Live data from Hacker News

Australian Federal Police and FBI nab underworld figures using encrypted app

abc.net.au

331–340 of 361 posts

Re: Australian Federal Police and FBI nab underworld figures using encrypted app

#331
post #327

Earlier quoted context omitted.

I think this comment is unnecessarily hostile. OP is not offering to build services; he's just asking. It's a valid question. Did you know ISIS had what amounts to an "HR department" ? https://en.zamanalwsl.net/news/article/23994/

Oh boohoo. Calling out a completely immoral business idea isn’t hostile. It’s moral.

To recycle your phraseology, "what the fuck is wrong with you?"

There are plenty of things that are illegal but not immoral. Sounds like you'd have railed against a steampunk app that helped the Underground Railroad operate, or Jews evade German checkpoints in 1938.

Technology making end-runs around government laws is not, per se, wrong.

Re: Australian Federal Police and FBI nab underworld figures using encrypted app

#332

Does anyone find it funny that each criminal group could have been better off relying on a "kid who knows computers" level of expertise and bog standard devices running open source software which at least wouldn't be trivially systematically turned against them all at once quite so easily.

I wonder about this too. What sort of people do international criminal organisations hire to manage their info-sec? A criminal that became a computer expert or a computer expert that became a criminal?

Watch "Start-up" in Netflix (American version, not the Korean one).

Re: Australian Federal Police and FBI nab underworld figures using encrypted app

#333
post #128

How would this be any different to creating a global back door in signal, wikr or slack?

The main difference is that by building their own honey pot, they did not have to rely on an external actor to maintain any secrecy. If they dug their claws into wikr, they'd have to worry about leaks from every single person involved with wikr on top of all potential leaks from law enforcement personnel. Also, I suspect it's easier to get the warrants needed to create a sting from the ground up than it is for severa…

Wickr is almost certainly compromised anyway.

Never trust an app that neither charges for its use (like Threema), nor takes donations (like Signal Foundation).

Wickr's funding is a huge mystery. Approach with caution.

Re: Australian Federal Police and FBI nab underworld figures using encrypted app

#335

This is how police should get around the problems presented with encryption. This is real policing. The PR barrage and faux posturing by the FBI to weaken encryption has always seemed like just lazy policing to me. If anything, the hacking attacks on industrial centers has better illustrated than anything why encryption is necessary, and this new triumph has demonstrated that police can continue to function, even thr…

> This is how police should get around the problems presented with encryption. By adding a backdoor to E2E encryption? That is pretty much what they have been asking for :) Amazing that criminals still pick some unknown device over an existing solution with a proven track record. This is not the first time something like this has happened: - https://en.wikipedia.org/wiki/EncroChat - https://en.wikipedia.org/wiki/Sky_…

> By adding a backdoor to E2E encryption? That is pretty much what they have been asking for :)

Not really. At least in Australia's case they asked for the ability to access data on the end point while it is unencrypted, which it must be when a human consumes it. They didn't want to backdoor encryption, just bypass it. And they didn't just ask for it - they got it.

Specifically, the Assistance and Access bill (2018) [0]. The "Assistance" in the title allows them to demand assistance from a software company (eg, Google / Microsoft / Apple) in developing an app (or a modified version of an existing app) that that won't trigger the OS's warnings while it provides access to data while it is unencrypted. The "Access" in the bills title refers to the fact they can they demand the software developer force the app to be "upgraded" to the "spy" version on targeted devices via their normal security patch mechanisms.

As you can probably gather from the date of the bill, this law has been in place or about 2 years now. But it probably wasn't in place when this started, as the law was passed New Years Eve, 2018, which explains all this social engineering cloak and dagger stuff.

When I first saw the story I thought it was odd they publicising a hack that only works when nobody knows about it. But now I think about it, my guess is they publicised it because they won't need to use it again. They've legislated far easier ways to spy on a phone.

[0] https://www.homeaffairs.gov.au/about-us/our-portfolios/natio...

Re: Australian Federal Police and FBI nab underworld figures using encrypted app

#336
post #79

Earlier quoted context omitted.

Agree with most of what you said but: > > especially in the US > The app was deployed in Australia. Australia has an even worse equivalent of US National Security Letters, allowing individual workers to be compelled to plant backdoors etc..

Not without notice of the company, and not for wide spreaed distribution, ie targeted enforcement.

I was also under the impression this can be served to individuals without the knowledge of their employer, leaving the individual in a position where they can consult a single lawyer about the legality of the request and face jail time for discussing the request with anyone else (including employers).

I would need to re-read the act, but the gov website[1] indicates you are correct that these requests are served to organisations and not individuals excepting sole traders.

[1] https://www.homeaffairs.gov.au/about-us/our-portfolios/natio...

Re: Australian Federal Police and FBI nab underworld figures using encrypted app

#337

Earlier quoted context omitted.

I think it is more accurate to say that this is simply a risk of engaging in activities with people who will kill you if they think you will tell the truth.

Yea.. I can see some people thinking that, but that sentiment kind of goes against the rule of law. If all of the criminals committed crimes that everyone agreed should be punishable by death I could see it being more acceptable, but if these are lesser crimes that wouldn't be punishable by death but where the individual could be killed by other criminals that believe them to be a snitch, having law enforcement risk…

>> having law enforcement risk a person's life seems to go against the rule of law.

Most criminals who engage in any kind of criminal activity are usually living dangerous lives as it is. Working with the mob? Drug dealing with Mexican cartels? Finance crimes with sketchy people like Jeffrey Epstein? Engaging in credit card fraud with Russian mobsters?

I would say a majority of profitable criminal activity involves dealing with some form of violence or violent people to begin with. Criminals know the inherit risk with what they do or who they're involved with.

Re: Australian Federal Police and FBI nab underworld figures using encrypted app

#338

Earlier quoted context omitted.

Could the OS lock down the app's permissions to prevent that? Like, this app can ONLY send/recv e2e encrypted messages, and not log anything or talk to other apps.

The app could still send your keys _as_ an e2e message (to the app author). OS enforcement would need to be pretty intrusive to stop this (e.g. a pop-up for every message sent, displaying the actual destination of the message). I bet users would get pretty blind to such pop-ups, and it would be easy to trick them into accepting the leaking of their private keys.

If you trust the OS, it could hypothetically be built into the OS such that the app only gives what needs to be encrypted to the OS and gets back an encrypted payload to send, then the app wouldn't need to access your keys?

Of course at that point the OS has to either provide good key management itself, or a good API so that the apps can still make things seamless while still not accessing the keys directly.. and probably other problems I haven't thought of.

Re: Australian Federal Police and FBI nab underworld figures using encrypted app

#339

Earlier quoted context omitted.

Fun.. I guess that's one way to figure out if someone is guilty or not. Either he's innocent and nothing happens or he's guilty and he dies or flips. The whole side stepping the judge/jury to go straight to the executioner part seems like it should violate some kind of law.

But he's not innocent, you missing the boat here jimmy ?

The point I'm trying to make is that we have judges and juries for prosecuting criminals and deciding sentences for guilty criminals. You don't think it's a little bit wrong that law enforcement is side stepping that and deciding for themselves that the criminal is guilty and that they should get the death penalty? Iirc, the fifth amendment grants individuals the right to refuse to testify against themselves, but this behavior is effectively removing that right for the accused.

Re: Australian Federal Police and FBI nab underworld figures using encrypted app

#340
post #327

Earlier quoted context omitted.

I think this comment is unnecessarily hostile. OP is not offering to build services; he's just asking. It's a valid question. Did you know ISIS had what amounts to an "HR department" ? https://en.zamanalwsl.net/news/article/23994/

Oh boohoo. Calling out a completely immoral business idea isn’t hostile. It’s moral.

> Calling out a completely immoral business idea isn’t hostile. It’s moral.

That’s fine, but it’s not what you seemed to be doing.

Post reply on HN