The Practical Limitations of End-to-End Encryption
soatok.blog
soatok.blog
Arch-revolutionary Che Guevara was tracked down and assassinated because the NSA cracked his "unbreakable" one time pads which would have been unbreakable if he'd only used them once.
https://www.kopaldev.de/2022/04/27/cryptography-for-everybod...
It's also running on a device that's had who knows what websites visited on it today.
It's not hard to imagine some foreign intelligence agency is sitting on some severe zero-day vulnerability, waiting to use it on very high value targets, such as senior administration staff.
Those unscrupulous enough to sell the vulnerability to the exploiters, there is gold. Of course we would rather they did the right thing and got the bugs fixed.
This is also something that comes up with esoteric cryptography schemes. There are systems designed so that you could theoretically deny whatever property, but in reality, the bad guy looks at your phone and believes whatever is on the screen anyway.
Of course, the real question is whether these led to any convictions. They did lead to a few prevented murders and the like, but given they're all sweeping / non targeted sting operations, they're not admissible in court in a lot of cases.
Each episode is chewed up slowly to the lowest common denominator, meaning half of an episode is condescending explanation of trivial matter. The misplaced air of faux mystery, true crime podcast style, does not help. The narrator being occasionally a free speech absolutist and explicitly in favour of money laundering services does not help.
Risky Biz covered Anom in https://risky.biz/RB751/ via a dense if a bit short interview with Joseph Cox, who wrote a book about it, starting around minute 35. Listen to that and respective Darknet Diaries episode to compare. In general Risky Biz offers more balanced, less boring, and up-to-date takes on cybercrime (sans interviews with actual criminals).
I'm willing to reexamine my appreciation for the darknet diaries,but I have never gotten this political take from the content itself. Rather he seems to simply be willing to engage with folks he disagrees with morally, as a matter similar to any journalist might. He does not engage with active crime or anything like that either.
I really like darknet diaries. I don't think it is just about cyber crime though. More like a human social journalism with a heavy cyber crime angle. So that's how you have such a range of content in my opinion.
Also, maybe listen at 1.3X? That makes the explanations and pacing imo easier
It was originally created by a private company, that went a bit too far in marketing it to criminals. Undercover agents asked the CEO "How do I use this to prevent the police from monitoring my drug smuggling", and he answered the question.
In order to keep the feds from throwing them in prison, the remaining execs needed to provide names, and what better way than to compromise the phone and market it to criminals?
Around the same time, law enforcement cracked a more popular custom phone used by criminals, so gangs started looking elsewhere. And the FBI was waiting for them.
It was an insane operation. It was being run from a local FBI office (San Diego), not headquarters. A bunch of low level agents.
But it provided massive police intelligence around the world.
It also screwed over a lot of the contractors who worked on it. The Android developers who designed the phone are now on organized crime's radar, even though they thought they were just making a secure phone.
The sales chain was what made the operation so effective. The only people who had the phones were the ones the FBI wanted with the phones.
The fact that it was really only criminals using it was the big selling point.
But even so, when stakes are high enough victim-blaming becomes both warranted and healthy. Even if there really was a deep-state conspiracy to embarrass the presidential cabinet (not that i think there was), the ultimate responsibility should still fall on their heads for not taking obvious precautions while planning an airstrike. If you can't verify that everybody in your signal conversation is actually supposed to be in the conversation, let alone that they are even who they appear to be, then it's obviously not an appropriate platform for this discussion.
The job in this case seems to be secure, ad-hoc communication between multiple parties while on the road (the VP at least was doing an event in Michigan). Clearly a public smartphone app isn't the right tool for the job. Is a SCIF the right tool though? I always thought of SCIFs as purpose-built rooms. It seems impractical that every time a message needs to be communicated, the parties have to be whisked away to a SCIF.
Failing that, these people almost certainly have laptops connected to DoD networks at a lower COMSEC level than a true SCIF (indeed, "high-side laptops" were mentioned in the Signal thread). They could have communicated with those. I don't know about DoD policy if those would be acceptable or not for discussions about planned strikes, but it'd be a hell of a lot more secure than unsecured public smartphones.
There are 'tents' as well; Obama in one:
* https://www.bbc.com/news/world-us-canada-12810675
* http://archive.is/https://www.nytimes.com/2013/11/10/us/poli...
It should have ended there. Smartphones are not secure and you must not trust them.
> When government and military officials want to discuss operations, they’re typically required to go into a SCIF (Sensitive Compartmented Information Facility), which ensures:
>
> - That they are not being wiretapped. (To this end, mobile phones are not permitted in a SCIF.)
Whether this is actually true or not I wouldn't know and can't be arsed to research, but it makes sense to me. Whether it's reasonable to assume based on this that phones are completely out I also don't know.
And by insecure here, he and I mean that its not a platform designed and manufactured to meet the large number of requirements for handing classified information. It may be secure in the sense of industry standards or conventions, but its not secure in the sense of military information security.
Any system where the government doesn't have total control over software deployment will never be viable for handling claasified information.
That is, if the reproducible build didn't constantly break https://github.com/signalapp/Signal-Android/issues/13565.
It also ignores the fact that the vendor could send updates targeted to specific devices.
"In some cases, Google has found Russia's notorious, stealthy hacking group Sandworm (or APT44, part of the military intelligence agency GRU), to work with Russian military staff on the front lines to link Signal accounts on devices captured on the battlefield to their own systems, allowing the espionage group to keep tracking the communication channels."
"In other cases, hackers have tricked Ukrainians into scanning malicious QR codes that, once scanned, link a victim’s account to the hacker’s interface, meaning future messages will be delivered both to the victim and the hackers in real time."
Gee, I dunno, sounds like hacking the endpoint to me (which always defeats end-to-end encryption).
Why would I not?