How the CIA used Crypto AG encryption devices to spy on countries for decades (2020)
washingtonpost.com
washingtonpost.com
"Cryptoleaks – Wie CIA und BND mit Schweizer Hilfe weltweit spionierten | Doku | SRF Dok" - https://www.youtube.com/watch?v=VWImO1Qz4Zo
https://www.youtube.com/playlist?list=PLrAvDZ9sYjXaF05SYkTJ3...
and the automatic translation seems not bad.
Always the past tense for these articles. What, they don't do that anymore?
The CIA used to spy on the world, allies and enemies [, install dictators and foment revolts in third world countries]. It still does, but it used to, too.
I'm actually curious here as to what we can & can't prove as to being 'secure'.
So that means all bets are off: it's entirely possible to implement a perfect peer reviewed protocol in a client and/or server full of backdoors that entirely bypasses the protocol deliberately?
The protocol does not trust the server. Android has reproducible builds, iOS doesn't.
Before you worry about super expensive hard to remove hardware bugs, you should worry far more about the software running on that hardware. It is much more likely that theres bugs in the software than the hardware.
No, that's not how cryptography works. Signal clients don't trust the servers, and it's entirely possible to review the client protocol and make sure that malicious server can't learn anything about the communication (except the dreaded metadata - who talks to whom). That's the point of E2E encryption.
> It can't improve the security of firmware directly, but it can certainly improve the isolation of it by auditing and improving IOMMU configuration
But I know of no Linux smartphone that would really satisfy either of those conditions properly.
Maybe I'm just being paranoid. I pay for Mullvad anyway, if my worst suspicions are true then it will still be good enough to hide my petty torrenting from MPAA lawyers (which is beneath the concern of the CIA/etc anyway.) There's no way I'd trust it if I were in Snowden's shoes though. For anything that might plausibly interest the CIA/NSA/FBI, I would not trust these tools (or others) to keep me private.
You’d think there would be some punitive action for the 2000s intel that Iraq had WMDs. This “intel” got us into a war that cost trillions of dollars and thousands of lives.
Nope, instead the CIA just got more money.
No US president in their right mind will ever do anything to reduce the powers of its intelligence agency.
I mention that because the politicians seem determined to break that trend.
Not Prescott Bush, who allegedly tried overthrowing the democratically elected U. S. Government, the other Bush senior.
Dedollarisation in the Middle-East and the potential death of the petrodollar was the real reason they invaded Iraq
"Iraq: Baghdad Moves To Euro" (2000) - https://www.rferl.org/a/1095057.html
We now have all the data to understand the events of the past
The CIA did something much worse. They never noticed that the Soviet Union was in collapse. Instead they had Team B imagine the Soviets were coming up with borderline magical technologies to spread communism everywhere.
In short, I disagree with you unless you have some reasonable proof to back that assertion.
Estimates are about half a million, actually. Most of them Iraqis, considered rather unimportant in US media.
Even if you personally believe the CIA is still engaging in these types of behaviors, the news isn't going to claim that without evidence.
You are joking, right? Or maybe your definition for "evidence" includes circular references, because that is what you get when "the news" is functionally captured but the government/uniparty.
Funny enough, the countries that spend a lot of effort into building their own stack are the ones designated as enemy, Russia/China for example, did they become immune to that strategy?
is a solution which soo often could have helped countries in all kind of ways
weather it's avoiding back doors
or if it's cooping with abandon ware, especially in combination with security gaps
best it doesn't even have to be truly open source, the source being open (visible, modifiable, etc.) to you (the state) and anyone you want to pass it to is good enough
(But truly open source can have benefits, too. But thats a different topic.)
P.S. before some schmuck die hard fan for signal start defending it:
Why do you think still it NEEDS your phone number and relies on a broken protocol (GSM) to authenticate/ID (or even 2F), a protocol easily accessible especially and quickly by 3 litters agencies?
Why during the whatsapp (default app in so many countries made by the company who doesn’t respect your data), why during the down time of WhatsApp, Siganl was shilled so heavily on social media as if it was the only viable way of alternative communication?
Do you have access to the server-side of signal any time you want? How do you guarantee that there are no side loaded software at the server level with backdoors, or memory injected, non-persistent backdoors/malware? Even if it was audited, no guarantee it didn’t happen after, so you have to “trust” whoever is running that server. E2EE doesn’t encrypt meta data, contacts data, location, etc. and even that encryption with the physical access to the server side, theoretically can be broken.
P.S. your comment loaded as 3 stars for some reason in the app, not the browser.
> "In September 2013, The New York Times reported that internal NSA memos leaked by Edward Snowden indicated that the NSA had worked during the standardization process to eventually become the sole editor of the Dual_EC_DRBG standard,[7] and concluded that the Dual_EC_DRBG standard did indeed contain a backdoor for the NSA.[8] As response, NIST stated that "NIST would not deliberately weaken a cryptographic standard."[9] According to the New York Times story, the NSA spends $250 million per year to insert backdoors in software and hardware as part of the Bullrun program."
https://en.wikipedia.org/wiki/Dual_EC_DRBG
There are also notions that the British government ran a similar program after WWII, distributing Enigma machines to all its colonies/ex-colonies, which was part of the reason they kept the codebreaking work on Enigma secret for decades (until the 1970s). I've never seen a similar expose of that, though.