14 ms·
How the CIA used Crypto AG encryption devices to spy on countries for decades
- NamTaf 7y agoReading between the lines on this, it's plainly apparent why there's been repeated attacks on encrpytion by the US government. From this, through RSA's Dual_EC_DRBG, to the present day, it's obvious that the US highly values rigging the deck to aid their decryption, and that the current democratisation of encrpytion protocols is a threat to them. I mean, you only need to read their repeated admissions that without MINERVA their intelligence recovery would've dropped from ~80% to ~10% to see why they're trying to play the same game plan again and again. Whether that's through puppetmastering encryption companies like in this article, sneaking it in via bribes (RSA's Dual_EC_DRBG), or most recently trying to legislate it through (FB, Whatsapp, etc. E2E encryption), it's all essentially the same play. As a corollary to all this, it's another point of evidence that strong encryption really is beyond the reach of even the biggest three-letter-acronyms, and that there's no secret sauce technology out there letting them mass-decrypt everything. If there was, then perhaps there wouldn't be such a strong push to rig the deck in the first place. At least that's heartening.
- edm0nd 7y agoI'm pretty sure the US government is why the TrueCrypt devs stopped all work. They got hit with a national security letter (NSL) or heavily leaned on and pressured to stop making their product so awesome and un-breakable.
- tptacek 7y agoOf all the cryptographic tools to mythologize, a crappy last-generation full-disk encryption tool?
- ameister14 7y agoI mean, Paul LeRoux is associated with it and he's been mythologized already himself
- jonny_eh 7y agoHave people settled on whether he's also Satoshi or not?
- alwayseasy 7y agoIt's unlikely to be him given his style of immediate profit-seeking and immense risk taking in the years that surround the creation of Bitcoin.
- lawnchair_larry 7y agoIt’s quite obvious that he is not.
- jonny_eh 7y agoWhy? Didn't Satoshi go quiet when Paul was arrested?
- rofo1 7y agoTo be clear, "associated" means absolutely nothing at all here. Zero proof or anything close.
- eitland 7y agoHe's not linked beyond reasonable doubt to TrueCrypt, but IIRC - there is clear evidence linking him to some earlier cryptographic software -and someone (the journalist who wrote the story?) tried to say that it was a precursor to TrueCrypt.
- jonathanpierre 7y agoIs that just a rant or do you have an actual reason to call TrueCrypt crappy? It was at least somewhat solid and it definitely had a great mindshare at the time. It wasn't niche. Also, describing small-scale intervention in cryptography by services "mythologic" in a thread about news about large-scale intervention in cryptography by those services is a bit odd.
- tptacek 7y agoI don't even understand the theory underneath this supposed conspiracy, since full-disk encryption is utterly mainstream at this point. I also don't need to get too deep into what I don't like about TrueCrypt; use it if you like it. The problem is with the model of full-disk encryption; outside of phones with deeply integrated hardware designs that support it, FDE is the least powerful form of encryption we use. It wasn't even a speed bump for the Ulbricht investigators. By all means: enable FDE. You have to turn it on. It's not optional. But the threat it defends against is not the threat many people think it defends against. It's hard to imagine it being such a priority that any government would launch a conspiracy to shut down an open source project.
- barrkel 7y agoAIUI it was a speedbump for Ulbricht; didn't they need to ambush him in a library in order to ensure they had access to his laptop's contents? (I mean, sure, it didn't protect him in the end. But it was a speedbump.)
- nyolfen 7y agothis is true but i wouldnt count on it as evidence either way; fbi would not have nsa tools
- pvg 7y agoambush him in a library Someone started talking to him while someone else snagged his laptop - a thing you and a friend can do to more or less anyone. It's not like people rappelled down from helicopters with guns drawn.
- tomc1985 7y agoWhy is it crappy?
- 93po 7y agoIt was the only non-microsoft option that was accessible and easy to use and free for Windows. And MS's FDE is likely compromised and backdoored.
- Someone1234 7y agoI'm sure they were pressured, but the USG has deep pockets if they wanted someone to stop doing something they just throw a few million at them and call it done, there's far less chance of PR blowback then. Even just reading this article should show you that they kill you with kindness when they want to keep things hush-hush. If someone is developing a free tool, and are offered a retirement-tier payoff to stop, they're going to stop.
- whatshisface 7y agoIf an average person got a huge windfall, that would raise a lot of attention, and people would wonder how they got the money. Police use sudden unexplained riches as a way to watch out for criminal activity, and everyone who knew the receiver of the windfall would ask questions. Between $10M and the other option, it may be easier to kill them with killing.
- K0SM0S 7y agoAgencies routinely set up fake businesses for cover, with the cooperation of insiders at big names (e.g. Dell). So you set up a fake SaaS, have your big name client buy the big thing 25k / CPU x however many you need to reach payout, done. All legitimized by a fancy public stock name. If things really get too hot, it's easy to send a letter to any country's IRS via their local intell agency. You'd be surprised how simple it is to close files in this world. I'd suggest reading Snowden's autobiography, Permanent Record. Very eye-opening and a great read.
- monocasa 7y agoThey didn't kill lavabit with kindness.
- jhart99 7y agoI always assumed that this is exactly what happened to Skype and Whatsapp.
- paganel 7y ago
- rebuilder 7y agoI'm not sure that makes sense. The US could compel the devs to compromise their product but not keep them from issuing a cryptic statement and stopping work on the product?
- criddell 7y agoIt doesn't make sense for two reasons to me. For one, the government can't compel you to do work. That's slavery. Also, it's open source software. TrueCrypt going down didn't change the security landscape at all.
- turk73 7y agoOn the face of it sure, but then the key people start having heart attacks and mysterious accidents and suddenly the problem goes away. And that's the world we live in.
- dboreham 7y agoThey offer you a large contract to do <something>, then they require that <some guy> they nominate work with you on the project. That guy introduces the backdoor.
- SkyBelow 7y agoThe government can. For example, take how the police will turn individuals into informants by getting them on trumped up drug charges and then offering them a deal if they work for the government, including engaging in acts that put them at risk of being killed. https://en.wikipedia.org/wiki/Murder_of_Rachel_Hoffman https://en.wikipedia.org/wiki/Murder_of_Rachel_Hoffman The end result is "Work for us or go to prison."
- ceejayoz 7y ago> For one, the government can't compel you to do work. That's slavery. Slavery's perfectly legal. The 13th Amendment: "Neither slavery nor involuntary servitude, except as a punishment for crime whereof the party shall have been duly convicted, shall exist within the United States, or any place subject to their jurisdiction." https://en.wikipedia.org/wiki/Penal_labor_in_the_United_States https://en.wikipedia.org/wiki/Penal_labor_in_the_United_Stat...
- jimbob45 7y agoBut the source-available VeraCrypt still exists and is maintained.
- turk73 7y agoThat sucks. No fan of the intel agencies in this country, they are the Deep State and will harm us just as readily as they would harm communists or terrorists. They are as much responsible for destroying our freedom as they are protecting it. The world needs strong crypto, even if it enables evildoers because it also protects the little people. Strong crypto makes the playing field level, something that control freaks all despise.
- RcouF1uZ4gsC 7y agoFrom the TrueCrypt webpage: http://truecrypt.sourceforge.net/ http://truecrypt.sourceforge.net/ > WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues The fact that they use awkward wording that contains words whose first letters that start with NSA (not secure as) is pretty suggestive that you are right.
- pstuart 7y agoWow. In a different timeline I'd dismiss that as tinfoil hat time, but in this one it seems spot on.
- ta999999171 7y ago> tinfoil hat time This trope needs to die already.
- pfundstein 7y agoWhat would you suggest instead? It's a good way to convey unfounded paranoia or to acknowledge that what you're saying sounds like a conspiracy theory.
- glitchdigger 7y ago> talking bout NSA “Unfounded” paranoia
- ta999999171 7y agoThere's nothing wrong with conspiracy theory. They regularly turn into conspiracy fact. That's not a dirty phrase either - regardless of what the media memo said back then. That's what I'm suggesting.
- maxerickson 7y agoIs the idea that there would be consequences for a blatant message but not for a sort of more subtle one?
- fredgrott 7y agono read the damn project notes on the ones that forked Truecrypt its obvious why as it needed fixes and someone clone and forked it to fix it. Not every action is NSA-CIA rigged..they are not hidden bogey men(women) and canni fact be defeated with light, truth, programming, and math
- vfclists 7y agoWhy then aren't they able to do the same with LUKS, dm-crypt, cryfs, bitlocker etc? Does that mean they are only available because the 3 letter agencies can hack them?
- lawnchair_larry 7y agoYou must have a low threshold for “pretty sure”, because there is no evidence whatsoever to suggest this. Also, it’s open source. Also, the author recommended bitlocker as a replacement. Also, the authors may not even be American (the original author of E4M wasn’t). Doesn’t really add up.
- navidr 7y agoWhat is MINERVA? Google didn’t give any related results.
- JorgeGT 7y agoThe codename for Crypto AG.
- reaperducer 7y agoIt's explained in the article.
- sounds 7y agoThe paywalled article? I didn't read it.
- reaperducer 7y ago"None are so blind as those who will not see." - Matthew 9:26
- netsec_burn 7y agoPutting my tinfoil hat on, after reading the Snowden disclosures I'm convinced that they do have limited means of attacking encrypted communication but they would rather rely on these (expendable) means. Once they lose their crypto vulnerabilities it will force them to be even more overt.
- dmix 7y agoThe key difference is that decrypting something would likely need to be targeted and on a case-by-case basis, as it would take specialized work, as opposed to these sorts of attacks (much like tapping all of the pipes which transit data underseas or elsewhere, which still goes on in every country or working directly with the ISPs and mobile operators which happens in most countries) which allows mass dragnet surveillance. I think most of us would be fine with the NSA doing what they do if it was targeted, like the police getting warrants to break privacy only in important cases for public safety. The problem will always be mass interception. Not only domestically either, as there is nothing protecting any foreign communications being intercepted in the US (and I'm sure Five eyes+ bypasses these legal roadblocks whenever needed). Which is why the push for encrypt-everything is so important. But as we've seen repeatedly, even when investigating the president and his people, even the allegedly "significant domestic protections" offered by FISA are a joke and basically rubber-stamp. WhatsApp and iMessage and other non-SMS communication as well as email providers finally adopting proper transit encryption probably has reduced the amount of this sort of unfiltered "intelligence" gathering by 90%+. But I'm sure there's still tons of mobile apps and websites which aren't doing things properly and are filling up their databases.
- einpoklum 7y ago> I think most of us would be fine with the NSA doing what they do if it was targeted You think wrong. That fact that there are opposing world states engaging in this nefarious, oppressive, terrible acts and they're not all aligned doesn't legitimize any of these states' activities. The NSA should essentially be shut down, or cut down to a small agency operating in public with a much more limited mandate. And no secret FISA courts all of that spy-movie crap. That should just stop, period.
- brightball 7y agoThat thought is one reason why I've always questioned this advice: "Don't roll your own encryption." I've always understood the arguments for it but that the advice is so widespread seemed a little counter intuitive. It always seemed, to me at least, that having millions of encryption algorithms out there would be inherently more secure than a lot of people standardized on one because the risk to any one would be so compartmentalized by comparison.
- deleted 7y ago[deleted]
- ninly 7y agoThe "don't roll your own" argument isn't against having lots of encryption algorithms, though. It's because it's nearly impossible for a nonspecialist to implement tools that other specialists can't fairly easily recognize as broken and exploit (whether cryptologically broken or due to side-channel exploits).
- bosswipe 7y ago> other specialists can't fairly easily recognize as broken and exploit Is there any supporting evidence for this claim? If I took an AES library and changed the order of some inner loop wouldn't it require extensive statistical analysis to notice the difference? Which means instead of throwing a bunch of compute at decrypting me, along with the masses 10 years from now, you would need to get a specialist to specifically target me and spend considerable time.
- Mirioron 7y agoI've wondered this as well. Are there tools that will automatically run through all kinds of existing cryptographic algorithms to figure out which ones you're dealing with? Because it sounds to me like throwing enough layers of shoddy algorithms would obfuscate things enough that somebody would actually have to look at it and try to explicitly figure out a way to bypass what you're doing.
- 7y ago
- garbage_88224 7y agoYour cellular phone modem is both remotely programmable and has full root memory access 24/7. Let that sink in a bit.
- tptacek 7y agoYour "cellular phone" does not in fact have "full root memory access 24/7". In modern phone designs, the baseband is a USB peripheral. The notion that the closed, secret baseband is a DMA backdoor into AP memory is a message board meme, not engineering reality.
- hjkgfdfgh 7y agoThat may be true of Apple, and is true of the PinePhone and Librem, but for the majority of Android devices, that's blatantly false. On Qualcomm chipsets in particular heavily utilize shared memory for baseband to application processor communication.
- tptacek 7y ago"The majority of Android devices" is a very wide net to cast.
- hjkgfdfgh 7y agoQualcomm alone covers 40%, and they're arguably the most likely to correctly implement their MMU (nevermind they've seen quite a few vulnerabilities in their MMU implementations over the years..) Meditek uses a similar architecture, and I sure as hell don't trust their MMU. Outside of Apple, Librem and Pine are just about the only way you're getting a USB attached baseband. edit - Here's a Mediatek Baseband->AP PoC even: https://comsecuris.com/blog/posts/path_of_least_resistance/ https://comsecuris.com/blog/posts/path_of_least_resistance/
- weeks 7y agohttps://googleprojectzero.blogspot.com/2017/10/over-air-vol-2-pt-3-exploiting-wi-fi.html https://googleprojectzero.blogspot.com/2017/10/over-air-vol-... Even Apple's IOMMU has had vulnerabilities allowing for full memory access from the WiFi modem.
- nimbius 7y ago>the current democratisation of encrpytion protocols is a threat to them. This is absolutely true and nowhere was it more evident than the Speck fiasco. Watching the old guard of the NSA show up and hammer a crypto forum with stonewalling and smug G-Man hand-waving would have been acceptable in 1995, but watching it take place after the snowden revelations was just cringe-worthy. The answer from the community wasnt just no, but hell no. https://www.tomshardware.com/news/nsa-speck-removed-linux-4-20,37747.html https://www.tomshardware.com/news/nsa-speck-removed-linux-4-... I suspect things like ED25519 and LetsEncrypt were probably a much more damning blow to the day-to-day business of warrantless telecom spying than we're led to believe, and its only going to get closer to that 10% pre-MINERVA figure as time rolls on. the Signal protocol has gained massive traction, and things like Tails are easy enough for a power user. Once someone rolls out a slick CSS frontend for wireguard its back to greasing the palms of guys like RSA in the hopes snooping corporate networks is just as fruitful as snooping the public internet. CryptoAG tips the governments hand on exactly why it disfavors crypto now. its not terrorists or posthumous parallel construction of $latest_shooter. its about control.
- mirimir 7y agoYes, and it started with the development of minicomputers and PCs, which facilitated the process, starting in the late 70s.
- chiefalchemist 7y ago> If there was, then perhaps there wouldn't be such a strong push to rig the deck in the first place. At least that's heartening. Intelligence isn't about truth and transparency. It's about deception. They're not going to run a Super Bowl advert saying they can crack anything. That's not how it works.
- _-___________-_ 7y agoGiven that the US has operations aiming to capture large amounts of Internet traffic, and given that most interesting Internet traffic is encrypted nowadays, doesn't it follow that they probably have a way to decrypt at least some of it? Capturing DNS queries and HTTP requests to aging websites that still haven't enabled TLS seems not worth the trouble.
- glitchdigger 7y agoIt’s pretty straightforward. They 0day, hardware backdoor and infiltrate the ranks of root CA’s. This is covert information war from blank-check black op military agencies we’re talking about. They will kill people if they have to and sleep at night like babies because it is a utilitarian philosophy these people hold, not some Kantian dream.
- adventured 7y agohttps://outline.com/tTTmh6 https://outline.com/tTTmh6 And http://archive.is/1w61P http://archive.is/1w61P
- Apofis 7y agoThanks, it gets irksome at some points that a large number of submitted content on HN is paywalled. I can't subscribe to all of these, just to read a couple of articles a month per publication.
- mellosouls 7y agoYes. It would be useful to have an accessible version posted with the original each time, and for it to be a preferred guideline for submitters. Though to be fair, I'm not sure if there are copyright issues involved, which might make such a guideline difficult.
- AnimalMuppet 7y agoIt is posted each time. Under the article, there are a number of little links ("flag", "hide", "past", and so on). You want the one that says "web".
- Apofis 7y agoThanks, I'll keep this in mind in the future.
- mellosouls 7y agoUseful info, thanks.
- tinus_hn 7y agoIf only the newspapers would just provide all their content for free, but without ads and tracking!
- 7y ago
- wycy 7y agoTwo parts of interest that jumped out to me: > The overlapping accounts expose frictions between the two partners over money, control and ethical limits, with the West Germans frequently aghast at the enthusiasm with which U.S. spies often targeted allies. > Hagelin had once hoped to turn control over to his son, Bo. But U.S. intelligence officials regarded him as a “wild card” and worked to conceal the partnership from him. Bo Hagelin was killed in a car crash on Washington’s Beltway in 1970. There were no indications of foul play.
- johnflan 7y ago> There were no indications of foul play. Yup
- sailfast 7y agoHave you ever driven on the beltway?
- wycy 7y agoI have. Nowadays it's generally slow enough that it's hard to imagine dying in an accident there. But this was so long ago that I imagine things were different with the Beltway back then, and of course cars were much more deadly at the time too.
- sailfast 7y agoIndeed. But it seems people keep finding new and innovative ways to crash spectacularly as well. Maybe it's foul play all the way down, but I'd bet most of money on Marylanders :)
- burakemir 7y agoTL;DR Swiss firm Crypto AG sold tech to governments for decades, but turns out to be owned and operated by CIA and BND who benefited from backdoors. From their POV, a wildly successful operation, beyond imagination. > At times, including in the 1980s, Crypto accounted for roughly 40 percent of the diplomatic cables and other transmissions by foreign governments that cryptanalysts at the NSA decoded and mined for intelligence, according to the documents.
- just_steve_h 7y agoIt certainly does make one wonder who else in the worlds of high technology (and journalism!) May be – wittingly or unwittingly – working for Uncle Sam. I've seen some deep integrations that have made me despair of any organization being free from the overweening influence of the "security services." I'm talking about groups as large as multi-billion dollar public US technology infrastructure companies and as small as anarchist cells planning to attend a political convention. Sometimes it seems that internal turf battles, budget disputes, careerism, and rank incompetence are our only protections against the machinations of the National Security State.
- cpr 7y agoLook up Operation Mockingbird on wikipedia. The same is still going on in spades.
- WarOnPrivacy 7y agoI don't think an operation like that is necessary. Most journalists seem to be eager to prove themselves as patriots by under-reporting Gov malfeasance, especially in IC matters where understanding a complex issue gets trumped by deadlines. Thank-you editors for our chronically uninformed electorate.
- paganel 7y ago> as small as anarchist cells planning to attend a political convention For what it's worth I fully expect a great percentage of any anarchist cell to actually be double agents/"agents provocateurs", in the end I think that's why the Okhrana [1] was so good at its job (relatively speaking, of course). As a matter of fact I think that the "Western" three-letter agencies are at a disadvantage because they're focusing too much on data collection and interception, they're too technical, so to speak, this is still a "humans-heavy industry" (for lack of a better phrase) and without controlling and understanding said humans all the information in the world will do almost nothing to further said secret agencies' goals. [1] https://en.wikipedia.org/wiki/Okhrana https://en.wikipedia.org/wiki/Okhrana
- WarOnPrivacy 7y ago
- blattimwind 7y agoIt has been known for a pretty long time that the Crypto AG is affiliated with or controlled by intelligence services. It was also always firmly in the "security through obscurity of our own cipher designs" department. Their C-52 (52 as in "1952") cipher machines were designed to enable decryption by Western intelligence. > Le Temps has argued that Crypto AG had been actively working with the British, US and West German secret services since 1956, going as far as to rig manuals after the wishes of the NSA. These claims were vindicated by US government documents declassified in 2015. http://www.spiegel.de/spiegel/print/d-9088423.html http://www.spiegel.de/spiegel/print/d-9088423.html (1996) https://en.wikipedia.org/wiki/Crypto_AG#Compromised_machines https://en.wikipedia.org/wiki/Crypto_AG#Compromised_machines
- fanf2 7y agoAlso https://web.archive.org/web/20130902003901/https://ciphermachines.com/hagelin https://web.archive.org/web/20130902003901/https://ciphermac...
- Ragnarork 7y ago> Andreas Linde, the chairman of the company that now holds the rights to Crypto’s international products and business, said he had no knowledge of the company’s relationship to the CIA and BND before being confronted with the facts in this story. I'm quite curious about this. As you said it's been known for a long time that, without knowing the full extent of the ties, there was ties between Crypto-AG and US agencies (at least). I find hard to believe the candor that this M. Linde displays here...
- eternalban 7y agoI saw this article and that is exactly the first thought that popped up. Second thought was why is Washington Post feigning ignorance of this fact.
- rtsil 7y agoThey didn't, following the arrest in Iran and subsequent release of a Crypto AG salesman in 92, they cite the salesman as talking with news organizations, they also cite a Swiss TV broadcast in 1994 and reports from Baltimore Sun in 1995. The new fact is that the company was co-owned, then fully owned by the CIA.
- apexalpha 7y agoWhat a treat to read a well written piece based on decent research. It's a long read but well worth your time. Kudo's to the journalists who helped uncover it. And the 'coup of the century' is far from clickbait, it's definitionally warranted for what the CIA and BND did here. It's a little ironic as well, especially since the US is so keen on blocking Huawei over espionage concerns.
- jvanderbot 7y agoI take this plainly without irony as evidence for the restriction of foreign government-controlled infastructure in series with trusted communication.
- tptacek 7y agoThe fact that the US has repeatedly succeeded in SIGINT capers like this makes their concern about Huawei kind of un-ironic, right?
- pjc50 7y agoWell, yes, but for third parties like the UK it makes it much more explicit that the choice is between the system that might be compromised by Huawei and the system that might be compromised by the US. Except the UK has its own little joint venture of security inspection of Huawei systems ...
- OBFUSCATED 7y agoplease expand..
- HenryBemis 7y agoNew account, 1 post.. I woulnd't answer "OBFUSCATED"'s question.. seems like he's already picked where to dig the ditch for the commenter. GCHQ? Something nastier?
- 7y ago
- willvarfar 7y agoBeing able to read diplomatic messages is a definite gold-mine. Of course, knowing the contents of diplomatic messages isn't always enough. A good example is described in Peter Wright's Spycatcher: the Brits were breaking the French diplomatic cipher, using an ingenuous attack on the electromagnetic noise of the cipher machine in the embassy. But all this intelligence was unable to stop De Gaulle thwarting their entering the European Common Market.
- C1sc0cat 7y agoAssuming they aren't coded as well or double enciphered eg XXX in 21Land is a WW
- bobosha 7y agoRelated question: do modern diplomats/negotiators automatically assume their comms are compromised? Are their "secure" lines ever truly secure? Surely they know the NSA/CIA would be listening.
- WarOnPrivacy 7y agoThey've all got massive bureaucracies above them that tightly control what they can do. Also, everyone wants to eventually end their shift and go home. That means just doing what you're told & screw the damage done.
- tinus_hn 7y agoNot all communication is compromised; for example for an embassy it could be practical to use a true one time pad which is uncrackable and attempts to intercept the key would lead to a diplomatic incident. Much of their communication probably isn’t that sensitive though.
- nroets 7y agoUntil the people slip up and use the same pad twice https://www.theregister.co.uk/2018/07/19/russia_one_time_pads_error_british/ https://www.theregister.co.uk/2018/07/19/russia_one_time_pad...
- sangnoir 7y ago> do modern diplomats/negotiators automatically assume their comms are compromised? Post wikileaks Diplomatic cable leaks - I think they assume their comms may eventually be compromised, but I don't think they assume their comms can decrypted in a matter of seconds.
- einpoklum 7y agoSomewhat surprisingly, it seems they don't. Just look at the diplomatic cables Wikileaks obtained. I mean, ok, they were leaked and not decrypted, but people were assuming that texts which can be accessed by tens of thousands of people would not leak.
- leowinterde 7y agoThe same report by the ZDF (second german television): https://www.zdf.de/nachrichten/politik/cryptoleaks-bnd-cia-operation-rubikon-100.html https://www.zdf.de/nachrichten/politik/cryptoleaks-bnd-cia-o...
- allovernow 7y agoAnd that's why we can't trust Uncle Sam with backdoors. You bet your ass they'll be reading everything and we won't find out for decades, if ever.
- rjsw 7y agoA slightly related article is this [1]. [1] https://www.bell-labs.com/usr/dmr/www/crypt.html https://www.bell-labs.com/usr/dmr/www/crypt.html
- snowwrestler 7y agoGives you a sense of why the U.S. intelligence community is so nervous about having Huawei at the core of the domestic 5G network. Would not be fun for the U.S. to have done to them what they've done to others. And as a U.S. resident, even as I acknowledge and deplore what the U.S. intelligence services have done to others, I still don't want China to do that to me. This is not an area where equitable (but bad) treatment makes things right IMO.
- AndyMcConachie 7y agoThe political squabble over 5G/Huawei is as much about western vendors using fear of China to prevent competition. Why should Cisco/Juniper/Ericsson/etc compete with Huawei when they can more easily use political pressure to exclude them from the market?
- rtkwe 7y agoIt wouldn't be so bad with ubiquitous end to end encryption though right? If everything was encrypted in transit it wouldn't really matter if Huawei (and by extension the supposition goes the Chinese government) because they'd just see noise. Guess they would also be able to do location tracking though and that's not so easily solved.
- snowwrestler 7y agoI mean, you can do a lot with metadata. Also, I think quite a bit of telecomm traffic is encrypted by the telecomm carrier itself. For example I don't think my iPhone, by default, encrypts/decrypts SMS or voice calls on the device. To the extent text messages and mobile phone calls are resistant to dumb eavesdropping, that's provided by the mobile carrier. So having access into all the equipment at the carrier would be a nice centralized place to sit and observe/record.
- ckocagil 7y agoGovernments are focusing more and more on end-to-end encryption. It can be banned within the next 5 years. They could need to manufacture some consent before that (e.g. mention e2e in the news every time a major crime is committed).
- PhantomGremlin 7y agoI have to disagree with the headline. The "intelligence coup of the century" came much earlier, during WWII. The Allies were reading a good deal of both Japanese and German encrypted communications. This saved the lives of many Allied solders and, perhaps, tipped the balance of the war. https://en.wikipedia.org/wiki/Magic_(cryptography) https://en.wikipedia.org/wiki/Magic_(cryptography) https://en.wikipedia.org/wiki/Ultra https://en.wikipedia.org/wiki/Ultra David Kahn's book, the Codebreakers, is a good introduction to cryptography and has a lot of this history in it. https://en.wikipedia.org/wiki/The_Codebreakers https://en.wikipedia.org/wiki/The_Codebreakers
- Psyladine 7y agoIn terms of scope & scale you may be underselling the title. Enigma, while perhaps more far-reaching in its consequences for computerization, did not have consistent application its breaking would suggest. American code-breakers had more success against the Japanese in practical terms, Midway most especially, but the imperials were a doomed effort[0]. As the cliche goes, British intelligence, American steel, and Russian blood, all of which overshadowed by the Bomb. To put it bluntly, the equivalent would have to be, say, informing Stalin about Barbarossa, or cracking Purple before Pearl Harbor. What the article describes, is the most thorough and long-running (known) intelligence operation in modern history. It is simply unparalleled in strategic depth and tactical implications, not to mention how it must have shaped global politics, economics & social development. [0]http://www.combinedfleet.com/economic.htm http://www.combinedfleet.com/economic.htm
- mzs 7y agoalso how Poland kept the Bolsheviks from sweeping across Europe https://warfarehistorynetwork.com/2016/10/05/polish-ciphers/ https://warfarehistorynetwork.com/2016/10/05/polish-ciphers/
- mxcrossb 7y ago> U.S. officials were even more alarmed when Wagner hired a gifted electrical engineer in 1978 named Mengia Caflisch. ... But NSA officials immediately raised concerns that she was “too bright to remain unwitting.” Wow, those are words to aspire to
- drummer 7y agoYou cannot get a better compliment than this.
- Psyladine 7y ago>Their [Soviet Union & China] well-founded suspicions of the company’s ties to the West shielded them from exposure, although the CIA history suggests that U.S. spies learned a great deal by monitoring other countries’ interactions with Moscow and Beijing. Fascinating use of 'negative space' in intelligence. Also appreciated the dig at Reagan, apparently gross intelligence breaches at the highest levels aren't anything novel.
- WarOnPrivacy 7y ago> gross intelligence breaches at the highest levels aren't anything novel True. Same portrayals too. If breacher is an R they're incompetent, it's a D they're a traitor.
- reddog 7y agoIt follows that private VPN firms would be a similar target for deep pocketed state intelligence agencies. What do you think the chances are that the VPN service or software you use hasn't been co-opted, compromised or is outright owned by state actors in China, Europe or the US?
- e12e 7y agoIt would be hopelessly naive to assume that intelligence services don't run a large number of VPN providers an tor relays, just as the used to run mix master smtp (email) relays.
- freeflight 7y agoWhile at the same time taking out the competition they can't get to comply [0] [0] https://www.theregister.co.uk/2019/09/30/cyberbunker_cb3rob_germany_police_raid/ https://www.theregister.co.uk/2019/09/30/cyberbunker_cb3rob_...
- DethNinja 7y agoYou can never trust VPN but it is important to have a legal case. Let’s say VPN is in a country where mass surveillance is illegal, then at least in future you can sue the VPN company if they are found out to be breaking their contract.
- mratsim 7y agoA country like Switzerland or Liechtenstein?
- tareqak 7y agoSame story from the Associated Press: Switzerland investigating alleged CIA, German front company - https://apnews.com/fbd5fe4261c8b326f860936de7c32a87 https://apnews.com/fbd5fe4261c8b326f860936de7c32a87
- deleted 7y ago[deleted]
- danso 7y agoThe popular belief is that the CIA and its intelligence colleagues will go to any lengths to protect its power and secrecy. But apparently a Crypto engineer discovered the secret conspiracy in 1977, and even fixed vulnerabilities on behalf of the Syrian state – and the CIA was content to leave him alone for the next 40 years? > In 1977, Heinz Wagner, the chief executive at Crypto who knew the true role of the CIA and BND, abruptly fired a wayward engineer after the NSA complained that diplomatic traffic coming out of Syria had suddenly became unreadable. The engineer, Peter Frutiger, had long suspected Crypto was collaborating with German intelligence. He had made multiple trips to Damascus to address complaints about their Crypto products and apparently, without authority from headquarters, had fixed their vulnerabilities. > Frutiger “had figured out the Minerva secret and it was not safe with him,” according to the CIA history. Even so, the agency was livid with Wagner for firing Frutiger rather than finding a way to keep him quiet on the company payroll. Frutiger declined to comment for this story.
- cameldrv 7y agoThis story was originally reported in CovertAction Quarterly 22 years ago: https://covertactionmagazine.com/wp-content/uploads/2020/01/CAQ63-1997-4.pdf https://covertactionmagazine.com/wp-content/uploads/2020/01/... (Page 36)
- istinetz 7y ago... What? This is a well written article covering essentially the same information. This is so confusing, why did nobody react back then? Why did governments continue to buy equipment from Crypto AG? Amazing. The only explanation I can think of is that CovertAction had much worse reputation and could be easily dismissed as conspiracy theory.
- drummer 7y agoThe CIA's current strategy is placing spies in all major tech companies: https://news.yahoo.com/shattered-inside-the-secret-battle-to-save-americas-undercover-spies-in-the-digital-age-100029026.html https://news.yahoo.com/shattered-inside-the-secret-battle-to...
- dropoutcoder 7y agoMy new startup focuses on human nervous system faraday cages embedded into next generation fashion technology. This tech covers your entire body, keeping you safe from remote scans, and includes realistic facial and body disguises. For your safety, our tech constantly scans your thought patterns and memories and keeps them safe with a static filled triple scrambled encryption method, and encodes them into specially placed augmented cellular technology at undisclosed locations in the body. For funding, please visit https://CE.YA/ https://CE.YA/
- AndyMcConachie 7y agoI love it!
- leroy_masochist 7y agoWould be cool if the Agency did relatively more of this kind of thing and relatively less of, for example, paying psychotic Afghan pedophile warlords hundreds of millions of dollars for reneged-upon power sharing agreements and HUMINT of dubious value.
- not2b 7y agoIt has long been known that the NSA had their hooks into Crypto AG; for example, that's how they managed to intercept Libyan communications. What's new is the report that the CIA actually partly owned the company.
- rafaelvasco 7y agoThis is one of the reasons why my tinfoil hat has been shinier than ever;
- edge17 7y agoIt's weird this article talks like this is new information. I guess it's not probably not widely known, but this stuff was discussed in James Bamford's Puzzle Palace, published in the early 1980's (nearly 35 years ago).
- yspeak 7y agoI'm shocked, shocked to find that gambling is going on in here! There's no scandal here. Asking the US to disband spying is like asking the US to disarm. This certainly does give credibility to suspicions regarding Chinese manufactured hardware.
- mpoloton 7y agoThere was a documentary about this company and other surveillance topics aired on Swiss TV in last November. https://www.rts.ch/dossiers/la-suisse-sous-couverture/ https://www.rts.ch/dossiers/la-suisse-sous-couverture/ It's in French and may not be accessible outside Switzerland but I highly recommend it.
- microcolonel 7y agoIs there a list somewhere of companies who are known to have bought and installed Crypto AG devices?
- RachelF 7y agoMakes you wonder about other Swiss based encryption providers like Proton Mail? Proton Mail would be a great honey pot for the CIA.
- NN88 7y agoJohn Schindler (Former NSA) has hinted Signal isn't secure either...
- not_buying_it 7y agoCan anyone here point out an actual case where the NSA was able to break or legitimately hack someone's crypto? I was under the impression that their track record was basically nil on this, and that virtually every instance of them spying on encrypted info boiled down to some sort of inside job that actually resulted in the encryption being weakened or thwarted. People speak about these guys like they have off the charts abilities, yet the available evidence is not so indicative of that. Just looks like a big government operation kinda bumbling along to me.
- glitchdigger 7y agoIf they had that ability they certainly wouldn’t broadcast that capability, but I’ve seen enough crazy shit in the legal 0day market alone to think they have some insane capabilities. However, you’d never know If they could crack RSA/AES, but assuming quantum computing is on its way I’m sure it won’t be long or happened 8 years ago.
- mindfulhack 7y agoThis article has made me decide to never mistake Huawei's ties to Chinese government surveillance for US political nonsense ever again. I may not like our current US president, but it doesn't mean he can't use truths as political instruments. Due to China's and Russia's human rights abuses, they are who I dislike the most. It might be by a small margin, but I would feel more comfortable having the CIA and NSA spy on me any day, than China or Russia. What's wild is that I know many in China would feel the same way - but in the reverse.
- anonu 7y agoAnyone have a link to the leaked doc referenced in the article?
- etiam 7y agoThere may be some new documents available now, but the story as such seems to have been known for a while. I first learned of it last summer while reading some of the drafts for Ross Anderson's update of his excellent Security Engineering. See chapter 26, https://www.cl.cam.ac.uk/~rja14/book.html https://www.cl.cam.ac.uk/~rja14/book.html
- hownottowrite 7y agoI’m surprised no one is talking about all the companies that have In-Q-Tel as an investor.
- Allower 7y agoWar crimes, hang em