17 ms·
A brief history of the U.S. trying to add backdoors into encrypted data (2016)
- hunglee2 3y agothe biggest threat to a citizens privacy is always your own government.
- BLKNSLVR 3y agoYep. I use Chinese brand phones because if they're snooping all my shit, they're much further away from me than my own government and not likely to have sharing arrangements.
- aspenmayer 3y agoWouldn’t Chinese branded phones be a higher priority target by foreign agencies in the first place?
- BLKNSLVR 3y agoIt's likely an additional data point in some kind of 'suspicious' rating. I think I hit quite a few of those 'suspicious' check-boxes that law enforcement would consider important, whilst actually technically knowledgeable people wouldn't even blink at them. Refer: https://news.ycombinator.com/item?id=39050898 https://news.ycombinator.com/item?id=39050898
- AtlasBarfed 3y agoI kinda disagree, because the government, even now, can be shamed and outraged. Corporations however? They are, by design, utterly amoral. So the modern state is that corporations are hoovering all your data they can for "ad research and optimization". I think I read recently that facebook has thousands of companies involved in the customer data supply chain? And if those companies have your data, it's not that YOUR government has it guaranteed. It's that ALL governments have your data.
- loughnane 3y agoThis topic comes up a bunch still. Someone please correct me, but as I understand it anyone using new chips that use Intel ME (or AMD's equivalent) have a gaping hole in their security that no OS can patch. I know puri.sm[0] takes some steps to try to plug the hole, but haven't read up to see if it's effective or no. [0] https://puri.sm/learn/intel-me/ https://puri.sm/learn/intel-me/
- bri3d 3y ago> anyone using new chips that use Intel ME (or AMD's equivalent) have a gaping hole in their security that no OS can patch Not really; anyone using chips with Intel ME or AMD PSP have an additional large binary blob running on their system which may or may not contain bugs or backdoors (of course, also realizing a sufficiently bad bug is indistinguishable from a backdoor). There are tens to hundreds of such blobs running on almost any modern system and these are just one example. I would argue that ME and PSP are not the worst blob on many systems; they have both unsupported but almost certainly effective (MEcleaner / ME code removal), supported and almost certainly effective (HAP bit), or supported and likely effective (ME / PSP disable command) mechanisms to disable their functionality, and they are comparatively well-documented versus the firmware that runs on every other peripheral (networking, GPU, etc.) and comparatively hardened versus EFI.
- loughnane 3y agoYeah, this lives in the back of my mind too. I run debian on 11th gen intel, but with the non-free blobs included to make life easier. I've been meaning to try it without them, but it's too tempting to just get things 'up' instead of hacking on it.
- mistrial9 3y agoDebian has been hacked by Intel's blobs from my point of view
- matheusmoreira 3y agoThere's little we can do about it short of running ancient libreboot computers. We'll never be truly free until we have the technology to manufacture free computer chips at home, just like we can make free software at home.
- hn8305823 3y agoIn case anyone is wondering about the context for this 2016 article, it was right after the 2015 San Bernardino attack and the FBI was trying to get into one of the attacker's phones. Apple resisted the request primarily because they wanted a certificate that would allow them to install any rogue firmware/app/OS on any iPhone, not just the attacker's. https://en.wikipedia.org/wiki/2015_San_Bernardino_attack https://en.wikipedia.org/wiki/2015_San_Bernardino_attack
- KennyBlanken 3y agoThe FBI has used damn near every major incident to push for nerfing encryption, and inbetween they bray about child porn.
- coppsilgold 3y agoFBI director James Comey have publicly lobbied for the insertion of cryptographic “backdoors” into software and hardware to allow law enforcement agencies to bypass authentication and access a suspect’s data surreptitiously. Cybersecurity experts have unanimously condemned the idea, pointing out that such backdoors would fundamentally undermine encryption and could exploited by criminals, among other issues. "could exploited by criminals" is sadly a disingenuous claim. A cryptographic backdoor is presumably a "Sealed Box"[1] type construct (KEM + symmetric-cipher-encrypted package). As long as the government can keep a private key secure only they could make use of it. There are plenty of reasons not to tolerate such a backdoor, but using false claims only provides potential ammunition to the opposition. [1] <https://libsodium.gitbook.io/doc/public-key_cryptography/sealed_boxes https://libsodium.gitbook.io/doc/public-key_cryptography/sea...>
- 2OEH8eoCRo0 3y agoAnd Apple has a backdoor that only Apple can use. Why don't criminals exploit Apple's backdoor?
- catlifeonmars 3y agoFWIW this is a fair and valid argument. Generally, no one entity should have that much power. Doesn’t really matter if it’s USG or a tech giant.
- frickinLasers 3y agohttps://arstechnica.com/security/2023/12/exploit-used-in-mass-iphone-infection-campaign-targeted-secret-hardware-feature/ https://arstechnica.com/security/2023/12/exploit-used-in-mas... Looks like criminals were using it for four years undetected.
- quickslowdown 3y agoWhich backdoor do you mean? I'm not an Apple expert by any means, but I thought they encrypted customer data in a way that even they can't get to it? Wasn't that the crux of this case, that Apple couldn't help the FBI due to security measures, prompting the agency to ask for a backdoor?
- dupertrooper 3y ago[flagged]
- progbits 3y agoAs this is from 2016 it doesn't include this new fun revelation: > On 11 February 2020, The Washington Post, ZDF and SRF revealed that Crypto AG was secretly owned by the CIA in a highly classified partnership with West German intelligence, and the spy agencies could easily break the codes used to send encrypted messages. https://en.m.wikipedia.org/wiki/Crypto_AG https://en.m.wikipedia.org/wiki/Crypto_AG
- hedora 3y agoMore details here: https://web.archive.org/web/20200212014117/https://www.washingtonpost.com/graphics/2020/world/national-security/cia-crypto-encryption-machines-espionage/ https://web.archive.org/web/20200212014117/https://www.washi...
- pgeorgi 3y agoThe CIA/BND connection wasn't known, but the collusion with certain agencies was known to different degrees for decades: https://en.wikipedia.org/w/index.php?title=Crypto_AG&oldid=751958423 https://en.wikipedia.org/w/index.php?title=Crypto_AG&oldid=7...
- lcnPylGDnU4H9OF 3y agoConsidering that I remember reading the CIA’s own historical document on this operation, I would guess its usefulness had run its course. If I’m not mistaken, it was the CIA who released the document to journalists; it seemed like bragging.
- _kbh_ 3y agoTo add another dimension to this, personally i think that the Crypto AG relationship is what is referred to as "HISTORY" in this leaked NSA ECI codenames list. https://robert.sesek.com/2014/10/nsa_s_eci_compartments.html https://robert.sesek.com/2014/10/nsa_s_eci_compartments.html > HISTORY HST NCSC (TS//SI//NF) Protects NSA and certain commercial cryptologic equipment manufacturer relationships.
- treflop 3y agoThe guy who founded Crypto AG was really good friends with a guy who became a top dog at the NSA.
- schmudde 3y agoSharing this seems like an appropriate way of commemorating David Kahn's passing (https://news.ycombinator.com/item?id=39233855 https://news.ycombinator.com/item?id=39233855). <3
- xyst 3y agofor a long time, the US considered cryptography algos as a munition. Needed some arms license to export. Also, US tried to convince the world only 56 bits of encryption was sufficient. As SSL (I don’t think TLS was a thing back then) was becoming more mainstream, US govt only permitted banks and other entities to use DES [1] to “secure” their communications. Using anything more than 56 bits was considered illegal. https://en.m.wikipedia.org/wiki/Data_Encryption_Standard https://en.m.wikipedia.org/wiki/Data_Encryption_Standard
- londons_explore 3y agoEven now, if you join a discussion on crypto and say something like "Why don't we double the key length" or "Why not stack two encryption algorithms on top of one another because then if either is broken the data is still secure", you'll immediately get a bunch of negative replies from anonymous accounts saying it's unnecessary and that current crypto is plenty secure.
- ahazred8ta 3y agoEVERYTHING IS FINE. WOULD YOU LIKE A BRAIN SLUG?
- paulpauper 3y agotwo encryption algorithms will mean needing two completely unrelated , unique passwords. this can be impractical and increase odds of being locked out forever
- ranger_danger 3y agono it doesn't mean that at all
- Geisterde 3y agoWell, I think that would sevearly inhibit future development. Scaling on bitcoin has been a delicate game of optimizing every bit that gets recorded, but also support future developments that dont even exist yet, there is no undo button either. New signature schemas and clevar cryptography tricks can do quite a bit, but when you slap another layer of cryptography on you will inevitably make things worse in the long run. Histories biggest bug bounty is sitting on the bitcoin blockchain, if it were even theoretically plausible to crack sha-256 like that then we would probably know, and many have tried.
- mannyv 3y agoThere's talk that the NSA put its own magic numbers into elliptical curve seeds. Does that count? https://www.bleepingcomputer.com/news/security/bounty-offered-for-secret-nsa-seeds-behind-nist-elliptic-curves-algo/ https://www.bleepingcomputer.com/news/security/bounty-offere...
- nimbius 3y agoEveryone forgets the speck and simon crypto the NSA wanted in the Linux kernel that were, ultimately, removed from it entirely after a lot of well deserved criticism from heavy hitters like Schneier. https://en.m.wikipedia.org/wiki/Speck_(cipher) https://en.m.wikipedia.org/wiki/Speck_(cipher)
- whatever3 3y agoI posted this because of the Enigma/Crypto AG mixup in the article, but it doesn't seem that anyone noticed. Seemed relevant considering the post about fabricated Atlas Obscura stories a few days ago.
- mmaunder 3y agoHonorable mention for the ITAR regs that prevented Phil Zimmerman from exporting PGP 128 bit encryption until Zimmerman and MIT press printed the source as a book protected by the first amendment, exported it, and this enabled others to OCR it, and recompile it offshore. Also that ITAR enabled Thawte in South Africa (where I’m from) as a business to completely dominate sales for 128 bit SSL certs outside the US. Thawte was eventually acquired by Verizon for $600 million and the founder Mark Shuttleworth used the cash to become an astronaut and then founded Ubuntu.
- lkdfjlkdfjlg 3y ago[flagged]
- halJordan 3y agoITAR is quite sensible. We can make mistakes and we can be sensible but wrong.
- FactKnower69 3y ago[flagged]
- alexdunmow 3y agoMaybe you just have a faulty sarcasm detector?
- bongodongobob 3y agoIt's no longer possible to tell. Some of the ideas that avg Americans have on the way just about anything works is frightening. My favorite lately is that the US was the real bad guy in WWII because we used nukes.
- int_19h 3y agoThat US was a "real bad guy", or that nuking cities was an evil and unnecessary thing? The latter, while not universally held, is a fairly common take, and has been that way for a few decades now.
- ETH_start 3y agoFor financial encryption, so essential is warrantless surveillance to their control of finance, that they've successfully argued that a neutral and immutable protocol instantiating open source code on a distributed public blockchain is property of a sanctionable entity, and thus within their authority to prohibit Americans from using: https://cases.justia.com/federal/district-courts/texas/txwdce/1:2023cv00312/1211705/94/0.pdf https://cases.justia.com/federal/district-courts/texas/txwdc...
- quasarj 3y agoI like that typo in the image label - the Chipper Clip lol
- bemusedthrow75 3y agoWe've had enough of chipper clips to last a lifetime! It looks like you're writing an article about encryption. Would you like help? (o) Insert a joke about Apple forcing a U2 album on us (o) Let me write the joke myself [x] Don't show me this tip again
- xrd 3y agoThat's the backdoor in the rot13 visible to the naked eye.
- jarjar2_ 3y agoOne of my favorite comics about cryptography. https://xkcd.com/538/ https://xkcd.com/538/ Government routinely posits a desperate need for backdoors in crypto and crypto secured products, but almost universally they get the data they want without needing a manufacturer provided backdoor. So why they insist on continuing to do that is beyond me. It's almost security theater. If they really want your protected information they will be able to get it. Either through a wrench or a legal wrench. In lieu of that they can use practically unlimited resources at their disposal from who they employ (or contract out to) to the long axis to which most secured devices succumb from, time. My personal threat model isn't to defeat the government. They will get the data eventually. My personal threat model is corporations that want to know literally everything about me and bad faith private actors (scammers, cybercrime and thieves) that do too. Ultimately it will take strict legislation and compliance measurement along with penalties to protect the government from overstepping the bounds they promise not to step over already, let alone new ones. It will take even stricter legislation to stop corporations from doing it. There are significant financial and political incentives for our ruling bodies to not do that, unfortunately. I mean honestly, when you have this kind of ability at your disposal... https://www.npr.org/2021/06/08/1004332551/drug-rings-platform-operation-trojan-shield-anom-operation-greenlight https://www.npr.org/2021/06/08/1004332551/drug-rings-platfor...
- paulpauper 3y agoA backdoor, which works anywhere and way better than the wrench option.
- jonathanyc 3y agoNow the argument coming from civil society for backdoors is based on CSAM: > Heat Initiative is led by Sarah Gardner, former vice president of external affairs for the nonprofit Thorn, which works to use new technologies to combat child exploitation online and sex trafficking. In 2021, Thorn lauded Apple's plan to develop an iCloud CSAM scanning feature. Gardner said in an email to CEO Tim Cook on Wednesday, August 30, which Apple also shared with WIRED, that Heat Initiative found Apple's decision to kill the feature “disappointing.” > “Apple is one of the most successful companies in the world with an army of world-class engineers,” Gardner wrote in a statement to WIRED. “It is their responsibility to design a safe, privacy-forward environment that allows for the detection of known child sexual abuse images and videos. For as long as people can still share and store a known image of a child being raped in iCloud we will demand that they do better.” https://www.wired.com/story/apple-csam-scanning-heat-initiative-letter/ https://www.wired.com/story/apple-csam-scanning-heat-initiat...
- rpmisms 3y agoCSAM is evil, and I personally believe we should execute those who distribute it. I have an even stronger belief in the right to privacy, and those in the government who want to break it should be executed from their positions (fired and publicly shamed).
- smolder 3y agoIn some cases artwork where no child was harmed counts as CSAM. Is that execution worthy?
- rpmisms 3y agoCan you give an example? If we're talking about Loli-type stuff, I hate it, but it doesn't harm kids directly, so execution is too harsh.
- smolder 3y ago> If we're talking about Loli-type stuff Yeah, IIRC, there is precedent for this being prosecuted. Reprehensible as it is, it worries me deeply that consuming fiction can cross a line into illegality. Pedophilia is such a rightfully hated thing that it's a powerful motivator in politics and social action; people will throw away their lives just to spite child abusers sometimes. I think we need to be extra careful about our response to the issue because of that, especially as it pertains to essential rights.
- Joel_Mckay 3y agoEncryption is meaningless with cpu-level side-channel memory key dumps active on most modern platforms. The reality is if you have been targeted for financial or technological reasons, than any government will eventually get what they are after. One can't take it personally, as all despotic movements also started with sycophantic idealism. Have a great day, =) https://xkcd.com/538/ https://xkcd.com/538/
- keepamovin 3y agoAgree with this. Makes me think that the code-breakers themselves must be using specialized hardware to protect their own side-channels. But for this to be feasible you need to have big chipmakers in on it. Fascinating to consider
- Joel_Mckay 3y agoNo need, data collection is a different function than exploitation. People that are turned into assets are often not even aware how they are being used. I once insisted I could be bribed to avoid the escalation of coercion as a joke, that was funny until someone actually offered $80k for my company workstation one day. It is a cultural phenomena, as in some places it is considered standard acceptable practice. My advice is to be as boring as possible, legally proactive, and keep corporate financial profit modes quiet. Good luck =)
- keepamovin 3y agoI was so curious about the origins of the SHA algorithms that I made a FOIA to NSA about SHA-0^0, as I wanted to understand how it was developed and requested all internal communications, diagrams, papers and so on responsive to that. Interestingly I found that after I got a reply (rough summary: you are a corporate requester, this is overly broad, it will be very expensive) I could no longer access the NSA website. Some kind of fingerprint block. The block persisted across IP addresses, browsers, incognito tabs, and devices so it can't be based on cookies / storage. Still in place today: Access Denied You don't have permission to access "http://nsa.gov/serve-from-netstorage/" on this server. 0: https://en.wikipedia.org/wiki/SHA-1#Development https://en.wikipedia.org/wiki/SHA-1#Development
- p-e-w 3y ago> Some kind of fingerprint block. The block persisted across IP addresses, browsers, incognito tabs, and devices so it can't be based on cookies / storage. Then what is it based on, if it happens across different devices and different IP addresses? I find it very surprising that the NSA would go to such technologically advanced lengths to block FOIA requesters from their website (which, needless to say, doesn't contain any sensitive information).
- keepamovin 3y agoYeah weird, right? Highly surprising, high entropy, highly informative bit of signal possibly. Obvious way to admit SHA-0 is a pressure point maybe. Idk, maybe you can figure out the block, I think it's beyond me. Here's a picture if that helps haha! :) https://imgur.com/a/rNIjrB2 https://imgur.com/a/rNIjrB2 Highly unlikely to be a coincidence but I took it to mean: Don't make these requests ... OK ... haha! :)
- lcnPylGDnU4H9OF 3y agoThis honestly seems kinda fun. If one was really dedicated: buy new device with cash; purchased and used outside city of residence; don’t drive there, non-electric bike or walk; only use device to connect to the website from public wifi; never connect to own wifi; don’t use same VPN service as usual. Not sure if I missed anything. Probably did.
- helpfulContrib 3y ago[dead]
- 5350-uiop-1130 3y agohow likely is it that whatsapp or telegram are backdoored? i wonder what tools do guerilla armies or drug lords use to communicate.. or maybe its better to hide in plain sight. just use some kind of double speak that gives plausible deniability.
- KennyBlanken 3y agoTelegram is a poster-child for sketchy security.
- KennyBlanken 3y agoThis leaves out at least one other proven case - the NSA worked to weaken an early encrypted telephone system that was sold to numerous other governments and allowed them to listen in on conversations. Then there's this: https://www.cnet.com/tech/tech-industry/nsa-secret-backdoor-paved-way-to-u-s-phone-e-mail-snooping/ https://www.cnet.com/tech/tech-industry/nsa-secret-backdoor-... And then there was the Tailored Access Operations group that backdoored hundreds if not thousands of computers and networking gear https://en.wikipedia.org/wiki/Tailored_Access_Operations https://en.wikipedia.org/wiki/Tailored_Access_Operations And then there's Bullrun where they partnered with commercial software and hardware companies to insert backdoors, specifically in many commercial VPN systems https://en.wikipedia.org/wiki/Bullrun_(decryption_program) https://en.wikipedia.org/wiki/Bullrun_(decryption_program) Let's also not forget the backdooring of Windows NT: https://en.wikipedia.org/wiki/NSAKEY https://en.wikipedia.org/wiki/NSAKEY ...and Lotus Notes was also backdoored, as well.
- AniseAbyss 3y ago[dead]
- qubex 3y agoThe image isn’t of an Enigma but of a Lorenz teleprinter encryption system. It was would be referred to now as a “stream cipher”.
- mstef 3y agoi believe the cryptomuseum has a more extensive list than the one in the link: https://www.cryptomuseum.com/intel/nsa/backdoor.htm https://www.cryptomuseum.com/intel/nsa/backdoor.htm particularly one is interesting as i have reverse engineered and proven its existence: https://www.cryptomuseum.com/crypto/philips/px1000/nsa.htm https://www.cryptomuseum.com/crypto/philips/px1000/nsa.htm
- sarahcerutti06 3y ago[dead]
- DougKahan 3y ago[dead]
- thewileyone 3y agoHuawei was targeted because they refused to allow backdoors in their switches and phones that the 5 Eyes could exploit.
- obinsonjoella 3y ago[dead]