on him just to get him? They need a scape goat and may as well

Not to say that they might not "may as well", but why exactly would the police need a scapegoat for arresting criminals?

Re: Australian Federal Police and FBI nab underworld figures using encrypted app

#255

Earlier quoted context omitted.

That is why effective end to end encryption is so important. It doesn't matter who is behind it. That is the whole point. No trust required.

The app can just leak your keys to a central database? Using code other people wrote/compiled always requires trust.

Could the OS lock down the app's permissions to prevent that?

Like, this app can ONLY send/recv e2e encrypted messages, and not log anything or talk to other apps.

Re: Australian Federal Police and FBI nab underworld figures using encrypted app

#256

I'm curious how this works constitutionally, in the US. Presumably the FBI did not have warrants for all the conversations they were listening in on, so it at least superficially seems like a fourth amendment violation.

Depends where they are prosecuted. In the US, we'll use the EU's copy of the data, vice versa (wish this was \s)

Re: Australian Federal Police and FBI nab underworld figures using encrypted app

#257

Earlier quoted context omitted.

That is why effective end to end encryption is so important. It doesn't matter who is behind it. That is the whole point. No trust required.

The app can just leak your keys to a central database? Using code other people wrote/compiled always requires trust.

The three requirements for effective end to end encryption:

1. All cryptographic keys controlled by the users.

2. Some way to confirm you are actually connected to who you think you are connected to.

3. A way to confirm that the code you are running is not leaking keys/content.

Re: Australian Federal Police and FBI nab underworld figures using encrypted app

#258

This seems to be just a messaging app, but is there a market for more full-featured ERP, CRM and project management software for criminal enterprises? I'm sure they would benefit from those just the same way legitimate enterprises do. The only difference is that they do more illegal stuff and use more violence, but the fundamental business dynamics should be the same.

What the fuck is wrong with you.

Re: Australian Federal Police and FBI nab underworld figures using encrypted app

#259
post #132
post #70

What we've learned is only what was in Austrlia's piece of the cake, given they started their day already. New Zeland had theirs already, too. I imagine thousands of arrests are still happening worldwide and several press conferences are going to be held today. Looking at the seal of the operation ( https://www.anom.io/trojan_shield_seal.jpg ), following countries participated in the operation: Canada, Australia, US,…

Sweden just announced 155 arrests: https://www.svt.se/nyheter/inrikes/europol-berattar-om-det-o...

Note that 155 is the grand total over the entire duration of the operation. The tally (given in your linked video) is:

* 70 yesterday in Sweden

* 5 yesterday in Spain (related to Swedish investigations)

* 80 earlier, candidly

I believe 70 is the figure that should be compared with the 800 total [1].

> A series of large-scale law enforcement actions were executed over the past days across 16 countries resulting in more than 700 house searches, more than 800 arrests [...]

1: https://www.europol.europa.eu/newsroom/news/800-criminals-ar...

Re: Australian Federal Police and FBI nab underworld figures using encrypted app

#260

Earlier quoted context omitted.

The app can just leak your keys to a central database? Using code other people wrote/compiled always requires trust.

Could the OS lock down the app's permissions to prevent that? Like, this app can ONLY send/recv e2e encrypted messages, and not log anything or talk to other apps.

The app could still send your keys _as_ an e2e message (to the app author). OS enforcement would need to be pretty intrusive to stop this (e.g. a pop-up for every message sent, displaying the actual destination of the message). I bet users would get pretty blind to such pop-ups, and it would be easy to trick them into accepting the leaking of their private keys.
Post reply on HN