Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

311–320 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#311

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

Funny, I don't really care China spying on me as much since they just don't have any handles that would be relevant. Your own government spying on you is much more dangerous. And since I don't have influence on policies of China, I can at least hold domestic politicians that strive for more surveillance accountable. At least theoretically. History shows that government isn't your friend at all. The US might be a rare…

You don't have to live in China for the Chinese government to have power over you. The threat of releasing your secret emails or browsing history is enough to get people to change their behavior. The internet enables such remote threats to your reputation.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#312
post #273

Earlier quoted context omitted.

Don’t understand the gun paragraph

It's something like people who are into violence being immoral, I suspect. Not that I'd pick religion as a reliable measure for morality.

Whatever your opinions about name brand organized religion, and froo froo piety...

Don't delude yourself about the stewards of weaponry, for they are not nice people, they are not stoics, they are not abstinent, and they aren't doing it because they're "savin' lives!"

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#313
post #139

Earlier quoted context omitted.

Even end to end encryption often leaves them with metadata [0] [0] https://www.nybooks.com/daily/2014/05/10/we-kill-people-base...

Which is why you'll want to use some open source onion-routed app like Briar, Ricochet, Cwtch, TFC, or Session.

Using tor to keep your communications secret is like having ACAB tattooed on your forehead - fine if you like the attention, not exactly useful if you don't.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#314

Earlier quoted context omitted.

> I think most of us would be fine with the NSA doing what they do if it was targeted You think wrong. That fact that there are opposing world states engaging in this nefarious, oppressive, terrible acts and they're not all aligned doesn't legitimize any of these states' activities. The NSA should essentially be shut down, or cut down to a small agency operating in public with a much more limited mandate. And no secr…

I love privacy 'n' stuff, for sure. But relative to the risk of global nuclear war, and the certainty of global climate disruption, I couldn't care less about the NSA and its adversaries. And hey, maybe all that spying reduces the risk of overt war.

And who is creating the risk of global nuclear war, if not those very same governments?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#315
post #30

It follows that private VPN firms would be a similar target for deep pocketed state intelligence agencies. What do you think the chances are that the VPN service or software you use hasn't been co-opted, compromised or is outright owned by state actors in China, Europe or the US?

You can never trust VPN but it is important to have a legal case. Let’s say VPN is in a country where mass surveillance is illegal, then at least in future you can sue the VPN company if they are found out to be breaking their contract.

A country like Switzerland or Liechtenstein?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#316

Earlier quoted context omitted.

Pretty sure you misinterpreted that comment. It's not suggesting that they pressured the devs to stop work, it says they were pressured to stop making it so awesome. The inference being that they were pressured to weaken the product and they walked away instead.

An NSL to that effect would also be unprecedented. There is no evidence that anything like that has ever happened.

While not an NSL, we do know USG leans on companies to implement weaker/breakable cryptography. There is at least one public example (attempts to compel Apple), and presumably there are many more successful undocumented attempts.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#317

Earlier quoted context omitted.

While what you are saying is possible technically, assuming any and all investigators in the US can tap into such capabilities is just FUD.

The biggest problem with FDE is that as long as you're using the encrypted computer, FDE isn't protecting you. It doesn't take technical capabilities to exploit this; you just wait until the target has their laptop open to do the interdiction. FDE's not worthless. Again, I don't think it's even optional; one of your laptops is eventually going to get stolen, and you're going to want the reassurance that at the very l…

Are Apple's new machines with T2 secure enclave less vulnerable in this regard? They claim all storage encryption goes through the chip, making it more like an integrated phone design.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#318

This story was originally reported in CovertAction Quarterly 22 years ago: https://covertactionmagazine.com/wp-content/uploads/2020/01/... (Page 36)

... What? This is a well written article covering essentially the same information. This is so confusing, why did nobody react back then? Why did governments continue to buy equipment from Crypto AG?

Amazing. The only explanation I can think of is that CovertAction had much worse reputation and could be easily dismissed as conspiracy theory.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#319
post #316

Earlier quoted context omitted.

An NSL to that effect would also be unprecedented. There is no evidence that anything like that has ever happened.

While not an NSL, we do know USG leans on companies to implement weaker/breakable cryptography. There is at least one public example (attempts to compel Apple), and presumably there are many more successful undocumented attempts.

[deleted]

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#320
post #29
post #17

Earlier quoted context omitted.

I'm pretty sure the US government is why the TrueCrypt devs stopped all work. They got hit with a national security letter (NSL) or heavily leaned on and pressured to stop making their product so awesome and un-breakable.

Of all the cryptographic tools to mythologize, a crappy last-generation full-disk encryption tool?

It was the only non-microsoft option that was accessible and easy to use and free for Windows. And MS's FDE is likely compromised and backdoored.
Post reply on HN