Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

321–330 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#321

Earlier quoted context omitted.

I didn't say anything about spying staving off climate change. That's pretty much a done deal, at least to the extent of destroying our current civilization. We've been in free fall to that, for at least a decade. And about nuclear war. Although I'm not expert, it seems pretty obvious that uncertainty increases the risk of war. Sure, I hate oppression. And I'm not into oppressing others. But the problem is all the as…

You could argue that uncertainty reduces the risk of war because you're only starting wars where you're reasonably certain that you can win. Uncertainty about your adversary's capabilities then prevents war.

Too much uncertainty can also risk war. It all depends on what you're uncertain about.

MAD doctrine is based on both sides being reasonably sure neither can get away with a first strike. There is interest in having that fact independently verifiable; spying is both providing that verification and serving as an incentive against overstating your actual capabilities.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#322

Earlier quoted context omitted.

The US mostly tries to project itself as "the good guys" to its own inhabitants, and secondly to the local and international media. But in most of the world you are often faced with the business end of a US-operated or US-financed weapon.

To be fair, it's a spectrum. The US has its share of bodies, but it also doesn't grind its citizens into a pulp with tanks when they protest.

The thing is, its subjects are mostly non-citizens, so it's enough to grind _those_ into a pulp. So far, the US has not seen a popular uprising which threatens the stability of the state(, excluding perhaps that of the native Americans, who were actually ground to a pulp, eventually).

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#323
post #300

Earlier quoted context omitted.

Have you ever driven on the beltway?

I have. Nowadays it's generally slow enough that it's hard to imagine dying in an accident there. But this was so long ago that I imagine things were different with the Beltway back then, and of course cars were much more deadly at the time too.

Indeed. But it seems people keep finding new and innovative ways to crash spectacularly as well. Maybe it's foul play all the way down, but I'd bet most of money on Marylanders :)

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#324

Earlier quoted context omitted.

iCloud just recently added Messages in iCloud, but I know a fair amount of people that turn it off since the default iCloud storage space is 5gb.

So the messages on your phone are not backed up with the normal iCloud backup? I know WhatsApp nags to turn on chat backup to the cloud.

normal iCloud backup I don't think so, but it does ask you to turn on 'messages in icloud' once you upgrade to iOS 13 and/or get a new phone, albeing one time only.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#325
post #112

Earlier quoted context omitted.

Putting my tinfoil hat on, after reading the Snowden disclosures I'm convinced that they do have limited means of attacking encrypted communication but they would rather rely on these (expendable) means. Once they lose their crypto vulnerabilities it will force them to be even more overt.

The key difference is that decrypting something would likely need to be targeted and on a case-by-case basis, as it would take specialized work, as opposed to these sorts of attacks (much like tapping all of the pipes which transit data underseas or elsewhere, which still goes on in every country or working directly with the ISPs and mobile operators which happens in most countries) which allows mass dragnet surveill…

iMessage is so riddled with problems from using weak RSA key sizes (1280 bits), to using RSA in the first place (thus no forward secrecy), to apple essentially managing the public keys for the user (which allows transparent MITM due to lack of public key fingerprints).

Also, both iMessage and WhatsApp are proprietary, thus it's almost impossible to verify the code you're running is safe. You're right in that E2EE has become more common, but seeing how the intelligence agencies have targeted major vendors like Crypto AG and RSA, we should be extra careful with popular, proprietary systems.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#326

Earlier quoted context omitted.

> I think most of us would be fine with the NSA doing what they do if it was targeted You think wrong. That fact that there are opposing world states engaging in this nefarious, oppressive, terrible acts and they're not all aligned doesn't legitimize any of these states' activities. The NSA should essentially be shut down, or cut down to a small agency operating in public with a much more limited mandate. And no secr…

I love privacy 'n' stuff, for sure. But relative to the risk of global nuclear war, and the certainty of global climate disruption, I couldn't care less about the NSA and its adversaries. And hey, maybe all that spying reduces the risk of overt war.

Most of it is economic and political espionage, not spying on each others' military secrets. That happens too, sure, but none of the other stuff is necessary to protect us from nuclear war.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#327
post #220

Earlier quoted context omitted.

I am fine getting rid of the NSA as soon as you can guarantee that Russia and China dismantle their equivalents. Not to mention all the other agencies in the world. Sorry but when you talk of those two in particular, the US is the obvious good guy. Regardless of the terrible shit Trump has done, we would never accept him murdering journalists or critics. That shit happens regularly in Russia and China

It takes a lot of hubris to think that you would ever know for sure if some US three letter agency was killing journalists and critics.

https://en.wikipedia.org/wiki/Gary_Webb#Death

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#328

Earlier quoted context omitted.

Just watch the "Mission Impossible" franchising. They are obviously dramatized stories but I would not be surprised that the world has been very closed to cease to exist as we know it and the only thing that prevented was that they did their job. Only few people know what they have done, no glory, no prizes, no recognition. What kind of people do that? Heros. Feel free to down vote me. I can only guess but I would no…

The world is far more Mr. Bean than James Bond.

Mad guy speeds across London streets with a highly customized vehicle. Also, tanks. I see no difference.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#329

Earlier quoted context omitted.

Putting my tinfoil hat on, after reading the Snowden disclosures I'm convinced that they do have limited means of attacking encrypted communication but they would rather rely on these (expendable) means. Once they lose their crypto vulnerabilities it will force them to be even more overt.

snowden explicitly said pgp was safe

Well not exactly. Snowden was extremely vocal about NSA going around encryption and stealing keys from the endpoints. I've collected those statements here: https://www.youtube.com/watch?v=3euYBPlX9LM

PGP uses RSA which means it's not forward secret. That means, when the agencies hack endpoints to steal PGP keys, they can use them to retrospectively decrypt all PGP-encrypted emails that user has received from their contacts, even if the user has deleted the original message long since.

So no, NSA can't break RSA (assuming it's at least 2048 bits) or AES, but they can bypass the encryption by hacking endpoints. PGP's algorithms are not weak, the key management is extremely weak.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#330
post #238

Earlier quoted context omitted.

So that's a "yes"? Presumably you think, similarly, that if NSA, say, breaks all elliptic curve discrete log crypto, a random analyst inside NSA will be able to submit a ticket and break random crypto? No, I don't think that's how it works. A class break in a core cryptography primitive or even a major break in a particular crypto format would be one of the most closely protected SIGINT secrets in the country; the nu…

To further your point, even Snowden didn’t have access to the documents that tell us precisely what BULLRUN is able to do, or how. (The speculation is, of course, with reasonable circumstantial support, is that it is a ~$1B program that has brute-forced the most common 1024 DH group in use.) We simply don’t have the hard data, it is (educated) speculation based on what information we do have. Even the existence of th…

Most keys are at least 2048 bits nowadays. Bullrun's not about breaking modern key sizes that much is sure.
Post reply on HN