Live data from Hacker News

The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

firstlook.org

31–40 of 200 posts

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#31
post #12
post #6

At this point, we might as well just go back to landlines and fax machines.

Aren't those even easier to wiretap? I believe (maybe I'm wrong here) that the word wiretap comes precisely because people could literally "tap" into the wire and listen everything. Or did I miss the sarcasm?

The old technologies required more effort (somebody had to go physically tap the wire).

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#32

I think its safe to say NSA/GCHQ are not the only ones in the game who have hit this target.

On that note, I wonder if their compromising of these systems affords the target any sort of immunization from attacks by other actors.

It would make sense that NSA/GHCQ wouldn't want their foreign competitors to share in the prize, and it would also be congruent with their interests to not afford competing actors access to such a prize.

Then again, this notion is likely far too romantic. The reality is probably closer to one where foreign actors have compromised everything just the same.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#33

Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…

"Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people" Nothing new here - as the Belgacom hack has shown already.

So I may have missed the details. I thought we knew they hacked Belgacom, but no one mentioned going through employee's personal email and social networks (though in light of this, we can assume they did). If they did mention it and I missed it, sure, nothing new. But the same entire thing then just applies to that instance too.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#34
post #31
post #12

Earlier quoted context omitted.

Aren't those even easier to wiretap? I believe (maybe I'm wrong here) that the word wiretap comes precisely because people could literally "tap" into the wire and listen everything. Or did I miss the sarcasm?

The old technologies required more effort (somebody had to go physically tap the wire).

You can't tap a cell phone call remotely either - you have to be pretty close to the cell phone.

So it's not that different, a bit easier, yes. But you still have to physically go there.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#35
post #31
post #12

Earlier quoted context omitted.

Aren't those even easier to wiretap? I believe (maybe I'm wrong here) that the word wiretap comes precisely because people could literally "tap" into the wire and listen everything. Or did I miss the sarcasm?

The old technologies required more effort (somebody had to go physically tap the wire).

When I re-read the parent's post I thought to myself "of course he is being sarcastic!"

But then I saw your post and it made me think. And I believe you are onto something here.

I mean, sure, probably tapping one phone is much easier physically, just connect the wires and you're done. However the point you bring is game-changer.

In ye' olden days spooks were interested in certain persons only, but now it seems that we are all fair game, and so the "easy" way of wiretapping becomes incredibly hard when you want to spy on everyone.

It's basically an scalability problem then. Never saw it that way.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#36

Earlier quoted context omitted.

"Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people" Nothing new here - as the Belgacom hack has shown already.

So I may have missed the details. I thought we knew they hacked Belgacom, but no one mentioned going through employee's personal email and social networks (though in light of this, we can assume they did). If they did mention it and I missed it, sure, nothing new. But the same entire thing then just applies to that instance too.

> While working to assess the extent of the infection at Belgacom, the team of investigators realized that the damage was far more extensive than they first thought. The [ed: NSA] malware had not only compromised Belgacom’s email servers, it had infected more than 120 computer systems operated by the company, including up to 70 personal computers.

https://firstlook.org/theintercept/2014/12/13/belgacom-hack-...

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#37

Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…

Preface: this is not a defense.

It's worth remembering that some tools are only useful with lots of data about innocent people. Some forms of network analysis fall into this category, I believe.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#38
Personally, my biggest takeaway is that anything centralized is compromised, period.

Any centralized system is such a juicy target that the NSA will compromise it. The only way to avoid dragnet issues is to decentralize and force the NSA to expend resources at the edges.

This doesn't means that you can make an individual target secure. The NSA can always outspend you. But you can prevent the NSA from easily just vacuuming up everybody cheaply.

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#39
post #32

I think its safe to say NSA/GCHQ are not the only ones in the game who have hit this target.

On that note, I wonder if their compromising of these systems affords the target any sort of immunization from attacks by other actors. It would make sense that NSA/GHCQ wouldn't want their foreign competitors to share in the prize, and it would also be congruent with their interests to not afford competing actors access to such a prize. Then again, this notion is likely far too romantic. The reality is probably clos…

Sometimes denying data to others is as good as advertising that someone else got there first. So you might want to leave the treasure trove in place so that nobody else figures out you have it.

Intelligence is wheels within wheels within wheels...

Re: The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle

#40
post #37

Personally, the biggest take away to this is the invasive targeting of completely innocent and ordinary people simply as a means to get access to things the NSA needed (sim Card keys). We have concrete evidence they nailed peoples personal email accounts and social networks merely as a means to an get crypto keys in mass. Sure, the potential mass surveillance is exceedingly problematic, but thats mainly problematic b…

Preface: this is not a defense. It's worth remembering that some tools are only useful with lots of data about innocent people. Some forms of network analysis fall into this category, I believe.

Sure.

Lets suppose it actually was a valid defense. But what does that have to do with going through the Facebook and personal email of individual employees to know who to target. That was done up close, in personal, by hand. By any definition, those people had their privacy specifically and intentionally violated by actual human analysts.

Post reply on HN