19 ms·
Hundreds arrested as crime chat network cracked
- boffinism 6y agoIs there anywhere we can learn more about EncroChat? Google took me to http://encrophone.com/ http://encrophone.com/ which is now 403ing
- codegladiator 6y agoBing gives correct result https://encrochat.us/ https://encrochat.us/
- lol768 6y agoI don't quite understand how this worked and the article is thin on details - was there not E2E encryption between the participants? > Our servers are node based and located all over the world; all input and output are true end-to-end encrypted. The Servers only initiate the tunnel. Their own statement suggests a zero-day? > Today we had our domains seized illegally by government entities. They repurposed our domain to launch an attack to compromise carbon units. > With control of our domain they managed to launch a malware campaign against the carbon to weaken its security.
- kemiller2002 6y agoHere is a link from another HN post. It explains a little about it from my quick scanning: https://www.vice.com/en_us/article/3aza95/how-police-took-over-encrochat-hacked https://www.vice.com/en_us/article/3aza95/how-police-took-ov...
- dmix 6y ago> French authorities had penetrated the Encrochat network, leveraged that access to install a technical tool in what appears to be a mass hacking operation, and had been quietly reading the users' communications for months. Sounds like their servers got popped, probably ones distributing updates, and also sounds like hand rolled crypto from their website although that doesn’t mean much if they can access the devices.
- jrexilius 6y agoThat's a good summary.
- zzzcpan 6y agoBreaking "hand rolled" crypto is a very hypothetical threat, almost a non-existent threat, as in practice software with centralizedly controlled distribution model has many much much bigger weaknesses that advanced threat actors are going to exploit, like updates. Assuming they even can successfully break such crypto at scale, imagine how much effort would it take just to get to the encrypted bytes given all the VPNs, TOR and overlay networks providing extra layers of encryption and privacy/anonymity hiding who talks to whom by sending packet through other countries. I guess what people should learn from this is that encryption isn't a protection without solving problems caused by centralization first.
- angry_octet 6y agoWell, I wouldn't say that's true, hand rolled crypto notoriously is weak when your adversary has cryptographers... like governments. And this system sounds extremely snake-oily, and likely making typical bad crypto mistakes everywhere.
- Cthulhu_ 6y agoThe other article I read about this is that law enforcement compromised the service's servers and pushed an update to the clients, making them send unencrypted messages, which allowed law enforcement to read them as they came through in real time.
- moduspol 6y agoDevil's advocate: Is there evidence law enforcement didn't start and run the project from the beginning? If they did, I wouldn't expect them to come out and acknowledge it. I'm similarly skeptical of popular VPN apps.
- chippy 6y agoHumans are often the weak link here. The most common scenario is that the police had some control over the project due to a compromised person. I'd wager that the police did not start the project, but soon after it was being used for crime, they took over it. I'm not sure it's possible to me to develop and run something with the assumption that even if I turned police intelligence asset, that the product would be untouched. Open source would help, and some kind of distributed, decentralised thing maybe
- moduspol 6y agoI agree. That seems more likely. I doubt we'll be told, but I'd be interested in the specifics. It seems like it might have ethical implications to take over it without the blessing of the owner(s) of the company. After all, I doubt they will be able to get many more customers now that it's widely known that it was compromised by law enforcement. Arguably law enforcement destroyed this company, which the owners might normally not be happy about. It may be as simple as: the business wasn't making money and the owners wanted out, so law enforcement bought it or paid them off. Then law enforcement isn't really "compromising" the company--they're in control of it (whether the employees know or not). At that point they can have the existing devs modify it however they want, or just hire a few new devs.
- rbrtl 6y ago
- paulie_a 6y agoSome government comms such as areas including disaster relief and simple police dispatch are end to end Thalw problem is the key is transmitted in dtmf or other means in the clear. I am not sure what my local pd uses for encryption but I'm guessing it's outdated. You can set the tornado sirens off with a small transmitter and recording the very consistent tone pattern of you wanted. The worrisome thing is that cops use their cellphones instead, which is much more secure but also is used accidentally or purposefully to avoid public records.
- angry_octet 6y agoPolice dispatch might be encrypted but not very well. https://www.mattblaze.org/blog/p25 https://www.mattblaze.org/blog/p25 It's actually worse than clear text radio in many ways. All cellphone call meta data and all SMSes are recorded, so while it avoids people listening in scanners and the public record it isn't very confidential. It's police using WhatsApp and Signal that will cause big problems.
- WJW 6y agoThe Dutch news mentions the police managed to snoop on the messages "before they were encrypted", so I assume they managed to hijack the app update process and installed a keylogger or something.
- secfirstmd 6y agoThis story is surprising as there were rumours about 18 months ago that EncroChat had been vulnerable. Esp when other similar services had been taken down and targeted. Random side story: Governments have become much more aware of the purposes of these sorts of phones and seller. About 18 months ago I was asked to meet with the sales people from a specialist phone company like this one, they were interested in selling them to the NGO/journalist market. I'm always happy to chat and test the utility of interesting security tech and compare versus more common setups (locked down phones, Signal etc). I've met a load of these sort of companies at trade shows etc as I'm sure many here have but they wanted to meet in person as they were in town talking to various potential clients. The product was decent enough but way beyond the price of anyone in the sector would be able to afford. Anyways the guys were nice and I genuinely didn't get a sense they particularly up to anything bad... However when I left the meeting (in a European capital) I had physical surveillance all over me. Not a particularly good team, hence I detected them. Totally caught me by surprise. Ran a hastily arranged surveillance detection route and managed to confirm a few (no doubt there may have been more). At first I thought it might be the company I had met doing it to me for some weird reason. However as I thought through the tactics, people profile and operational reason for doing it to me I can only assume that whoever the local police were had been watching closely anyone who was meeting with the secure phone providers (they were foreign to the country in question, so probably came under more suspicion). No doubt this was because of the connection between a lot of these sort of companies and the criminal underworld. (Again, I didn't get the sense these particular sellers were up to no good, I just thought it was an interesting perspective)
- have_faith 6y ago> Ran a hastily arranged surveillance detection route What did this entail?
- trabant00 6y agoOfc we are going to get no details on how they managed to penetrate the network. The real question for me is how the criminals trusted the product.
- raxxorrax 6y agoAllegedly they captured the servers and compromised the clients through an update. The trust was probably due to not getting caught for a while.
- rollulus 6y agoDo I sense some Brexit here? The BBC article mentions "The NCA worked with forces across Europe on the UK's "biggest and most significant" law enforcement operation.", while the Joint Eurojust-Europol press release [1] doesn't mention the Brits at all, but calls it a Dutch / French operation. [1]: http://www.eurojust.europa.eu/press/PressReleases/Pages/2020/2020-07-02b.aspx http://www.eurojust.europa.eu/press/PressReleases/Pages/2020...
- JoeSmithson 6y agoIt was a joint operation lead by France/Netherlands but a very large number of the suspects were in the UK. This is a BBC article and focuses on the UK arrests.
- djmobley 6y agoFor what it’s worth, in an earlier statement to Vice, a company representative claimed the attacks appeared to originate from the UK. https://www.vice.com/amp/en_us/article/5dz9qx/encrochat-hacked-shutting-down-encrypted-phone https://www.vice.com/amp/en_us/article/5dz9qx/encrochat-hack...
- PoachedSausage 6y agoFrom Cheltenham perhaps?
- mellosouls 6y agoMore info: https://www.vice.com/en_us/article/3aza95/how-police-took-over-encrochat-hacked https://www.vice.com/en_us/article/3aza95/how-police-took-ov...
- crispyporkbites 6y agoThis contains some really interesting info. Basically someone (i.e. a government, likely the Dutch) managed to install malware on a bunch of the phones. Each phone only communicates with other phones in the network so once they got one zero-day and put malware on a phone and could spread it, it could spread very quickly.
- globular-toast 6y ago> Officers are said to have prevented people being murdered after covertly monitoring planned attacks and threats to life on the encrypted service. Now they can't do that any more. It's a dilemma that British intelligence faced a lot during the world wars: if they acted on information gleaned from secret channel it would reveal to the enemy that the channel was compromised. Makes me wonder how long they were monitoring and possibly letting crime take place before deciding that now was the time to strike.
- yomly 6y agoSame problem as planting an officer into a criminal org. Presumably the agent has to witness and commit crimes until they've infiltrated deeply enough for their mission
- JoeSmithson 6y agoEncroChat realised a couple of weeks ago and warned their customers https://www.vice.com/amp/en_us/article/5dz9qx/encrochat-hacked-shutting-down-encrypted-phone https://www.vice.com/amp/en_us/article/5dz9qx/encrochat-hack...
- makomk 6y agoNot just during the world wars. British intelligence apparently faced the same dilemma when infiltrating the IRA, and some of the results were quite ugly (look up Stakeknife if you're interested).
- secfirstmd 6y agoVery true. Though Stakeknife was also used in a way to remove hardline individuals seen as problematic to the more pragmatic parts of the Republican movement who were open to negotiate and protect other sources higher up. With obviously terrible consequences for many innocent people.
- trengorilla 6y agoThere's a podcast series called "Hunting Warhead" wich documents how the largest child abuse site (sadly had over a million members) was taken over by law enforcement. It turns out they carried on running the site for about a year, even posting child abuse images themselves as the admin to maintain legitimacy. Definitely a moral gray area there. Great podcast series but also made me feel sick and keeps creeping into my head periodically..
- rxsel 6y agoLooks like another episode in the failed war on drugs. While this may look “good” and someone will be able to say “look at those figures” in reality we’re addressing a side effect of a much deeper issue.
- neilsimp1 6y agoAm I happy guns are off the streets? Hell yes. Would I be happier with sane drug laws so as to not necessitate a black market? Double hell yes.
- scarface74 6y agoOk. Guns are off the street. It’s not like it’s not easy for criminals to get more guns.
- red_admiral 6y agoIn the UK specifically, it's definitely possible to get guns with the right connections, but it's not completely easy.
- crispyporkbites 6y agoIn the UK I can pick from 26k guns available here: https://www.guntrader.uk/ https://www.guntrader.uk/
- luckylion 6y agoThat wouldn't change anything regarding the guns or the amount of crime - career criminals don't do it because they believe in selling drugs, they sell drugs because it's an easy way to make money. In that regard: keeping a black market for drugs may even be a good thing. Otherwise they'd move on to other ventures that might be more harmful, kidnapping, murder for hire etc.
- yboris 6y ago
- orthoxerox 6y agoIf we mentally replace criminals with dissidents and France/Britain with PRC, what could EncroChat have done differently to shulield its users?
- red_admiral 6y agoIf the adversary controls the phone network and the baseband processor - not much. If only a small percentage of the population buys encro phones, it might even be worthwhile for the authorities to log and plot all their movements and interactions, all the time. Even without breaking encryption, the traffic analysis alone would give valuable insights.
- draugadrotten 6y agoCompartmentalize into small groups aka cells. It is centralizing around EncroChat which was the mistake here. All the eggs in one basket will always carry this type of risk. There is also another difference. Drug dealers usually wants to get rich, and have no real interest in any larger cause than their own profit. Dissidents are sometimes willing to sacrifice themselves for the larger cause. What is important for such a dissident is not that nobody gets caught, but that the events are beneficial for the cause and that certain key individuals are protected. Even martyrdom is useful for a dissident, but rarely to a drug dealer. Dissidents should keep working in cells to minimize the risk of discovery. The drop hollows the stone is the working principle for dissidents. The most influential dissident may have a very small network of contacts but with a large fan-out a few layers down. This tactic is for example how Bin Ladin was able to stay in hiding, he was meeting very few people and it was hard to find him because of that even when he was the top target.
- secfirstmd 6y agoIn reality the nature of drug dealing would make it tricky to implement a cell structure. If you look at the IRA, implementing it meant in theory it was very hard for one cell to know another and only certain parts would supply arms, intelligence etc. This resulted in a drop in attacks for a long time because of the difficulties in keeping to that. Though it did of course decrease infiltration for awhile. Until the UK found the weaknesses and targeted those who had permission to oversee and deal with everything - the internal security section and leadership. Drugs is a much more dynamic industry where are some points there is a need for a lot of contact, travel, managing big groups of individuals...Not that it couldn't work that way but it would be very hard when people are out making money all day rather then at home in a dissident sense waiting months/years until a short/fast operation.
- Fiveplus 6y agoClaims of said encrochat: * Each message session with each contact is encrypted with a different set of keys. If any given key is ever compromised, it will never result in the compromise of previously transmitted messages – or even passive observation of future messages. * Anyone can forge messages after a conversation is complete to make them look like they came from you. However, during a conversation the recipient is assured all messages received are authentic and unmodified. This assures non-reputability of messages. * The algorithms employed are many times stronger than that of PGP (RSA+AES). We employ algorithms from different families of mathematics, which protects message content in the event that one encryption algorithm is ever solved. * Messages do not employ digital signatures that provide third party proofs. However, you are still assured you are messaging with whom you think you are. source: https://encrochat.us/ https://encrochat.us/
- fredley 6y ago> We employ algorithms from different families of mathematics Did they roll their own?
- 0xFluegel 6y agoCould also simply mean that they are chaining different encryption algos from libraries (à la TrueCrypt) which would indeed add to the security level or even at worst not harm it. (This assumes that each step is not broken...)
- alias_neo 6y agoIt's unclear, but that statement alone makes me shudder. Anyone doing secure comms at this level, and is talking about families of mathematics always gives me the impression they don't really know what they're doing.
- 0xFluegel 6y ago> Anyone doing secure comms at this level, and is talking about families of mathematics always gives me the impression they don't really know what they're doing. Why is that? Do you assume that making competent choices for encryption algorithms (for which you try to understand the math problems involved) and trying to market the systems security means that they also try to implement it themselves? Or is the "family of mathematics" a sign for incompetence that I just don't recognize?
- nujabe 6y agoDumb question....but would they have been better off using Signal? Assuming a burner sim for registration.
- jrexilius 6y agoyes, if they could keep shuffling physical phones and sims with high frequency. But that is _serious_ operational drag and discipline. Professionals can't generally manage that at scale. We're talking criminals here..
- nujabe 6y agoWhy would they have to change sims? IIRC Signal only requires a number for UX purposes, numbers are never stored on their servers.
- kybernetikos 6y agoSignal is installed from the platform stores, which have the ability to push updates. As far as we can tell, the compromise was done via a pushed update. It's likely that Signal wouldn't have helped.
- cesarb 6y agoOn Android, I recall that updates to a package must be signed by the same key as the package being updated, otherwise the device itself will reject the update. Doesn't that mean that only the Signal developers (who are the ones who signed the original package) would be able to create a compromised update?
- kybernetikos 6y agoThat is likely what happened in this situation (although I don't have details).
- tda 6y agoSome more backgrounds: https://alarmeringen.nl/gelderland/well-gelderland/123823-live-acces-to-criminals-in-the-netherlands.html https://alarmeringen.nl/gelderland/well-gelderland/123823-li... Not sure if it was the Dutch or French police that did the actual hack, anyone have details on this? Apparently the investigation was code named 26Lemont
- alibert 6y agoThe Europa article links to this document in French: http://www.eurojust.europa.eu/press/Documents/2020-07-02_EncroChat-investigation-in-France_FR.pdf http://www.eurojust.europa.eu/press/Documents/2020-07-02_Enc... Some parts: > "Dès 2017, les téléphones utilisant le moyen de communication sécurisée EncroChat sont détectés par le département Informatique Électronique (INL) de l'Institut de Recherche Criminelle de la Gendarmerie Nationale (IRCGN)" First device using EncroChat were discovered in 2017. > "La JIRS de Lille s'est saisie de l'enquête sur la solution de communication chiffrée EncroChat à raison de la localisation de serveurs en assurant le fonctionnement." Special section JIRS in France was mandated to investigate because the servers used by EncroChat were hosted in the north region of France. > "un dispositif dont la conception et le fonctionnement sont couverts par le secret de la défense nationale, mais qui a été reçu et déployé par un service habilité par la loi pour ce faire, le Service Central de Renseignement Criminel de la Gendarmerie Nationale (SCRC) du Pôle Judiciaire de la Gendarmerie Nationale (PJGN) en application de l’article D15-1-6 du Code de procédure pénale." The "device" (not necessarily a hardware device) used to intercept coms are classified but was "received" and "deployed" by "Service Central de Renseignement Criminel de la Gendarmerie Nationale". So it was deployed by French police but it's not clear if they made it.
- unnouinceput 6y agoAnd the obvious conclusion, if you're a criminal, is that don't rely on others to encrypt your comms. Either go with classic PGP or make your own layers (as Schneier puts it). But criminals are usually just dumb in regards to this, they are only "street smart". Those who are "intellectual smart" don't do it. Or if they do they don't get caught until they jump over the horse (see the current scandal with 2 billions "siphoned")
- StavrosK 6y ago> don't rely on others to encrypt your comms. Either go with classic PGP or make your own layers You're saying "don't rely on others to encrypt your comms" and then the very next sentence says "use something someone else has made". Those two are conflicting. "Making your own" is even worse, because cryptographers don't usually have to resort to crime.
- trabant00 6y agoThere is making encryption tools and then there is using them. "don't rely on others to encrypt your comms" means don't let others use encryption on your behalf, it means encrypt it yourself. It also does not mean to make your own encryption tool. So your comment parent meant use a reputable tool yourself. And I would agree with that.
- StavrosK 6y agoI'm not sure what you mean. They were using a tool that encrypted their communications, it just wasn't good. What's the difference between using Signal and using what they were using, or using GPG and what they were using?
- red_admiral 6y agoIf the attack was that the NCA compromised a server and then pushed an update, then using Signal would buy you that you have people of the calibre, reputation and public platform size of the Signal developers in charge of protecting the servers. Moxie going on twitter to say the cops have broken into Signal would be headline news, at least in the tech world.
- pjc50 6y agoThis is going to make arguing against EARN-IT a lot harder just now.
- jacquesm 6y agoNo, it actually weakens it.
- AHappyCamper 6y agoIs it just me or does the timing of this story seem a little fishy considering the EARN IT act that US Senators are trying to push through? https://foundation.mozilla.org/en/campaigns/oppose-earn-it-act/ https://foundation.mozilla.org/en/campaigns/oppose-earn-it-a...
- rollulus 6y agoI'd say the contrary: isn't this a prime example of how law enforcement can work around encryption without weakening encryption in general by law?
- soulofmischief 6y agoIt's a shaky argument, because ideally these systems would be so secure that they wouldn't be able to have done what they did. They relied on human error and that seems like a bad excuse to penetrate a system.
- moomin 6y agoYes, but I'm not sure we should be giving up real rights to imagined threats. In practice, what encryption systems do is make it sufficiently inconvenient to steam open our letters that the authorities only do it with motivation. The only real case for some of these proposed laws is "we don't want to employ specialists in this field" not "these systems are uncrackable".
- red_admiral 6y agoOr: we want the full firehose of data, and then we want to employ Machine Learning specialists. ML is apparently magic.
- treis 6y agoThe motivation driving these laws is E2E encryption that if implemented correctly are uncrackable. Today, pretty much everything is encrypted but since the provider has the keys they can access the messages. E2E encryption shifts the keys to the user which means that the provider has no access to the content of the message. They are theoretically uncrackable without the user's secret and when it's Apple, Google, Facebook, et.al. implementing the system and not some 2 bit criminal operation it will be uncrackable in practice.
- ColanR 6y agoGiven the care with which the software was built, I wonder if the hardware itself was compromised. The open hardware folks always talk about the insecurity of the closed hardware in phones; I wonder if any official narrative discussing a software exploit is simply a parallel construction. [1] [1] https://en.wikipedia.org/wiki/Parallel_construction https://en.wikipedia.org/wiki/Parallel_construction
- deleted 6y ago[deleted]
- jacobush 6y agoYeah, I wonder too. I had Cyanogenmod on a very old Android phone, and after a while messaging started to act up in strange ways. The paranoid side of me started to weigh different explanations against each other, and one would be a compromised base band processor which tried to do something to the Android side, but failing, since it was no longer the vendor image it (hypothetically) was expecting to manipulate. Security is tricky and must be designed in depth and a mistrust of all layers. If the hardware is designed such that the baseband the main CPU are not separated by a communications channel, all can be lost if one does not control the baseband firmware too. (For instance if the baseband processor has shared memory access, that's a problem. If it's just a data interface, treat the baseband processor as a hostile network.) In my case, the likelier cause was probably something buggy in the Cyanogenmod image, or, while still unlikely but less so than baseband exploit, that the Android side itself had gotten some kind of virus because of some kind of security flaw in that particular Cyanogenmod version.
- bladegash 6y agoI think even more likely, is that EncroChat employees and/or the company itself were compromised.
- jrexilius 6y agoThe article makes mention of using their network to deliver an exploit. It could have been software, firmware, or hardware related. I'm guessing one of the existing zero-days that they hadn't patched yet. Once the end device is compromised the encryption used doesn't really matter as keys and plain text can be intercepted by the kernel. How they got access to the network for delivery is likely via the company itself. A knowingly or unknowingly compromised employee as mentioned seems the most likely.
- onetimemanytime 6y agoToo risky to use such services,. As soon as they become too big, they have nation state resources thrown at them...and they're without Google or FB resources to defend. If all else fails, DEA-like agencies can easily offer employees millions of dollars for keys or assistance to plant bugs, offer immunity and so on. Very hard to resist.
- cynusx 6y agoIt's interesting that law enforcement can hack it but eventually they have to burn the network because they have to make arrests using the information. They should buy/hack all these companies and then run false flag operations to hide the fact they own the comms. Like the germans never realized that enigma was hacked
- onetimemanytime 6y agoThey do it but at some point they have to arrest...and warn Johnny that he will be killed this Saturday.
- PoachedSausage 6y agoThese tactics are as old as international drug smuggling itself. Howard Marks(Mr Nice)[0] says in his book that he stationed one of his associates in Amsterdam to operate as a communications node, he finds out later that the Dutch police had tapped the phone lines within weeks. [0]https://en.wikipedia.org/wiki/Howard_Marks https://en.wikipedia.org/wiki/Howard_Marks
- sillysaurusx 6y agoIf you wanted to get into the criminal drug trade, how would you start? Is there a guide somewhere I can follow? $13M in cash is an impressive amount. It makes me wonder: There must be all kinds of operations happening around us daily, yet nobody knows about them. And those operations need members. Where do they come from? The inner workings of this stuff is fascinating. To be honest, I wish it were possible to go observe the system in action as a spectator. I'd love to see how the packaging is done, the supply lines, the transport logistics... (I balance this with a deep hatred for cartels. If you trace these questions far enough, it seems to often lead to "the cartels are at the center of it all." And they're responsible for unspeakable miseries.) To be clear, my question is: how is the knowledge necessary for such operations preserved? I'm a programmer. I learned it from the internet. Where do they learn? And these aren't street dealers. It's an organized, carefully designed, well-oiled machine. How does this machine work? How does it survive the loss of so many members?
- Apofis 6y agoThere's a ton of "inside look" type videos on Vice on YouTube if you're interested. Try a "{any drug name} vice" query.
- red_admiral 6y agoYou would join an existing organisation, as you'd have no chance setting yourself up as a "startup" - existing gangs would not take kindly to someone trying to disrupt their business.
- reedwolf 6y agoThe criminal world offers a fascinating glimpse into what pure, unrestrained capitalism would look like. If we look at what trading corporations do in times and places where they can get away with it, we see: -Aggressive acquisition of natural resources to protect the supply chain -Use of armed force to gather and protect said natural resources and the geographic territory wherein they're contained. -Use of armed force to protect and expand market capitalization (markets, trade routes etc) This is pretty much identical to what a drug cartel does on a day-to-day basis.
- lifeisstillgood 6y agoThe amazing thing here is this was a perfect piece of viral marketing - one criminal presumably recommending / refusing to do business without another one buying a new phone. But it also has huge knock on effects - I mean there are 60,000 people identified on here - and they won't be the bottom level of crime organisations. I don't have a clear number but this must be a large chunk of all established criminal networks in huge numbers of countries. Seems to me the level of competition has dropped in the criminal industry - VC opportunity perhaps :-)
- londons_explore 6y agoMight encrochat and its shareholders have a case against various european governments here? Are they supposed to simply accept that the government will hack into their servers and users devices with no compensation?
- consp 6y agoConsidering they operated in France and the Netherlands and even 'had a shop there' (whatever that means): Yes, but looking at all the articles I'm pretty sure they are also building a case against EncroChat for participating or actively facilitating criminal behavior, in which case the point is mute anyway. Some requests can be made to ask you participate making you sort-of free of prosecution as you are cooperating, but I doubt they would do that with companies with shady structures and owners.
- hhp1771611da90 6y agoIt's moot
- thu2111 6y agoEncroChat is not an app you get from an app store. It came with the EncroPhone, which are physical Androids you rent for some absurdly high price (like $3000/year-ish). And EncroPhone didn't sell online. You had to get them via a reseller i.e. someone you knew, or they had a few physical stores in the Netherlands.
- jacquesm 6y agoThey're lucky if they don't end up being named as enablers / accomplices, or dead if their customers catch up with them.
- multjoy 6y agoLol, ‘shareholders’
- nelaboras 6y agoAh yes, you caught us supporting a drug network with 60k members, we will sue you for harming our business.
- praptak 6y agoI guess the lesson here is clear: don't overrely on technology. There are tried and tested methods for running a covert organisation and they all rely on organisational resilience rather than ultra clever tech. Also, don't reuse channels - actual intelligence operations failed because of breaking this rule.
- dillonmckay 6y agoThis sounds like a plot device from the most recent season of West World.
- reedwolf 6y agoA few years ago I decided that all of the encryption in the world isn't going to protect you from state-actors. Even if your software is perfectly implemented (it won't be), your hardware is mostly a black box.
- jrexilius 6y agoComplex systems are the core problem. Hardware, firmware, third-parties and black boxes all over, live updates, OS, apps, network, etc. etc. The upside is that it also makes them hetergeneous which is more difficult to roll en masse.
- JoeAltmaier 6y agoConfused: OP says the service was taken down. That seems the most significant part of this action, even beyond the criminal arrests. Is an encrypted communications company liable/responsible if criminals use their product? Surely there were many, many legitimate users e.g. lawyers, business negotiators, lovers. Can the 'bad apples' be laid on the communication company's doorstep? If so, why not Facebook, Zoom or even Apple? Why is HN not addressing this point? Instead of speculating about criminal activities etc.
- bladegash 6y agoIt’s hard to say. At least in the U.S., there has been some precedent relatively recently where companies knowingly facilitating criminal activity can be subject to prosecution. They could probably argue that they didn’t have access to the the contents of communications so they were unaware of the criminal activities. However, they (it’s unclear if it was resellers or the company doing this) actively marketed to criminals, via ad placements on websites known to be used for criminal activity. Needless to say, it’s a pretty complicated situation in terms of liability.
- JoeAltmaier 6y agoSee? The websites "known to be used for criminal activity" we ok somehow, but not this company. Were the ISP or site hosting organizations shut down? Why not? And selling communications equipment to a criminal - maybe they wanted to talk to their sweetie without being monitored. They also bought a bagel and took a taxi ride. Is the bagel store shut down too? The taxi company? There's lots to talk about here.
- bladegash 6y agoI think there needs to be a certain level of reasonableness when tracing back liability. I mean, why stop at the ISPs? Why not take it all the way up to RIPE for allocating IPs to the company? Or how about the telecommunication companies that used government allocated RF spectrum to facilitate the communications. In that case, the telecoms and the Government(s) themselves should be liable. As for people wanting to talk to their sweetie without being monitored, I believe authorities have already said people who were using the services for legitimate purposes may request to have their communications excluded from any legal proceedings and naturally, won't be prosecuted just for using the devices.
- Allower 6y ago"Criminal drug trade" This is a fake problem created by governments as an excuse to brutalize and oppress particular members of society. Its stunting human evolution and should be considered treasonous to facilitate such policies
- jacquesm 6y agoYou're only hearing about this now because the cat was out of the bag as of a couple of weeks. If not for that the data gathering would have continued and more people would have been caught.
- gruez 6y ago>EncroChat sold encrypted phones with a guarantee of anonymity, with a range of special features to remove identifying information. The phones themselves cost roughly £900 (€1,000) each, with a subscription costing £1,350 (€1,500) for six months. That's a pretty pricey for what's basically a chat app. Is there a reason why they were able to command such a high price even though there are plenty of free/open source solutions on the internet? Marketing? Trust? Criminals thinking more $$$ = better?
- Nightshaxx 6y agoWhen you have a ton of money and you aren't super Technically savy, you don't always make the right decisions.
- draugadrotten 6y agoScreen shot of EncroChat message claiming authorities seized their domain names and compromised their "carbon" units with malware. https://twitter.com/Borisuithetbos/status/1271730179958865920?s=20 https://twitter.com/Borisuithetbos/status/127173017995886592...
- Nextgrid 6y agoSeems like they didn't sign software updates with an offline key and relied on the transport (TLS via the domain) to authenticate them. If they used an offline key (GPG?) to sign updates, a compromised transport wouldn't have allowed an attacker to deploy malicious updates to the devices. That's exactly how most Linux distributions operate, the mirrors themselves are untrusted and packages are often fetched via unencrypted HTTP, but that doesn't matter because the signatures are checked independently of the transport.
- deleted 6y ago[deleted]
- crispyporkbites 6y agoNow that Encrochat is gone, if anyone fancies playing ethical hacker: - buy one of these https://omertadigital.com/collections/frontpage/products/the-signature-magnum-opus-ultimate-privacy-package-with-encrypted-smartphone-sim-card-mobile-data?variant=33265453596808 https://omertadigital.com/collections/frontpage/products/the... - find a zero day - install malware - ??? - Profit!
- ur-whale 6y ago"several dozen guns"
- alistproducer2 6y agoThe moral of the story is there's no such thing as plug and play opsec. It requires thought, patience and domain knowledge. You can't outsource it because that contractor becomes your immediate and obvious weak link and will be compromised. Whether it's El Chapo's IT guys or fools who thought a cell phone company would keep them out of prison, this story just repeats itself.
- charwalker 6y agoExactly like The Wire plot with burner phones. As soon as compromised phones made it into rotation, they were sunk.
- upofadown 6y agoThese days messaging security pretty much comes down to end point security ... and end point security is terrible. If you want to be sure you have to do some sort of air gapping, either with something like a Yubikey, or even better, with a dedicated device with a screen and keyboard.
- ximeng 6y agohttps://www.vice.com/en_us/article/wjwbmm/inside-the-phone-company-secretly-run-by-drug-traffickers https://www.vice.com/en_us/article/wjwbmm/inside-the-phone-c... this is another crazy story about links between secure phone companies and organised crime including torture and murder
- thu2111 6y agoPredicted a few weeks ago, before any news of this came out: https://moderncrypto.org/mail-archive/messaging/2020/002586.html https://moderncrypto.org/mail-archive/messaging/2020/002586....
- zelly 6y agoAnyone got a copy of the APK? Let's decompile it
- ccvannorman 6y agoI wish more HN threads were of this particular flavor! [insert "can we run DooM on it?" joke]
- ideals 6y agoDecember 2017 - encrochat hacked https://encrochathacked.wordpress.com/2017/12/09/encrochat-hacked/ https://encrochathacked.wordpress.com/2017/12/09/encrochat-h... https://www.vice.com/en_us/article/mbpyea/encrochat-secure-phone-hacking-video https://www.vice.com/en_us/article/mbpyea/encrochat-secure-p... The writing was on the wall and is was ignored
- vivekd 6y agoThe article says the encryption was cracked on April 1st but apparently a whistleblower said that the police used a warrant to get access to the company's infrastructure back in March - which suggests to me that the whole "cracked encryption" story might not be fully legitimate https://medium.com/@fordnic/evidence-suggests-encrochat-is-working-with-the-nsa-and-other-authorities-281bfd05ed9e https://medium.com/@fordnic/evidence-suggests-encrochat-is-w...
- kjaftaedi 6y agoThe encryption was likely 'cracked' by gaining access to the infrastructure and then putting something in place to view the encrypted traffic. .. changing keys to a known value, pushing out a custom software update, etc.
- deleted 6y ago[deleted]
- bobdole12345 6y agoI think the take home message is: Police had a way to intercept these communications, but they managed to have that information leaked before they could finish their operation, only managing success because it was already too late for most of the participants. Sort of illustrates the futility of giving the police keys to access communications, when the number of times they pull this off without a leak is near zero.