I wonder if the press knows what it's talking about.
I wonder if the press knows what it's talking about.
Fun, unrelated story: apparently some of the intelligence operations managed to get their hands on the laptop of a target while it was at some maintenance store to get the screen replaced. They managed to install a physical keylogger inside it with its own radio, but hooked up to the laptops power supply. This is the kind of shenanigans you have to be aware of and defend against when you run a service like Sky ECC. The slightest slip up and you are doomed.
But is it me or police techniques such as gaining physical access to criminals, flipping them to informers, close surveillance, etc. continue to be very efficient even in the face of quite good technology ?
Not open source: check
Not federated (so they can force you to update the client): check
Integrates with carrier value add: check (SIM crap)
Integrates with OS vendor value add: check
Flashy website with third party requests to google.com: check
Yeah this looks like crap to me.
Does not federated mean not using a jailbroken phone?
Or is it related to how the app is installed?
Or the underlying infrastructure relying on a central server instead of distributed?
This could still happen with any one or two or multiple federated apps, but the changes at a lot less likely this would go undetected.... then again... I have less faith in the “many eyes” theory of these things since HeartBleed was an OpenSSL flaw for years and that was open source no one ever noticed.
Encryption is really hard, and one mistake can unravel all of your efforts. I doubt that a boutique shop like Sky ECC's owners had the resources to secure it as well as they claimed.
Also encryption is as good as its weakest link, in this case are humans. Probably police flipped some criminals to be informers and now it's running a smoke&mirrors campaign in media in order to send rest of criminals to make more mistakes.
As for the ideal way to do organized crime the main ingredient is to own judges + police and you're set for life. From time to time let some minor transport get intercepted by your corrupt policemen, have some small fish get fried by your judge and stir waters for a few days in media in their favor. Maybe this news is exactly that and while the newspapers are reporting few millions captured you haul the rest of billions without a hiccup.
"Sky ECC platform remains secure and our authorized devices have not been hacked.
There have been recent news articles that claim Sky ECC has been hacked and is involved in criminal activity. This information is not accurate. We have looked into these claims and discovered that a small group of individuals illegally created and distributed an unauthorized version of Sky ECC which they modified and side-loaded onto unsecure devices. Security features that come standard with the Sky ECC phones were eliminated in these bogus devices. ..." [0]
Pretty much every company responds to this kind of stuff with "nothing to see here, move along"
Sowing confusion with bold claims of compromise will lead criminals to not believe encrypted platforms are not secure and not use them, instead using easier to intercept methods of communication.
But those bold claims of compromise are backed up by a large, international, and simultaneously-executed roundup of the service's users, who from the likes of it all had Sky ECC in common. Also, the last time this happened was when Encrochat was compromised? That wasn't even all that long ago.
Have you read those bizarre fake facts like "it is illegal to eat oranges in your bathtub in California" ? If you haven't, I am sure you have broken myriad weird laws like that and are, in fact, a criminal ! :-).
Not sure why they said they cracked this app, because now they lost a source of intelligence.