Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

281–290 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#281

Earlier quoted context omitted.

When this stuff is used against you, it is FAR more likely going to be from a domestic group hostile to a political opinion you might have. Imagine if an outfit like Cambridge Analytica had the resources of a nation state helping it collect and process information about who might support any given policy (and be given the carrot) and who might oppose it (and be given the stick). That's the scale of threat we face. Wh…

I'm not clear if your post was implying this was the case or not, but this is an interesting, well-sourced article on the links between Cambridge Analytica and Russia [1]. [1] https://www.nytimes.com/2018/03/17/us/politics/cambridge-ana...

[dead]

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#282
post #217

Earlier quoted context omitted.

From the TrueCrypt webpage: http://truecrypt.sourceforge.net/ > WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues The fact that they use awkward wording that contains words whose first letters that start with NSA (not secure as) is pretty suggestive that you are right.

Doesn't seem like awkward wording to me (as a native English speaker, fwiw); just a routine disclaimer. I suppose the fact that it contains words that start with TIN (TrueCrypt is not) provides sufficient justification for your hat, anyhow.

It's in need of a comma, though.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#283
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

Given that the US has operations aiming to capture large amounts of Internet traffic, and given that most interesting Internet traffic is encrypted nowadays, doesn't it follow that they probably have a way to decrypt at least some of it? Capturing DNS queries and HTTP requests to aging websites that still haven't enabled TLS seems not worth the trouble.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#284
post #112

Earlier quoted context omitted.

Putting my tinfoil hat on, after reading the Snowden disclosures I'm convinced that they do have limited means of attacking encrypted communication but they would rather rely on these (expendable) means. Once they lose their crypto vulnerabilities it will force them to be even more overt.

The key difference is that decrypting something would likely need to be targeted and on a case-by-case basis, as it would take specialized work, as opposed to these sorts of attacks (much like tapping all of the pipes which transit data underseas or elsewhere, which still goes on in every country or working directly with the ISPs and mobile operators which happens in most countries) which allows mass dragnet surveill…

> WhatsApp and iMessage

Don't both of these have default/recommended configurations that back up your chats to cloud services?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#285
post #112

Earlier quoted context omitted.

The key difference is that decrypting something would likely need to be targeted and on a case-by-case basis, as it would take specialized work, as opposed to these sorts of attacks (much like tapping all of the pipes which transit data underseas or elsewhere, which still goes on in every country or working directly with the ISPs and mobile operators which happens in most countries) which allows mass dragnet surveill…

> WhatsApp and iMessage Don't both of these have default/recommended configurations that back up your chats to cloud services?

iCloud just recently added Messages in iCloud, but I know a fair amount of people that turn it off since the default iCloud storage space is 5gb.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#286

Earlier quoted context omitted.

> WhatsApp and iMessage Don't both of these have default/recommended configurations that back up your chats to cloud services?

iCloud just recently added Messages in iCloud, but I know a fair amount of people that turn it off since the default iCloud storage space is 5gb.

So the messages on your phone are not backed up with the normal iCloud backup?

I know WhatsApp nags to turn on chat backup to the cloud.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#287
post #4

Two parts of interest that jumped out to me: > The overlapping accounts expose frictions between the two partners over money, control and ethical limits, with the West Germans frequently aghast at the enthusiasm with which U.S. spies often targeted allies. > Hagelin had once hoped to turn control over to his son, Bo. But U.S. intelligence officials regarded him as a “wild card” and worked to conceal the partnership f…

> There were no indications of foul play. Yup

Have you ever driven on the beltway?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#288

Earlier quoted context omitted.

> tinfoil hat time This trope needs to die already.

What would you suggest instead? It's a good way to convey unfounded paranoia or to acknowledge that what you're saying sounds like a conspiracy theory.

> talking bout NSA

“Unfounded” paranoia

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#289
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

Given that the US has operations aiming to capture large amounts of Internet traffic, and given that most interesting Internet traffic is encrypted nowadays, doesn't it follow that they probably have a way to decrypt at least some of it? Capturing DNS queries and HTTP requests to aging websites that still haven't enabled TLS seems not worth the trouble.

It’s pretty straightforward. They 0day, hardware backdoor and infiltrate the ranks of root CA’s. This is covert information war from blank-check black op military agencies we’re talking about. They will kill people if they have to and sleep at night like babies because it is a utilitarian philosophy these people hold, not some Kantian dream.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#290

Can anyone here point out an actual case where the NSA was able to break or legitimately hack someone's crypto? I was under the impression that their track record was basically nil on this, and that virtually every instance of them spying on encrypted info boiled down to some sort of inside job that actually resulted in the encryption being weakened or thwarted. People speak about these guys like they have off the ch…

If they had that ability they certainly wouldn’t broadcast that capability, but I’ve seen enough crazy shit in the legal 0day market alone to think they have some insane capabilities. However, you’d never know If they could crack RSA/AES, but assuming quantum computing is on its way I’m sure it won’t be long or happened 8 years ago.
Post reply on HN