Live data from Hacker News

New German law would force ISPs to allow secret service to install trojans

privateinternetaccess.com

91–100 of 245 posts

Re: New German law would force ISPs to allow secret service to install trojans

#91

Earlier quoted context omitted.

Presumably, Germany would have little trouble compelling at least one root CA to sign any TLS certificates they wanted. Just a cursory search shows that Google Chrome, on Linux, trusts, e.g. > CN = D-TRUST Root CA 3 2013 > O = D-Trust GmbH > C = DE There is certificate transparency and pinning and so on, and they would be caught (probably, maybe) if they abused this carelessly and at scale, but in practice, for a sma…

Google, Mozilla, et al. should make a commitment to revoke the trust of any CA that is found to partake in behavior like that. Even retroactive revocation of existing certificates shouldn't be off the table if the offense is egregious enough. It's actually pretty scary seeing just how many CAs are in the list of trusted CAs on any given device. While no government is beyond reproach, I do wish there were a way for me…

You could, for example, use the Certificate Manager in Firefox to delete specific authorities you do not trust.

Re: New German law would force ISPs to allow secret service to install trojans

#92

Earlier quoted context omitted.

For many things there isn't really need to get the payload. Get the IP addresses, DNS lookups and TLS SNI information and correlate to information gathered from elsewhere and you can derive a lot.

+1 Hopefully DNS over tls and new sni encryption standards will put an end to all this in next 5-10 years

+1 for the optimism, but unfortunately even with those mitigations it is not enough. Using a VPN in combination with DoT/H is currently best practice I believe.

Re: New German law would force ISPs to allow secret service to install trojans

#93
post #48

What does "trojans at ISPs" even mean? TLS works end-to-end and ISPs can do absolutely nothing to see the plaintext. It's unless the CAs at users-side are manually replaced with fake ones nothing can be done. I've never used Windows since I was a kid but I am sure this is pretty much impossible on Linux for example since adding CAs require root privilege.

think mobile - isp are the place to conduct baseband attacks from.

Think storage - in a snowglobe kind of way, networking is just a dynamic storage pool (or tamperable storage in this case).

No-frills data means a lot nowadays.

Re: New German law would force ISPs to allow secret service to install trojans

#94
post #36

Pretty shocking in a state that has such strict privacy laws. Not sure how the two can come from the same mouth, and even be in public view. My understanding is that the privacy restrictions are largely the result of half the country having lived under the Statsi, and thus being extremely weary of government eyes. Here it’s out in the open!

By no means. The Stasi was active in the GDR (German Democratic Republic, "East Germany"), and it is not as if those from the east are particularly watchful for state-instigated surveillance. This predates the wall, but the wall only confirmed what was going on beforehand.

https://www.japantimes.co.jp/news/2013/11/19/world/stasi-leg...

Re: New German law would force ISPs to allow secret service to install trojans

#95
post #48

What does "trojans at ISPs" even mean? TLS works end-to-end and ISPs can do absolutely nothing to see the plaintext. It's unless the CAs at users-side are manually replaced with fake ones nothing can be done. I've never used Windows since I was a kid but I am sure this is pretty much impossible on Linux for example since adding CAs require root privilege.

FinFisher has "drive by infection" packages for sale called FinFly that require traffic injection, according to their brochure. How exactly those work today, i do not know. For example: until 2011 they used a bug in the self update code of iTunes. Having a network level man in the middle can benefit many complex exploit chains.

Re: New German law would force ISPs to allow secret service to install trojans

#99

Pretty shocking in a state that has such strict privacy laws. Not sure how the two can come from the same mouth, and even be in public view. My understanding is that the privacy restrictions are largely the result of half the country having lived under the Statsi, and thus being extremely weary of government eyes. Here it’s out in the open!

Some other shocking stuff from Germany: far right supporters in the military stealing ammunition/weapons (and an alleged plot to assassinate someone):

https://www.bbc.com/news/world-europe-53237685

https://en.wikipedia.org/wiki/Day_X_plot

Someone said that's a result of constant under-funding and treating your military with no respect - when it's only seen as a choice for those who can't "do any better", you'll get extremists among the ranks.

Sounds plausible, at least in the US soldiers seem to be highly respected and in turn, they respect the country and its people.

Re: New German law would force ISPs to allow secret service to install trojans

#100

Earlier quoted context omitted.

>Pretty shocking in a state that has such strict privacy laws. Not sure how the two can come from the same mouth, and even be in public view. Because they're not necessarily contradictory. This doesn't just give secret services a blank cheque to spy on everyone, it just provides intelligence agencies with a tool. I'm German and I don't object in principle to the fact that intelligence, under supervision of the govern…

The scary stuff about the current development is, that we get flooded with arguments about hardcore criminals, but if you look at the actual changes to the laws, such restrictions are not made, instead these extreme measures are allowed for petty reasons and some politicians will still keep pushing for even more totalitarianism. These siloviki want mass surveillance comparable to what Chinas Ministry of State Securit…

The surveillance, including the mass surveillance of the communication, existed even in older times. It is, for example, documented that both British and US secret services went through all the telegrams that passed their commercial infrastructure, often based on a simple "gentleman's agreement" with the companies, even in the 19th century, and certainly in the 20th.

Other countries were somehow aware of that weakness of telegrams, and the practice of attempting to use some code for telegram messages existed even then.

Post reply on HN