Live data from Hacker News

How the CIA used Crypto AG encryption devices to spy on countries for decades

washingtonpost.com

1–10 of 353 posts

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#2
Reading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them.

I mean, you only need to read their repeated admissions that without MINERVA their intelligence recovery would've dropped from ~80% to ~10% to see why they're trying to play the same game plan again and again. Whether that's through puppetmastering encryption companies like in this article, sneaking it in via bribes (RSA's Dual_EC_DRBG), or most recently trying to legislate it through (FB, Whatsapp, etc. E2E encryption), it's all essentially the same play.

As a corollary to all this, it's another point of evidence that strong encryption really is beyond the reach of even the biggest three-letter-acronyms, and that there's no secret sauce technology out there letting them mass-decrypt everything. If there was, then perhaps there wouldn't be such a strong push to rig the deck in the first place. At least that's heartening.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#4
Two parts of interest that jumped out to me:

> The overlapping accounts expose frictions between the two partners over money, control and ethical limits, with the West Germans frequently aghast at the enthusiasm with which U.S. spies often targeted allies.

> Hagelin had once hoped to turn control over to his son, Bo. But U.S. intelligence officials regarded him as a “wild card” and worked to conceal the partnership from him. Bo Hagelin was killed in a car crash on Washington’s Beltway in 1970. There were no indications of foul play.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#5
TL;DR Swiss firm Crypto AG sold tech to governments for decades, but turns out to be owned and operated by CIA and BND who benefited from backdoors. From their POV, a wildly successful operation, beyond imagination.

> At times, including in the 1980s, Crypto accounted for roughly 40 percent of the diplomatic cables and other transmissions by foreign governments that cryptanalysts at the NSA decoded and mined for intelligence, according to the documents.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#6
It certainly does make one wonder who else in the worlds of high technology (and journalism!) May be – wittingly or unwittingly – working for Uncle Sam.

I've seen some deep integrations that have made me despair of any organization being free from the overweening influence of the "security services." I'm talking about groups as large as multi-billion dollar public US technology infrastructure companies and as small as anarchist cells planning to attend a political convention.

Sometimes it seems that internal turf battles, budget disputes, careerism, and rank incompetence are our only protections against the machinations of the National Security State.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#7
It has been known for a pretty long time that the Crypto AG is affiliated with or controlled by intelligence services. It was also always firmly in the "security through obscurity of our own cipher designs" department. Their C-52 (52 as in "1952") cipher machines were designed to enable decryption by Western intelligence.

> Le Temps has argued that Crypto AG had been actively working with the British, US and West German secret services since 1956, going as far as to rig manuals after the wishes of the NSA. These claims were vindicated by US government documents declassified in 2015.

http://www.spiegel.de/spiegel/print/d-9088423.html (1996) https://en.wikipedia.org/wiki/Crypto_AG#Compromised_machines

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#8
What a treat to read a well written piece based on decent research. It's a long read but well worth your time. Kudo's to the journalists who helped uncover it.

And the 'coup of the century' is far from clickbait, it's definitionally warranted for what the CIA and BND did here.

It's a little ironic as well, especially since the US is so keen on blocking Huawei over espionage concerns.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#9
Being able to read diplomatic messages is a definite gold-mine.

Of course, knowing the contents of diplomatic messages isn't always enough. A good example is described in Peter Wright's Spycatcher: the Brits were breaking the French diplomatic cipher, using an ingenuous attack on the electromagnetic noise of the cipher machine in the embassy. But all this intelligence was unable to stop De Gaulle thwarting their entering the European Common Market.

Re: How the CIA used Crypto AG encryption devices to spy on countries for decades

#10

What a treat to read a well written piece based on decent research. It's a long read but well worth your time. Kudo's to the journalists who helped uncover it. And the 'coup of the century' is far from clickbait, it's definitionally warranted for what the CIA and BND did here. It's a little ironic as well, especially since the US is so keen on blocking Huawei over espionage concerns.

I take this plainly without irony as evidence for the restriction of foreign government-controlled infastructure in series with trusted communication.
Post reply on HN