12 ms·
Cracking of encrypted messaging service dealt major blow to organised crime
- LaundroMat 6y agoAs a Belgian citizen (but not a criminal, as far as I know) I'm very interested to hear the HN community's take on this. The local press is saying no encryption is safe for the police (anymore) and that it was Belgian law enforcement that was able to crack the encryption of the app the criminals were using. I wonder if the press knows what it's talking about.
- swiley 6y agoLets see here: Not open source: check Not federated (so they can force you to update the client): check Integrates with carrier value add: check (SIM crap) Integrates with OS vendor value add: check Flashy website with third party requests to google.com: check Yeah this looks like crap to me.
- iorrus 6y agoWhat is federation in this context? Does not federated mean not using a jailbroken phone? Or is it related to how the app is installed? Or the underlying infrastructure relying on a central server instead of distributed?
- dboreham 6y agoFederated means everyone gets to pick which server they use, including one that's specific to just that one user.
- SV_BubbleTime 6y agoTo expand in case it isn’t clear... if you have a federated client it has to work to a standard, a backdoor at the client could be added on one app but probably not all the options. If you were trying to hack a system like this and they don’t use a federated client, the only option is the “official app” and authorities could have taken control of that, added a backdoor, and pushed it out as an update. This could still happen with any one or two or multiple federated apps, but the changes at a lot less likely this would go undetected.... then again... I have less faith in the “many eyes” theory of these things since HeartBleed was an OpenSSL flaw for years and that was open source no one ever noticed.
- swiley 6y agoOpen source is more of a minimum requirement not assurance of quality.
- tomc1985 6y agoMost likely Sky ECC had some kind of weakness or vulnerability that made it vulnerable to attack. Encryption is really hard, and one mistake can unravel all of your efforts. I doubt that a boutique shop like Sky ECC's owners had the resources to secure it as well as they claimed.
- iorrus 6y agoSeems crazy to do things this way. Why not use signal or telegram secure chat, get lost in the crowd
- unnouinceput 6y agoBecause Signal definitely will comply with a judge if given good reasons, like "here is a criminal organization using your app, help us dismantle it" and Telegram is the same as Signal with the exception is Russian. Also encryption is as good as its weakest link, in this case are humans. Probably police flipped some criminals to be informers and now it's running a smoke&mirrors campaign in media in order to send rest of criminals to make more mistakes. As for the ideal way to do organized crime the main ingredient is to own judges + police and you're set for life. From time to time let some minor transport get intercepted by your corrupt policemen, have some small fish get fried by your judge and stir waters for a few days in media in their favor. Maybe this news is exactly that and while the newspapers are reporting few millions captured you haul the rest of billions without a hiccup.
- deleted 6y ago[deleted]
- LockAndLol 6y agoSignal doesn't store the keys on their servers, nor do they know who is talking to whom. You should read up their protocol.
- joemazerino 6y agoNeither of those options provide revenue.
- WJW 6y agoFrom what I read in the Dutch news, they managed to crack about half the messages so far. That they haven't cracked them all indicates that it is not a vulnerability in the encryption itself. I suspect that the police managed to gain physical access to the servers and went from there. Opsec is really really hard. Fun, unrelated story: apparently some of the intelligence operations managed to get their hands on the laptop of a target while it was at some maintenance store to get the screen replaced. They managed to install a physical keylogger inside it with its own radio, but hooked up to the laptops power supply. This is the kind of shenanigans you have to be aware of and defend against when you run a service like Sky ECC. The slightest slip up and you are doomed.
- wiz21c 6y agoIt'd be nice a to have police officer talk about this :-) But is it me or police techniques such as gaining physical access to criminals, flipping them to informers, close surveillance, etc. continue to be very efficient even in the face of quite good technology ?
- sleepytimetea 6y agoLove the disclaimer ("but not a criminal, as far as I know"). Have you read those bizarre fake facts like "it is illegal to eat oranges in your bathtub in California" ? If you haven't, I am sure you have broken myriad weird laws like that and are, in fact, a criminal ! :-).
- ENOTTY 6y agoA great source of these for the US federal jurisdiction is the CrimeADay Twitter account https://twitter.com/crimeaday https://twitter.com/crimeaday
- joemazerino 6y agoWhen your client base is comprised of child traffickers, cocaine smugglers and murderers. A company that prides itself on hiding nefarious figures with little to no legitimate clients will surely find itself at the end of a LEO hack.
- shin_lao 6y agoIt is in their interest to make you believe they can crack anything. Not sure why they said they cracked this app, because now they lost a source of intelligence.
- doublextremevil 6y agowhy would anyone use this over something like signal?
- er4hn 6y agoAt a guess - flashier marketing sold to consumers who don't know better.
- vecinu 6y agoAnother likely scenario, people who do "underground" things prefer using not so popular tools to evade authorities but that may prove to have the opposite effect if they're not built robustly.
- wp381640 6y agoThe devices do more than signal since they remove GPS, microphones, have a custom OS and provide anonymous burner SIMs on a subscription Most of these hacks are the equivalent of hacking signal and backdooring the software This shit is hard especially when LE is determined, but criminal syndicates aren’t dumb and hire a lot of smart people
- topynate 6y ago> since they remove GPS, microphones, have a custom OS and provide anonymous burner SIMs on a subscription That is, do a bunch of crap that will immediately make you stand out to any modern (by which I mean, total) surveillance agency. The syndicates' problem isn't stupidity but immodesty – typical of organized crime. They thought they were, not smart, but the smartest, and that made it easy for other criminals to sell them garbage security products.
- wp381640 6y agoFrom a network perspective it’s indistinguishable from a 4G hotspot The devices are also heavily rotated, they can also have IMEI numbers updated To date with all of the public breach details it’s always been humint that lead to the networks being taken down
- headmelted 6y agoI’m a little surprised they would choose to advertise the fact that they’ve been able to gain access to this traffic. Surely disclosing that will just have driven the same users to other apps and they’ll have to start from scratch (and presumably get lucky again in the future)?
- goatsi 6y agoThey have to disclose the source of information to be able to use it in criminal cases. >Surely disclosing that will just have driven the same users to other apps and they’ll have to start from scratch From the sounds of it this app had already been cracked when the Eurochat bust was announced, allowing them to scoop up all the users who tried to just move to the next alternative. I imagine trust in the "secure communications for criminals" ecosystem will be low for a while. Police did a similar thing with darknet markets, they secretly took control of the second largest (Hansa) and then publicly announced the bust of the largest (Alphabay). They ran it for a month, collecting all the information (and money) they could (even pulling tricks like deleting all the images so drug vendors might accidentally reupload ones with EXIF data) before shutting it down. All the better to erode trust in the entire ecosystem.
- kingsloi 6y agoI had just read about Dutch meth. That's one thing I never thought I would hear about, Dutch meth. However, a Breaking Bad European spin off would be interesting.
- samatman 6y agoNot quite Breaking Bad, because it comes at the story from the other direction, but there's a German show on Netflix called How To Sell Drugs Online (Fast), which is pretty entertaining so far. I expect if the series lasts long enough they'll work the storyline up to manufacture.
- kazen44 6y agoUndercover[1] is a dutch series depicting a pretty common scenario. The south of the country supplies a majority of the world in xtc. [2] [1]https://en.wikipedia.org/wiki/Undercover_(2019_TV_series) https://en.wikipedia.org/wiki/Undercover_(2019_TV_series) [2] https://i.redd.it/v31h0g7tnhc51.jpg https://i.redd.it/v31h0g7tnhc51.jpg
- jacquesm 6y agoAfter Encrochat you'd think they would wise up, this is pretty much a re-run.
- iudqnolq 6y agoI enjoyed this snark, but I wonder if they're actually legally entitled to it. > Sky ECC promised a 5 million USD (€4.2 million) prize on its website, which is currently down, to anyone who could crack its encryption. > It is not yet clear if Belgian authorities plan to claim the reward.
- LorenPechtel 6y agoMost of the time it's not actually cracking the encryption that breaks these things.
- tgragnato 6y agoTheir website talks about 521bit ECDH, but that’s necessarily part of the key agreement protocol. Confusing the KEX with the encryption itself “521-ECC encryption”, does not inspire much confidence.
- wmf 6y agoThose companies never pay out anyway.
- iudqnolq 6y agoStill, it would be a fun lawsuit
- asperous 6y agoDemonstrates what I've heard before as a warning about those cracking bounties. If someone is able to break it, is it more valuable for them to claim the reward or exploit it? Especially when the crack could be sold to or done by government actors.
- ricardobayes 6y agoChange my mind on this, but in countries with freedom of speech, the only reason to have this much 'privacy' is if you're doing something shady. Again, looking for a conversation here. edit: By 'this much' I mean going extreme lengths to secure privacy, the online equivalent of using a numbered swiss bank account. Nice discussion so far, thoroughly enjoying it. I don't mind the dislikes, if that makes your day better, dislike away.
- black6 6y agoNot sure of the provenance of the quote, but I heard it from Steve Gibson: "I don't have anything to hide when I'm using the toilet, but I still like my privacy when doing so."
- unnouinceput 6y agoExactly this, +1. I definitely have nothing to hide but I really don't want my photos of my kids to end up in some dark web location used by pedophiles, just because google is an idiot and let it slip while backed my photos without my consent in their cloud (true story, I had to fight 3 months to have that backup deleted from their server).
- yakz 6y agoThe key word in what you wrote is "shady" because that word is going to be open to interpretation by the enforcers who are almost certainly corrupt to some extent. So, it's better to just limit the power of the enforcers as much as possible (in other words, the maximum limit that you can convince your society to allow).
- abstractbarista 6y agoDo you have blinds on your windows?
- ricardobayes 6y agoInteresting point. In the Netherlands, many houses don't have curtains, you can see directly into the living room from the street. It stems from the old tradition of wives being accountable when their husbands were at sea. I learned from your comment (perceived) privacy is also cultural.
- upofadown 6y ago>Sky ECC promised a 5 million USD (€4.2 million) prize on its website, which is currently down, to anyone who could crack its encryption. > >It is not yet clear if Belgian authorities plan to claim the reward. For the EncroChat takedown they didn't crack the encryption. They instead flipped an employee who cooperated in the installation of a remote access Trojan on all the phones. Are they actually claiming they did something different here?
- deleted 6y ago[deleted]
- joemazerino 6y agoSource for the trojan/employee flipping claim?
- upofadown 6y agoThe Trojan angle is pretty solid because EncroChat was at one point fighting malware on the phone[1]. Not so much for the insider angle so I was probably thinking of another case. Too late to edit unfortunately... [1] https://en.wikipedia.org/wiki/EncroChat#Infiltration https://en.wikipedia.org/wiki/EncroChat#Infiltration
- neves 6y agoThe belief in encrypted message apps is a gold mine. In Brazil, the former president Lula has been convicted to jail. A hacker broke Telegram and got the messages that demonstrated a conspiracy between the judge and the prosecution: https://www.wired.com/story/brazil-hacker-bolsonaro-car-wash-leaks/ https://www.wired.com/story/brazil-hacker-bolsonaro-car-wash... The conviction prevented him to run for office (he was the favorite in the polls). Yesterday the ex-president got his political rights back and will probably be candidate in 2022 to try to defeat Bolsonaro. Everything due to the hacker (And the journalist Glenn Greenwald of Snowden fame)
- matthewdgreen 6y ago>The belief in encrypted message apps is a gold mine. I think you mean "the belief that non-E2E encrypted messaging apps are actually E2E-encrypted messaging apps" is a goldmine. Ditto TFA. Real E2E systems aren't invulnerable: there are certainly hacks that target endpoint devices. But it's astonishing to me how many people end up using centralized, non-E2E apps when secure ones are available.
- dr_dshiv 6y agoOMG I had no idea. Thank you. I am a news junkie. I can't believe I missed all that?!
- neves 6y agoAnyone wanting to know more about the case, can read this just published Glenn Greenwald's article: https://greenwald.substack.com/p/brazils-high-court-invalidates-lulas?token=eyJ1c2VyX2lkIjo0MjcxNjc1LCJwb3N0X2lkIjozMzQ1Njg4MiwiXyI6IjFjQ1VYIiwiaWF0IjoxNjE1MzgxMzE1LCJleHAiOjE2MTUzODQ5MTUsImlzcyI6InB1Yi0xMjg2NjIiLCJzdWIiOiJwb3N0LXJlYWN0aW9uIn0.2opEhf-mX0cURCDOBFtXqQbEguZGFpIDJS5eTFvZVUc&utm_source=substack&utm_medium=email&utm_content=share https://greenwald.substack.com/p/brazils-high-court-invalida...
- matheusmoreira 6y agoEnd-to-end encryption protects against interception. No encryption will help you if your phone is compromised since the data is just sitting there in the clear. The judge may have been compromised but there are also cases where brazilian judges retaliated against WhatsApp when it failed to deliver decrypted messages: https://theintercept.com/2016/05/02/whatsapp-used-by-100-million-brazilians-was-shut-down-nationwide-today-by-a-single-judge/ https://theintercept.com/2016/05/02/whatsapp-used-by-100-mil...
- deleted 6y ago[deleted]
- fitblipper 6y ago>It defended its services, stating they “strongly believe that privacy is a fundamental human right.” > But critics say more than 90% of its customers are criminals. How do the critics know? This appears to be an attack on privacy. The implied idea is that personal communication for all should be published at least to law enforcement so law enforcement can do a better job of finding the baddies.
- PoignardAzur 6y agoGiven that the app has features like "delete messages after 30 seconds" and "enter a panic password to delete all your data", a 90% drug-dealer/political-activist ratio doesn't seem far-fetched to me. If you build an anti-witch-hunt app, most of your clients will be witches.
- zionic 6y agoHow do you know even 1% of their users use that function? If Facebook adds that feature tomorrow do billions suddenly become criminals? You assume just because the feature exists the clientele are using it.
- salawat 6y agoOne is not caused by the other, and reality never ceases to surprise. Though with the monetization model, I will admit, they surgically targeted their demographic. Besides which, stop marginalizing the 5 civil libertarians you insensitive clod. (The Aphorism goes: Make a country where witch hunts are illegal, then the population will be 5 civil minded libertarians and a million witches). Of course nobody wants to discuss that the 5 civil minded libertarians might have a point, and the unsaid snicker that reverbrates in the ensuing silence is that if you make something easier, you select for it, therefore one should not make undesirable things easier. Therefore the implication is left that the one being persuaded is too dim to realize the consequences of their decision. This goes completely out the window when one takes into account that there may be a legitimate, though unpleasant need to tolerate the existence of something unpleasant due to the greater damage that could result from doing something drastic. Fun and hilarity only continue to escalate from here. The wise would be well advised to simply move on.
- usernamebias 6y agoIf you visit the app's website, you get this big popup. ------------- Sky ECC platform remains secure and our authorized devices have not been hacked. There have been recent news articles that claim Sky ECC has been hacked and is involved in criminal activity. This information is not accurate. We have looked into these claims and discovered that a small group of individuals illegally created and distributed an unauthorized version of Sky ECC which they modified and side-loaded onto unsecure devices. Security features that come standard with the Sky ECC phones were eliminated in these bogus devices. Sky ECC considers these actions as malicious and we are taking legal action against these individuals for defamation and fraud. We have also blocked these users from our system and enhanced security to prevent reoccurrence of this issue. The implementation of these enhancements temporarily interrupted our Sky ECC service which has now been re-established. We continue to stand by our position and our product. We strongly support that people have the fundamental right to privacy. With the extensive and broadly documented rise worldwide of corporate espionage, cybercrime and malicious data breaches, systems like SKY ECC are the foundation of the effective functioning for many industries including legal professionals, public health providers and vaccine supply chains, celebrities, manufacturers and many more. We believe that the individual right to privacy is paramount for those who are acting within the law and we do not condone the use of our product for criminal activity. We also have our Terms of Service that every user must adhere to and, provided that they do, our company will work feverishly to protect their rights with the world's most secure platform. ------------ Thoughts?
- ALittleLight 6y ago"It didn't happen but we're taking steps to make sure it doesn't happen again" doesn't seem like a consistent message.
- stubish 6y agoSounds like they are attempting to stop the unauthorized/compromised versions from working with legit versions, or some sort of validation routine such as keys only provided to the client if installed via legit means and passes some sort of local audit (yes, all defeatable, but making the process harder).
- filleokus 6y agoMaybe I'm overconfident in the security of an up-to-date iOS device with a complex passcode, but I would have just used Signal if I was tasked with running the IT ops of some crime syndicate. Turn of all cloudy functions, hell maybe use some kind of enterprise MDM to enforce polices on your subordinates.
- dgellow 6y agoSignal is bound to a phone number, no? I think I would go with OTR via XMPP, or whatever is a modern protocol. Or maybe Matrix is now a good alternative? I didn’t use OTR since a long time now, so not sure if that’s still a good choice, but it’s quite versatile and easy to setup. Edit: OTR doesn’t seem to be recommended anymore, OMEMO seems to be the modern alternative https://en.wikipedia.org/wiki/OMEMO https://en.wikipedia.org/wiki/OMEMO
- deleted 6y ago[deleted]
- thepangolino 6y agoIsn’t OTR protocol Indeoendent? I remember using it even through Facebook via Pidgin. OMEMO seems tied to XMPP.
- upofadown 6y agoThe OMEMO killer feature is that it can deal with clients that are offline. Unfortunately it needs access to cryptographic state stored on a server to do that. So it can't be used in a generic way like OTR. In the case of OMEMO it uses a generic XMPP persistent data feature to store that state. So OMEMO causes a requirement for a particular feature enabled on the server ... which is slightly tacky in the XMPP world.
- MattJ100 6y agoFor the record this feature is a pretty core part of many things in XMPP, and is enabled on 98% of this sample of 670 servers: https://compliance.conversations.im/test/xep0163/ https://compliance.conversations.im/test/xep0163/ The ones without it are mostly special cases (e.g. gmail.com is on the list, of course).
- cybert00th 6y ago>But critics say more than 90% of its customers are criminals. They're a bit thin on the details of exactly who those critics are, which makes that statement inadmissible other than for us to draw the inference that the critics are law enforcement agencies - or worse still, governments. Don't get me wrong, I'm not condoning the misuse of encrypted messaging, only pointing out the convenient straw man that's been erected here to manipulate readers' emotions in order to short-circuit their ability to think critically about what's ACTUALLY been done by the authorities.
- pentaphobe 6y agoCompletely agree on all points - it also kind of buries the lead with regard to the rather cliche false equivalency Up there with [cash is used for bad things, so we should ban cash](https://www.businessinsider.com.au/why-cash-should-be-illegal-2015-3?r=US&IR=T https://www.businessinsider.com.au/why-cash-should-be-illega...)
- bobbylarrybobby 6y agoFYI https://www.merriam-webster.com/words-at-play/bury-the-lede-versus-lead https://www.merriam-webster.com/words-at-play/bury-the-lede-...
- pentaphobe 6y agooh wow - thanks! I'll remember this next time I'm feeling haughty about common malapropisms :-|
- buran77 6y agoIt's the typical "think of the children" or "but the terrorists" approach. Everyone is treated like a criminal because some of them could be. Calling the users "criminals" makes it harder to defend them at first glance because the first reaction is "you're defending criminals". And attaching a number to this, even an impossible to support statistic, is meant to make the statement more believable, everyone likes nice, round numbers. Of course they hope nobody raises the not so obvious points. Even taking that statement at face value (which you definitely should not) what about the other 10% non-criminals whose privacy was violated without any reasonable cause? Where else are they using the excuse that 90% success rate is acceptable? If 90% is enough to paint everyone with the same brush, when 90% of users are not criminals why aren't the other 10% also treated as innocent too? In reality just about 100% of "critics" saying this are law enforcement agencies or governments who will violate your rights or break the law in a heartbeat if it means getting their way.
- boringg 6y ago17 tonnes of cocaine - thats a crazy amount.
- pfundstein 6y agoWhat will the authorities do with the 15 tonnes of cocaine to dispose of it? Incinerate?
- csense 6y agoAny technical info on how the app was compromised? If I worked for the government and I wanted to break into an app, I'd simply send a letter to the app store saying "Yeah you have to post this app update that contains code written by government hackers to leak the keys / messages of (investigation targets | everyone). If you don't, your executives / employees will (be sent to jail | be kidnapped by black ops forces, shot, and buried in an unmarked grave). Ditto if you tell anyone about this letter."
- Crosseye_Jack 6y agoNot 100% sure about the iOS side of things (my guess is because App Store apps are signed by Apple and you can get a new dev cert issued to you from Apple, Apple could sign what ever app the 3 letter agency supplied them. But but someone will notice that there was a new update and it wouldn’t take long before news of which would get back to the devs, same would also apply to Android), On Android you used to have to sign your apps yourself before uploading them to the play store. The store wouldn’t accept an app signed with a different key. Even if you bypassed that (by sideloading the app for example) the OS would still refuse to update the app. It was fairly common to see on Android dev forums people posting “I’ve lost my signing key, what do I do?” To he told they gotta upload under a different package name and hope their existing users would migrate over to the “new app” Now these days Google offer to hold your signing keys for you (cause if you lose your keys you lose the ability to update the app) and if you want to use Googles App Bundle ability you have to opt in (because Google repackage your app for different device types automatically) but you are still free to hold the keys yourself and sign your builds without Google taking a peak at them. Opting into App Bundles for an existing app requires you to upload your existing signing key, so Google can sign on your behalf and devices with your existing app will accept the updates Google’s bundle process produce. Now of cause Google could push some updates to Android as a whole and make a back door to bypass app sig checking, but that would be opening holes on a lot of devices, most of which won’t actually be your target. And if we are going to go down the road of back roofing OS’s to allow apps from unknown keys, might as well just back door the OS and skip the process of creating a fake update for that one app. Now if the app is using Google’s App Bundle feature, it would be possible. But if you were creating a “secure messaging app” why would you hand the keys to the kingdom to anyone else? Just write some extra build scripts, compile the different builds your self and keep those security brownie points.
- smitty1e 6y agoBottom line is that, were I ever interested in double hush-hush activities, I'd use a one-time pad[1]. If it's digital, you have little control. [1] https://en.wikipedia.org/wiki/One-time_pad https://en.wikipedia.org/wiki/One-time_pad
- breischl 6y agoEasier said than done. Read the "Key distribution" section of that page.
- ALittleLight 6y agoProvided you sometimes meet your fellow criminals in person, or you have deaddrops or runners who can distribute things for you, you could just hand out a terabyte+ harddrive worth of pads every once in a while.
- smitty1e 6y agoDepends upon on how dire your second-story work is, I suppose.
- WalterBright 6y agoAs Admiral Doenitz found out, never ever assume your encryption is unbreakable. I'd have used one-time pads in conjunction with Enigma.
- TwoBit 6y agoHmm, Sky ECC says they weren't cracked but rather some users were tricked into using a faked version of it: https://finance.yahoo.com/news/sky-ecc-platform-remains-secure-044100200.html https://finance.yahoo.com/news/sky-ecc-platform-remains-secu...
- freebuju 6y ago> Sky ECC promised a 5 million USD (€4.2 million) prize on its website, which is currently down, to anyone who could crack its encryption. It is not yet clear if Belgian authorities plan to claim the reward This tongue-in-cheek comment made me chuckle. Anyway, Hail hydra. Another one will take its place soon enough.