Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

331–340 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#331
post #254
post #249

Earlier quoted context omitted.

I read it as the opposite. "No decrypt available for _this_ PGP encrypted message." You don't write an error message that way unless the code has a success case as well.

The NSA has likely harvested and cached thousands of PGP secret keys from passive monitoring of internet links public and private (Google famously failed to use encryption on internal WAN links for a long time), active exploitation of host and workstation systems, and bulk exfiltration of nonpublic data from service providers (think stored records: emails and files). (Unrelated: As well as TLS long term keys, passwor…

Plus there's the good old endpoint hacking for key exfiltration Snowden said the NSA was doing every single day.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#332

Earlier quoted context omitted.

Not mutually exclusive, it's possible the Momo and the time thieves and the NSA are working together - the UTC is NSA , is the combined message

Do you think you're making a point, or just being edgy with your humor? For some people out there, this kinda shit keeps them safe/alive.

There's nothing that shows TrueCrypt is backdoored. Read the audit by nccgroup: https://opencryptoaudit.org/reports/TrueCrypt_Phase_II_NCC_O...

There were vulnerabilities in the software, but nothing that allows the governments to break the encryption with. The Windows client had some privilege escalation attack but that doesn't allow decryption of data at rest. On Linux TrueCrypt is still fine to use, the only downside is, the password based key derivation function is starting to show it's age. However, provided your password is around 128 bits, that's not a problem.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#333

Earlier quoted context omitted.

Just like lavabit: https://en.wikipedia.org/wiki/Lavabit#Suspension_and_gag_ord...

Lavabit was a service that effectively held keys for its users and was compelled to disclose them. If we were discussing whether a vulnerable service was somehow compelled by the USG, I wouldn't argue. I doubt you'd even need an NSL compromise Lavabit; you might even be able to do it with routine civil litigation. Don't ever use things like Lavabit. That's why we talk about "end to end encryption", as opposed to the…

Lavabit also sent the private keys from their servers to clients using TLS that utilized RSA for key exchange. Levison was to put it into a word, a fool, for letting that happen. Once he had to submit the private RSA-key for the certificate, FBI could decrypt every past session, and every private key of every user. IMO he'd have to put a hell of a lot of effort if I'm ever going to look at his creations again.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#334
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

That thought is one reason why I've always questioned this advice: "Don't roll your own encryption." I've always understood the arguments for it but that the advice is so widespread seemed a little counter intuitive. It always seemed, to me at least, that having millions of encryption algorithms out there would be inherently more secure than a lot of people standardized on one because the risk to any one would be so…

having millions of encryption algorithms out there would be inherently more secure than a lot of people standardized on one

Enclosing letters in paper the thickness of which has a million variations doesn't mean one of them is magically more secure than one made from two inch thick steel. The point of encryption is it's a standard that needs to be interoperable. Also, NSAs of this world aren't breaking modern ciphers. They're circumventing encryption by going for the keys: There's three choices

1) If communication system uses TLS-encryption (e.g. Telegram cloud messages), there's no need to break encryption, just hack server and read messages from there.

2) If the system uses E2EE where user has no way to verify fingerprints (e.g. iMessage, Confide), compromise the server legally or by hacking it, and perform undetectable MITM attacks.

3) If the system uses E2EE where fingerprints can be verified, hack the user's endpoint to steal their private keys and perform undetectable MITM attack (or just steal their chat logs or take screenshots).

So, to sum it up, the game when modern ciphers are used, is not with cipher security, but everything else around it.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#335

Earlier quoted context omitted.

For downvoters - constructive counterarguments are welcome.

I don’t mean to be rude, but it’s quite obvious by what you wrote that you are barely literate in cryptography, yet you are fairly certain of yourself. Your confidence is misplaced. This isn’t the type of thing that encourages actual experts to bother replying. Examples: “side channel such as a backdoor that secretly stores keys used somewhere”, “blowfish”, nonsensical mixing of block ciphers and stream ciphers witho…

"by far the largest weak point"

Well, if the nested ciphers are all properly implemented AEAD schemes, use unique keys, and don't rely on public key crypto for key exchange, cascading crypto is fine.

Other than that their discourse was that of a novice, sure.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#336

Earlier quoted context omitted.

For downvoters - constructive counterarguments are welcome.

Combining standard algorithms doesn't constitute rolling your own crypto. Arguably, even increasing the number of rounds in a standard cipher doesn't, either. A back door is not a side channel.

Rolling one's own crypto has become a catch-all phrase. It's of course very important to remember implementing standard algorithms in non-standard way can be incredibly dangerous too. I've seen unauthenticated AES-CBC way too many times. I've seen fingerprints calculated by hashing pre-master secrets (completely insecure), I've seen crypto libraries that rely on completely insecure structures for their RNGs (worst was probably LCG fed from math.random). I've seen fixed IVs with fixed keys, E2EE without fingerprints (way too often), ones with expired primitives (SHA-1 in PGP). I've seen RSA PKCS #1.5 deployed in brand new products (https://trailofbits.files.wordpress.com/2019/07/image13-1.pn...).

So the correct advice is, "don't deviate from best practices, and hire a cryptographer."

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#337
post #313
post #139

Earlier quoted context omitted.

Which is why you'll want to use some open source onion-routed app like Briar, Ricochet, Cwtch, TFC, or Session.

Using tor to keep your communications secret is like having ACAB tattooed on your forehead - fine if you like the attention, not exactly useful if you don't.

It is when everyone uses Tor.

Nobody uses Tor: Everyone is surveilled.

Few activists use Tor: Activists are easy to pick and everyone else is easy to surveill.

Everyone uses Tor: Nobody can be surveilled.

Nothing to gain by not using Tor, only one way to win, use Tor and tell everyone else to use Tor too.

It's like the prisoner's dilemma, and not using Tor is like betraying others just in case things ever get bad.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#338
post #22

Earlier quoted context omitted.

It wouldn't be so bad with ubiquitous end to end encryption though right? If everything was encrypted in transit it wouldn't really matter if Huawei (and by extension the supposition goes the Chinese government) because they'd just see noise. Guess they would also be able to do location tracking though and that's not so easily solved.

Governments are focusing more and more on end-to-end encryption. It can be banned within the next 5 years. They could need to manufacture some consent before that (e.g. mention e2e in the news every time a major crime is committed).

Not going to happen, considering djb vs US declared code free-speech; E2EE is implemented in code so you can't ban it without violating the constitution.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#339
post #105

What a treat to read a well written piece based on decent research. It's a long read but well worth your time. Kudo's to the journalists who helped uncover it. And the 'coup of the century' is far from clickbait, it's definitionally warranted for what the CIA and BND did here. It's a little ironic as well, especially since the US is so keen on blocking Huawei over espionage concerns.

No, this is not original research, this isn't being uncovered now, and I'm not sure why this is being republished now in 2020. There have been detailed leaks since 1995 on cryptome.org and crypto mailing lists about CryptoAG, including details about the message format and the bits used to leak parts of the key (16 bit leak, IIRC). The CryptoAG story has tainted all Swiss-based crypto/security firms since 1994. [1] ht…

The news is this:

"CIA owned CryptoAG in collaboration with the intelligence establishment of West-Germany"

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#340
post #248

Earlier quoted context omitted.

> How on Earth would he know? I'm sure he said "to my knowledge" or something to that effect. That is, at least for at least relatively far into the circles of confidence, people did not know about encryption being broken algorithmicly or PGP broken in practice.

Which might also be a false-flag to encourage the use of PGP. Russia has world class cryptographers too, and may have beaten the NSA to the punch. Snowden is after all currently living under FSB protection, which I doubt came for free. Someone willing to sell out their country would likely sell out its people too.

Snowden as a false flag? Well, it's theoretically possible, but quite unlikely IMHO.
Post reply on HN