Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

341–350 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#341
post #236

Earlier quoted context omitted.

A spy agency is necessary for the USA to compete on the world stage. Though, it's operations should be significantly limited. The CIA is a disaster that needs to be dismantled.

> The CIA is a disaster that needs to be dismantled. Working for the CIA is like being a sysadmin. The world only knows you exist when you fuck up. There was a great CCC talk recently that showed how one of the Vault 7 tools wasn't a remote assassination boogieman drone tool like Wikileaks framed it, but actually a control the CIA developed that allowed them to give anti-air weapons to friendlies in Syria and Ukraine…

CCC... Communist Congress of China? Christian Columnist Caucus? Conference on Computational Complexity?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#342

Earlier quoted context omitted.

>based on decent research The story was handed to him by the Agency, or agents of. The only "research" seems to be calling the names in the story for fact checking, and wapo couldn't even determine if some of them were alive or dead. This story is dangerously close to being nothing but a CIA press release.

Ok, what so you think the purpose is?

Specifics? No telling...

But it is the CIA, so I'm assuming information was used as currency in paying off a favor to wapo.

Plus they get to brag about a huge success story in times where the public has... doubts ... About the competency and value of the intelligence community in general. Without revealing much that want already public knowledge.

Factor in the timing of FASA court investigations, the impeachment, and the AWS government cloud suit, and there are thousands of directions it could take.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#343
post #333

Earlier quoted context omitted.

Lavabit was a service that effectively held keys for its users and was compelled to disclose them. If we were discussing whether a vulnerable service was somehow compelled by the USG, I wouldn't argue. I doubt you'd even need an NSL compromise Lavabit; you might even be able to do it with routine civil litigation. Don't ever use things like Lavabit. That's why we talk about "end to end encryption", as opposed to the…

Lavabit also sent the private keys from their servers to clients using TLS that utilized RSA for key exchange. Levison was to put it into a word, a fool, for letting that happen. Once he had to submit the private RSA-key for the certificate, FBI could decrypt every past session, and every private key of every user. IMO he'd have to put a hell of a lot of effort if I'm ever going to look at his creations again.

It was a deeply irresponsible service for Levison to be selling to people.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#344
post #236

Earlier quoted context omitted.

> The CIA is a disaster that needs to be dismantled. Working for the CIA is like being a sysadmin. The world only knows you exist when you fuck up. There was a great CCC talk recently that showed how one of the Vault 7 tools wasn't a remote assassination boogieman drone tool like Wikileaks framed it, but actually a control the CIA developed that allowed them to give anti-air weapons to friendlies in Syria and Ukraine…

CCC... Communist Congress of China? Christian Columnist Caucus? Conference on Computational Complexity?

Probably Chaos Computer Club, a German association of hackers. At least in Europe quite well known. They do a lot of cool stuff, like looking for security flaws in voting machines and such stuff.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#345
post #109

Earlier quoted context omitted.

Again: why do you use such belittling words like "conspiracy theory"? We know that the services interfere. We know that they interfered with vendors of cryptography products. And we know that National Security Letters exist, as do other – legal – means to pressure such vendors. There is no conspiracy needed for them to try to pressure someone by, say, threatening them with denial of a entry visa. Or they could have s…

> what would they have done if the suspect hadn't used his laptop in a public place? Screw open his laptop when it's turned off and he's away from home, install a keylogger into the bios. Put a camera onto the shelf to film which keys he types to log in. If he puts a blanket over his head: solely rely on the sound each key makes. Hack his computer remotely using one of the government owned 0days and dump the keys. Us…

Yeah, but are there any other forms of encryption that could have mitigated any of those attacks? Once your adversary has physical access to your environment/hardware, it's pretty much game over for security.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#346

Earlier quoted context omitted.

"The majority of Android devices" is a very wide net to cast.

Qualcomm alone covers 40%, and they're arguably the most likely to correctly implement their MMU (nevermind they've seen quite a few vulnerabilities in their MMU implementations over the years..) Meditek uses a similar architecture, and I sure as hell don't trust their MMU. Outside of Apple, Librem and Pine are just about the only way you're getting a USB attached baseband. edit - Here's a Mediatek Baseband->AP PoC e…

The HTC One M9+, you say.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#347
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

Putting my tinfoil hat on, after reading the Snowden disclosures I'm convinced that they do have limited means of attacking encrypted communication but they would rather rely on these (expendable) means. Once they lose their crypto vulnerabilities it will force them to be even more overt.

I think this very suspicion is the reason Tor usage inflected down in Germany after the Snowden disclosures.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#348

Earlier quoted context omitted.

Qualcomm alone covers 40%, and they're arguably the most likely to correctly implement their MMU (nevermind they've seen quite a few vulnerabilities in their MMU implementations over the years..) Meditek uses a similar architecture, and I sure as hell don't trust their MMU. Outside of Apple, Librem and Pine are just about the only way you're getting a USB attached baseband. edit - Here's a Mediatek Baseband->AP PoC e…

The HTC One M9+, you say.

Where are you trying to go with this?

You start off trying to claim the entire class of vulnerability isn't possible because a few vendors made sane architectural decisions. When it's pointed out those sane vendors are in the minority, and there are real world examples of the terrible shared memory architecture being exploited, you scoff at the example being for a single device.

Nobody is claiming baseband == root, only that the terrible architecture prevalent in Android phones (the devices that make up the majority of the market) combined with the terrible software practices of SoC vendors results in a situation far more likely to be exploitable than shunting the baseband off on a non-dma capable bus.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#350

Earlier quoted context omitted.

Funny, I don't really care China spying on me as much since they just don't have any handles that would be relevant. Your own government spying on you is much more dangerous. And since I don't have influence on policies of China, I can at least hold domestic politicians that strive for more surveillance accountable. At least theoretically. History shows that government isn't your friend at all. The US might be a rare…

Even saying that the US is your friend isn't really true. The Tuskegee syphilis experiment and MKULTRA were only ended in the 70s, Orlando Letelier happened the same decade, as did the discovery of Operation Mockingbird and other Church Committee findings. Every peek we've had into that world since then continues to come up dirty too. Operation SHAMROCK was considered a big deal at the time, but we've since then allo…

For those, like me, who didn't know about Letelier:

https://en.wikipedia.org/wiki/Orlando_Letelier

Post reply on HN