Police raids across Europe after encrypted phone network shut down
theguardian.com
theguardian.com
It reads like it's written by someone who skimmed three other news articles without really comprehending what's going on, then wrote whatever.
Police never "shut down" Sky ECC, especially not prior to the raid.
https://www.politico.eu/article/cryptophone-firm-dismisses-b...
Sky ECC denies the breach (see also [0]):
> "a fake phishing application falsely branded as Sky ECC was illegally created, modified and side-loaded onto unsecure devices"
The belgian police claims:
> Sky ECC's claims were "bullshit."
> So confident were the police that they broke Sky ECC's code, they said they sent the firm their bank account details to claim a $5 million (€4.2 million) bug bounty Sky ECC promised to pay out to security researchers that had managed it.
Quite ballsy.
> “The work is only starting,” a spokesperson for the Belgian judicial police had said Tuesday, adding that many more investigations were likely to follow as the decrypted messages yielded more leads.
I don't see why they'd give those criminals this notice to prepare. I'd assume a bunch of surprise house-visits would be more effective, if they have all this info.
The story smells somewhat fishy from both ends. Good drama though. If they really breached Sky ECC's security, they should be able to prove this by solving a cryptographic challenge by them.
[0] https://www.skyecc.com/sky-ecc-platform-remains-secure-and-n...
The Galaxy brain move is maybe to realize that this news will cause the crims to move to a new network, and to have one waiting for them.
E:sp
> I don't see why they'd give those criminals this notice to prepare. I'd assume a bunch of surprise house-visits would be more effective, if they have all this info.
This actually happened ([1]). In 1 huge operation, 1600 agents performed 200 house searches. This resulted in 48 arrests.
[0] https://www.vrt.be/vrtnws/nl/dossiers/2021/03/politieoperati... [1] https://www.vrt.be/vrtnws/nl/2021/03/09/huiszoekingen-200-15...
The defenses in both cases can be quite different. For some people, a cheap Chromebook that you can wipe quickly plus 2FA gives great security, or using a modern (encrypted) phone with Signal. But what if you are, say, protesting against the construction of a new Google campus on top of your neighborhood? Then you'd don't want all your secret stuff on their infrastructure. Normally you assume everybody is playing fair, but it would be so easy for them to push out a malicious update to your phone to gather dirt on you.
If one has experience with AOSP and security, there seems to be a market for an open, secure phone. But I wonder how you'd keep the organized crime out, or at least keep plausible deniability to not get into trouble...
If someone wanted to make a modem with no binary blobs we could have fully Open hardware in toto.
There's the opportunity to make Linux programs scalable to small screens right now; that's a big part of the dev time currently.
It's like building a private house with barbed wire, armed guards, ... people will wonder what's going on inside.
Today, the only way to make it as a criminal in the West is to fly under the radar.
Stuff like "the Amazon of drugs", or "the WhatsApp for criminals" will always be taken down.
If you want secure hardware, it's basically impossible. All cellular modems are backdoored: https://www.gnu.org/proprietary/malware-mobiles.en.html
If you want a Signal-like app that doesn't need a phone number you can use www.groupsapp.online
E2EE is implemented with RSA+AES. iOS uses keychain and CommonCrypto. Android uses a modified BouncyCastles. I'll probably open source the code once I've figured out the licensing details
Because anyone who can do that wouldn't waste their lives workin for criminals when they can make safe money legally.
The skills required to set up a secure communications network aren't that valued (as in it won't make you a millionaire) in the legal world, and even less so in Europe where IT salaries are absolutely terrible.
Look I know because I've been between those two worlds. When I was around criminals I had the option of working for them for money and would probably make more than I do today because it would be tax free. But it wouldn't be millions because I'd be in the background helping out with IT infra and policy. So if you're smart you take less money to be left as far outside as possible.
The problem is that it's not possible to be outside of that world. You will be taken advantage of. You will be a golden goose that everyone wants a part of just because you can manage their IT securely.
So I was smart and got a safe IT job where I make enough to live very comfortably, work where I want, practically when I want and with people who are not openly sociopaths.
I know as well because when starting my career I had to make a choice - if it wasn't for a stroke of luck I may have had to pick the wrong path out of desperation (whether I would've made it anywhere is another question - sounds like you looked into it farther than I did).
Thankfully everything worked out and I haven't needed to be on the wrong side of the law, but this was down to luck - you can very well have the skills that would pay well in the criminal world while being stuck in a situation where you can't get much out of those skills in the legal world, so I disagree with the idea that having those skills automatically gives you the option to make a good living legally.
Not only EU perspective but Swedish one too where it's very difficult to launder cash.
So it's just not a smart decision to get in bed with crazy criminals. It was a decision I pondered as a young and short sighted 20 year old.
In retrospect it's much easier to make a comfortable living as a simple SRE, Sysadmin or Devops consultant. What ever basic knowledge you must have to setup a proper PKI is enough skill to become at least one of those professions.
Sky ECC wipes messages after 30 seconds, meaning a seized phone is of limited value to investigators.
I don't know about Sky ECC, but Signal requires a Phone # to register, as far as I remember. It's increasingly hard to get anonymous Phone # in the EU. That might be an argument against using it.
They will not always be shown, but they are downloaded.
I'd also wonder if there's an element of buying access. If all the top people in some criminal industry use it, it may be a way to signal membership.
[0] not that there haven't been numerous whatsapp zerodays and expecting the Signal honeymoon to last makes about as much sense as "there's no Linux/Mac malware"
This was largely how the Mob operated for decades and why RICO was created.
Communications security against national state level organisations in the current environment is a no-win situation for the defending side, you can make their life more difficult but for you to go truly dark means using nothing that shuffles electrons around.
I'd also question how many highly hierarchical criminal organizations exist today and how many have in the recent past. Media and governments love to overemphasize the organized element for simplicity. Likewise many "terrorist organizations" aren't organized either. In practice you mostly see very lose networks that operate a lot like the rest of the economy. There may be some emergent structure but it's usually not deliberate.
> If you where a really high level criminal you wouldn't use a phone at all, you'd pass all your instructions in person to lieutenants who'd pass them on down the chain.
> This was largely how the Mob operated for decades and why RICO was created.
That would be a legal strategy not a communications security one. It may have been more feasible to proxy away legal responsibility before RICO and such.
Yeah, because they want the world to know they are successful criminals. Just wondering: do they also wear a Beagle Boys mask?
There was a case where a company was selling a "PGP phone" where it turned out that, to save having to bother the customer with key generation on the phone, they were doing it on the servers[1]. So the police grabbed the servers with all the private keys and there were a lot of sad customers.
To do end to end encryption in a way that works, there is a minimum level of understanding required. These "secure" phones are really a type of scam that preys on the not sufficiently informed.
Note that Signal on a smart phone is not anywhere near the most secure way to communicate over the internet. Smart phones themselves are not particularly secure and are vulnerable any time they are unlocked. Instant messaging is inherently insecure because it is always on and thus makes it impossible to keep the secret key information locked up securely when the user is not in a safe environment.
[1] https://securityaffairs.co/wordpress/57036/cyber-crime/black...
Also I was just wondering, albeit maybe ridiculous, if criminals have the same issues with messenger apps as the rest of us, in so far that you are kinda forced to use whichever app is the most popular. I reckon there is not much criming to be done, if everyone in your gangster-circle is using a different app.
I don't think criminals lower down the hierarchies have or have access to much security knowledge, so they might just pick the currently most popular or use multiple apps depending who they talk to.
National security letters are still very much a thing there. Signal has fought at least one and won (https://signal.org/bigbrother/) we can only know about ones they've won against.
Plus say you use Signal, how are you connecting? If that's through an app store then your binary has been replaced. A similar thing happened with Hushmail and their 'client side pgp' jar file: https://archive.is/IRYoh.
Then you have to consider the sealed-sender stuff, and other metadata. If your crime group isn't specializing in tech crime in general then outsourcing to a third-party (that could use the Signal code internally) probably makes more sense then trying to figure this stuff out yourself.
Maybe I've been watching too much TV, but would it be better to pay some random person to go into a store and buy my sim/chromebook/phone in cash and then bring it to me at a location I know does not have video surveillance?
After Encrochat[1], Criminals in Netherland/France/Belgium are really the dumbest around. I mean, good for us ? Fool me once, shame on me, fool me twice...
or maybe the reason is because there is a large platform of drug traffic in those areas compared to others..
These smartphone apps have spent orders of magnitude less time under attack, are often closed source, often integrate OS vendor and carrier value add in ways that make them weak, and their centralized and closed nature makes forcing both en mass and targeted key exfiltration updates on users trivial.
There are zero secure messaging smartphone apps and there never will be unless smartphones substantially change.
Agreed - if you really wanted to make a (more) secure messaging device then you wouldn't base it on a phone to start with.