Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

91–100 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#91
post #29
post #17

Earlier quoted context omitted.

I'm pretty sure the US government is why the TrueCrypt devs stopped all work. They got hit with a national security letter (NSL) or heavily leaned on and pressured to stop making their product so awesome and un-breakable.

Of all the cryptographic tools to mythologize, a crappy last-generation full-disk encryption tool?

Why is it crappy?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#92
post #11

Related question: do modern diplomats/negotiators automatically assume their comms are compromised? Are their "secure" lines ever truly secure? Surely they know the NSA/CIA would be listening.

> do modern diplomats/negotiators automatically assume their comms are compromised?

Post wikileaks Diplomatic cable leaks - I think they assume their comms may eventually be compromised, but I don't think they assume their comms can decrypted in a matter of seconds.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#93

> U.S. officials were even more alarmed when Wagner hired a gifted electrical engineer in 1978 named Mengia Caflisch. ... But NSA officials immediately raised concerns that she was “too bright to remain unwitting.” Wow, those are words to aspire to

You cannot get a better compliment than this.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#94

Earlier quoted context omitted.

Yes. It would be useful to have an accessible version posted with the original each time, and for it to be a preferred guideline for submitters. Though to be fair, I'm not sure if there are copyright issues involved, which might make such a guideline difficult.

It is posted each time. Under the article, there are a number of little links ("flag", "hide", "past", and so on). You want the one that says "web".

Useful info, thanks.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#95

What a treat to read a well written piece based on decent research. It's a long read but well worth your time. Kudo's to the journalists who helped uncover it. And the 'coup of the century' is far from clickbait, it's definitionally warranted for what the CIA and BND did here. It's a little ironic as well, especially since the US is so keen on blocking Huawei over espionage concerns.

There's nothing ironic, weird, or surprising about the US wanting to stop other countries from doing to them what they do to other countries. It's hypocritical in some sense, mostly because the US tries to project itself as the good guys, but it's just basic international relations. That's how every country has always operated and will always operate.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#97
post #87

Earlier quoted context omitted.

Is that just a rant or do you have an actual reason to call TrueCrypt crappy? It was at least somewhat solid and it definitely had a great mindshare at the time. It wasn't niche. Also, describing small-scale intervention in cryptography by services "mythologic" in a thread about news about large-scale intervention in cryptography by those services is a bit odd.

I don't even understand the theory underneath this supposed conspiracy, since full-disk encryption is utterly mainstream at this point. I also don't need to get too deep into what I don't like about TrueCrypt; use it if you like it. The problem is with the model of full-disk encryption; outside of phones with deeply integrated hardware designs that support it, FDE is the least powerful form of encryption we use. It w…

Again: why do you use such belittling words like "conspiracy theory"? We know that the services interfere. We know that they interfered with vendors of cryptography products. And we know that National Security Letters exist, as do other – legal – means to pressure such vendors. There is no conspiracy needed for them to try to pressure someone by, say, threatening them with denial of a entry visa. Or they could have simply tried to buy them off which they might not have liked. It's not a crazy idea by any stretch.

> It wasn't even a speed bump for the Ulbricht investigators.

Are you talking about the situation where they had to very carefully snatch a running laptop from a suspect so that they can't lock it? Seems to me like FDE would have been at least a significant speedbump had they not circumvented it. Why else would they go to such trouble? And what would they have done if the suspect hadn't used his laptop in a public place?

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#98

Earlier quoted context omitted.

I mean, Paul LeRoux is associated with it and he's been mythologized already himself

Have people settled on whether he's also Satoshi or not?

It's unlikely to be him given his style of immediate profit-seeking and immense risk taking in the years that surround the creation of Bitcoin.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#99
post #2

Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MI…

Putting my tinfoil hat on, after reading the Snowden disclosures I'm convinced that they do have limited means of attacking encrypted communication but they would rather rely on these (expendable) means. Once they lose their crypto vulnerabilities it will force them to be even more overt.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#100
post #17

Earlier quoted context omitted.

I'm pretty sure the US government is why the TrueCrypt devs stopped all work. They got hit with a national security letter (NSL) or heavily leaned on and pressured to stop making their product so awesome and un-breakable.

I'm sure they were pressured, but the USG has deep pockets if they wanted someone to stop doing something they just throw a few million at them and call it done, there's far less chance of PR blowback then. Even just reading this article should show you that they kill you with kindness when they want to keep things hush-hush. If someone is developing a free tool, and are offered a retirement-tier payoff to stop, they…

I always assumed that this is exactly what happened to Skype and Whatsapp.
Post reply on HN