Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

41–50 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#41

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

Funny, I don't really care China spying on me as much since they just don't have any handles that would be relevant. Your own government spying on you is much more dangerous. And since I don't have influence on policies of China, I can at least hold domestic politicians that strive for more surveillance accountable. At least theoretically. History shows that government isn't your friend at all. The US might be a rare…

Even saying that the US is your friend isn't really true. The Tuskegee syphilis experiment and MKULTRA were only ended in the 70s, Orlando Letelier happened the same decade, as did the discovery of Operation Mockingbird and other Church Committee findings. Every peek we've had into that world since then continues to come up dirty too. Operation SHAMROCK was considered a big deal at the time, but we've since then allowed American intelligence to vastly eclipse anything even conceivable at the time.

Other countries programs aren't good or anything, but anyone who's deluded themselves into thinking the US is some kind of clean actor, not participating in this sort of stuff, or only using it for good is more optimistic than I could ever manage being.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#42
post #29
post #17

Earlier quoted context omitted.

I'm pretty sure the US government is why the TrueCrypt devs stopped all work. They got hit with a national security letter (NSL) or heavily leaned on and pressured to stop making their product so awesome and un-breakable.

Of all the cryptographic tools to mythologize, a crappy last-generation full-disk encryption tool?

I mean, Paul LeRoux is associated with it and he's been mythologized already himself

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#43
post #28

What a treat to read a well written piece based on decent research. It's a long read but well worth your time. Kudo's to the journalists who helped uncover it. And the 'coup of the century' is far from clickbait, it's definitionally warranted for what the CIA and BND did here. It's a little ironic as well, especially since the US is so keen on blocking Huawei over espionage concerns.

The fact that the US has repeatedly succeeded in SIGINT capers like this makes their concern about Huawei kind of un-ironic, right?

Well, yes, but for third parties like the UK it makes it much more explicit that the choice is between the system that might be compromised by Huawei and the system that might be compromised by the US. Except the UK has its own little joint venture of security inspection of Huawei systems ...

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#44
post #22

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

It wouldn't be so bad with ubiquitous end to end encryption though right? If everything was encrypted in transit it wouldn't really matter if Huawei (and by extension the supposition goes the Chinese government) because they'd just see noise. Guess they would also be able to do location tracking though and that's not so easily solved.

I mean, you can do a lot with metadata.

Also, I think quite a bit of telecomm traffic is encrypted by the telecomm carrier itself. For example I don't think my iPhone, by default, encrypts/decrypts SMS or voice calls on the device. To the extent text messages and mobile phone calls are resistant to dumb eavesdropping, that's provided by the mobile carrier. So having access into all the equipment at the carrier would be a nice centralized place to sit and observe/record.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#45

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

When this stuff is used against you, it is FAR more likely going to be from a domestic group hostile to a political opinion you might have. Imagine if an outfit like Cambridge Analytica had the resources of a nation state helping it collect and process information about who might support any given policy (and be given the carrot) and who might oppose it (and be given the stick). That's the scale of threat we face. While certain governments around the world are asking for mandatory back door access to encryption, rest assured they have a "plan B" for getting access to your information without it, and the 3 letter departments are front and center in those plans.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#46
post #15

Earlier quoted context omitted.

Thanks, it gets irksome at some points that a large number of submitted content on HN is paywalled. I can't subscribe to all of these, just to read a couple of articles a month per publication.

Yes. It would be useful to have an accessible version posted with the original each time, and for it to be a preferred guideline for submitters. Though to be fair, I'm not sure if there are copyright issues involved, which might make such a guideline difficult.

It is posted each time. Under the article, there are a number of little links ("flag", "hide", "past", and so on). You want the one that says "web".

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#47

I have to disagree with the headline. The "intelligence coup of the century" came much earlier, during WWII. The Allies were reading a good deal of both Japanese and German encrypted communications. This saved the lives of many Allied solders and, perhaps, tipped the balance of the war. https://en.wikipedia.org/wiki/Magic_(cryptography) https://en.wikipedia.org/wiki/Ultra David Kahn's book, the Codebreakers, is a goo…

also how Poland kept the Bolsheviks from sweeping across Europe

https://warfarehistorynetwork.com/2016/10/05/polish-ciphers/

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#48
post #22

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

It wouldn't be so bad with ubiquitous end to end encryption though right? If everything was encrypted in transit it wouldn't really matter if Huawei (and by extension the supposition goes the Chinese government) because they'd just see noise. Guess they would also be able to do location tracking though and that's not so easily solved.

Governments are focusing more and more on end-to-end encryption. It can be banned within the next 5 years. They could need to manufacture some consent before that (e.g. mention e2e in the news every time a major crime is committed).

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#49

It has been known for a pretty long time that the Crypto AG is affiliated with or controlled by intelligence services. It was also always firmly in the "security through obscurity of our own cipher designs" department. Their C-52 (52 as in "1952") cipher machines were designed to enable decryption by Western intelligence. > Le Temps has argued that Crypto AG had been actively working with the British, US and West Ger…

> Andreas Linde, the chairman of the company that now holds the rights to Crypto’s international products and business, said he had no knowledge of the company’s relationship to the CIA and BND before being confronted with the facts in this story.

I'm quite curious about this. As you said it's been known for a long time that, without knowing the full extent of the ties, there was ties between Crypto-AG and US agencies (at least). I find hard to believe the candor that this M. Linde displays here...

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#50
post #13

It certainly does make one wonder who else in the worlds of high technology (and journalism!) May be – wittingly or unwittingly – working for Uncle Sam. I've seen some deep integrations that have made me despair of any organization being free from the overweening influence of the "security services." I'm talking about groups as large as multi-billion dollar public US technology infrastructure companies and as small a…

Look up Operation Mockingbird on wikipedia. The same is still going on in spades.

I don't think an operation like that is necessary. Most journalists seem to be eager to prove themselves as patriots by under-reporting Gov malfeasance, especially in IC matters where understanding a complex issue gets trumped by deadlines.

Thank-you editors for our chronically uninformed electorate.

Post reply on HN