7 ms·
Police raids across Europe after encrypted phone network shut down
- rubatuga 6y agoLol they probably would have been caught sooner if they used PGP
- swiley 6y agoPGP is known to have worked for at least a handful of people and it's easy (comparatively) for normal people to understand the dangers of using. These smartphone apps have spent orders of magnitude less time under attack, are often closed source, often integrate OS vendor and carrier value add in ways that make them weak, and their centralized and closed nature makes forcing both en mass and targeted key exfiltration updates on users trivial. There are zero secure messaging smartphone apps and there never will be unless smartphones substantially change.
- temptemptemp111 6y agoWire + GrapheneOS isn't secure? Security experts seem to be above justifying their claims 99% of the time these days.
- noir_lord 6y ago> There are zero secure messaging smartphone apps and there never will be unless smartphones substantially change. Agreed - if you really wanted to make a (more) secure messaging device then you wouldn't base it on a phone to start with.
- chmod775 6y agoThis article is so full of vague information and flat-out wrong information, I recommend reading another one. It reads like it's written by someone who skimmed three other news articles without really comprehending what's going on, then wrote whatever. Police never "shut down" Sky ECC, especially not prior to the raid.
- sva_ 6y agoThis article is quite interesting https://www.politico.eu/article/cryptophone-firm-dismisses-belgian-claims-of-cracked-drug-traffickers-messages/ https://www.politico.eu/article/cryptophone-firm-dismisses-b... Sky ECC denies the breach (see also [0]): > "a fake phishing application falsely branded as Sky ECC was illegally created, modified and side-loaded onto unsecure devices" The belgian police claims: > Sky ECC's claims were "bullshit." > So confident were the police that they broke Sky ECC's code, they said they sent the firm their bank account details to claim a $5 million (€4.2 million) bug bounty Sky ECC promised to pay out to security researchers that had managed it. Quite ballsy. > “The work is only starting,” a spokesperson for the Belgian judicial police had said Tuesday, adding that many more investigations were likely to follow as the decrypted messages yielded more leads. I don't see why they'd give those criminals this notice to prepare. I'd assume a bunch of surprise house-visits would be more effective, if they have all this info. The story smells somewhat fishy from both ends. Good drama though. If they really breached Sky ECC's security, they should be able to prove this by solving a cryptographic challenge by them. [0] https://www.skyecc.com/sky-ecc-platform-remains-secure-and-no-authorized-sky-ecc-device-has-been-hacked/ https://www.skyecc.com/sky-ecc-platform-remains-secure-and-n...
- kc0bfv 6y agoIn a cop show, they'd bust everyone they could with the info they have. Then they'd say something publicly like, "the work is only starting", to make the folks they can't bust nervous enough to do something stupid. The Galaxy brain move is maybe to realize that this news will cause the crims to move to a new network, and to have one waiting for them. E:sp
- throwaway0a5e 6y agoIn the levels of government of which the bureaucrats and appointees in charge of this operation are a part creating grandiose publicity for career purposes with no intention of following through and every intention of leaving it for the next guy to mop up is far more common than "galaxy brain" moves.
- 6y ago
- captainmuon 6y agoReading about this, I wonder if there is a market for legitimate secure phones, i.e. not marketed towards criminals. Businesses are afraid of industrial espionage. Political activists are afraid of persecution (and yes, it can also happen in the west, even if you are doing "good" things and are non-violent). The defenses in both cases can be quite different. For some people, a cheap Chromebook that you can wipe quickly plus 2FA gives great security, or using a modern (encrypted) phone with Signal. But what if you are, say, protesting against the construction of a new Google campus on top of your neighborhood? Then you'd don't want all your secret stuff on their infrastructure. Normally you assume everybody is playing fair, but it would be so easy for them to push out a malicious update to your phone to gather dirt on you. If one has experience with AOSP and security, there seems to be a market for an open, secure phone. But I wonder how you'd keep the organized crime out, or at least keep plausible deniability to not get into trouble...
- yrgulation 6y agoI dont even need a legitimate secure phone. All i want is a phone where i can install debian or any linux flavour, just like on a regular pc or a raspberry pi. There are too few options that allow for it and are quite low spec. Once we gain such freedom then we can get the security we want the way we want - not security as defined and controlled by a third party.
- ttt0 6y agoThat'd definitely be an improvement, but you still have backdoors on your CPU brought to you by Intel(tm).
- mPReDiToR 6y agoThe only closed (and staying closed) part of the PinePhone is the FCC regulated part of the modem. If someone wanted to make a modem with no binary blobs we could have fully Open hardware in toto. There's the opportunity to make Linux programs scalable to small screens right now; that's a big part of the dev time currently.
- 6y ago
- JustFinishedBSG 6y agoAgain ? After Encrochat[1], Criminals in Netherland/France/Belgium are really the dumbest around. I mean, good for us ? Fool me once, shame on me, fool me twice... [1] https://en.wikipedia.org/wiki/EncroChat https://en.wikipedia.org/wiki/EncroChat
- cyberlab 6y agoI don't see how the latest iPhone with Signal installed and a text-based diceware passphrase for locking it would be inferior to EncroChat. You can even turn on a feature that resets the phone to factory settings once ten wrong tries have occurred.
- deleted 6y ago[deleted]
- Despacito2019 6y agoOr perhaps the dutch/french/belgium cops are smarter than the average one ? or maybe the reason is because there is a large platform of drug traffic in those areas compared to others..
- aliyfarah 6y agoThis may be a dumb question, but is there any reason why these crime groups don't just use Signal? I understand a phone number is required upon registration but a burner sim could be used and discarded for that purpose.
- collaborative 6y agoIt's not a dumb question at all. I bet you that 99% of criminals already use Signal. These ones were dumb enough not to use it and got caught If you want a Signal-like app that doesn't need a phone number you can use www.groupsapp.online
- years3500 6y agoYou should have disclosed that groupsapp is your app. How's it better than signal in terms of security other than not requiring phone number? How is the E2EE implemented? Is it open source?
- collaborative 6y agoIndeed, I disclose here that I am the developer. It's not better or worse, it's different. You can see a list of features in the link, that should be better than me writing them here (main security pluses are: doesn't read from phone book, email can be masked, sent messages can be deleted even after having been read, and there is a self-destruct mechanism) E2EE is implemented with RSA+AES. iOS uses keychain and CommonCrypto. Android uses a modified BouncyCastles. I'll probably open source the code once I've figured out the licensing details
- years3500 6y agoThank you.
- collaborative 6y agoWelcome :)