Swiss government files criminal complaint over Crypto AG scandal involving CIA
intelnews.org
intelnews.org
This should be embarrassing for the Swiss intelligence services whose job it was to detect and prevent these sorts of shenanigans...
Also, have I misunderstood? The criminal case should be against the company executives surely, not "persons unknown". Or is that just to include whoever bribed them?
Some alledge that the NDB/FIS (Federal Intelligence Service) knew about the operation. [1]
> The criminal case should be against the company executives surely, not "persons unknown".
At this point, it is not known who was involved in what way exactly. Some executives? Definitely. All executives? Maybe not.
A former employee believes that only 2-3 executives knew about the whole scheme and maybe 10-15 technicians put two and two together or suspected something. [2]
[1] https://www.srf.ch/news/schweiz/geheimdienstaffaere-cryptole... (german)
[2] https://www.srf.ch/news/schweiz/17-jahre-bei-der-crypto-ag-e... (german)
I don't know about Switzerland, but in some European countries this enables a judge to be designated to carry out a formal investigation and to then decide who to specifically go after. In addition, filing a complaint against a specific person opens you to be sued back if that person is then shown to have done nothing wrong. This means that it is very common for criminal complaints to be initially filed against "persons unknown".
(I am just looking into certificate pinning, but CA can generate another certificate or wildcarded certificate that client trusts, which enables mitm, I am doing it all the time on https proxy (http://www.squid-cache.org/Doc/config/ssl_bump/). This way you can decrypt traffic - redirect traffic to your server and impersonate the right one while proxying data from original server)
I wonder what percentage of internet connections hops through a cisco device at some point...?
In addition to this you have Certification Authority Authorization (CAA) which uses DNS to tell what CAs are allowed to sign certificates for a certain domain.
There are services you can subscribe to that will tell you when a certificate signed by a (or anyone but) CA for a domain you want to monitor.
Overall I would argue that companies that are dealing with sensitive data should be using EV certs anyway to help users defend against phishing attacks which Let's Encrypt doesn't offer to my knowledge. This is tangential to your point though.
Especially since the 5G situation even kinda smells the same:
https://www.washingtonpost.com/graphics/2020/world/national-...:
> As Widman settled in, the secret partners adopted a set of principles for [Crypto AG's] rigged algorithms, according to the BND history. They had to be “undetectable by usual statistical tests” and, if discovered, be “easily masked as implementation or human errors.”
> In other words, when cornered, Crypto executives would blame sloppy employees or clueless users.
https://www.theregister.co.uk/2019/03/28/hcsec_huawei_oversi...:
> Huawei savaged by Brit code review board over pisspoor dev practices
> "The work of HCSEC [Huawei Cyber Security Evaluation Centre]… reveals serious and systematic defects in Huawei's software engineering and cyber security competence," said the HCSEC oversight board in its annual report, published this morning.
The assumption that you can trust communications infrastructure is outdated. It must not matter if an adversary has back doored a router or cell tower or similar to send copies of all traffic to them, since the data should be entirely encrypted (except for some minimal routing information). The 3GPP designed the 5G standards to allow back doors, so we get back doors.
It's like checksums, really ;) Point-to-point is helpful, but not sufficient.
Small countries can never threaten a big state realistically, however they have the ability to harrass people who work for these big states in the hope of discouraging future action
If I was responsible for selling rigged encryption equipment, I'd be wary that this might backfire on me - even in a decade or two.
there is a good chance the Swiss intelligent apparatus knew what was going on so if this complaint vanishes or settles quietly we will know what is up
When swiss newspapers reported on it in 1994, the cold war was still present in the minds of my fellow citizens and the US was seen as an ally and friend, so the general public probably just didn't consider it to be that important if the CIA maybe bugged some conversations. Also, the swiss government "preferred not to know anything" and obstructed investigations, despite some employees of Crypto AG coming forward with information to the federal police.
The world (or rather our view of it) is quite different today. Hidden data collection is a popular topic and it's harder to pretend that there are only friends in the west and only enemies in the east. It's also easier to share information worldwide and media coverage was much larger this time.
Here German intelligence and US intelligence owned a Swedish entity. Thats how free trade works.
It was trending on Instagram and MTV/TLC?
Switzerland?
If so, what do they hope to gain from it?
Maybe they should have used the money to develop 5G instead, lol.
> Switzerland’s Prime Minister, Simonetta Sommaruga
For a supposed website about intelligence, strange of them to use the phrase "Prime Minister" to describe the President of Switzerland (who actually is just a figurehead with the same power as the other members of the 7-member Federal Council).
Don't let me stop you thinking that but I'll keep running faster, thanks.
I'm not sure what point you're trying to make here.
I'm not seeing that quote used, but mistaking "prime minister" and "president" is an understandable mistake.
Making that mistake for a layperson is understandable sure, but a website about intel, you have to lol. Probably why they fixed it up so quickly.
The website is run by laypersons who actively deal in covering the president or prime minister of hundreds of countries. Covering intel doesn't really prevent this mistake.
Also, at the very top of their website it says "a specialized intelligence website written by experts", and in the sidebar they list their qualifications - so they apparently want to claim they are not laypersons. Lol, but you are trying to claim it?
Granted it's pretty subjective, so whatever. I don't think my standards for this topic are much different from other people's standards for other topics with similar shapes.
Sports commentators make mistakes on a regular basis, things like calling a defender a forward or mistaking a players name. They often correct themselves immediately or things move past it so quick nobody cares.
> - so they apparently want to claim they are not layperson
I took your use of the word "layperson" there to mean "not a professional in a field specialized in state politics." The authors of the site are professionals, just that doesn't prevent that mistake. Worded by me, but my point was that they are still normal error prone humans.