‘Every message was copied to the police’
theguardian.com
theguardian.com
> $1,700 for the handset, with a $1,250 annual subscription
> Almost 10,000 users around the world had agreed to pay
So the FBI built a 8 figure ARR hardware business...
But they did leverage their position as law enforcement to arrest all of their competitors
That 'market' is called crime, and obviously criminals will be more than happy to fork over money for tools that help them to commit crimes without being arrested. In reality though, that market doesn't exist because if you or I would address that market we'd be hit hard by the authorities, and for good reason.
I think this part is underestimated by most people. Celebrities are frequently under a microscope and having to live your life while worrying about somebody overhearing it and taking it to the press must be frustrating. Everyone has bad moments in their lives, but at least for most of us these won't be dragged up and published to the world. A device like this could help alleviate that fear a little bit.
They quickly found their primary market was, well... crime.
That said, having met the "ad tech" industry[2] when doing a search engine I can say there are a large number of people who are perfectly happy to take the money from bad actors with a "perfectly legal" product and reasonable deniability.
But all of these schemes have a certain "addressable market" and an "expected return" which are hard to judge. Putting numbers to the "completely anonymous" phone scam was interesting.
[1] https://www.wired.com/2012/11/zeta-radio/
[2] And to be clear, there are legitimate folks trying to do ad tech in legitimate ways, but there is also a lot of fraud in ad tech which involves setting up networks to take money from advertisers and feed it to bad actors.
5 days ago, 31 points, 5 comments: The story of An0m Chat, Run by the Police https://news.ycombinator.com/item?id=28490871 https://www.theguardian.com/australia-news/2021/sep/11/insid...
3 months ago, 130 points, 62 comments: Why no-one in America was arrested as part of Operation Ironside https://news.ycombinator.com/item?id=27509550 https://www.abc.net.au/news/2021-06-15/no-one-in-america-arr...
3 months ago, 431 points, 350 comments: Australian Federal Police and FBI nab underworld figures using encrypted app https://www.abc.net.au/news/2021-06-08/fbi-afp-underworld-cr... https://news.ycombinator.com/item?id=27430508
3 months ago, 18 points, 5 comments: Hundreds arrested in global crime sting using messaging app https://www.bbc.com/news/world-57394831 https://news.ycombinator.com/item?id=27435467
Search also under "at0m", "operation ironside", and "operation trojan shield".
Can someone please build this? Restrictions: You may only use Rust and sparkle some AI on it.
an0m: https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
operation ironside: https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
operation trojan shield: https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...
You can also search comments; many of the headlines, as in this case, don't mention any of the keywords used here, and I turned up most of the articles based on comment search.
I'd recalled the investigation sufficiently to know that it had been mentioned, and what search terms were likely to turn it up.
[1] https://www.npr.org/2011/12/09/143442365/mexico-busts-drug-c...
Soldiers seized 167 antennas, more than 150 repeaters and thousands of cellphones and radios that operated on the system.
It sounds like it had both radio and cell bands if phones were able to use it.
a) Crypto is secure, b) Infiltration is difficult, and c) You can't trust hardware and software vendors.
From what I can tell the criminals need international communications to facilitate their operations.
Ergo, my earlier speculation that the technologically savvy ones will adapt and develop their own proprietary software.
Maybe the juice isn't worth the squeeze for criminals to learn software development, but I worry about criminals who do learn.
however, most known criminal dev teams are hacker groups in Russia who either operate as part of official espionage activities, or are allowed to operate as long as their victims aren't Russian.
all that being said, though, this "criminal software" idea probably isn't as true as you think. criminal enterprises are inherently risky, and there's so much money to be made in software that anybody good enough to do well in a criminal enterprise could do well normally.
(unless we count normal companies which get away with breaking the law in the course of normal business as criminal organizations — e.g., Amazon and Tesla for union-busting — in which case, there are probably a lot of people reading this who technically belong to criminal organizations, although some percentage of them would intend otherwise.)
citation, please!
That "yet" is terrifying. If you thought the PATRIOT Act was an overstep, you need to read TOLA. This is the revival of the crypto wars. Good write up on it here [1]
[1] https://www.internetsociety.org/news/press-releases/2021/new...
I hope you're strongly /s, because if HTTPS being used as transport is enough to rubber-stamp a warrant, then this is in practice a blanket agreement to surveil all communications on the Internet.
Furthermore, everyone on this thread is talking about more secure communication. But my mind always goes to assuming every communication channel is compromised by default, and then flooding it with many, many false messages and wasting adversary resources chasing them.
I don't think we need to defund the police but they need more oversight based on certain experiences and things I've read about over the years.
The same thing happened when the Soviet Union was going through its slow collapse. KGB type agencies became more and more powerful and the average citizens suffered as a result. Many of their methods have now made it here with things like psychological torture and using the mental health system to practice punitive psychiatry.
One silver lining to having a stasi-esque surveillance state is that it watches everyone, even the crooked cops involved in a conspiracy. Unfortunately, the public in the U.S. seems to be fully onboard as we continue our descent into a fascist state.
I wonder how many crypto currency tumblers are actually run by law enforcement?
A starting point might be to use battle-tested open source systems but subject them to detailed in-house analysis and audit.
First, you need to generate large amounts of unbiased, true random data. If it is not true randomness, you have a stream cypher, and if you "rolled your own", probably not a good one.
They you have to store the one-time pad. It is usually too big to memorize. You have to store in on a device like a USB stick or a book, and guard it well.
Then, you have to share the secret, and for that you need a secure channel and that shouldn't rely on encryption, because it would miss the point. Essentially, you need to meet in person, in a secure location.
Then, you need to make sure that the one-time pad really is one-time. It should be securely destroyed after each use, preferably on both ends.
For something like coke smuggling you just need to know its on the way, get ready. So the OTP could be something as lame as "if you get a phone call from some rando who says 'Taste the Feeling'" then the next boat is full of coke, or if not, then the next boat is not full of coke". Actually terrible idea as taste the feeling was a coke company slogan a couple years back, but you get the general idea.
I had recently finished reading both books by Robert Mason, who started out flying helicopters for the Army in Vietnam and ended up smuggling literal tons of weed and got caught and did federal time. Pretty interesting autobiography. Anyway my comments fit pretty well with his description contained in his second book.
Mr Mason got caught by bad luck. There will always be small timers who do things small timer style who get caught by being verbose and oversharing, and to catch those we'll have "encrypted" smartphones.
Using enough data warehousing and artificial intelligence, eventually some algorithm would notice that every time some dude gets a phone call, next month the same boat gets a bill for servicing its water intakes, and a month later coke supply increases in .au decreasing the price. Might take a few times, but someone's getting caught.
The best part is if they go in shooting on a warrant and kill some random completely uninvolved people, it was all an algorithm's fault and nobody is to blame and I guess we just need more police involvement and surveillance to prevent future tragedies.
You might even schedule regular communications to avoid being caught by traffic metadata analysis.
Sometimes when I'm wearing my tinfoil hat I wonder if the advice to avoid rolling your own crypto is a conspiracy. The powers that be want to maintain their backdoors, maybe? Probably not. Of course, it's definitely true that there are more attack vectors out there than an amateur can be aware of.
I think I remember a scifi story that mentioned some character who worked in the one-time-pad shipping business. I guess a spacecraft full of data storage can hold enough random data to last for a long time.
Seems like we should at least come up with a proper protocol for it, so we can at least get started with something that's broadly compatible.
…you're not using a one-time pad. OTP requires the pad to be truly random: at least one bit of unique, never-used-elsewhere entropy for every bit in the message. Merely XORing some plaintext with a pseudo-random stream based on a smaller seed, which as you say is the basis for various other encryption algorithms, is not a one-time pad.
The real problem with OTP is key distribution: You need to share pads with everyone you might want to communicate with, one pad per sender/receiver pair, and those pads need to be at least as large as all the message you'll eventually want to exchange. There is no OTP equivalent to public-key cryptography where you only need one private/public keypair per recipient.
Unless that was a preshared key, you're not talking about a one time pad. One time pads are inherently symmetric. If you're comparing symmetric to assymmetric crypto systems, you might as well just say that 'if my grandmother had wheels, she'd be a bicycle'.
Stream ciphers and OTPs are both symmetric.
The "symmetric" part is the fact that the same key is used for encryption and decryption, not that the plaintext and key are the same length.
I wouldn't call OTP "fragile" or "hard to use", but you're correct about the key distribution difficulties.
> I think I remember a scifi story that mentioned some character who worked in the one-time-pad shipping business.
A Fire Upon the Deep, by Vernor Vinge.
The strength of the system can be viewed from multiple angles. From a practical angle, applying one kind of commercial encryption on top of another type of commercial encryption turns it into a technically weaker, but unique cryptosystem. And uniqueness has value if you're just a single fish in a big pond.
For instance, if one single An0m customer had applied a caesar cypher to their communications, the cops might have skipped over him due to the unknown cost of putting dedicated crypto effort into one person in a massive dragnet.
And since you mentioned Schneier textbook, he also said that a good safe is the one that you give to your adversaries with the blue print of how it's made and still is uncracked, not the one that you dump in the middle of the ocean and ask your adversaries to crack it (security through obscurity).
PGP is still uncracked, if I'd become a criminal then public PGP with at least 8k bits key would be my choice.
It's not PGP that is uncracked, PGP is a set of tools built on top of RSA. RSA is still secure (other than brute force factoring) with appropriately sized keys.
The biggest problem with PGP isn't PGP itself, it's your opsec approach to everything else. Example... after decrypting a PGP payload - did you save it to disk unencrypted? Did the recipients to your messages save it unencrypted? Are any machines infected with keyloggers? PGP is a great tool, but still requires good opsec overall.
I think that if we are going to be concerned about multiple layers of encryption, as you say, then we should be equally concerned with things such as what encoding we use to send text with, or whether we use gzip or bzip. It would suck having to worry about all that; good encryption algorithms work regardless of how their plaintext is encoded, and home grown encryption is just another form of encoding.
2. It was fictional.
2. There were a lot of non-fictional organizations that ran just fine without any modern means. Genghis Khan conquered a lot of countries without relying on radio for communications or satellites for reconnaissance. Using a WhatsApp-like chat apps to communicate about criminal activities is very convenient, but opens a new vector of attack against you.
An0m created two vulnerabilities to its users:
- It was specifically marketed to criminal entities. That is, it sharply reduced the search space. In a 33 bit world, An0m is 14 bits.
- It was specifically back-doored.
"Roll your own" avoids the 2nd case but not the first. By definition, rolling your own already reduces search space to the domain of interest. (Other means of evidence gathering may be needed, but should be reasonably viablle.)
Instead, what you want is:
- Blend in with the crowd.
- Utilise widely-shared communications protocols, implementations, and tools.
- Ensure that these have secure cryptographic methods and implementations.
- Audit the hell out of these and offer bounties for any vulnerabilities which can be demonstrated.
If at all possible, see to it that widely-used, generally-available communications tools themselves offer secure cryptographic methods and implemntations. And school your minions in their proper and effective use and limits.
> - Audit the hell out of these and offer bounties for any vulnerabilities which can be demonstrated.
The NSA backdoors will be pretty hard to find if they are there - It's not like you are going to see something like "If User == "NSA" Then Divulge_Key()". The backdoor is going to be something like a very subtle bug with how a particular crypto library is implemented, or some obscure buffer oveflow attack, and it probably won't even be discernible from an accidental bug.
In reality I doubt there is any way to know if the NSA can eavesdrop, it's a complete coin toss.
Avoiding NIST-recommended ciphers seems to be generally-advisable in this case.
There are other backdoors (see the case of Juniper Networks), but there's probably an enumerable set of pracices.
One helpful option is to use Free Software tools in which single actors are ulikely to be able to subvert the tool, and many have an interest in its integrity.
Wait a second, why would he have to go to prison? If all he did was selling phones, what charges could there possibly be?
I'm also missing a third option that he refused to cooperate "for idiological reasons".
He pleaded guilty to racketeering charges.
https://www.justice.gov/usao-sdca/pr/chief-executive-communi...
Imagine if there was a small handheld device that you could type messages into (along with a secret phrase or a private key), and it would spit out a string of encrypted text that could be entered into ANY messaging app (or even published publicly on a billboard if you wanted). You could even encode the encrypted text as a scannable QR code if you wanted.
On the receiving side of things, the decrypter device could have a camera that could read QR codes (or maybe OCR an encrypted string of text). The most basic solution would be to type the entire encrypted string of text into the box and then enter the secret pass phrase or key to decrypt it.
The point, however, is that the encryption and decryption HAVE to be done on a separate hardware device that is air-gapped and does NOT have internet access in any way.
> Every single message sent on the app since its launch in 2018 – 19.37m of them – had been collected, and many of them read by the Australian federal police (AFP) who, together with the FBI, had conceived, built, marketed and sold the devices
For example:
"Hey Bill, I'm going to steal the car at 123 Anywhere Street on Thursday at 2 am."
Police then put a camera at 123 Anywhere St., and a reasonable juror would likely conclude there are two lines of legitimate evidence.
It would be interesting to see what would happen if anyone ever tried the deniability defence in court:
"Ha Ha. You can't link those messages to my public key. They could of been forged."
"We can't for sure link your identity to your public key in the first place. Why should we care about any of this?"
https://www.xda-developers.com/fbi-backdoor-pixel-arcaneos-a...
Unlocking the phone with a normal PIN code shows some normal apps like Tinder,
Netflix, and Facebook, but none of the apps actually open when you tap their
icon. However, unlocking the Pixel phone with a different PIN code reveals icons
for a clock app, a calculator app, and the device’s settings. Tapping the
calculator icon doesn’t actually open a calculator app, however. Instead, it
opens a login screen for the ANOM service
What percentage of HN's population would find this convincing? What's interesting here is that any one of us could have pointed out the absurdity of this, but black markets don't have a way to propagate such information it seems.The less legitimacy I assign to criminal law and criminal justice, the more infuriating it is that the budgets of law enforcement agencies grow ever more inflated to do ridiculous schemes like this to enforce ridiculous laws against things like drugs or voluntary sex work, and that this cost is seen as more necessary and inevitable by our governments than alleviating poverty or providing essential services like healthcare
But even if criminalization isn't creating these problems, it certainly is doing nothing to solve them, and making it harder for anyone who's found themselves involved in these activities to seek out help from more above-board sources (Including the police themselves, but also for example medical practitioners, who might report them to the police)
And of course this all leaves aside the philosophical objection I have to hunting people down and putting them in cages, not because they've harmed people, but because we think maybe something else they're doing is associated with that harmful behavior in many instances. This is just not something I can get behind
But at the end of the day, all of this pales in comparison to the systemic consequences of creating a powerful police state that has license to surveil and invade people's homes, confiscate their property, or even gun them down because of suspicion about contraband. This social cost is more than I would pay for murder investigations, let alone controlling what substances people can ingest or what motivations they have for their sex lives
The real reason drug dealers tool-up isn't to deal with cops; it's to deal with robbers. Dealers hold stock and cash, and if those are stolen, there's not much the dealer can do - he certainly can't report the robbery to the police.
So as a few people have noted above, decriminalisation would result in a significant reduction in both violence and firearms offences.
Solution: avoid hanging around with bad-tempered people.
Alternative solution: launch an unwinnable global war on drugs.
FBI agents were not allowed to download or read any messages sent from AN0M accounts in the United States because of privacy laws. President of the NSW Council of Civil Liberties Pauline Wright said the US had "pretty strict protections around human rights and privacy" which Australia did not have. "It illustrates that Australia is an outlier in terms of protections for human rights and civil liberties," she said.
https://www.abc.net.au/news/2021-06-15/no-one-in-america-arr... (https://news.ycombinator.com/item?id=27509550)
For all the devices sold and messages surveilled, "over 800" arrests occurred in 18 countries, the bulk in in Australia, though also Germany, Sweden, and the Netherlands (https://www.theguardian.com/australia-news/2021/jun/08/anom-...). 12,000 devices were issued (https://www.bbc.com/news/world-57394831).
That's a ratio of about 7% arrests --- which means that for every 15 persons whose every communication was monitored for a year and a half, sufficient evidence to make an arrest could not be found for 14 of them. And that the investigation would have included all of Xheir furXher conXacXs as well. Xhis in a world where six degrees separates any two people.
I'm not sure these 11,200 or so people are pure as the driven snow, but they did give up their privacy rights under a general warrant, but not under direct suspicion according o he reports I've seen. And he legality has been questioned:
https://www.necessarybehavior.com/blogs/news/operation-troja...
I suspect a fair argument could be made that the FBI exceeded its legal authority in this operation and that the operation itself was illegal.
That there have been no US arrests officially linked to the operaiton isn't a guarantee that none will occur, though those might well occur under "parallel construction" or similar pracXices, where inadmissable evidence is used as the pretext to obtain evidence that can stand in US courts. The very fact that the FBI were active participants in An0m / Operation Trojan Shield / Operation Ironside taints any investigations for years going forward.
The other tradecraft lessons are that:
- Only cryptographic methods secure enough to be of interest to criminals are sufficient for the rest of us.
- Whether a criminal or simply on watchlists for other reasons, those who need cryptography are best served where their use of it doesn't significantly highlight them from the rest of the population.
It's that second factor which both makes tools such as An0m so inherently risky to the privacy-conscious, and which explains the 30-year-long concerted an unyielding press by world governments to keep effective cryptography out of the general public's hands by preventing its being built into generally-used tools. Even strong crypto, if sufficently rarely used, becomes just another metadata point in identifying subjects of interest
That is to say, there is never a good solution to this basic problem which should have been solved 30 years ago, on top of having to convince your mob boss on what to use.
I would ask about legality, but I am worried its in a very, very grey area.
This is one instance though where even from a layperson definition I'm really not sure how this could possibly be interpreted as entrapment.
"The key aspect of entrapment is this: Government agents do not entrap defendants simply by offering them an opportunity to commit a crime. Judges expect people to resist any ordinary temptation to violate the law. An entrapment defense arises when government agents resort to repugnant behavior such as the use of threats, harassment, fraud, or even flattery to induce defendants to commit crimes."[1] [1] https://www.nolo.com/legal-encyclopedia/entrapment-basics-33...
That said, I think and other posters have a point about entrapment. Needless to say, I am not a lawyer.
No. Stop. This is not how you report news. This is a failed fiction author’s blog post.
When I read a news story, I want the facts, not a goddamned noir piece. Give me the facts, and I’ll respond to your plea for funding. I have a recurring donation to Wikimedia because they do this properly. If I wanted to pay for pretty narrative, I’d buy your ebook or subscribe to your LiveJournal or whatever.
Point me towards a “simple facts” version, and I’ll submit that link instead. This is the first I have heard of it, and I want to know more, but I do not want to read a spy novel to get the primary info.
The style you are calling «journalism», others call "entertainment". The article does provide information, but the idea implied in the opening, of "bringing you somewhere" (as if fiction), clashes with the supposed intention of inform and comment (the «lightly pattering rain» is irrelevant to the story). If a journal is intended for recording idle remarks, its purpose may be artistic, if for annotations, informative, if for reasoning, analytical: the three can find an organic balance in a journal, finding a thread in the person of the writer. But the idle remarks are not required in the loci for information and analysis, where they are dissonant. Similarly, the "imagery" used as introduction clashes with the piece and looks like clumsy obedience to some weakly grounded convention.
That kind of imagery is not necessary in long feature pieces and journalism. And it mixes up registers with doubtful purpose and effect ("are we reasoning or are we feeling, imagining dreaming...?").
> Chiba (千葉市, Chiba-shi, Japanese: [tɕiꜜba]) is the capital city of Chiba Prefecture, Japan. It sits about 40 kilometres (25 mi) East of the centre of Tokyo on Tokyo Bay.[1] The city became a government-designated city in 1992. In June 2019, its population was 979,768, with a population density of 3,605 people per km2. The city has an area of 271.77 square kilometres (104.93 sq mi).
The sky above the port was the color of television, tuned to a dead channel.
"It's not like I'm using", Case heard someone say, as he shouldered his way through the crowd around the door of the Chat. "It's like my body's developed this massive drug deficiency". It was a Sprawl voice and a Sprawl joke. The Chatsubo was a bar for professional expatriates; you could drink there for a week and never hear two words in Japanese. [...]
Pseudo-W.Gibson
I can imagine future organized crime information flows more closely resembling what was depicted in John Wick: a lot of secretaries and file clerks pushing paper around, using old mechanical adding machines and typewriters; if they do touch a computer, it's a VIC-20 or similarly ancient, internet-incapable device.
In major business districts throughout the Western world, document disposal companies will drive their collection truck to a given business address and shred the collected paper right there in the street as it's loaded into the truck.
You can see them everywhere.
You can hear them long before you see them.
It's possible that paranoia might lead to criminals avoiding even technology that they could be using safely, further slowing them down.
An old fashioned system also seems like it would require more people, opening up more opportunities for human intelligence operations targeting the network.
Properly installed (F-Droid) on off-the-shelf phones with fresh prepaid sims and OS updates disabled, it can be considered secure software against all but the most sophisticated adversaries.
Then, simply verify the handshake key for your contacts, and you can be sure there is no man in the middle attack. Rotate phone+sim every 2 months, while keeping the same "outside" number, say, a landline you control.
There are attacks against this too, but they are very noisy (modify all Signal binaries delivered to a certain area) or typically exceed the technical capabilities of run-of-the-mill agencies (exploit an OS zero day).
Or pull off to the side of the road, walk in well dressed, wave a dead iphone in front of them, ask the receptionist "hey my car broke down and my battery is dead, could you call this number and tell them my car broke down?" Or bonus points if the cops arrive because you're blocking traffic, ask the cop to call on their phone.
(edited I got the best idea that most anyone would fall for: Slip a kid $20 to ask an adult to call his mommie because he got lost...)
Good Samaritanism?
What specifically in this comment would you penalise?
https://news.ycombinator.com/item?id=28620403
And how would you address the issue of people being good sams --- making calls on behalf of someone else when they ask, in good faith.
See for example RMS:
When I need to call someone, I ask someone nearby to let me make a call. If I use someone else's cell phone, that doesn't give Big Brother any information about me.
One comment up from that I said:
> The easier way to attack this is by instituting a know your customer law for phone systems including prepaid SIMs, combined with accomplice charges for anyone who's SIM is used in connection with criminal acts.
~~~~~~~~~~~~~~~~
> And how would you address the issue of people being good sams --- making calls on behalf of someone else when they ask, in good faith.
Prosecutorial discretion.
And to be clear I'm not pushing for these laws; I think they're awful. I just see it as a clear direction that .gov is going to go if they feel the need to that's easier than maintaining zero days for general law enforcement. The ability to actually tie phones to personal identity in a way good enough for a court room.
And I suspect there'd be all kinds of challenges to such a requirement.
Again, the Good Sam loophole is huge.
Yep. It would have to be enacted in the kind of furvor like existed around 9/11. But, the PATRIOT act had been floating around DC for years before 9/11 too.
> And I suspect there'd be all kinds of challenges to such a requirement.
> Again, the Good Sam loophole is huge.
In the US, it really isn't. It's a patchwork of state and local laws that could absolutely be invalidated by the feds in the case of a global communications medium like the phone network, since that implies interstate commerce.
It's one thing to put leverage on the already marginal. Another to haul upstanding citizens off for offering a stranger a phone call. Resistance would be huge. No matter how weak any perceived legal shield would be.
Think about it: unless you distribute SIMs at the local police station, your last mile enforcement officer is just some guy in a kiosk making minimal wage. Assuming he is motivated by law to do his job right, and photocopy IDs etc., he's still untrained to spot fake ones, unwilling to make a ruckus if the customer face does not really match the ID etc.
All it takes is one rogue distributor or some homeless guy, and you will have thousands of SIMS that can't be traced. Then you have anonymous roaming sims for people willing to pay the data roaming fees.
It's a friction, not a silver bullet.
IMEI will identify the phone.
Signal does not work well without GCM.
So you will prove the target uses a phone, and that phone connects to Signal servers or some offshore VPN. That's not very useful.
The quest is to access communication contents, or map out a criminal network that can then then lead to identifying other physical locations of terminals and unknown members of the ring.
https://web.archive.org/web/20210730214414/https://spectrum....
(GDPR-noncompliant cookie policy at origin.)
Though I think there are actually at least two discussions being had here, apparently talking past one another:
One, that a vendor which promises some service but fails to deliver on it, as An0m did here, would be subject to civil claims for fraud or false representation. This seems to be your general argument.
Another is that any given business has concerns over surveillance and privac breaches, whether from law enforcement or other entities, and that any use of digial communictations and data systems exposes them to this risk. Paper-based systems have, of course, far lower capabiliies to data processing, but also to data exfiltration*.
Both are risks.
You're focused on one. Others take a broader view, myself included.
Outside of exceptionally high risk (or exceptionally low revenue) businesses , I don't think many are going to choose to go back to paper. Although, we may see more systems being air-gapped, virtualized, or using other forms of isolation. The types of enterprises that could afford the labor cost of using paper can also afford the price tag on digital solutions that do a good job of mitigating those risks. Most breaches, ransomware attacks, etc are things that could have been prevented. Rarely do incident response crews say "this company couldn't have done anything to prevent this"
Additionally, legitimate businesses have customers that will demand that they use digital solutions. Criminals dealing with other criminals might be willing to use paper to mitigate risks. Customers of established B2B or B2C companies will not.
HN has an 80-character maximum length, submitters have to make choices. That said, I'd have gone with the 2nd phrase here.
You used the word "entrap". I don't think it means what you think it means.
Setting up surveillance of people doing what they independently decide to do on their own, is not entrapment.
Entrapment is when you interact with a target and actively convince them and/or enable them to do a criminal act that they (arguably) would not have done on their own without your prompting/enabling actions.
All of this money and effort just to continue to prosecute a meaningless and harmful "drug war."
At this point, countries are literally spending money to prevent themselves from making money (by setting up legal markets and tax structures).
It's all so absolutely and miserably asinine.