Crooks’ mistaken bet on encrypted phones
newyorker.com
newyorker.com
The standard playbook for rolling up criminal conspiracies is to arrest a low level member, offer him a reduced sentence in return for testimony, arrest the next guy higher up based on that testimony, etc. (The only way to prevent that would be a fully trustless "cell" structure where none of conspirators know each other, which has never been done in real life.)
You will notice none of this requires communications intercepts. This is because the feds are simply lying when they say encryption prevents law enforcement operations.
When properly done, such organization is almost impossible to find. I'd not be too sure about them not existing. The idea is well known, so someone must have tried it at least.
Somehow they managed perfect forward secrecy.
For a while.
(Btw, you've been shadowbanned a while ago. I'm only mentioning this, because your recent comments seem sane as far as I can tell.)
I've only ever heard it on an episode of Monty Python. Wonder if it's just a UK thing.
You can’t have a network with more than one cell where no one outside of the cell knows that it exists, and without those people using a communication method to people in the cell that at least one person in the cell knows exists. And when you minimize down to the minimum contact, the network is very much non-resilient: its hard to discover and roll-up, but (especially if the cells are doing high-risk functions, which is probably why you want to do it) its also easy to disintegrate accidentally, even without being discovered and rolled-up.
But practically there's a whole bunch of problems as you say - you've no idea how many - if any - cells exist, they can't coordinate on which one picks up a particular target, the communicator is obviously at risk from being tracked down, how do you tell people where the radio broadcast is, authorities can obviously listen in once they've found the broadcast, etc.
Couldn't be done by sending messages encrypted with private key and the cells decode it with public key?
Then the problem is: How to trust public keys to have been provided by the "right" correspondent, and not someone from another gang or law enforcement?
Cell systems have order, but only where the most risk is imposed. Lesser risk, less order. Infact, too much order imposes far more risk.
The Crips and the Bloods are kind of like that cell structure, but cells have internal beef all the time. If you had different cells have no communication, that would happen way more as they try to expand
Think of a cell like a class in programming. If a class has a bug you can fix the bug, or make a new class with the same ins and outs. Never have to restructure the entire code base. Properly made classes don't leak to other ones. Worst case internal beefs take down prod for a bit but they don't take down the entire program
Perhaps you are in it for the ideology? Or perhaps they pay you?
"Why am I Mr. Pink?"
My sense is that it has become a bit more lax since Apple has grown and, well, let's face it, Steve is no longer with the company.
Or you just have your buddies enact violence on the friends/relatives of anyone caught squealing.
Good opsec is exceptionally hard. If you aren't building it from scratch it probably isn't secure. And even if you are, if you're a big enough target for nation states to be looking you're still going to have a hard time.
And if you are building it from scratch, it is definitely not secure.
Also they didn’t use disappearing messages or delete them so the full history was available without breaking any encryption
They'd need to kill those SWE to be -safe- after
PS: I wouldn't take a job that can get me killed, there's a reason I like working with computers
For reference, in Bosnia and Herzegovina, the median salary for a software engineer is 3650 BAM (1867 EUR at today's rate), per month, making a yearly 43800 BAM / 22404 EUR, and that's gross, before taxes and stuff. 6 figures EUR, even assuming low 6 figures like 300k, is the equivalent of more than 13 yearly salaries, and is of course untaxed, so even more with that. One can comfortably retire with 300k EUR in Bosnia.
There are much more lucrative paths for intelligent psychopaths in the professional world.
So all the cops need to do is go after the central server and then quietly hijack it. After that the choices are pretty much endless. If they used non-standard encryption, ggez, they're probably not smarter than the police. If they did, chances are that the server has an OTA mechanism to update the message application on the phone, so just push out a malicious update that quietly just resends every message to a police controlled server and uploads all messages still stored on the device. Less useful (not as much access to historical messages) but still very useful for tracking criminal activity if you run the tracking net for long enough.
Very few "crypto" exploits are ever the issue. It's almost always easier to break some other part of the system than the crypto.
To be honest, if someone were trying to sell me a cryptosystem for a criminal enterprise and I were in the market for one, I'd happily start tracing everybody in that company as they are almost certainly part of the Feds.
If you are the target of a nation state actor, you're pretty much fucked. Once a nation decides to put down that much resource to get you, you're getting gotten.
Crypto is only valuable in the sense of "I don't have to outrun the hungry tiger. I just have to outrun you so the tiger stops chasing me to eat." If you, specifically, are a target, crypto won't help you much.
Real winners write the law books.
Whether that's European colonial settlers, or William of Normandy.
(Not known as "William the Negotiator", or "William the all-around nice guy").
Descendants of the local warlords he installed still own huge (well, by British standards, the entire country isn't much bigger than New York State) tracts of land, a thousand years later.
https://en.wikipedia.org/wiki/A_language_is_a_dialect_with_a...
Or they just call up discord and ask for the name and billing address on the account.
Then there's traffic analysis (a talk to b, b kill c, b talk to a). See also: "well done".
The Pegasus malware for example was able to infect and spy any phone.
They claim it’s super secure, and then apparently implement whatever with no oversight.
The companies offering encrypted phones were infiltrated. Servers hacked. Employees intimidated with prosecution. Bank accounts seized.
This shouldn't work on AT&T (though room 641[1] showed that it does), but I'm less concerned about grabbing the mob's customer list wholesale than the grocers.
> Gendarmerie executed a warrant to secretly copy EncroChat’s servers
Yes, there was initially one warrant. But there could have been many others. And even if there weren't, why is that a bad thing? What is your actual complaint?
> It went on to return everything in about 180 of those boxes after failing to produce evidence to support the allegations, court documents show. Those box holders retrieved more than $27 million. Attorneys for other customers say they recovered close to $25 million more through private negotiations with the U.S. attorney’s office.
https://www.latimes.com/california/story/2022-09-23/fbi-beve...
That's $52 million and that's just from the attorneys they talked to - I think another LA Times article mentioned that around 5% of boxholders didn't even claim anything. They seized a few million from Poliak the owner but they had him talking about being a professional criminal for hours and hours. Still messed up but maybe if another judge sees it goes another way.
Per this ruling, if the FBI obtained a warrant to confiscate Google's servers using proof that Google is engaging in criminal behavior, they could then claim to start an inventory of every Gmail account in order to give people back access to their accounts. If they do so, they would then be perfectly justified in starting investigations into each and every Gmail user for anything they find in their emails, without any warrant whatsoever, because their inventory of the emails and pictures was not solely motivated by fishing for evidence.
Similarly, they could seize a post office and do the same with un-opened mail, per the same logic.
Actually there was a case some time ago very similar to your post office example: Someone was stealing letters/packages in a post sorting center near the Dutch-german border. Supervisors found a stash of partially opened/damaged/illegibly addressed letters and the suspected thief. Hand everything over to the police. Police opens all letters and reads them ostensibly to determine whether things are missing and where the letter is supposed to be delivered. One letter is from some german dude to some dutch dude asking for cannabis seeds. Oops. A few busted down doors later german dude is convicted, appeals on the grounds that it was obviously illegal for the police to just read his letter for no reason. Appeal denied - sure it was illegal for the police to do that, but he didn't get convicted based on the letter, but based on his plantation that was found during a raid.
So, as a general rule, it usually doesn't matter how or why police knew about something, if they have solid, physical evidence at the end of the day, it will not be thrown out just because some constitutional rights were ignored along the way.
Is that "geared towards criminals?" I can see how you'd say yes, but there are plenty of other people who would be interested in such a thing. It's also very similar to the sales pitch of any encryption protocol.
Not your keys not your comms. But even then then, apply defense in depth.
> "Sky’s messages ran on a different system than EncroChat’s, and it was more difficult to infect the network with bulk malware. Instead, someone with knowledge of the investigation told me, analysts seem to have launched a “protocol attack” that deceived handsets into revealing their private keys."
Just how long will it take politicians to finally recognize that prohibition is the problem? It didn't work for alcohol in the US (and created Al Capone in the process), it didn't work for cannabis, it didn't work for sex work, it didn't work for porn, it didn't work for any other kind of drug. All it ever created was senseless suffering on all levels, from governments whose budgets were and are drained by the cost of prosecuting all the drug crime, over the users who literally die like flies from contaminated products or accidental overdoses, to society which can't rely on not being shot in a drive-by gang fight or walking home without stepping over feces and heroin needles.
The only place where prohibition somehow works halfway is CSAM and pedophilia, but only because everyone but the pedos hates the pedos and agrees it's inacceptable - and even there, with this worldwide unity, there's still more than enough pedos that corrupt local officials in poor countries where pedos from all over the world exploit the utter poverty that leads people to send their children into human trafficking.
I hope the executives of our society stops one day for “hoping” the wall will move while keeping on bouncing on it.
As peer commenter said, prohibition never really worked to combat crimes outside in real world. What does work is legalization of production and sells. Not as giving up but as controlling the market. Would you try meth of it where legal ? Probably not and neither does your folks.
On the cultural and health side we have the clear exemple of tobacco marketing legislations that have a strong effect on consommation. How will be one (non Islamic) country if it stop advertising alcool ? While it’s mitigated with internet ads, my bet is less alcool will be consumed > better health. And on the working side, c’mon we surely can find or create jobs for our wine-yard workers that will be helpful for our society as a whole.
Given that a lot of ADHD medications are methamphetamine based... yes.
Think about Monero - it's a lot more suspicious to be dealing with that than regular bitcoin.
For privacy advocates it's fine, you aren't doing anything wrong by using e2e and monero, any govt looking at you won't be able to get past reasonable suspicion.
But if you're a criminal you're basically glowing in the dark by doing this stuff. Regular phones are also encrypted! Facetime is e2e? What was the point of the "AN0M" phones. What did they give you except a supply chain risk and a 100x SIGINT interest factor than a normal person.
The balance between privacy and the authority is just that. We outsourced the rule of law to the state in order to have a fair and just society. Ipso facto the government should be fair and just to have the right to invade some amount of privacy in order to keep a society free, fair and just.
That’s why the judicial branch exist: to see if what the government (or anyone) did was playing by the rules.
Which brings us back to politics being a danger to a society if people vote in unjust or unfair people.
Instead, they were pointing out that it's hard to imagine why the people who knew they were engaging in criminal activity and were hoping to hide it thought it would be a good idea to have specialized equipment/services rather than blending in the crowd with normal phones and apps.
At some point you have to trust others in order to take advantage of network effects, and network effects are exactly what these crooks were seeking to manage. The criminals in this case wanted secure, supported hardware in order to conduct operations and logistics across a range of countries.
> exactly what these crooks were seeking to manage
Use iMessage and Facetime without iCloud. Like, to be targeted by Pegasus they have to know who you are, and each time you infect a new target, you risk the exploit being discovered and patched.
Just be buying these "hardened" deviced, police identified criminal cells they didn't even know existed.
They pay thousands for a bespoke solution that puts them 3 OPSEC steps backwards.
While good, this is fishing the ocean with a fishing rod to me. The comfiest, surface-nearest and most trusting fish get arrested, which ironically could well be strengthening the real underground.
Even if the phone was on, unencrypted, and locked it would fail.
Edit: I initially misunderstood where you were coming from. Yes, today things are more secure, but if someone has unfettered physical access to your device they can just as easily install hardware that waits for you to login and then do these things or replace your charger plug (on a mobile device) or use a modified Bluetooth or USB proxy to keylog (on a full device). We're of course getting into high-level corporate attacks at that point if to be unnoticed (i.e. no popups, prompts, unexpected changes), so the average user is much more safe.
At some point, if you have physical access and the device pin, you should assume it’s game over, but there may also be a point in time where we no longer care about physical security as much, if at all.
https://amp.cnn.com/cnn/2019/01/09/americas/el-chapo-it-tech...
It isn't like they can settle their differences in drug court. Black markets and the associated attempts to shut them down naturally generate violence. The people involved literally have no other choice.
Why would law enforcement do that? They are self-made honeypots, evidence-collectors, and tracking devices all rolled into one. And these people can't seem to muster the self-discipline to lay off the sweet stuff.
These networks are being used for drugs, fraud, sex trafficking. But almost nothing legal. Encrypted hardened phone with specialist app in one pocket, iPhone for facebook/instagram in the other
The primary take away from most of what you see in the news (a failed LE investigation of "encryption" or darkweb almost never makes it to the news) ... opsec is hard.
You have no right to privacy. The government can and will spy on everything you do.
If you thought being spied on was bad, wait til you hear what the government does when it thinks you're guilty of a crime.
but especially in Europe
https://www.abc.net.au/news/2023-04-18/accused-criminals-cha...
What is surprising is that such cons - such signalling and trust in it - as spread to legitimate business at the highest levels. It's run SV and much more for awhile now. Really, the criminals made the same mistake that all the celebrated investors did make, and continue to make, with the endless parade of SV fraud.
My expectation is that all NSA CNSA[1] encryption standards are backdoored at the implementation level (by the NSA who uses Suite A for its own communication and I suspect military communications outside of that in weapons systems that can fall into enemy hands)
I guess the propaganda is driven by FBI and law enforcement agencies.
1. https://en.wikipedia.org/wiki/Commercial_National_Security_A... 2. https://en.wikipedia.org/wiki/NSA_Suite_A_Cryptography
Is it the word propaganda that patriots dislike ? Not sure if some soviet connotation is involved in US but for me it’s just a synonym of “public lobbying” of “ideology gov marketing”.
I know those subjects can become polemic and I don’t want to throwing oil on the fire, but an “out of debate” clarification would be nice and helpful.
Then you have stuff like BIP39 protecting people's money (cryptocurrency) that can be cracked for $350/hr on GPU rigs. Someone even wrote a how-to.
Current security makes it harder, but not sufficiently harder, to break into systems. I mean... HN crowd is probably high schoolers and non-tech people just out here to argue.
This doesn't appear to be true (in the sense that yes it is feasible to crack 4-word BIP pass phrases, but all wallets that I'm aware of use at least 6 words, which is estimated to take 11 years for a hypothetical ASIC cracker)
https://coldbit.com/can-bip-39-passphrase-be-cracked/
Perhaps you are meaning this attack where someone was able to brute-force 4 words from a 12 words phrase. It matches your $350 cost, but of course is dramatically different to "cracking BIP39": https://medium.com/@johncantrell97/how-i-checked-over-1-tril...
That's not too far off, maybe a few years before one is commercially available.
The encryption algorithms in CNSA are broadly accepted by the security community. Just saying "NSA backdoor" is a cheap shot.
Depending on what you accept as an evidence, but this theory is surely supported by precedent(s?) [0]
Just saying “another conspiracy theory” is a cheap shot : conspiracy are bad and should be fought. Theories are a useful process to make knowledge advance. Conspiracy theories are often discussed in an awful way on social medias, can’t HN do better than just downvoted them ?
[0] https://www.theguardian.com/books/2014/may/12/glenn-greenwal...
https://twitter.com/4chan_greentext/status/84511828265908224...
1) Did NSA modify Cisco routers? Yes
2) Did NSA get a backdoor in Dual EC_DRBG? Yes
3) Did NSA get a backdoor in the CNSA algorithms? There is no evidence to suggest they have and plenty the other way.
The original claim was (3) but the "NSA does stuff" thing overrides any attempt at discussion of that specific piece of misinformation.
I'm having a hard time keeping up with it all, it's nuts. But my understanding is that the NSA backdooring protocols is totally supported by evidence? We saw it in the Snowden revelations? RSA being the company nobody will ever trust again?
Is that all wrong somehow?
It's important to be very precise.
I think you might be confusing backdooring specific pieces of software produced by RSA-the-company (specifically things using Dual EC_DRBG) with the RSA algorthim that company is named after, which is included in the CNSA.
Dual EC_DRBG was a bad algorithm which many people had serious doubts about from the start - and indeed it was backdoored by NSA. That is different to the algorithms in CNSA which (as I said earlier) are well regarded by the same security researchers.
There is no evidence (or serious claims) that the RSA-algorithm is backdoored.
Technology simply has become far too complex to be reasonably secure, even if you have the financial firepower of being Apple, Sony, Microsoft, Nintendo or Amazon.
If it installs updates without requiring you to specify the desired updates explicitly (i.e. by cryptographic hash), it should not be considered "your" device from a security perspective.
CNSA / NSA Suite B are pretty much entirely public encryption standards that have stood up to public scrutiny for decades at this point.
They are also approved by the USA to encrypt TS SCI information, why would they approve that if they had backdoors?.
Because Suite A are a set of non public algorithms that are used to encrypt data.
Them being non public makes it harder to workout how to decrypt the data.
They are also likely protected against a number of attacks that aren't public, even if these attacks aren't feasible against current algorithms.
For reference, see DES, where the NSA adjusted the algorithm to protect from a not publicly understood differential cryptanalysis attack. Many people claimed that the adjustment by the NSA was clear backdooring, though we know that was not true.
It was however purposely deficient in the length of its key, allegedly because "it was good enough" and for export reasons, but also because the NSA considered it easy enough to brute force.
https://www.washingtonpost.com/archive/opinions/1999/06/28/o...
It didn't seem to have been archived before either:
People are social, and when push comes to shove they're more than willing to throw someone else under the bus.
The question is, why hasn't anyone designed a standard cell-like structure for an encrypted communication app? Cell-based structures have been known for a long time.
How do you verify + vouch for a new user in a way that's secure yet anonymous?
How do you handle anonymous + secure + directed communication?
> How do you handle anonymous + secure + directed communication?
I believe the answer is PGP key meet-ups.
But then you have the other operational issues with the cells, like what do you do when your cell is compromised, or how does a cell reattach to the network if an upper level point-of-contact is compromised.
And there are administrative issues...like a shared calendar. Payroll. Inventory. Logistics alone makes a cell structure difficult, because logistics means coordination among many people.
It would be an interesting project to make for sure.
I assume for a compromise you can just do the same set-up as pre-compromise except at level+1 and level-1 instead of level+1 and level. Figuring out who is compromised is non-trivial but that was the case without a cell structure anyways.
Cell structures should make logistics easier. Thing about MergeSort vs BubbleSort. The amount of comparisons needed by MergeSort is less because of the cell structure. If you're trying to make a master calendar, it's going to be easier to have the cells create their own calendar and then merge them at the cell level and then merge those at the next level and etc until they're all merged than have everybody make their own calendar and talk to everybody else to resolve conflicts.
IIUC, payroll works this way for the federal government. Treasury has a big pile of money it lumps out to various departments which lump it out to divisions which goes out to actual employees.
[1]: https://en.wikipedia.org/wiki/Six_degrees_of_separation
It's often tough for developers to see this for the same reason it's tough to write documentation-- reasoning about a beginner's perspective is a specific skill that takes study and practice. That's why software companies that need financially stable products hire technical writers and interface designers, and it's a place where FOSS really struggles.
For example, Mastodon's active userbase has dropped 50% since its peak during the beginning of the Musk/Twitter debacle... even for the ones brave enough to plunge in head-first, it was too much technical resistance compared to the more straightforward alternatives that they had already abandoned. I think it was a missed opportunity.
All the classic mob movies have something about never talk business on the phone, always meeting in person in some dark waterfront or warehouse location. Here, they would only be required to meet in person once! If someone is too lazy even for that, well then, enjoy prison I guess