Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

71–80 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#71
The popular belief is that the CIA and its intelligence colleagues will go to any lengths to protect its power and secrecy. But apparently a Crypto engineer discovered the secret conspiracy in 1977, and even fixed vulnerabilities on behalf of the Syrian state – and the CIA was content to leave him alone for the next 40 years?

> In 1977, Heinz Wagner, the chief executive at Crypto who knew the true role of the CIA and BND, abruptly fired a wayward engineer after the NSA complained that diplomatic traffic coming out of Syria had suddenly became unreadable. The engineer, Peter Frutiger, had long suspected Crypto was collaborating with German intelligence. He had made multiple trips to Damascus to address complaints about their Crypto products and apparently, without authority from headquarters, had fixed their vulnerabilities.

> Frutiger “had figured out the Minerva secret and it was not safe with him,” according to the CIA history. Even so, the agency was livid with Wagner for firing Frutiger rather than finding a way to keep him quiet on the company payroll. Frutiger declined to comment for this story.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#72

Earlier quoted context omitted.

I'm not sure that makes sense. The US could compel the devs to compromise their product but not keep them from issuing a cryptic statement and stopping work on the product?

It doesn't make sense for two reasons to me. For one, the government can't compel you to do work. That's slavery. Also, it's open source software. TrueCrypt going down didn't change the security landscape at all.

They offer you a large contract to do , then they require that they nominate work with you on the project. That guy introduces the backdoor.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#73
post #11

Related question: do modern diplomats/negotiators automatically assume their comms are compromised? Are their "secure" lines ever truly secure? Surely they know the NSA/CIA would be listening.

Not all communication is compromised; for example for an embassy it could be practical to use a true one time pad which is uncrackable and attempts to intercept the key would lead to a diplomatic incident.

Much of their communication probably isn’t that sensitive though.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#74
post #17

Earlier quoted context omitted.

I'm pretty sure the US government is why the TrueCrypt devs stopped all work. They got hit with a national security letter (NSL) or heavily leaned on and pressured to stop making their product so awesome and un-breakable.

I'm not sure that makes sense. The US could compel the devs to compromise their product but not keep them from issuing a cryptic statement and stopping work on the product?

Well, there is an argument that IC does not have a problem with other interested parties chasing their tail trying to figure out what that really meant similar to the way government occassionally releases few tidbits about Kennedy assasination just to keep the flames flowing and activist distracted from what is going on right now.

There is value in misdirection.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#75
post #15

https://outline.com/tTTmh6 And http://archive.is/1w61P

Thanks, it gets irksome at some points that a large number of submitted content on HN is paywalled. I can't subscribe to all of these, just to read a couple of articles a month per publication.

If only the newspapers would just provide all their content for free, but without ads and tracking!

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#76
post #29

Earlier quoted context omitted.

Of all the cryptographic tools to mythologize, a crappy last-generation full-disk encryption tool?

I mean, Paul LeRoux is associated with it and he's been mythologized already himself

Have people settled on whether he's also Satoshi or not?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#77
post #29

Earlier quoted context omitted.

Of all the cryptographic tools to mythologize, a crappy last-generation full-disk encryption tool?

I mean, Paul LeRoux is associated with it and he's been mythologized already himself

To be clear, "associated" means absolutely nothing at all here. Zero proof or anything close.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#78
post #22

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

It wouldn't be so bad with ubiquitous end to end encryption though right? If everything was encrypted in transit it wouldn't really matter if Huawei (and by extension the supposition goes the Chinese government) because they'd just see noise. Guess they would also be able to do location tracking though and that's not so easily solved.

There is metadata, but you also have frequent bugs or other errata that render encryption vulnerable.

A nation-state type actor can hoover up everything and retroactively decrypt.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#79

What a treat to read a well written piece based on decent research. It's a long read but well worth your time. Kudo's to the journalists who helped uncover it. And the 'coup of the century' is far from clickbait, it's definitionally warranted for what the CIA and BND did here. It's a little ironic as well, especially since the US is so keen on blocking Huawei over espionage concerns.

Hypocritical, not ironic. You mean to highlight that the USA does not treat other sovereign states like the USA expects to be treated. There is no ironic contrast between the USA funding Crypto AG and China funding Huawei.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#80
post #17
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

I'm pretty sure the US government is why the TrueCrypt devs stopped all work. They got hit with a national security letter (NSL) or heavily leaned on and pressured to stop making their product so awesome and un-breakable.

From the TrueCrypt webpage: http://truecrypt.sourceforge.net/

> WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues

The fact that they use awkward wording that contains words whose first letters that start with NSA (not secure as) is pretty suggestive that you are right.

Post reply on HN