4 ms·
As a Belgian citizen (but not a criminal, as far as I know) I'm very interested to hear the HN community's take on this. The local press is saying no encryption
by LaundroMat 6y ago
As a Belgian citizen (but not a criminal, as far as I know) I'm very interested to hear the HN community's take on this. The local press is saying no encryption is safe for the police (anymore) and that it was Belgian law enforcement that was able to crack the encryption of the app the criminals were using.
I wonder if the press knows what it's talking about.
- swiley 6y agoLets see here: Not open source: check Not federated (so they can force you to update the client): check Integrates with carrier value add: check (SIM crap) Integrates with OS vendor value add: check Flashy website with third party requests to google.com: check Yeah this looks like crap to me.
- iorrus 6y agoWhat is federation in this context? Does not federated mean not using a jailbroken phone? Or is it related to how the app is installed? Or the underlying infrastructure relying on a central server instead of distributed?
- dboreham 6y agoFederated means everyone gets to pick which server they use, including one that's specific to just that one user.
- SV_BubbleTime 6y agoTo expand in case it isn’t clear... if you have a federated client it has to work to a standard, a backdoor at the client could be added on one app but probably not all the options. If you were trying to hack a system like this and they don’t use a federated client, the only option is the “official app” and authorities could have taken control of that, added a backdoor, and pushed it out as an update. This could still happen with any one or two or multiple federated apps, but the changes at a lot less likely this would go undetected.... then again... I have less faith in the “many eyes” theory of these things since HeartBleed was an OpenSSL flaw for years and that was open source no one ever noticed.
- swiley 6y agoOpen source is more of a minimum requirement not assurance of quality.
- tomc1985 6y agoMost likely Sky ECC had some kind of weakness or vulnerability that made it vulnerable to attack. Encryption is really hard, and one mistake can unravel all of your efforts. I doubt that a boutique shop like Sky ECC's owners had the resources to secure it as well as they claimed.
- iorrus 6y agoSeems crazy to do things this way. Why not use signal or telegram secure chat, get lost in the crowd
- unnouinceput 6y agoBecause Signal definitely will comply with a judge if given good reasons, like "here is a criminal organization using your app, help us dismantle it" and Telegram is the same as Signal with the exception is Russian. Also encryption is as good as its weakest link, in this case are humans. Probably police flipped some criminals to be informers and now it's running a smoke&mirrors campaign in media in order to send rest of criminals to make more mistakes. As for the ideal way to do organized crime the main ingredient is to own judges + police and you're set for life. From time to time let some minor transport get intercepted by your corrupt policemen, have some small fish get fried by your judge and stir waters for a few days in media in their favor. Maybe this news is exactly that and while the newspapers are reporting few millions captured you haul the rest of billions without a hiccup.
- deleted 6y ago[deleted]
- LockAndLol 6y agoSignal doesn't store the keys on their servers, nor do they know who is talking to whom. You should read up their protocol.
- joemazerino 6y agoNeither of those options provide revenue.
- WJW 6y agoFrom what I read in the Dutch news, they managed to crack about half the messages so far. That they haven't cracked them all indicates that it is not a vulnerability in the encryption itself. I suspect that the police managed to gain physical access to the servers and went from there. Opsec is really really hard. Fun, unrelated story: apparently some of the intelligence operations managed to get their hands on the laptop of a target while it was at some maintenance store to get the screen replaced. They managed to install a physical keylogger inside it with its own radio, but hooked up to the laptops power supply. This is the kind of shenanigans you have to be aware of and defend against when you run a service like Sky ECC. The slightest slip up and you are doomed.
- wiz21c 6y agoIt'd be nice a to have police officer talk about this :-) But is it me or police techniques such as gaining physical access to criminals, flipping them to informers, close surveillance, etc. continue to be very efficient even in the face of quite good technology ?
- sleepytimetea 6y agoLove the disclaimer ("but not a criminal, as far as I know"). Have you read those bizarre fake facts like "it is illegal to eat oranges in your bathtub in California" ? If you haven't, I am sure you have broken myriad weird laws like that and are, in fact, a criminal ! :-).
- ENOTTY 6y agoA great source of these for the US federal jurisdiction is the CrimeADay Twitter account https://twitter.com/crimeaday https://twitter.com/crimeaday
- joemazerino 6y agoWhen your client base is comprised of child traffickers, cocaine smugglers and murderers. A company that prides itself on hiding nefarious figures with little to no legitimate clients will surely find itself at the end of a LEO hack.
- shin_lao 6y agoIt is in their interest to make you believe they can crack anything. Not sure why they said they cracked this app, because now they lost a source of intelligence.