Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

31–40 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#31

It certainly does make one wonder who else in the worlds of high technology (and journalism!) May be – wittingly or unwittingly – working for Uncle Sam. I've seen some deep integrations that have made me despair of any organization being free from the overweening influence of the "security services." I'm talking about groups as large as multi-billion dollar public US technology infrastructure companies and as small a…

US Telcos have been jointed at the hip w/ the USIC for generations. AT&T's history of proactively helping the US spy on US Citizens+Everyone hints at the company's deep desire to be a spy entity in it's own right. Even though the knowledge of that is/was public, it wasn't widely know until the Edward Snowden revelations - largely due to the relative disinterest of US news orgs (even when faced with clear evidence of…

Worth pointing out that the rules around telco accounting are pretty much designed to give Interested Parties a single point to siphon off call metadata.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#32
post #17
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

I'm pretty sure the US government is why the TrueCrypt devs stopped all work. They got hit with a national security letter (NSL) or heavily leaned on and pressured to stop making their product so awesome and un-breakable.

I'm sure they were pressured, but the USG has deep pockets if they wanted someone to stop doing something they just throw a few million at them and call it done, there's far less chance of PR blowback then.

Even just reading this article should show you that they kill you with kindness when they want to keep things hush-hush. If someone is developing a free tool, and are offered a retirement-tier payoff to stop, they're going to stop.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#33

I have to disagree with the headline. The "intelligence coup of the century" came much earlier, during WWII. The Allies were reading a good deal of both Japanese and German encrypted communications. This saved the lives of many Allied solders and, perhaps, tipped the balance of the war. https://en.wikipedia.org/wiki/Magic_(cryptography) https://en.wikipedia.org/wiki/Ultra David Kahn's book, the Codebreakers, is a goo…

In terms of scope & scale you may be underselling the title. Enigma, while perhaps more far-reaching in its consequences for computerization, did not have consistent application its breaking would suggest. American code-breakers had more success against the Japanese in practical terms, Midway most especially, but the imperials were a doomed effort[0]. As the cliche goes, British intelligence, American steel, and Russian blood, all of which overshadowed by the Bomb.

To put it bluntly, the equivalent would have to be, say, informing Stalin about Barbarossa, or cracking Purple before Pearl Harbor.

What the article describes, is the most thorough and long-running (known) intelligence operation in modern history. It is simply unparalleled in strategic depth and tactical implications, not to mention how it must have shaped global politics, economics & social development.

[0]http://www.combinedfleet.com/economic.htm

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#34
post #30

It follows that private VPN firms would be a similar target for deep pocketed state intelligence agencies. What do you think the chances are that the VPN service or software you use hasn't been co-opted, compromised or is outright owned by state actors in China, Europe or the US?

It would be hopelessly naive to assume that intelligence services don't run a large number of VPN providers an tor relays, just as the used to run mix master smtp (email) relays.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#35
post #17
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

I'm pretty sure the US government is why the TrueCrypt devs stopped all work. They got hit with a national security letter (NSL) or heavily leaned on and pressured to stop making their product so awesome and un-breakable.

I'm not sure that makes sense. The US could compel the devs to compromise their product but not keep them from issuing a cryptic statement and stopping work on the product?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#36
post #17
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

I'm pretty sure the US government is why the TrueCrypt devs stopped all work. They got hit with a national security letter (NSL) or heavily leaned on and pressured to stop making their product so awesome and un-breakable.

But the source-available VeraCrypt still exists and is maintained.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#37
post #17

Earlier quoted context omitted.

I'm pretty sure the US government is why the TrueCrypt devs stopped all work. They got hit with a national security letter (NSL) or heavily leaned on and pressured to stop making their product so awesome and un-breakable.

I'm not sure that makes sense. The US could compel the devs to compromise their product but not keep them from issuing a cryptic statement and stopping work on the product?

It doesn't make sense for two reasons to me. For one, the government can't compel you to do work. That's slavery.

Also, it's open source software. TrueCrypt going down didn't change the security landscape at all.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#38
post #15

https://outline.com/tTTmh6 And http://archive.is/1w61P

Thanks, it gets irksome at some points that a large number of submitted content on HN is paywalled. I can't subscribe to all of these, just to read a couple of articles a month per publication.

Yes. It would be useful to have an accessible version posted with the original each time, and for it to be a preferred guideline for submitters.

Though to be fair, I'm not sure if there are copyright issues involved, which might make such a guideline difficult.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#39
post #17

Earlier quoted context omitted.

I'm pretty sure the US government is why the TrueCrypt devs stopped all work. They got hit with a national security letter (NSL) or heavily leaned on and pressured to stop making their product so awesome and un-breakable.

I'm sure they were pressured, but the USG has deep pockets if they wanted someone to stop doing something they just throw a few million at them and call it done, there's far less chance of PR blowback then. Even just reading this article should show you that they kill you with kindness when they want to keep things hush-hush. If someone is developing a free tool, and are offered a retirement-tier payoff to stop, they…

They didn't kill lavabit with kindness.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#40

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

Funny, I don't really care China spying on me as much since they just don't have any handles that would be relevant. Your own government spying on you is much more dangerous. And since I don't have influence on policies of China, I can at least hold domestic politicians that strive for more surveillance accountable. At least theoretically. History shows that government isn't your friend at all. The US might be a rare…

You might be a god-fearing clean-shaven American, but I strongly suspect the number of Americans who have secrets they can be blackmailed over is at least one percent. While I’d like to change every society so such secrets are not big issues, I don’t expect that to happen, and 3.5 million Americans being potentially blackmailed by a superpower is something I’d prefer to avoid even though I’m not an American and don’t expect to live in the USA.
Post reply on HN