UK spies: You know how we said bulk device hacking would be used sparingly?
theregister.co.uk
theregister.co.uk
https://www.theguardian.com/uk-news/2018/sep/21/british-spie...
> UK spies are planning to increase their use of bulk equipment interference, as the range of encrypted hardware and software applications they can't tap into increases.
So past communication methods came with built-in backdoors for UK spies (and, as it turns out, around 32 other EU agencies). These backdoors are becoming useless for them, and so they seek to force everyone else into providing backdoors for them again.
This shift was predicted long in advance and is clearly a response to the increasingly saturation-level usage of SSL. GCHQ and NSA have for decades been oriented primarily around bulk interception of unencrypted radio and fibre traffic, see:
http://www.lamont.me.uk/capenhurst/original.html
But what happens when nearly all traffic becomes encrypted? Then they must become ever more reliant on hacking the endpoints, to get at data before the encryption is applied.
What's happening is easily explainable without needing to refer to apparently non-existent back doors. The closest thing to that was the EC-DRB algorithm, but nobody ever used that except RSA Inc who got paid to use it, because their back doored algorithm sucked and the back door was spotted very quickly. I doubt it ever had much operational impact.
I think GCHQ's intercept capabilities are pretty well documented in the ANT catalog:
https://en.wikipedia.org/wiki/NSA_ANT_catalog
I know for a fact that GCHQ are customers of JUNIORMINT.
(Check for fingerprints and other sloppy cleaning on the wrappers of those "brand new laptops", folks.. the ones that spent a couple of days in limbo at a 'shipping hub' somewhere around Heathrow/Stanstead, etc.)
This is the issue with the duplicity inherent in the 5-eyes agreement - what we think only 'the other guys' can do, our guys can do when they work with the 'other guys'.
Or you know, they just use gloves because they work for a signals intelligence agency installing implants for a living.
D'uh .. Its the first option. We didn't think about it much, ordered the keyboard config we wanted, thought about the interception/implant issue, paid close attention to the wrapping upon receipt of the laptop, decided that we'd probably been intercepted along the way somewhere ..
If the intelligence agencies are really spending time and resources on such ludicrously inefficient and ineffective techniques as installing backdoors on random laptops in warehouses, you should be glad!
https://www.standard.co.uk/news/london/police-foil-seven-ter...
In short, given the current state of media and government, it wouldn't surprise me if this were just propaganda.
The flip side of your view is that there are absolutely cases that are real, which don't even make it to the press at all. I was an expert witness for a terrorism case in the UK - the guy was convicted - and nothing about it ever surfaced in the media.
The reality is that there are a stream of people in the UK who try to carry out terrorist attacks, and who are stopped by the police. Attempting to argue against a bad policy by claiming terrorists are establishment propaganda is likely to be a bad strategy as a result.
A much better approach is to ask how many of these terrorists are really using sophisticated cryptography, and how many successful attacks would have been stopped if not for encryption? And there we find the answer is "not many" and "essentially none".
There is a great article on that very topic, written by a British journalist who also has acted as an expert witness in many terrorism trials:
http://privacy-pc.com/articles/how-terrorists-encrypt-threat...
It looks at many cases of busted terrorist attacks over many years, and examines the involvement of cryptography. The conclusion is that the intersection of terrorists and sophisticated users of encryption is the empty set. The closest you get is a groupie who worked on things like propaganda and funding, but who wasn't involved in any attacks themselves.
Now that article was written quite a few years ago and I suspect the new attitude of companies like Facebook towards encryption has changed the game somewhat, WhatsApp end to end encryption (assuming it's really on for everyone) makes it much easier to protect conversations than before so, it would stand to reason that cryptography does foil terrorism investigations more often than it used to. However, we don't know that, and the IC was yelling about the danger of cryptography for decades already - certainly in the time frame that Duncan Campbell's analysis was written in.
In conclusion, I'd focus more on whether real terrorist plots are happening successfully because GCHQ couldn't hack things fast enough, than on whether terrorists exist at all.
https://ctc.usma.edu/how-terrorists-use-encryption/
I would be very surprised indeed if the intersection of front-line terrorists and users of industrial encryption was an empty set.
I think it's more likely the intersection of caught and prosecuted terrorists and users of industrial encryption is an empty set - or at least a much smaller set than those who use FB Messenger to coordinate attacks.
This is not an argument for backdoors. I suspect the real inefficiencies in monitoring don't come from lack of evidence, but from lack of efficient data processing and flagging.
In particular your paper discusses the "Tadpole" program developed by Rajib Karim to communicate with Al-Awlaki, albeit it doesn't refer to it by that name. It's interesting to see how there are different spins on the same event.
http://privacy-pc.com/articles/how-terrorists-encrypt-7-pecu...
Both papers point out that: Police described his use of encryption as “the most sophisticated they had seen in a British terrorist case.”
In the talk by Campbell, Tadpole is described as amateur hour. It's literally a Caeser cipher implemented using Microsoft Excel, with the results copied into password protected Word documents. Campbell observes that even a very rudimentary intelligence agency would be easily able to break this code without access to any of the underlying materials ... in fact, the technique for breaking such a cipher was first described by an Arabic mathematician over a millenium ago. This was used in preference to the "Asrar" PGP GUI that was circulating amongst jihadis, because it wasn't clear to Karim that Asrar was really trustworthy. Was it an NSA plant? This problem crops up all the time with jihadis trying to use strong encryption: they can't implement it themselves, they don't trust western apps and struggle to verify the origins of programs claiming to be written by fellow jihadis.
Overall Campbell treats Tadpole as a joke: a textbook study in why terrorists+encryption are not anything worth worrying about.
In the West Point paper you link to, the same program is described in quite different terms. It's described as an "intricate system", an "unorthodox and complex technique based on cipher codes and passwords stored on Excel spreadsheets" that produced "end to end encryption". It says "Western intelligence agencies were not able, as far as is known, to intercept any of his communications in real time". The West Point author appears to be under the impression that the only mistake Karim made was not wiping his laptop in time, which allowed police to access the underlying spreadsheets he was using.
This is a fascinating study in how the capabilities of terrorists are sometimes exaggerated to build the case for all-backdoors-all-the-time. Tadpole wouldn't have stopped a clever teenager with access to some intercepts, let alone an intelligence agency as sophisticated as GCHQ. Yet it is being used as evidence of fundamental shifts that require deep social and policy changes.
Westpoint paper in this case appears to be clearly hiding an agenda. Don't courts have some sort of checks and balance to minimise this type of influence from expert witnesses?
Can you give us a rough idea why that trial was keept a secret from the public?
The police wanted it kept quiet for the usual reasons. There's some amount of luck involved in foiling any crime, especially before it happens, and when the details of a trial are broadcast it necessarily implies teaching future criminals how their predecessors were caught. The police don't like that, it just makes their jobs harder.
PsychOps 101.
the little microcosm that is HN is just fun to watch with stories replete with people demanding intervention standing side by side with stories claiming over reach. I am not sure you can have your cake and eat it to.
[1] https://www.nbcnews.com/news/world/nsa-program-stopped-no-te...
And I bet they could foil even more crimes if everyone had to wear an ankle monitor. Does that make it a good idea?
If I seem aggressive, it's not intentional - your post only highlighted relevant data, which is always commendable.
In 2017, Prime Minister Malcolm Turnbull said, "The laws of mathematics are very commendable, but the only law that applies in Australia is the law of Australia".
The unprecedented and abysmal Assistance and Access Bill was just rushed through, against the advice of all legal and technology experts.
Any individual employee of a company can be compelled to install malware on their systems under threat of 10yrs jail and 50k, and they're not even allowed to inform their employer!
There is no judicial oversight and the one who determines if the spying is proportionate is the agency requesting the data, which is even State Police.
Under five eyes, that will be used to spy on UK, US, etc citizens and the information will be shared back. It enables the US/UK government to spy on their own citizens in ways that are illegal in their own countries.
Every Australian citizen has just become an unpaid black hat hacker/spy for the Australian government.
Have no doubt, this is coming to a nation near you.
They exist to protect and maintain the status quo for those that benefit from it.
That's the theory. In practice, of course, the truth has been weighted more to one side or the other at different times and in different places.
But there will always be sociopaths who would rather be dictator or a pathetic state of starving and poor people rather than president of a prosperous.
https://assets.publishing.service.gov.uk/government/uploads/...
(PDF)
Either you have them flopped yourself, or leave it to the enemy.
But in any way, the West has more urgent issues than Chinese popping their routers, namely the issue of their own spy agencies running rampant.
But there are exceptions. China has gone after supporters of the Dalai Lama globally. Dropping malware, backdooring servers, etc. But yes, they can't arrest you.
The US, on the other hand, has more "friends". Consider The Pirate Bay. Even Russia has turned over "cybercriminals".
Meanwhile international diplomacy's track record is clear.
I'd rather expect that the access vectors get noticed and applied by criminals en masse.
Every networked product should come with a legally binding A4/letter-sized sheet that clearly shows the last date the product is guaranteed to receive security patches. Not fulfilling the requirements would have to result in a buyback with the sum directly proportional to whatever time of the promised lifetime is left unused.
EU countries already have rather strict consumer protection laws but they really haven't been designed for situations where a hardware product can be rendered unusable by insecure software.
That is definitely covered by the standard 2 year warranty as insecurity (when security is expected) is seen as defect. If they don't fix it you get your money back. I successfully got my money back for several phones after 1 to 1.5 years.
We can’t win the ok battle any more as no one up top gives a shit clearly.
We're going full speed into totality. It was absolutely the same when the communist regime started in my home country: People were saying they would not use their new powers against ordinary people and that seizing all farmland would be impractical and then after few years of silence KGB and gulags and executions happened (our local alternatives of course).
After paying £27k+ in tuition fees grad priority is earning so the government chased them off too.
I'm not for a moment suggesting this is right for ref. Individual merit is much more important.
That's the reason to battle, not the reason you lost before you even did that.
The threat is in not dealing with politics before it deals with you, and a good way to do that is seeing "the government" of a democratic nation as something totally separate from a citizen in that nation... instead of getting engaged because it's so messed up, to disengage further because it's so messed up.
even in the first episode of cryptolog (nsa) they state that collectors 'might chose or not chose what rules to adhere to to complete their collection job'. so theres rules not to do things and people with choices (like everywhere in life) and these choices aren't aligning to these rules. like always, a channel for plausible deniability and if the shit hits the fan a scapegoat is chosen to mitigate any damages if public eye caught something suspicious. plain and simple how the intelligence agencies work in whatever context.