Uncovering the CIA's Crypto AG operation
npr.org
npr.org
Sounds like a great employer. Knowingly sells backdoored equipment to foreign governments, allows their employees to be arrested and held for nine months even though they know nothing about it, pays the bail, then immediately fires them and tries to recoup the bail.
- UK government secretly changes its own rules on arms to Iraq
- encourages a company to ship such weapons to Iraq
- they get caught by UK Customs
- this gets all the way to the trial and potential jailing of the directors
- UK government (in particular, Kenneth Clarke) directs suppression of vital evidence through "Public Interest Immunity Certificates"
- Judge refuses to go along with the coverup and jail innocent people, and the whole thing blows up in the newspapers.
https://www.independent.co.uk/news/uk/scott-report-the-essen...
The employer was US Intelligence anencies. That is how they operate. The ends justifies the means. Collateral damage, be it physical, emotional, personal or professional is seen as part of the role.
I'm not saying I agree. But it's important to point out how skewed (usually mistakenly) most ppl's perception is of those three-letter outfits.
https://en.m.wikipedia.org/wiki/Crypto_AG
And there were many suspicions going even back to a “tell all” by Ronald Reagan
https://news.ycombinator.com/item?id=18693073
I've often thought an interesting place for an intelligence agency to place or recruit a source would be in a code review organisation. There are a couple of high profile ones that do a lot of work on open source projects. Let's be honest, very few people have the time, energy and skills to review a project independently of this.
Of course there comes a point where too much tinfoil makes the hat fall off.
It also makes sense why the US is banning Huawei equipment. If the US can do it, why can't the Chinese?
You can't trust the network. Rather than trying to avoid Huawei, energy should be spent engineering things so Huawei equipment doesn't need to be trusted. Until then, China and everybody will continue to be able to snoop, regardless of who built the network components.
There's also the drama last year where US claimed Huawei technicians was helping Uganda and Zambia spy on political opponents. Political opponents being Washington friendly anti-establishment candidates, and helping being acceding to request for lawful interception duties as vendor. To be fair the technicians also helped used Israeli spyware to extract Whatsapp data. The TL;DR of the entire debacle being Chinese hardware actively undermines US foreign influence operations abroad.
*I surmise the reason US is having so much trouble producing convincing evidence of Huawei malfeasance is that China actually haven't exploited Huawei hardware because they don't want to risk damaging the brand's reputation. That's not to say China doesn't spy, of course they do. They just have the capability to do so without going through Huawei.
Which leaves three explainations:
1. The chinese are so good the 5 eyes can't proof it
2. The 5 eyes can proof it but don't dare to for certain reasons (which wont stop independend researchers)
3. It doesn't actually happen (yet)
Meanwhile we've got tons of actual backdoors from the US side.
The U.S. government could divulge credible information about a particular Huawei attack, especially if it were as pervasive as they seem to claim. I can think of many reasons why they wouldn't do this (e.g. exploits make more than just Huawei look bad, such as other American suppliers), but few that bolster their case against Huawei as a distinct threat to telecommunications security.
Rather, it seems their beef with Huawei is two-fold: 1) generalized national security interest in preventing China from dominating the telecommunications market (i.e. concern over relative tactical and strategic positions of China and U.S. SIGINT capabilities), and 2) protecting the profit margins of Qualcomm and other American suppliers.
I wish this "useful idiot" chatter would stop.
Their founder is former Chinese army.
There is a Defcon talk on how bad their security is on medium-sized devices.
With that as a starting point, why would you ever trust Huawei?
Also lots of devices with bad security and spaghetti code. Huawei is probably the most scrutinized vendor in the last decade, national and private investigators from a host of countries found nothing to suggest links to Chinese espionage. Hundreds of mobile operators with years of experience found nothing. NSA with access to Huawei internal networks found nothing. GCHQ with Huawei code to audit found nothing. The only people who claim to have evidence but steadfastly refuse to release any until recently is current US administration with Mike Pompeo leading the charge. Which turned out to be non specific claims about legally mandated lawful interception function, aka Vodaphone SSH tier of vapidness. Unsurprisingly, this has convinced no new countries, and the countries have firm banned Huawei all have exeptional dependence on US security and intelligence sharing. With all that as the starting point, why would you ever trust allegations?
Even straight from this article:
>So one other - there was another Swiss company at the time - Gretag is what it was called - that was trying to become a rival to Crypto. And the CIA and U.S. intelligence helped to sort of orchestrate smear campaigns around the world to spread disinformation that Gretag's devices couldn't be trusted; there were vulnerabilities in them.
The playbook hasn't changed. Neither have the interests. There's nothing wrong with US intelligence pursing self interest based purely on the fact that Chinese are security competitors despite complete lack of evidence. But the only useful idiots are people who believe the US smear campaign around Huawei blindly.
And like 70% of all Silicon Valley big firms have been founded with direct help from In-Q-Tel....
Why would you ever trust any US corporations?
Snowden, Intel Management Engine etc.
(Corporate) backdoors everywhere...
I think RISC-V, open hardware and OSS has to be the future.
>Malcolm Turnbull has warned Boris Johnson that allowing Chinese company Huawei to build Britain's 5G network would compromise the ability of the Five Eyes countries to collect and share intelligence.
>Mr Turnbull said the main risk the Australian security agencies had identified was not through potential Chinese interception of intelligence but by denial of access to the network.
If you follow the story closely, the intelligence community began to intervene loudly once US escalated to severing intelligence sharing if countries didn't ban all Huawei gear. To the point where you have UK firing defense minister over Huawei leak. Which is understandable, FVEY domestic security is built around hacking each other's citizens to get around domestic legislation and only NSA has access to western tech giants.
For the lazy, a 3G tower dev kit from Range Networks is $8,000 [1].
I've never done it, but I suppose you could use 2 SDRs. One for setting up OpenBTS, one for jamming 4G/LTE.
Fake base station attacks do not work with 4G/5G, but a downgrade attack to 2G might still be possible.
Did this make the news? I've never heard of it.
https://www.politico.com/story/2019/09/12/israel-white-house...
(and the government response)
https://www.cbsnews.com/news/white-house-spying-israel-pm-be...
So one can assume that major governments are operating their own stingers in DC.
Yes, Israel usually gets a pass on espionage, and Russian election interference is a years-long story. But in any particular incident it's hard to tell whether the public is disinterested in the incident or disinterested in the adversary. Plus, to be fair, reports of actual Russian incidents are fairly common. I mean, they've literally built a niche industry for social media hacking. Reporting on it is easy; you don't need to wait for intelligence leaks. And they publicly gloat about their strategy and tactics. By contrast, Israel is usually far more discrete[1] and publicly identified incidents are few and far between.
[1] Operationally and politically. They certainly don't gloat. They stick to a very strict recitation: "Israel does not spy against the United States."
This might well be a plausible reason why this old story resurfaced recently.
Snowden used an open source implementation of PGP based on his knowledge of the NSA's capabilities at the time. He did not go shopping at the crypto store.
something like: https://www.itworld.com/article/2922074/significant-virtual-...
Seems like creating a foundational open source project and introducing a few key bugs would be the best way to hide in the open.
I've seen questions raised here on HN about Signal and Tor: where they came from, and where their funding comes from. If I had to bet, then I'd bet both of those are modern day Crypto AG variants.
Turnkey black box solutions may be reviewed more regularly by a dedicated team but you have to admit that they're subject to flimsy and easy manipulation by state actors and the greed and coruptability of their owners.
I think the Crypto AG story is sufficient proof of itself to look with suspicion at all related open source projects. In situations where there are known bad actors and we are dependent on security, we should look with suspicion unless we know better. "Insecure until proven secure" is probably a good motto.
So just always insecure, as no amount of testing can guarantee there isn't some heartbleed like bug in there still.
The community has been aware of this for a very long time. Many eyes still provides better security than few eyes, which is why singling out free software as your concern seems misplaced.
>f I had to bet, then I'd bet both of those are modern day Crypto AG variants.
Though it's possible Signal is compromised, it's basically known that the proprietary offshoot WhatsApp is compromised. Free software is still your best bet, likely even better than doing it yourself for 99.9% of the world
By from scratch, I mean building a CPU from transistors and writing (or at least carefully auditing) all the code on it.
People have done comparable projects (like a clone of the Apollo 11 guidance computer) as a labor of love.
If you can audit completely enough to not leave anything then the question becomes why not audit the commodity? Lack of availability of auditable components or proportionate costs of doing so is the main answer I can think of.
What I'd still like to see is... how did this influence domestic crypto policy and export controls? It seems entirely too coincidental that right after the cat is fully out of the bag with the Iran thing, the US is suddenly easing export restrictions on crypto, trying to shove Clipper / Key Escrow down our throats, coming for Zimmerman, etc.
https://arstechnica.com/information-technology/2020/03/5-yea...
https://www.swissinfo.ch/eng/crypto-leaks_swiss-authorities-...
I’m aware of another(potentially) where an employee credibly alleged it.
From the perspective of a national intelligence service, it is likely a far better return on investment to proactively catalogue compromised communications at root, rather than intercept and brute force it later.
Protonmail uses JavaScript, which can theoretically be serving nonsense to a specific client. There's no way you will audit the source every time you use it. I use it, for larping, and because I like the though that there is still some competition in the e-mail landscape.
Tor is a completely different league... but I don't consider the actions I (might) perform there to be confidential for the rest of my life, so I act accordingly. YMMV.
But a good point, for Tor hosts.
― Aleksandr Solzhenitsyn
In the digital age, information is everything. And information usually precedes action, so in my eyes your argument is wilfully ignorant to the larger reality of a complex globalized world.
I think the US and other Global North countries have a massive shadow: https://www.youtube.com/watch?v=j800SVeiS5I
If unfamiliar, this is a guide to Jung's concept of the shadow: https://highexistence.com/carl-jung-shadow-guide-unconscious...
I wrote this before and then edited, without realizing that now my main argument has become for the opposite of what I intended it to be for. Now I can't edit it. Original post:
"Wow very selective mind you've got there. Please tell me this is a joke?
In the digital age, information is everything. And information usually precedes action, so in my eyes your argument is wilfully ignorant to the larger reality of a complex globalized world.
I think the US and other Global North countries have a massive shadow: https://www.youtube.com/watch?v=j800SVeiS5I
Guide to Jung and the shadow: https://highexistence.com/carl-jung-shadow-guide-unconscious...
The secret is that information doesn't matter to the evil fools, it is all a pretext for self justification whether consciously or otherwise. In order for the delusional evil to die and stay dead the secret must be widely exposed.
Donald Trump: “I think Snowden is a terrible threat, I think he’s a terrible traitor, and you know what we used to do in the good old days when we were a strong country — you know what we used to do to traitors, right?” Trump
Eric Bolling (Fox and Friends): “Well, you killed them, Donald,”
Donald Trump: “Well, he is damaging America.”