Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

51–60 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#51
post #11

Related question: do modern diplomats/negotiators automatically assume their comms are compromised? Are their "secure" lines ever truly secure? Surely they know the NSA/CIA would be listening.

They've all got massive bureaucracies above them that tightly control what they can do.

Also, everyone wants to eventually end their shift and go home. That means just doing what you're told & screw the damage done.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#52

>Their [Soviet Union & China] well-founded suspicions of the company’s ties to the West shielded them from exposure, although the CIA history suggests that U.S. spies learned a great deal by monitoring other countries’ interactions with Moscow and Beijing. Fascinating use of 'negative space' in intelligence. Also appreciated the dig at Reagan, apparently gross intelligence breaches at the highest levels aren't anythi…

> gross intelligence breaches at the highest levels aren't anything novel

True. Same portrayals too. If breacher is an R they're incompetent, it's a D they're a traitor.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#53
post #17
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

I'm pretty sure the US government is why the TrueCrypt devs stopped all work. They got hit with a national security letter (NSL) or heavily leaned on and pressured to stop making their product so awesome and un-breakable.

[dead]

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#54

Earlier quoted context omitted.

I'm not sure that makes sense. The US could compel the devs to compromise their product but not keep them from issuing a cryptic statement and stopping work on the product?

It doesn't make sense for two reasons to me. For one, the government can't compel you to do work. That's slavery. Also, it's open source software. TrueCrypt going down didn't change the security landscape at all.

On the face of it sure, but then the key people start having heart attacks and mysterious accidents and suddenly the problem goes away. And that's the world we live in.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#55
post #22

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

It wouldn't be so bad with ubiquitous end to end encryption though right? If everything was encrypted in transit it wouldn't really matter if Huawei (and by extension the supposition goes the Chinese government) because they'd just see noise. Guess they would also be able to do location tracking though and that's not so easily solved.

Even end to end encryption often leaves them with metadata [0]

[0] https://www.nybooks.com/daily/2014/05/10/we-kill-people-base...

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#56
post #34
post #30

It follows that private VPN firms would be a similar target for deep pocketed state intelligence agencies. What do you think the chances are that the VPN service or software you use hasn't been co-opted, compromised or is outright owned by state actors in China, Europe or the US?

It would be hopelessly naive to assume that intelligence services don't run a large number of VPN providers an tor relays, just as the used to run mix master smtp (email) relays.

While at the same time taking out the competition they can't get to comply [0]

[0] https://www.theregister.co.uk/2019/09/30/cyberbunker_cb3rob_...

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#57

Earlier quoted context omitted.

Yes. It would be useful to have an accessible version posted with the original each time, and for it to be a preferred guideline for submitters. Though to be fair, I'm not sure if there are copyright issues involved, which might make such a guideline difficult.

It is posted each time. Under the article, there are a number of little links ("flag", "hide", "past", and so on). You want the one that says "web".

Thanks, I'll keep this in mind in the future.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#58
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

What is MINERVA? Google didn’t give any related results.
Post reply on HN