Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

271–280 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#271
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

Putting my tinfoil hat on, after reading the Snowden disclosures I'm convinced that they do have limited means of attacking encrypted communication but they would rather rely on these (expendable) means. Once they lose their crypto vulnerabilities it will force them to be even more overt.

No tinfoil hat necessary. You're simply being practical. I mean, only the naive expect honesty from the three-letter acronyms. Honest is not their job.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#272

Earlier quoted context omitted.

So that's a "yes"? Presumably you think, similarly, that if NSA, say, breaks all elliptic curve discrete log crypto, a random analyst inside NSA will be able to submit a ticket and break random crypto? No, I don't think that's how it works. A class break in a core cryptography primitive or even a major break in a particular crypto format would be one of the most closely protected SIGINT secrets in the country; the nu…

agee was a mere case officer and knew about minerva, wrote about it in the book he published in the 70s. snowden had access to documentation for dozens or hundreds of projects, many of which were much more damaging to leak (eg technical details for xkeyscore) than a pgp attack. nsa breaks things so their analysts can decrypt intelligence. it's not much use if your people can't use it.

agee was a mere case officer and knew about minerva, wrote about it in the book he published in the 70s.

Agee was higher up in the intelligence hierarchy than Snowden and the MINERVA secret, while a fairly big deal, is not nearly as big of a deal as 'NSA can break some kinds of modern crypto' would be.

More importantly, I think you're misreading what the new writeups on this story say about Agee's knowledge. He doesn't mention MINERVA and didn't know anything about the BND-CIA joint infiltration of the company. Here's what he writes in Inside the Company:

The National Security Agency cannot break this code system mathematically but they can do so if sensitive recordings can be obtained of the vibrations of the encrypting machine when the discs clack to a stop. The recordings are processed through an oscilloscope and other machines which reveal the disc settings. Knowing the settings, NSA can put the encoded messages, which are intercepted through the commercial companies, into their own identical machines with identical settings, and the clear text message comes out. Although the Swiss manufacturer when selling the machine emphasizes the need to use it inside a sound-proof room on a table isolated by foam rubber, we hope this particular code clerk is careless. If we can discover the settings on this machine in Montevideo, NSA will be able to read the encrypted UAR messages on the entire circuit to which their Montevideo Embassy pertains.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#273

Earlier quoted context omitted.

I love privacy 'n' stuff, for sure. But relative to the risk of global nuclear war, and the certainty of global climate disruption, I couldn't care less about the NSA and its adversaries. And hey, maybe all that spying reduces the risk of overt war.

Okay, but these big picture perspectives don't materialize in a vacuum. It's not just this binary do-or-die nuclear deterrence that such a mindset acquiesces to. The rubber meets the road, and real names are drawn from a hat somewhere along the line. After we shoo away that pesky threat of hypersonic implosion triggered plutonium cores raining down upon our heads, the sun rises on a new day, and we have to put on cof…

Don’t understand the gun paragraph

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#274
post #243
post #220

Earlier quoted context omitted.

I am fine getting rid of the NSA as soon as you can guarantee that Russia and China dismantle their equivalents. Not to mention all the other agencies in the world. Sorry but when you talk of those two in particular, the US is the obvious good guy. Regardless of the terrible shit Trump has done, we would never accept him murdering journalists or critics. That shit happens regularly in Russia and China

> Regardless of the terrible shit Trump has done, we would never accept him murdering journalists or critics There is strong evidence that Turkish intelligence intercepted the telephone call between Trump's son-in-law Jared Kushner and Bin Salman green-lighting the killing of Jamal Khashoggi, and used it as leverage to force the US drawdown in Syria. Turkish state media was the source of the audio recording of the mu…

Source for Kushner phone call claim?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#275

Earlier quoted context omitted.

There's nothing ironic, weird, or surprising about the US wanting to stop other countries from doing to them what they do to other countries. It's hypocritical in some sense, mostly because the US tries to project itself as the good guys, but it's just basic international relations. That's how every country has always operated and will always operate.

The US mostly tries to project itself as "the good guys" to its own inhabitants, and secondly to the local and international media. But in most of the world you are often faced with the business end of a US-operated or US-financed weapon.

To be fair, it's a spectrum. The US has its share of bodies, but it also doesn't grind its citizens into a pulp with tanks when they protest.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#276
post #112

Earlier quoted context omitted.

The key difference is that decrypting something would likely need to be targeted and on a case-by-case basis, as it would take specialized work, as opposed to these sorts of attacks (much like tapping all of the pipes which transit data underseas or elsewhere, which still goes on in every country or working directly with the ISPs and mobile operators which happens in most countries) which allows mass dragnet surveill…

> I think most of us would be fine with the NSA doing what they do if it was targeted You think wrong. That fact that there are opposing world states engaging in this nefarious, oppressive, terrible acts and they're not all aligned doesn't legitimize any of these states' activities. The NSA should essentially be shut down, or cut down to a small agency operating in public with a much more limited mandate. And no secr…

NIST and the NSA should be shunned when it comes to setting crypto standards (apart from setting their own FIPS and such for government users) because they've demonstrated their corruption and efforts to work against the public interest. Instead, an international nonprofit that encourages transparency and academic adversarial due-diligence across the whole lifecycle of standards would be a better vehicle for crypto standards, like an Underwriters Laboratory or similar. (NESSIE-ish but even broader.) It's impossible to remove gamification and attempts to infiltrate standards bodies, but it's important to remove both appearances of condoning their subversion and proactively mitigating all actual infiltration should a fellow, contributor or other affiliate be working on behalf of a foreign government. It's not a "all gubberment bad" thing, but particular parts of government who's culture has infected the integrity of the process to deliver modern, reliable cryptography as a net commonwealth good, but they've chosen instead to create more liabilities and doubt that defeat and outweigh the "benefit" they brought to the table for users outside of government.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#277
Can anyone here point out an actual case where the NSA was able to break or legitimately hack someone's crypto? I was under the impression that their track record was basically nil on this, and that virtually every instance of them spying on encrypted info boiled down to some sort of inside job that actually resulted in the encryption being weakened or thwarted. People speak about these guys like they have off the charts abilities, yet the available evidence is not so indicative of that. Just looks like a big government operation kinda bumbling along to me.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#278
post #273

Earlier quoted context omitted.

Okay, but these big picture perspectives don't materialize in a vacuum. It's not just this binary do-or-die nuclear deterrence that such a mindset acquiesces to. The rubber meets the road, and real names are drawn from a hat somewhere along the line. After we shoo away that pesky threat of hypersonic implosion triggered plutonium cores raining down upon our heads, the sun rises on a new day, and we have to put on cof…

Don’t understand the gun paragraph

It's something like people who are into violence being immoral, I suspect. Not that I'd pick religion as a reliable measure for morality.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#279

Earlier quoted context omitted.

Okay, but these big picture perspectives don't materialize in a vacuum. It's not just this binary do-or-die nuclear deterrence that such a mindset acquiesces to. The rubber meets the road, and real names are drawn from a hat somewhere along the line. After we shoo away that pesky threat of hypersonic implosion triggered plutonium cores raining down upon our heads, the sun rises on a new day, and we have to put on cof…

It is arguable that the US and Russia have collectively committed a crime against humanity that's comparable to genocide. Not in any simple numeric sense, of course. But even 1% annual risk of killing a billion people, protracted over several decades, is a pretty big number. And yes, humanity is highly stratified. Socially, economically, whatever. But that just reflects what we are. Hate on it all you want, it's not…

OK, so reckless endangerment is a crime.[0] It's especially serious when weapons are involved, and when children are endangered. How does that not apply?

Except, of course, that there's no body with the requisite authority or power. But maybe someday there will be.

0) https://www.legalmatch.com/law-library/article/reckless-enda...

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#280
This article has made me decide to never mistake Huawei's ties to Chinese government surveillance for US political nonsense ever again.

I may not like our current US president, but it doesn't mean he can't use truths as political instruments.

Due to China's and Russia's human rights abuses, they are who I dislike the most. It might be by a small margin, but I would feel more comfortable having the CIA and NSA spy on me any day, than China or Russia.

What's wild is that I know many in China would feel the same way - but in the reverse.

Post reply on HN