Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

261–270 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#261
post #251

Earlier quoted context omitted.

Qualcomm alone covers 40%, and they're arguably the most likely to correctly implement their MMU (nevermind they've seen quite a few vulnerabilities in their MMU implementations over the years..) Meditek uses a similar architecture, and I sure as hell don't trust their MMU. Outside of Apple, Librem and Pine are just about the only way you're getting a USB attached baseband. edit - Here's a Mediatek Baseband->AP PoC e…

https://googleprojectzero.blogspot.com/2017/10/over-air-vol-... Even Apple's IOMMU has had vulnerabilities allowing for full memory access from the WiFi modem.

The wifi stack isn't the cellular modem. There's a reason people are particularly concerned about the baseband.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#262

Earlier quoted context omitted.

I love privacy 'n' stuff, for sure. But relative to the risk of global nuclear war, and the certainty of global climate disruption, I couldn't care less about the NSA and its adversaries. And hey, maybe all that spying reduces the risk of overt war.

Why do you believe NSA spying decreases the risk of nuclear war, or helps stave off climate change? Also, it's not that we "love privacy", it's that we dislike oppression. And believe you me - most people in my part of the world know very well how the US is oppressing them through military and intelligence means. We don't want to live under the US' boot, and the NSA is part of that boot.

To be fair, I don't think a search warrant is oppression if used correctly. If there was something analogous for encryption I wouldn't mind. Problem is an "encryption search warrant" likely would happen without anyone knowing about it.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#263

Earlier quoted context omitted.

I love privacy 'n' stuff, for sure. But relative to the risk of global nuclear war, and the certainty of global climate disruption, I couldn't care less about the NSA and its adversaries. And hey, maybe all that spying reduces the risk of overt war.

Okay, but these big picture perspectives don't materialize in a vacuum. It's not just this binary do-or-die nuclear deterrence that such a mindset acquiesces to. The rubber meets the road, and real names are drawn from a hat somewhere along the line. After we shoo away that pesky threat of hypersonic implosion triggered plutonium cores raining down upon our heads, the sun rises on a new day, and we have to put on cof…

It is arguable that the US and Russia have collectively committed a crime against humanity that's comparable to genocide. Not in any simple numeric sense, of course. But even 1% annual risk of killing a billion people, protracted over several decades, is a pretty big number.

And yes, humanity is highly stratified. Socially, economically, whatever. But that just reflects what we are. Hate on it all you want, it's not gonna change.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#264

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

it could be as simple as Huawei refusing to install a backdoor for them.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#265

Earlier quoted context omitted.

I love privacy 'n' stuff, for sure. But relative to the risk of global nuclear war, and the certainty of global climate disruption, I couldn't care less about the NSA and its adversaries. And hey, maybe all that spying reduces the risk of overt war.

Why do you believe NSA spying decreases the risk of nuclear war, or helps stave off climate change? Also, it's not that we "love privacy", it's that we dislike oppression. And believe you me - most people in my part of the world know very well how the US is oppressing them through military and intelligence means. We don't want to live under the US' boot, and the NSA is part of that boot.

Gives those who get a kick out of war and conflict something to do that isn't lob nukes at each other.

Same reason you want layers of government with progression at a small scale available to many. So all the people with political ambitions aren't all trying to start their own governments and revolutions.

Busy is stability.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#266
post #109

Earlier quoted context omitted.

> what would they have done if the suspect hadn't used his laptop in a public place? Screw open his laptop when it's turned off and he's away from home, install a keylogger into the bios. Put a camera onto the shelf to film which keys he types to log in. If he puts a blanket over his head: solely rely on the sound each key makes. Hack his computer remotely using one of the government owned 0days and dump the keys. Us…

While what you are saying is possible technically, assuming any and all investigators in the US can tap into such capabilities is just FUD.

Or...properly assessing risk?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#267
post #112

Earlier quoted context omitted.

Putting my tinfoil hat on, after reading the Snowden disclosures I'm convinced that they do have limited means of attacking encrypted communication but they would rather rely on these (expendable) means. Once they lose their crypto vulnerabilities it will force them to be even more overt.

The key difference is that decrypting something would likely need to be targeted and on a case-by-case basis, as it would take specialized work, as opposed to these sorts of attacks (much like tapping all of the pipes which transit data underseas or elsewhere, which still goes on in every country or working directly with the ISPs and mobile operators which happens in most countries) which allows mass dragnet surveill…

All it takes is one elected president who could upend the other branches, and the three letters become much more scary.

But thats just a partisan political beliefs, right?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#268
post #220

Earlier quoted context omitted.

I'm sure that's what you would have told me 300 years ago if I claimed we should abolish monarchy and hereditary rule...

I am fine getting rid of the NSA as soon as you can guarantee that Russia and China dismantle their equivalents. Not to mention all the other agencies in the world. Sorry but when you talk of those two in particular, the US is the obvious good guy. Regardless of the terrible shit Trump has done, we would never accept him murdering journalists or critics. That shit happens regularly in Russia and China

Thinking of the US as “the good guy” deters improvement. If anything, the US is “the better guy,” a more modest claim.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#269
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

>the current democratisation of encrpytion protocols is a threat to them.

This is absolutely true and nowhere was it more evident than the Speck fiasco. Watching the old guard of the NSA show up and hammer a crypto forum with stonewalling and smug G-Man hand-waving would have been acceptable in 1995, but watching it take place after the snowden revelations was just cringe-worthy. The answer from the community wasnt just no, but hell no.

https://www.tomshardware.com/news/nsa-speck-removed-linux-4-...

I suspect things like ED25519 and LetsEncrypt were probably a much more damning blow to the day-to-day business of warrantless telecom spying than we're led to believe, and its only going to get closer to that 10% pre-MINERVA figure as time rolls on. the Signal protocol has gained massive traction, and things like Tails are easy enough for a power user. Once someone rolls out a slick CSS frontend for wireguard its back to greasing the palms of guys like RSA in the hopes snooping corporate networks is just as fruitful as snooping the public internet.

CryptoAG tips the governments hand on exactly why it disfavors crypto now. its not terrorists or posthumous parallel construction of $latest_shooter. its about control.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#270
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

> If there was, then perhaps there wouldn't be such a strong push to rig the deck in the first place. At least that's heartening.

Intelligence isn't about truth and transparency. It's about deception. They're not going to run a Super Bowl advert saying they can crack anything. That's not how it works.

Post reply on HN