Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

81–90 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#82

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

Not because they uniquely enable the user to switch off their 2G radios and thereby defeat now trivial MITM?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#83
post #43
post #28

Earlier quoted context omitted.

The fact that the US has repeatedly succeeded in SIGINT capers like this makes their concern about Huawei kind of un-ironic, right?

Well, yes, but for third parties like the UK it makes it much more explicit that the choice is between the system that might be compromised by Huawei and the system that might be compromised by the US. Except the UK has its own little joint venture of security inspection of Huawei systems ...

please expand..

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#84
post #17

Earlier quoted context omitted.

I'm pretty sure the US government is why the TrueCrypt devs stopped all work. They got hit with a national security letter (NSL) or heavily leaned on and pressured to stop making their product so awesome and un-breakable.

From the TrueCrypt webpage: http://truecrypt.sourceforge.net/ > WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues The fact that they use awkward wording that contains words whose first letters that start with NSA (not secure as) is pretty suggestive that you are right.

Wow. In a different timeline I'd dismiss that as tinfoil hat time, but in this one it seems spot on.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#85
post #17
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

I'm pretty sure the US government is why the TrueCrypt devs stopped all work. They got hit with a national security letter (NSL) or heavily leaned on and pressured to stop making their product so awesome and un-breakable.

no read the damn project notes on the ones that forked Truecrypt its obvious why as it needed fixes and someone clone and forked it to fix it. Not every action is NSA-CIA rigged..they are not hidden bogey men(women) and canni fact be defeated with light, truth, programming, and math

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#86

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

When this stuff is used against you, it is FAR more likely going to be from a domestic group hostile to a political opinion you might have. Imagine if an outfit like Cambridge Analytica had the resources of a nation state helping it collect and process information about who might support any given policy (and be given the carrot) and who might oppose it (and be given the stick). That's the scale of threat we face. Wh…

I'm not clear if your post was implying this was the case or not, but this is an interesting, well-sourced article on the links between Cambridge Analytica and Russia [1].

[1] https://www.nytimes.com/2018/03/17/us/politics/cambridge-ana...

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#87
post #29

Earlier quoted context omitted.

Of all the cryptographic tools to mythologize, a crappy last-generation full-disk encryption tool?

Is that just a rant or do you have an actual reason to call TrueCrypt crappy? It was at least somewhat solid and it definitely had a great mindshare at the time. It wasn't niche. Also, describing small-scale intervention in cryptography by services "mythologic" in a thread about news about large-scale intervention in cryptography by those services is a bit odd.

I don't even understand the theory underneath this supposed conspiracy, since full-disk encryption is utterly mainstream at this point. I also don't need to get too deep into what I don't like about TrueCrypt; use it if you like it. The problem is with the model of full-disk encryption; outside of phones with deeply integrated hardware designs that support it, FDE is the least powerful form of encryption we use. It wasn't even a speed bump for the Ulbricht investigators.

By all means: enable FDE. You have to turn it on. It's not optional. But the threat it defends against is not the threat many people think it defends against. It's hard to imagine it being such a priority that any government would launch a conspiracy to shut down an open source project.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#88

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

Funny, I don't really care China spying on me as much since they just don't have any handles that would be relevant. Your own government spying on you is much more dangerous. And since I don't have influence on policies of China, I can at least hold domestic politicians that strive for more surveillance accountable. At least theoretically. History shows that government isn't your friend at all. The US might be a rare…

[deleted]

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#89

Gives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treat…

Funny, I don't really care China spying on me as much since they just don't have any handles that would be relevant. Your own government spying on you is much more dangerous. And since I don't have influence on policies of China, I can at least hold domestic politicians that strive for more surveillance accountable. At least theoretically. History shows that government isn't your friend at all. The US might be a rare…

You might not care if China spies on you, but you might put others in danger who you communicate with. They could get to them through you. This goes for all spying agencies.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#90
post #87

Earlier quoted context omitted.

Is that just a rant or do you have an actual reason to call TrueCrypt crappy? It was at least somewhat solid and it definitely had a great mindshare at the time. It wasn't niche. Also, describing small-scale intervention in cryptography by services "mythologic" in a thread about news about large-scale intervention in cryptography by those services is a bit odd.

I don't even understand the theory underneath this supposed conspiracy, since full-disk encryption is utterly mainstream at this point. I also don't need to get too deep into what I don't like about TrueCrypt; use it if you like it. The problem is with the model of full-disk encryption; outside of phones with deeply integrated hardware designs that support it, FDE is the least powerful form of encryption we use. It w…

AIUI it was a speedbump for Ulbricht; didn't they need to ambush him in a library in order to ensure they had access to his laptop's contents?

(I mean, sure, it didn't protect him in the end. But it was a speedbump.)

Post reply on HN