The Great SIM Heist: How Spies Stole the Keys to the Encryption Castle
firstlook.org
firstlook.org
First, it came for the terrorists, and I did not speak out, because I was not a terrorist.
Then, it came for the muslims, and I did not speak out, because I was not a muslim.
Then, it came for the Dutch, Belgian, and German engineers, and I did not speak out, because I was not a Dutch, Belgian, or German engineer.
If you're an engineer, developer, sales staff, or pretty much anything else, and you work at a company that has something worth stealing, you should think about how this ends. If they don't come for you first, your personal life is now completely fair game for nation state attackers.
They will stop at nothing, they have limitless budgets, they will attack your private life, they will reflash the firmware in components of your personal devices, and they will stalk you. Even when you did nothing wrong, even when your employer did nothing wrong, even when your social graph is in no way linked to anyone who ever did anything wrong.
No, don't look in the mirror, waste of time. Walk away from your job.
From a technical perspective, the sort of research going on at Google (deep neural nets, etc) is in a whole other intellectual league.
Think about it: You're a NSA/Mossad/MI5 NetOps operative. You can have access to a lot of information without risking your life, get paid by your agency AND google/facebook. What's not to like?
Google, for example, has a large security team in Switzerland, with quite a few German and British employees. The NSA sees itself as a military organisation, it is bound by military rules.
What rules would that be? In the military, actively seeking (and using) information you have no right/classification to see is a serious offence. According to articles I've read, not a single NSA employee was disciplined for e.g. spying on their SOs or Exs.
Also: If the NSA doesn't have Swiss and German citizens working for it, it's not a very good intelligence agency. And we know for a fact that it is, at least as far as reach is concerned.
You should assume that the Dutch, Belgian and German agencies already came for you though. Perhaps they are less competent than the NSA, and maybe one of those countries actually acts morally - but there are over a hundred countries out there. At least one of them has a competent intelligence service and no morals.
This is not supported by any of the leaked documents. GCHQ certainly had full access to Gemalto's email servers, and several documents refer to information retrieved from there. There is nothing to show that data was ingested into XKEYSCORE and absolutely nothing to show that the employees' personal emails were in XKEYSCORE.
I cringe a little bit whenever someone starts on the "first they came for..." monologue. Not because it isn't true, but because it first was used talking about the Jews in WWII Germany. You're effectively playing the Hitler card in a debate that isn't about Hitler.
The US was built in part by this type of security. Chances are things would be very different here if the security professionals over the years made decisions based on moral qualms.
I am playing the devils advocate, but when you look at the senate, it's hard to actually point a finger at the intelligence agencies. This is the world we have made, fear mongering hardly fits into this argument, and certainly adds nothing of substance.
The US was not built by this type of security. What the NSA is doing only became possible quite recently. It's just in a whole other world to what was previously imaginable.
The absolute lowest bar for surveillance seems to be that a government doesn't use it to intentionally target innocent people/ those not in the game (hell, lets lower it even further to be only people the government themselves believe are innocent).[0]
That potentially allows dragnet collection of data if no one looks at it. It might allow hacking just a company's servers to get access to third party data. It probably allows you to spy on foreign heads of state (even if it's a boneheaded move). But it damn well doesn't allow you to go through the personal communications of people who you know have done nothing wrong and aren't even working for someone who has.
[0] This is precisely the woefully low bar Obama has been espousing : “The bottom line is that people around the world, regardless of their nationality, should know that the United States is not spying on ordinary people who don’t threaten our national security and that we take their privacy concerns into account in our policies and procedures,”
I wonder which non-US country, where the NSA's actions aren't made "legal" by secret FISA courts or acts of (US) Congress, will be the first to start throwing that kind of legal threat at NSA staff responsible for this?</wishful-thinking>
I guess a _lot_ of what goes in in state sponsored espionage happens outside the civilian legal system - at least in "major" countries - but surely there's scope for a criminal trial and civil damages case against NSA/GHCQ operatives when their espionage involves widespread network exploitation and privacy violation of corporate networks and staff. Crimes which would _clearly_ be aggressively prosecuted if committed by Anonymous Skript Kiddies or criminal credit card fraud gangs. Why shouldn't NSA agents be held just as accountable in this case by non US legal systems? Sure, root the embassy network and expect to be held diplomatically responsible if you get caught. Private companies and citizens though? Go to jail just like anybody else.
Ireland rushed to retroactively OK british spying. Germany ignored it (with some theatrical "I'm insulted" remarks from Merkel, but no real action).
The assumption that any government out there actually wants to enforce its laws with respect to mass spying against its people is not supported by facts.
http://mobile.reuters.com/article/idUSKBN0JP1QG20141211?irpc...
> "the document presented in public as proof of an actual tapping of the mobile phone is not an authentic surveillance order by the NSA. It does not come from the NSA database.
> "There is no proof at the moment which could lead to charges that Chancellor Merkel's phone connection data was collected or her calls tapped."
Take a look at the cold war, most of the directly tasked targets of US and Soviet intelligence efforts were "small fish" with the right access, anything from a hotel employee to a secretary or a cook or even your hair dresses.
At least with this NSA thing they don't end up with 2 bullet holes at their back of the head at the bottom of a trash chute.
Spy agencies always have and always will operate in such manner really not sure why people still act in any sort of shock this is the most basic trade craft.
All the NSA did is to steal keys which they can then use to interdict cellular communications, it's not like they put in a weakness by design and then exploited it (which they might have done in other operations but that's a completely different story).
This thing is no different than the digital signatures on the driver used by Stuxnet ("oddly enough" both companies which were compromised were in the same industrial park just a across of a shared parking lot from each other ;)).
Sadly this level of operation is plausible to be committed not only by private intelligence agencies (which we had too many off already) but by crime organizations as well. I've seen case of corporate espionage which were more complex than this one.
Instead of huffing and puffing at the NSA the proper lesson to learn from this is that cellphone carriers should stop relying on SIM card manufacturers in China and India for their encryption.
Heck if the NSA can interdict equipment in transit to tamper with it, how hard would you think does the Chinese intelligence service has to work to go down the street and just demand the keys straight from the source?
It's about a good damn time that people start asking questions on who has access to the private keys which are used in so many day to day operations from the keys used to authenticate your cable modem to the keys in the card reader you swiped your card trough at your local coffee shop. The answer to this should force quite a few people to live in a hunting lodge in Montana for sure.
I in fact would be very surprised to find a single mass used commercial cryptosystem which is actually secure. Because which each and everyone of those the keys to the castle end up being in the hands of the lowest paid employees out there and business practices will always force availability and serviceability over security.
Actually there were certain projects got pushed back like the IDEA from ETH Zurich or ECC from University of Washington and other potentially vulnerable alternatives were promoted. ECC btw. is pretty strong for a very long time, even today, if you don't use the backdoored version...
http://csrc.nist.gov/publications/nistpubs/800-90A/SP800-90A...
I also hope that you don't insinuate that ECC was "invented" by UW since elliptic curve cryptography was known for quite a long time.
By the backdoor I assume you mean the whole NIST curves fiasco, well besides the fact that it was in use almost no where, if you speak to actual mathematicians you'll find out that it wasn't a big deal. The NIST curve was more about performance enchantment than backdooring, altough sadly for NIST and for the NSA it failed at providing both.
The big problems with ECC is that it's extremely susceptible to side channel attacks especially in embedded implementations, and that if you have the capability to use quantum computing for cryptanalysis then to break ECC you'll need only about 25-50% of the compute time/power than you would need to break RSA.
Also since ECC is asymmetric and quite resource consuming it's not really used in encryption as much as you think, sure it's good in any situation where you can use PKI but PKI is rarely used to encrypt actual data. The common uses of PKI are for authentication and initial key exchange data encryption whether it's in rest or in motion is usually based on symmetric encryption.
Nothing new here - as the Belgacom hack has shown already.
https://firstlook.org/theintercept/2014/12/13/belgacom-hack-...
It is gradually recursing backward to "invasive targeting of completely innocent and ordinary people simply as a means to get access more innocent and ordinary people in order to ...etc"
Alternate version: If you aren't three or fewer connections away from anyone with something to hide, you have nothing to fear.
It's worth remembering that some tools are only useful with lots of data about innocent people. Some forms of network analysis fall into this category, I believe.
Lets suppose it actually was a valid defense. But what does that have to do with going through the Facebook and personal email of individual employees to know who to target. That was done up close, in personal, by hand. By any definition, those people had their privacy specifically and intentionally violated by actual human analysts.
If we judge the means by the ends, I do not believe that their end provides sufficient justification for their means. They appear to believe otherwise, however they fail to offer any evidence for their perspective; as an American, I am feeling ever more alienated from the organizations which were theoretically founded for our benefit.
Did it? Has it? Unknown.
The trouble with intelligence is that it's only effective when done with secrecy and fairly broad latitude to operate. There are few easy answers here.
In short, it sounds like you are advocating for an agency which can take arbitrary extralegal action at its own discretion, without providing reason or explanation, and without providing any demonstrable benefit to anybody, because it's secret.
Frankly, I find the idea terrifying. I understand that intelligence agencies need some quantity of secrecy and some degree of latitude. Like you have repeatedly stated, there are no easy answers. But that doesn't mean we shouldn't ask the question. What the hell are these people doing, and should we let them continue? What is growing in our intelligence sector -- is it an institution that will be found to have brought the world benefit, like Bletchley Park, or will it be seen to have become a thin facade over a malignant, self-interested organization, potentially culminating in something like a secret police?
I would argue that theoretically, a government (or other entity) could use intelligence but use it within a set of moral and/or ethical guidelines that uses a system of checks and balances.
Generally, intelligence cannot operate openly, even under a strict set of guidelines. Further, there will always be situations where efficacy runs into guidelines and something has to give. Would you be willing to violate the privacy of one person to prevent an attack that would kill five thousand? How about a dozen people's privacy? A hundred? A thousand? A million?
As I understand it, those aren't purely theoretical questions in the world of intelligence.
Why don't we skip the suggestive "thought experiments" and look at some facts instead.
A grand total of 3467 people in the USA have been killed by terror attacks since 1970[1].
In the same timeframe 2091 americans were killed by lightning strike[2] and roughly 102.000.000 died of old age.
Please explain how these numbers justify the NSA's yearly budget of $75 billion dollars, and their documented, ongoing violation of millions of people's privacy.
[1] http://www.start.umd.edu/gtd/search/Results.aspx?chart=fatal...
[2] http://en.wikipedia.org/wiki/Lightning_strike#Epidemiology
[3] http://money.cnn.com/2013/06/07/news/economy/nsa-surveillanc...
[4] https://firstlook.org/theintercept/2014/08/25/icreach-nsa-ci...
Can this claim be substantiated with evidence?
The idea that "spys gonna spy" is one we need to start collectively challenging. Why do we need these organisations at all? If NSA/GCHQ were wound up and their technical specialists re-allocated 80% to domestic law enforcement for computer forensics purposes, and 20% to a new dedicated counter-intel-only organisation, would the sky fall? I doubt it.
[1] - http://justsecurity.org/10311/michael-hayden-kill-people-bas...
But the means of doing so is truly questionable, even given all their assertions about trust us and we don't look at everyones stuff.
There's no such limitation on their activities outside of the U.S.
(Hence there is no reason to make an inference about what capabilities they would attempt to build out)
Anyway, this sucks because the Gemalto guys I did this with were to this day among the best vendors I've ever worked with. Really awesome guys, smart, and incredibly willing to share what they knew and did. And it's somewhat ironic that Gemalto are trusted by the UK MoD for sourcing their smart card components in Europe.
So much for keeping it local to avoid hacks.
Any centralized system is such a juicy target that the NSA will compromise it. The only way to avoid dragnet issues is to decentralize and force the NSA to expend resources at the edges.
This doesn't means that you can make an individual target secure. The NSA can always outspend you. But you can prevent the NSA from easily just vacuuming up everybody cheaply.
If that's true, then NSA/GCHQ aren't the only people who could have grabbed a big pile of keys.
Notably this mechanism would not protect the keys against an attacker who was inside Gemalto's or the customer's secure network, as seems to be the case here.
I'd be interested in knowing which keys specifically you are talking about.
Of course, there are lots of things I didn't have visibility on and it is possible that I am overly optimistic.
Information minimization and avoiding single points of failures could have prevented this.
My understanding is that the root of the SIM cards are always "owned" by the company sourcing them.
Great - on the open net. No 2FA visible in the first peek.
Way to fuck your customers customers privacy.
1. You get ignored.
2. Your boss (or coworkers) make you want to quit.
3. You get fired.
Intel really needs to figure out how to protect the SGX system against such a key robbery, and not by promising to only give access to a couple of employees in the whole company who know a very special hand-shake. Intel needs to modify the SGX system in such a way that you don't have to trust Intel (or anyone hacking Intel) to keep the key secure, even if that means the company not giving itself access to SGX at all (which includes not having the ability to update it).
[1] - http://blog.invisiblethings.org/2013/09/23/thoughts-on-intel...
But yes, any situation like this where you cannot be trusted means a hacker can gain a higher level of trust than you if they break the security.
By the way, very frequently the owner of a computer is not in fact trustworthy. Situations where that occurs crop up all the time in security engineering.
For example a big use of TC is making Bitcoin wallets that are secure against malware. There are other uses too, like safe outsourcing of private data storage/computation to the cloud.
It was one week ago that Obama was arguing that this kind of activity is necessary.
http://www.newyorker.com/business/currency/stanford-obama-ti...
This is not a republican/democrat problem. This is an institutional problem. We need comprehensive reform of both parties and it should be followed by a purging of the existing federal machine.
Remember times when the USofA wasn't adopting the smart card technology ? Well it had something to do with this chip technology (crypto) being a foreign technology which coincidently was the propriety of the French company Gemplus.
At the turn of the millenium an US investment funds (Texas Pacific Group) managed to find its way in Gemplus capital after a couple denials, which is the start what is known in France as l'affaire Gemplus. To summarize instead of helping to conquer the US market, TPG used its power to change the board of director (and choose Alex Mandl as the head), initiated rounds of layoff and moved the R&D to the US to take control of the sought after technology.
The whole thing is shown to be an operation of the C.I.A. through In-Q-Tel to take control of the chip card technology and possibly insert backdoors before exporting. Slow to react, it takes several years for the french government to create its own version of In-Q-Tel called "Fonds Stratégique d'Investissement" and try to reclaim Gemplus, now Gemalto, by becoming the majority stakeholder with 8% of shares in 2009, a move that happens too late and TPG having gotten what they wanted sells its share a year later.
And guess what, Gemalto merged with SafeNet the other day.
http://www.safenet-inc.com/SafeNet-Gemalto-Merger/
Everything is compromised. Everything!
References:
https://www.box.com/blog/breaking-the-last-barrier-to-cloud-...
http://www.safenet-inc.com/data-encryption/hardware-security...
https://www.fsf.org/blogs/community/replicant-developers-fin...
If you want more details you may check OsmocomBB site and IRC.
> Germany and France should have an interest that their communication can't be trivially backdoored by the NSA.
Nobody saying that governments don't have trusted hardware with only their own backdoors. In almost every country manufacturer have to provide source code and specs in order to pass certification so gov does have everything needed.
Though it's not help anybody else as it's will never be open.
This applies to mobile hotspots built around Qualcomm baseband/application processors, in other cases you would have to exploit the main CPU first.
You are still being tracked (GSM, wifi) and vulnerable to local hacks. Due to the nature of the devices (millions of identical devices are produced for major models), their distribution patterns (model selection led by fashion and price point), their homogeneity (two dominant embedded OS platforms only), their complexity (leading to a very large potential attack surface), and their ubiquitousness (your phone number, IMEI, local physical cell, or email address is probably terribly easy to find) it would be extremely foolhardy to rely upon the security of a modern, commercially available handset.
https://security.stackexchange.com/questions/42428/is-genera...
Statists are gonna state, I guess.
Anyway, you really think the "bad countries" you named from a 5-year-old document are an exhaustive list of what they've got today? You think the agencies won't scoop up any other countries' keys, including the United States', just in case their metadata graphs later suggest sleeper agents in "the good countries"?
I'm too ticked to make a good argument about morality or lack thereof right now, so I'll just leave it here. They hacked and surveilled non-terrorists to get the keys, and got the keys of at least one "non-terrorist country" (Iceland), so no, I don't find your argument convincing, and I think the parent post's point stands.
I don't dispute the fact that the US government has intelligence-gathering priorities that don't involve terrorism. I would argue that at least one reason terrorism is discussed is that there are diplomatic consequences to saying one spies on foreign governments. I also agree with the more cynical view, that terrorism is cited as a rationale because terrorism is scary and something opposed by everyone the US is trying to convince.
I believe very strongly that the world would be a lot safer if the US government knew certain things like the intentions of the Russian leadership and the capabilities of the Russian armed forces. Or the state of the Iranian nuclear program and that country's negotiating position. Or what exactly is happening on the ground in the midst of all the chaos in Libya or Syria or Yemen.
The answers to these questions will determine the fate of entire regions of the world.
*A subsequent document puts a later figure for Somalia at 300,000.
I don't know how far I'd be willing to go to effect a hypothetical, unknown increase in safety and control. I do know that the US government and its allies are destroying the reputations of innocent companies, the peace of mind of hundreds of Gemalto/network employees who will now be wondering if they were personally hacked and to what extent, and the human rights of privacy of hundreds of thousands of people who use SIM cards. Is it worth it? I guess we'll never know, and I don't think the spies can truly say either.
Maybe some of that falls on leakers' shoulders too, but in any case it's not very confidence-inspiring that lowly people like Manning and Snowden were able to steal what they did.
Did he really steal info on that many headline-worthy stories all in one go, or does he have fresh sources?
Sometimes this feels like another instance of what I call the "weird al phenomenon", where any person who hears a silly parody of a pop song attributes it to weird al, because "wait, you're telling me there are other song parody writers?"
1. Snowden
2. Unknown NSA leaker
3. Unknown National Counterterrorism Center (NCTC) leaker
It would make sense that NSA/GHCQ wouldn't want their foreign competitors to share in the prize, and it would also be congruent with their interests to not afford competing actors access to such a prize.
Then again, this notion is likely far too romantic. The reality is probably closer to one where foreign actors have compromised everything just the same.
Intelligence is wheels within wheels within wheels...
Aren't mind games fun?
Emphasis on can, of course.
On the other hand, good offensive capabilities, even if kept secret externally, are loud and flashy within the organisation, and come with lots of political capital beyond it.
Because of this asymmetry, I think it's almost impossible for an intelligence organisation to stop its "defense" mission being swallowed by the "attack" one. And so we all end up less free and less safe.
I do sometimes wonder what the world would be like if the NSA took it as its mission to secure the internet and chain of encryption, rather than constantly breaking it. If, for example, they used their resources to seek out vulnerabilities and exploits and fix them.
Maybe such a world is impossible. But I do think there's a valid space for a national cyber defense organisation that runs counter to this trend, that acts to shore up the infrastructure rather than constantly subverting it.
"GCHQ operatives identified key individuals and their positions within Gemalto and then dug into their emails. In one instance, GCHQ zeroed in on a Gemalto employee in Thailand who they observed sending PGP-encrypted files, noting that if GCHQ wanted to expand its Gemalto operations, “he would certainly be a good place to start.”"
> [GCHQ operatives] noted that the use of PGP could mean the contents were potentially valuable.
This good reminder that encrypting everything is important for security. Only encrypting valuable or sensitive information provides information to an attacker on where they should focus their efforts.
http://www.cso.com.au/mediareleases/21603/gemalto-releases-f...
I know that only 4% of US citizens have passports, and most countries rely on US trade, but still it would certainly send a message?
Simplistic I know but somehow we need to voice our dissatisfaction with the way things are headed. Foreign citizens can't change US policy, only US citizens can vote out their corrupted system.
The privacy of non-US citizens is considered as fair game. We have no comeback presently.
You're off by an order of magnitude. It's actually about 38% [0]. Bear in mind Americans even need a passport to travel to Canada or Mexico now.
I also do not think that preventing Americans from travelling abroad will improve their global perspective.
[0] http://travel.state.gov/content/passports/english/passports/...
Each member can undertake surveillance of the domestic communications of the other members, thus absolving the own-state surveillance apparatus from claims of domestic spying. But the poisoned fruit may be (and appears to be) freely shared.
I would think if anyone could work their way through the "standing" restrictions, it could be shown in court that the NSA violated the Constitution by receiving "stolen" surveillance data.
The reason why we have the 4th Amendment is not because the act of spying is feared (as egregious as that is), it's because of what the government might do with the results. So receiving the data violates at least the spirit of the constitution, and I would think the letter also.
But an organize "we'll spy on yours if you spy on ours" arrangement, particularly with a "don't ask for it, we'll just give it to you" understanding. That's violating the intent of legal and constitutional protections every which way.
At the same time, if a talent scout in North Whateveristan gets handed a sheaf of goatskins exfiltrated from the local TCP-over-parchment connectivity provider, the legality of that data's acquisition shouldn't be a hinderence.
But if North Whateveristan happens to be a friend and we're concerned with that the goatskins reveal, then breaking that information to the government (or other friends in slow places) should be possible at some level.
If there's a resolution by law in this, it's likely going to have to require explicit controls over how and when data of a given nation's nationals or residents is provided to that nation. And bars on mass transfers.
Perhaps mandating them outside intelligence services through diplomatic channels?
At least that'll give Wikileaks a sporting chance.
That is exactly my point. And it's horrible, it's the government thuggishly wiping its ass with the Constitution. East Germany would have swooned in ecstasy at all the intelligence porn collected by the NSA.
"Billing servers to suppress SMS billing"
were the GCHQ risking bankrupting the government because of abusive SMS billing from the telcos?[1] https://firstlook.org/theintercept/document/2015/02/19/cne-a...
> Additionally, the spy agency targeted unnamed cellular companies’ core networks, giving it access to “sales staff machines for customer information ...
So these corporations had customers' personal data stolen. I believe they're obligated to inform those customers, and possibly other obligations. (No direct knowledge, just spouting off what I've read during the Target and Home Depot breaches.)
I am every day more appalled by the scale of the data breaches we learn about every week.
While I agree in principle about open source, using purely open-source software would not have provided any defence here.
In open source software / hardware there wouldn't be "master key" that can't be changed and that have to be used by telecom's. Yeah of course no doubt NSA may penetrate in network of every of them, but it's would be a lot more costly.
Any architecture that requires pre-shared symmetric keys is going to have this problem. The fix is architectural, not open sourcing stuff. From what I understand LTE is significantly better.
I believe (maybe I'm wrong here) that the word wiretap comes precisely because people could literally "tap" into the wire and listen everything.
Or did I miss the sarcasm?
But then I saw your post and it made me think. And I believe you are onto something here.
I mean, sure, probably tapping one phone is much easier physically, just connect the wires and you're done. However the point you bring is game-changer.
In ye' olden days spooks were interested in certain persons only, but now it seems that we are all fair game, and so the "easy" way of wiretapping becomes incredibly hard when you want to spy on everyone.
It's basically an scalability problem then. Never saw it that way.
Even companies like AT&T, who you'd think with exorbitant prices would always pay for proper direct connections, actually try to find the cheapest bidder in any way possible. For some destinations, they might a list that's 20+ resellers deep.
In short, tapping major connectivity points is probably enough to capture a lot of calls even if you place them from a landline. (Not to mention there's no real security mindset in telecom at all.)
Internationally, it depends on what carrier they interconnect with and what they want. Generally speaking, I think Verizon will use more IP-based routes (usually to more expensive countries) then the other two.
By contrast, landline service coming from the cable company generally does go over voip, but only within their internal network. For local and inbound calls, it'll still hit some DSx trunks back to the phone network. 1+ long distance traffic, at least on Comcast, is definitely in IP format, and could very well even be hitting the public internet for least cost routing operations.
Now things are the opposite. It is easier to sweep up a bunch of local stuff in the form of cell phone calls but you need a physical connection to tap fibre..
With SS7, widely deployed in Europe and then the rest of the world, probing (tapping) was quite straight forward when the SP complied with local lawful intercept regulations.
So it's not that different, a bit easier, yes. But you still have to physically go there.
Deleted comment
That's different than collecting everyone'ss data and claiming you never look at it unless someone does something to loose their innocence. Orwellian nightmare that that is and probably bullshit, revelations along those lines are not surprising. The systematic targeting of the personal lives of random employees (at least of non-governmental/ non defense industry ones), is new.
Tell me again why I (or anyone else) should find the fact that you foresaw this outcome comforting -- or relevant at all.
> Rooms can be bugged.
Yeah but they need a warrant, it costs money to bug a room, and they can't decide to retroactively bug every room their target has ever been in. To make things concrete, do you really think none of these powers would have made a difference if they had had them back when they were trying to sink MLK's platform?