13 ms·
Anom Encrypted App Analysis
- Yeri 5y agoGuess this person was right :)
- 542458 5y agoYes, but also no. Right in that AN0M wasn’t secure. Wrong in that it wasn’t insecure because it didn’t disable Google services, or use secure updates or whatever - it was insecure because it just deliberately sent everything to the Feds.
- yawaworht1978 5y agoIt also phones home to a logging service. Why would an app like that keep logs.
- hn_throwaway_99 5y agoWell, this analysis specifically points out that the app is making connections to suspicious places where it shouldn't need to.
- bcraven 5y ago"STAY AWAY FROM ANOM IF YOU VALUE YOUR PRIVACY & SAFEY, THEY ARE COMPROMISED, LIARS AND YOUR DATA IS RUNNING VIA USA – Passed onto LAW ENFORCEMENT and other Entities"
- skissane 5y agoArchived versions: https://archive.is/jtJvK https://archive.is/jtJvK https://web.archive.org/web/20210608102417/https://webcache.googleusercontent.com/search?q=cache:bP-g6VgD1JcJ:https://anomexposed.wordpress.com/2021/03/29/anom-encrpted-scam-exposed/+&cd=1&hl=en&ct=clnk&gl=au https://web.archive.org/web/20210608102417/https://webcache.... (Since, as we all know, Google’s webcache won’t last)
- nix23 5y ago>Stock Android Operating system with special Enterprise level Encryption OHOOO Enterprise level encryption...FIPS :) Stay away from both.
- jeltz 5y agoIs there any reason to believe that CIPHR is not just yet another police honeypot? This could just be two police agencies shitting on each other's honeypots.
- zenexer 5y agoIf I were such an agency, I'd definitely have multiple honeypots competing with each other.
- sarnowski 5y agoI guess it’s related to https://www.europol.europa.eu/newsroom/news/800-criminals-arrested-in-biggest-ever-law-enforcement-operation-against-encrypted-communication https://www.europol.europa.eu/newsroom/news/800-criminals-ar...
- worldsayshi 5y agoMain (I think) hacker news thread regarding this event: https://news.ycombinator.com/item?id=27430508 https://news.ycombinator.com/item?id=27430508
- captainmuon 5y agoMaybe it is not normal, but when I read about these gangsterphones I think, hmm I want to make my own (legit) secure phone :-) It seems they use off-the-shelf phones and put a custom ROM on them. Can anybody recommend a state of the art phone that has good custom ROM support (close to mainline Linux if possible; custom images have full hardware support)? I imagine to use it for "citizen journalism", i.e. safely taking pictures and posting them anonymously to social media. For that reason the PinePhone would be out - it doesn't have a very good camera and doesn't run social media apps.
- merlinscholz 5y agoUsually Google Pixel phones have the best OS support and the most hardware security features. Most security focused Android distros are only available for them: https://grapheneos.org/faq#device-support https://grapheneos.org/faq#device-support
- willis936 5y agoPractically speaking, an iPhone is your best bet in terms of least likely to be backdoored and best security practices. Everything spooky like location services, tracking, phoning home, etc. is well explained in the settings and can be turned off. If you just want a secure hardware platform there is no reason to attempt to reinvent the wheel and increase your surface area. VPNs work fine on them. You can set up your own tor nodes to VPN in behind from another VPN, etc. A tinfoil hat can have many layers. It just won't be a cheap secondary burner toy phone because they're so expensive.
- GekkePrutser 5y agoThese gangsterphones are far from cheap. I remember the earlier network of them that was taken down in the Netherlands. I forget the name but the phones apparently cost around €2000 which is more than the most expensive iPhone you can buy. I guess gangsters only trust other shady types to sell them stuff. In this case the trust was misplaced because they stored all the keys centrally and the cops were listening in for months before they shut it down.
- layoutIfNeeded 5y ago"Encrypted Military Grade Encryption" - LOL
- emptyparadise 5y agoMust be the same military that puts nuclear secrets on flashcard websites
- GekkePrutser 5y agoThis 'analysis' seems to be more PR speak by another similar network? I wouldn't put much trust in people using terms such as 'ENTERPRISE MILITARY GRADE', of course in all caps to emphasize the effect. Has snake oil written all over it. I thought this article would be a genuine analysis by a security researcher as a tie-in to the news today:)
- hn_throwaway_99 5y agoI think you don't understand what is going on here. ANOM was just admitted by the Australian Police and FBI to have been specifically built to infiltrate organized crime. The whole app was a plot to get access to the messages of these purported criminals. This analysis came out a couple months ago, and was exactly correct. Also, you are blaming the style of the writing but ignoring the substance, which is that the app is most definitely making encrypted connections where it has no need to do so.
- thieving_magpie 5y agoNot to speak for them but I experienced the same feeling of interest in who the author was. For me it sounded like someone associated with CIPHR or another messaging application that did this analysis (still factual analysis) on a rival application. There was some marketing-type language in there that made me think that.
- GekkePrutser 5y agoI didn't know that when I wrote that, no. I thought it was the same story as EncroChat at the time (where an existing network was taken over by the police). I saw it in more detailed news reports since. The points might have been valid but the language is not instilling any kind of confidence: "This is an ENTERPRISE MILITARY GRADE Encrypted setup." doesn't exactly make it seem like a security researcher who knows what they're talking about. And add many other words capitalised for maximum shock effect: "imagine you were meeting up with someone like an EX-LOVER your partner may not approve of" It all sounds very much FUD and biased. If you do a good analysis, this is not how you present it. The main points he really makes are poor endpoint security (not uncommon in this market, as many such networks have been breached) and noticed some suspicious traffic which is indeed a telltale that something more is going on. But it sounds way too much like someone with 'skin in the game' was trying to spin it and turned out to be right.
- tomcooks 5y ago> "in ROMANIA which is a third world country" Classic. No matter how powerful the infrastructure or skilled the local personnel, some countries are doomed to be put always in the same bucket by certain people from certain other countries.
- vodkapump 5y agoCan't even use the "Clearly they were using the cold war era definition" excuse, as Romania would be a second world country by that definition.
- buran77 5y ago> a third world country that may state they take privacy seriously but as the old saying goes “shit walks, money talks” You didn't even have to read that much into the article to spot the ignorance. Whether by gun, "law", or money, there's no place where your data untouchable. But you could have stopped right here: > This is an ENTERPRISE MILITARY GRADE Encrypted setup. The famed "military encryption".
- pacman2 5y agoRomania is a very interesting place. An Bucharest, "The Paris of the East" must not be afraid compared to Prague or Budapest. Estonia, is a third world country. Total breakdown of any governmental admiistration, corrupt etc. (dont ask how I know)
- mads 5y agoHow do you know?
- pacman2 5y agoBecause I lost all my saving there and was dealing with 1. The Police 2. The Financial Supervision of Estonia and Madis Reimand (Head of Estonian Financial Intelligence Unit) Having worked for military and police enforcement in the US before, I can say with confidence: I you want to do a financial scam, do it in Estonia. Nobody will care. Seriously. (and dont worry, Madis knows who I am)
- yawaworht1978 5y agoWow, is this really all true? How could he find out the hosting was on AWS? How did none of the criminals get to see this blog? Did the police intervene and had him remove the blog?
- hn_throwaway_99 5y ago> How did none of the criminals get to see this blog? Did the police intervene and had him remove the blog? I mean, it's pretty clear to me that (a) criminals are highly unlikely to see this blog and (b) if they did, so what, they wouldn't have understood it/believed it anyway. Half the comments on HN don't give it any credence because it's written by someone whose first language is obviously not English and who likes hyperbolic ALL CAPS, despite the fact that the underlying analysis is valid.
- hkyigkfnrj 5y ago4D chess theory: This analysis was written by law enforcement in advance of the takedown to promote the next backdoored app.
- ______- 5y agoMaybe I'm missing something vital here, but why trust these `drug dealer` phones? What's wrong with using Signal on an encrypted Android device? Since the Encrochat scare I would imagine no dealer in their right mind would ever use a crimephone again.
- 9wzYQbTYsAIc 5y agoApparently there’s criminals that only trust other criminals (also apparently, those same criminals are highly likely to betray each other) and those trusted criminals are saying “use this phone, it’s secure”. Plus, managing DIY security is more complicated than just running Signal on an encrypted phone. Same concerns regarding supply chain interdiction, remote code execution, and other security vulnerabilities on the operating system running Signal.
- md_ 5y ago> Plus, managing DIY security is more complicated than just running Signal on an encrypted phone. Same concerns regarding supply chain interdiction, remote code execution, and other security vulnerabilities on the operating system running Signal. Yes, but specifically to supply chain security, as this attack shows, the most affordable option to secure your supply chain is to ensure your devices and downloads cannot be uniquely targeted. Buying a stock iPhone in cash and downloading Signal from the App Store is a far better approach than buying a "drug dealer phone." I do think this attack, as you imply, simply highlights how hard it is for even motivated consumers in the market to make actually secure choices, which in turn is why the market underemphasizes real security improvements.
- 9wzYQbTYsAIc 5y agoWell put, and I agree that right now the most effective thing would probably be to buy a stock iPhone, from a random source, in cash, etc. That said, one huge caveat: any stock, internet-connected phone is always one law away from being rendered completely transparent to law enforcement with legal jurisdiction over the place of sale. In the US, for example, Congress could write a law that forces a back door. The back door doesn’t even have to be to the encryption keys or algorithm, but could be a simple screen capture interface that can be remotely triggered with a warrant.
- thieving_magpie 5y agoI've never considered JIRA would be used by the FBI or intelligence agencies. The user stories would be fun to read. I wonder why this blog was deleted by the author. Get a phone call from the FBI?
- vmception 5y ago> STAY AWAY FROM ANOM IF YOU VALUE YOUR PRIVACY & SAFEY, THEY ARE COMPROMISED, LIARS AND YOUR DATA IS RUNNING VIA USA – Passed onto LAW ENFORCEMENT and other Entities
- na85 5y ago>This is an ENTERPRISE MILITARY GRADE Encrypted setup. I'll take "Signs someone doesn't know what they are talking about for 200, Alex"