Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

291–300 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#291
post #84

Earlier quoted context omitted.

Wow. In a different timeline I'd dismiss that as tinfoil hat time, but in this one it seems spot on.

Nope, still tinfoil hat. This is just apophenia.

Thank you for the new word.

You make your case as if you have proof, which you likely don't. It's a moot point.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#292

Earlier quoted context omitted.

They have a little bit at the top claiming that it's newsworthy because they had access to a complete internal history which is rarely declassified. Okay. I'll buy that. And at the end, they mention a good article from the Baltimore Sun that is MORE THAN 20 YEARS OLD! But that's at the end. Along the way, I wouldn't blame any reader for assuming that this is entirely new information.

The main (new) thing is that it was 100% CIA and German Intelligence owned, followed by 100% CIA owned. Not sure exactly how big of deal that really is... (Edit: other than being a longtime profit center for CIA slush money.) It's all a bit fishy, especially since it's admittedly sourced from within the agency. A lot depends on if it was an approved leak or not. With the divestment in 2018, and no other really new in…

They forgot to add that after the CIA ownership, which was blown by Buehler's and Bamford's books, it was 100% Mossad owned via Marc Rich.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#293
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

>the current democratisation of encrpytion protocols is a threat to them. This is absolutely true and nowhere was it more evident than the Speck fiasco. Watching the old guard of the NSA show up and hammer a crypto forum with stonewalling and smug G-Man hand-waving would have been acceptable in 1995, but watching it take place after the snowden revelations was just cringe-worthy. The answer from the community wasnt j…

Yes, and it started with the development of minicomputers and PCs, which facilitated the process, starting in the late 70s.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#294

Earlier quoted context omitted.

"The majority of Android devices" is a very wide net to cast.

Qualcomm alone covers 40%, and they're arguably the most likely to correctly implement their MMU (nevermind they've seen quite a few vulnerabilities in their MMU implementations over the years..) Meditek uses a similar architecture, and I sure as hell don't trust their MMU. Outside of Apple, Librem and Pine are just about the only way you're getting a USB attached baseband. edit - Here's a Mediatek Baseband->AP PoC e…

Right. and even better, move the baseband to a USB-tethered device.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#295

Earlier quoted context omitted.

> tinfoil hat time This trope needs to die already.

What would you suggest instead? It's a good way to convey unfounded paranoia or to acknowledge that what you're saying sounds like a conspiracy theory.

There's nothing wrong with conspiracy theory. They regularly turn into conspiracy fact.

That's not a dirty phrase either - regardless of what the media memo said back then.

That's what I'm suggesting.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#296
post #230

Earlier quoted context omitted.

>Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network Makes me wonder what we've done using the fact US companies (ex: Cisco) control large swathes of the internet's infrastructure.

> US companies (ex: Cisco) control large swathes of the internet's infrastructure. Wouldn't China/Russia make some noise if they had proof the Cisco was hiding something in their infra?

I think they're pretty good at keeping it hidden and remote. It was proven the US did economic espionage on a German firm but the snowden files showed a range of other European companies also targeted. No doubt they also focus on "less friendly" targets industry, infrastructure and politics.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#297
post #236

Earlier quoted context omitted.

A spy agency is necessary for the USA to compete on the world stage. Though, it's operations should be significantly limited. The CIA is a disaster that needs to be dismantled.

> The CIA is a disaster that needs to be dismantled. Working for the CIA is like being a sysadmin. The world only knows you exist when you fuck up. There was a great CCC talk recently that showed how one of the Vault 7 tools wasn't a remote assassination boogieman drone tool like Wikileaks framed it, but actually a control the CIA developed that allowed them to give anti-air weapons to friendlies in Syria and Ukraine…

> Working for the CIA is like being a sysadmin. The world only knows you exist when you fuck up.

While there's some truth to that, this way of thinking entirely ignores the opportunity cost that all those agencies have. With those insane budgets, you could do so much good in the world that one wouldn't have to fear the problems those agencies try to solve, because a lot of them wouldn't exist in the first place.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#298
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

Putting my tinfoil hat on, after reading the Snowden disclosures I'm convinced that they do have limited means of attacking encrypted communication but they would rather rely on these (expendable) means. Once they lose their crypto vulnerabilities it will force them to be even more overt.

I think so too but reserve them for Bin Laden or "Iran is planning a Pearl Harbor type attack" cases, otherwise people would stop using these methods of communicating. Maybe very few people within the CIA /NSA even know of such abilities.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#299

Earlier quoted context omitted.

Why do you believe NSA spying decreases the risk of nuclear war, or helps stave off climate change? Also, it's not that we "love privacy", it's that we dislike oppression. And believe you me - most people in my part of the world know very well how the US is oppressing them through military and intelligence means. We don't want to live under the US' boot, and the NSA is part of that boot.

I didn't say anything about spying staving off climate change. That's pretty much a done deal, at least to the extent of destroying our current civilization. We've been in free fall to that, for at least a decade. And about nuclear war. Although I'm not expert, it seems pretty obvious that uncertainty increases the risk of war. Sure, I hate oppression. And I'm not into oppressing others. But the problem is all the as…

You could argue that uncertainty reduces the risk of war because you're only starting wars where you're reasonably certain that you can win. Uncertainty about your adversary's capabilities then prevents war.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#300

Earlier quoted context omitted.

> There were no indications of foul play. Yup

Have you ever driven on the beltway?

I have. Nowadays it's generally slow enough that it's hard to imagine dying in an accident there. But this was so long ago that I imagine things were different with the Beltway back then, and of course cars were much more deadly at the time too.
Post reply on HN