Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

61–70 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#61
post #40

Earlier quoted context omitted.

Funny, I don't really care China spying on me as much since they just don't have any handles that would be relevant. Your own government spying on you is much more dangerous. And since I don't have influence on policies of China, I can at least hold domestic politicians that strive for more surveillance accountable. At least theoretically. History shows that government isn't your friend at all. The US might be a rare…

You might be a god-fearing clean-shaven American, but I strongly suspect the number of Americans who have secrets they can be blackmailed over is at least one percent. While I’d like to change every society so such secrets are not big issues, I don’t expect that to happen, and 3.5 million Americans being potentially blackmailed by a superpower is something I’d prefer to avoid even though I’m not an American and don’t…

> but I strongly suspect the number of Americans who have secrets they can be blackmailed over is at least one percent.

1 %? I assume 80+ %. E v e r y o n e has secrets.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#62
post #58
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

What is MINERVA? Google didn’t give any related results.

The codename for Crypto AG.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#63
post #58
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

What is MINERVA? Google didn’t give any related results.

It's explained in the article.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#64

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

Funny, I don't really care China spying on me as much since they just don't have any handles that would be relevant. Your own government spying on you is much more dangerous. And since I don't have influence on policies of China, I can at least hold domestic politicians that strive for more surveillance accountable. At least theoretically. History shows that government isn't your friend at all. The US might be a rare…

As a US citizen and resident I would far more prefer to have to contend with the US Govt than the CCP on this matter. At least in the US there is some legal procedure, accountability and civil society culture around limiting govt power. With the CCP there is none of that, neither for Chinese citizens nor foreigners.

It’s clear that the CCP is assembling a database of information on everyone in the developed world, not just in China, and that they intend to use it as part of their soft power arsenal (along everything else from economic incentives to Confucious Institutes).

The CCP is much more frightening and less accountable than the US Govt, especially as they reach parity in soft and hard power.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#65
post #22

Earlier quoted context omitted.

It wouldn't be so bad with ubiquitous end to end encryption though right? If everything was encrypted in transit it wouldn't really matter if Huawei (and by extension the supposition goes the Chinese government) because they'd just see noise. Guess they would also be able to do location tracking though and that's not so easily solved.

Governments are focusing more and more on end-to-end encryption. It can be banned within the next 5 years. They could need to manufacture some consent before that (e.g. mention e2e in the news every time a major crime is committed).

[deleted]

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#66
post #17

Earlier quoted context omitted.

I'm pretty sure the US government is why the TrueCrypt devs stopped all work. They got hit with a national security letter (NSL) or heavily leaned on and pressured to stop making their product so awesome and un-breakable.

I'm sure they were pressured, but the USG has deep pockets if they wanted someone to stop doing something they just throw a few million at them and call it done, there's far less chance of PR blowback then. Even just reading this article should show you that they kill you with kindness when they want to keep things hush-hush. If someone is developing a free tool, and are offered a retirement-tier payoff to stop, they…

If an average person got a huge windfall, that would raise a lot of attention, and people would wonder how they got the money. Police use sudden unexplained riches as a way to watch out for criminal activity, and everyone who knew the receiver of the windfall would ask questions. Between $10M and the other option, it may be easier to kill them with killing.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#67
post #22

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

It wouldn't be so bad with ubiquitous end to end encryption though right? If everything was encrypted in transit it wouldn't really matter if Huawei (and by extension the supposition goes the Chinese government) because they'd just see noise. Guess they would also be able to do location tracking though and that's not so easily solved.

Yes, this is my understanding. But, haven't USA for Adobe history wrt "backdooring" the encryption algorithms themselves (ie private knowledge allows decryption to be made plausible [but still costly]).

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#68
post #22

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

It wouldn't be so bad with ubiquitous end to end encryption though right? If everything was encrypted in transit it wouldn't really matter if Huawei (and by extension the supposition goes the Chinese government) because they'd just see noise. Guess they would also be able to do location tracking though and that's not so easily solved.

The US government does not get to dictate mobile phone standards so that is irrelevant. Besides, it’s not like the US government doesn’t have its hand in the sniffing cookie jar, they don’t really want the traffic to be indecipherable.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#69
post #29
post #17

Earlier quoted context omitted.

I'm pretty sure the US government is why the TrueCrypt devs stopped all work. They got hit with a national security letter (NSL) or heavily leaned on and pressured to stop making their product so awesome and un-breakable.

Of all the cryptographic tools to mythologize, a crappy last-generation full-disk encryption tool?

Is that just a rant or do you have an actual reason to call TrueCrypt crappy? It was at least somewhat solid and it definitely had a great mindshare at the time. It wasn't niche.

Also, describing small-scale intervention in cryptography by services "mythologic" in a thread about news about large-scale intervention in cryptography by those services is a bit odd.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#70

It has been known for a pretty long time that the Crypto AG is affiliated with or controlled by intelligence services. It was also always firmly in the "security through obscurity of our own cipher designs" department. Their C-52 (52 as in "1952") cipher machines were designed to enable decryption by Western intelligence. > Le Temps has argued that Crypto AG had been actively working with the British, US and West Ger…

I saw this article and that is exactly the first thought that popped up. Second thought was why is Washington Post feigning ignorance of this fact.
Post reply on HN