You're only anonymous as long as you're not actively targetted, despite using "secure" apps and stuff like Tor, which media makes it seem are unbreakable.
You're only anonymous as long as you're not actively targetted, despite using "secure" apps and stuff like Tor, which media makes it seem are unbreakable.
[0]https://webcache.googleusercontent.com/search?q=cache:PwQXt6...
[0] https://en.wikipedia.org/wiki/Parallel_construction?wprov=sf...
That is because the usability of PGP is so bad, they wouldn't have any time to actually operate their criminal enterprise.
Also - email, PGP or not, leaks metadata, and the police will happily end your whole criminal career based on metadata.
None of these were exploited to retrieve this data, and the third party app that was installed was not intended to encrypt conversations given that it was a honeypot.
> popular apps
This was a small app unknown by anyone outside of criminal orgs. It had no "legitimate" non-criminal users.
> especially in the US
The app was deployed in Australia.
> can always be commandeered
Why distribute a random app when they could have gotten the criminals to use Signal or Telegram and bust them there?
> as long as you're not actively targeted
How long did it take to find Bin Laden?
> despite using "secure" apps
This was not a secure app and any audit would have revealed this (audits such as the ones that Signal and friends have undergone).
> and stuff like Tor,
Tor was not involved.
> media makes it seem are unbreakable.
None of the apps hyped as "unbreakable" were broken here, so...point still stands, I guess?
Honestly, if anything, the recommended approach from this incident would be to use the walled garden - an FBI-backed honeypot would have a lot harder time getting from the App/Play Store onto a user's phone if it was obviously a scam to collect user conversations, asked for a bunch of permissions, had no reviews, and no apparent update history. Who would download some random chat app that nobody uses?
> > especially in the US
> The app was deployed in Australia.
Australia has an even worse equivalent of US National Security Letters, allowing individual workers to be compelled to plant backdoors etc..
Oh? The reports I read were that they could compel an individual to do something and not tell their employer.
I'm as suspicious about the Assistance and Access Bill as anyone, but the "telling an employee to implement a backdoor without telling their employer" is really a red herring and I don't know why the Australian tech community was so keen to go along with that.
Why not leave it at the employer? Just because won't cut it.
Eh, from where I'm sitting, that's a pretty common tactic to pacify opposition to legislation that grants the government too much power.
I would need to re-read the act, but the gov website[1] indicates you are correct that these requests are served to organisations and not individuals excepting sole traders.
[1] https://www.homeaffairs.gov.au/about-us/our-portfolios/natio...
Bin Laden used couriers in place of digital communications. And the trail that led to him began with his most trusted courier.
Allegedly, al-Kuwayti was uncovered, some of his communications were intercepted, and then he was followed up to Bin Laden's refuge.
> Who would download some random chat app that nobody uses?
The only thing that slowed the capture was using a courier network. Are you a criminal? Do not use a phone.
Seriously, criminals should know better, whether they are petty drug dealers or major terrorists.
Misplaced faith in cryptography is the gift that keeps on giving.
For me the lesson here is the same old lesson - Your security is only as good as the humans that interact with it.