Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

301–310 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#302
There may be some new documents available now, but the story as such seems to have been known for a while. I first learned of it last summer while reading some of the drafts for Ross Anderson's update of his excellent Security Engineering.

See chapter 26, https://www.cl.cam.ac.uk/~rja14/book.html

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#303
post #258
post #243

Earlier quoted context omitted.

> Regardless of the terrible shit Trump has done, we would never accept him murdering journalists or critics There is strong evidence that Turkish intelligence intercepted the telephone call between Trump's son-in-law Jared Kushner and Bin Salman green-lighting the killing of Jamal Khashoggi, and used it as leverage to force the US drawdown in Syria. Turkish state media was the source of the audio recording of the mu…

So you are saying the US killed Khashoggi. Of course you don't mean that. What you mean is that the US didn't intervene. Yes, I am certain the world that hates the US would have loved the US intervening in Saudi Arabia's affairs. Whether the US gov't knew Saudi was going to do it or not is different than the US gov't pulling the trigger. Can you name the Trump, Obama, or Bush vocal american citizen critics that have…

Not really about critics, but murder of Epstein pretty much shows corruption of the US establishment.

I'm pretty sure there more deaths like this but I don't collect this data and US is the country with most efficient propaganda and brainwashing. It's extremely effective at hiding unpleasant facts and dissemination of fake news.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#304
post #112

Earlier quoted context omitted.

Putting my tinfoil hat on, after reading the Snowden disclosures I'm convinced that they do have limited means of attacking encrypted communication but they would rather rely on these (expendable) means. Once they lose their crypto vulnerabilities it will force them to be even more overt.

The key difference is that decrypting something would likely need to be targeted and on a case-by-case basis, as it would take specialized work, as opposed to these sorts of attacks (much like tapping all of the pipes which transit data underseas or elsewhere, which still goes on in every country or working directly with the ISPs and mobile operators which happens in most countries) which allows mass dragnet surveill…

> I think most of us would be fine with the NSA doing what they do if it was targeted, like the police getting warrants to break privacy only in important cases for public safety.

Except it's not getting a warrant, but simply deciding whether to spend resources. Which is not something that, like a warrant, I would be fine with.

Also there's another difference, technically it'll never really be on a case-by-case basis, because they can store all the encrypted communication (text chats, just store everything, easily). And they can in hindsight decide to decrypt any of that history (depending on ample metadata).

Or maybe they have a tiered system, a first-pass filter that detects a very vague definition of "possibly maybe interesting" (again, metadata) that would never ever pass a warrant request. Then just store everything that passes the filter, forever, and decrypt when needed.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#306
post #28

What a treat to read a well written piece based on decent research. It's a long read but well worth your time. Kudo's to the journalists who helped uncover it. And the 'coup of the century' is far from clickbait, it's definitionally warranted for what the CIA and BND did here. It's a little ironic as well, especially since the US is so keen on blocking Huawei over espionage concerns.

The fact that the US has repeatedly succeeded in SIGINT capers like this makes their concern about Huawei kind of un-ironic, right?

My take is that Huawei was bugging their hardware the same way the NSA does it and there can be only one. Plus, the US doesn't want Chinese bugged hardware.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#307
post #128

Earlier quoted context omitted.

The "don't roll your own" argument isn't against having lots of encryption algorithms, though. It's because it's nearly impossible for a nonspecialist to implement tools that other specialists can't fairly easily recognize as broken and exploit (whether cryptologically broken or due to side-channel exploits).

> other specialists can't fairly easily recognize as broken and exploit Is there any supporting evidence for this claim? If I took an AES library and changed the order of some inner loop wouldn't it require extensive statistical analysis to notice the difference? Which means instead of throwing a bunch of compute at decrypting me, along with the masses 10 years from now, you would need to get a specialist to specific…

> If I took an AES library and changed the order of some inner loop wouldn't it require extensive statistical analysis to notice the difference?

Unless you knew why it was organized the way it is in the original spec, altering it may weaken it. The DES S-boxes were altered by the NSA and everyone was suspicious, but it turns out they had made things stronger:

* https://en.wikipedia.org/wiki/Differential_cryptanalysis

Turns out the NSA was (at the time) over a decade ahead in crypto knowledge than the public.

As it stands, AES is approved for even TOP SECRET labelled information:

* https://en.wikipedia.org/wiki/NSA_Suite_B_Cryptography#Comme...

As are the various ECDH NIST curves that so many people are anxious about.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#308

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

Or maybe simply because the US intelligence not having a backdoor is why the're demonizing Huawei in Europe for example. That doesn't imply that Huawei does have a backdoor, simply that they'd not be able to spy anymore...

Not sure how that makes sense when the alternatives to Huawei proposed and supported by the US are European, primarily Ericsson and Nokia.

Where is the self-interest in the US pressuring European (mostly EU) countries to use EU competitors?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#309
post #43
post #28

Earlier quoted context omitted.

The fact that the US has repeatedly succeeded in SIGINT capers like this makes their concern about Huawei kind of un-ironic, right?

Well, yes, but for third parties like the UK it makes it much more explicit that the choice is between the system that might be compromised by Huawei and the system that might be compromised by the US. Except the UK has its own little joint venture of security inspection of Huawei systems ...

The alternatives that the US supports are European (Ericsson and Nokia, IIRC) so I see little benefit for at least EU countries regardless of their ties to the US to choose Huawei in this case.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#310
post #236

Earlier quoted context omitted.

> The CIA is a disaster that needs to be dismantled. Working for the CIA is like being a sysadmin. The world only knows you exist when you fuck up. There was a great CCC talk recently that showed how one of the Vault 7 tools wasn't a remote assassination boogieman drone tool like Wikileaks framed it, but actually a control the CIA developed that allowed them to give anti-air weapons to friendlies in Syria and Ukraine…

> Working for the CIA is like being a sysadmin. The world only knows you exist when you fuck up. While there's some truth to that, this way of thinking entirely ignores the opportunity cost that all those agencies have. With those insane budgets, you could do so much good in the world that one wouldn't have to fear the problems those agencies try to solve, because a lot of them wouldn't exist in the first place.

The budget of intelligence agencies is not anywhere near that big.
Post reply on HN