3 ms·
This sounds like a counter-surveillance technique. If you're an island nation with one cable for all your traffic you are very susceptible to a variety of stat
by trotsky 14y ago
This sounds like a counter-surveillance technique.
If you're an island nation with one cable for all your traffic you are very susceptible to a variety of state actor attacks: traffic analysis, mitm, protocol downgrades etc.
If your traffic goes out one way and back in via a totally divergent link these kinds of techniques become significantly harder to pull off and much easier to detect their use.
Passive undersea fiber monitoring is well within the means of more than a few intelligence operations and quite popular. They're in international water, unguarded, unrealistic to regularly inspect and they can be modified to leak just enough light to see every bit while being pretty difficult to detect.
A cable strung between Venezuela and Cuba would be impossible to resist for anyone in the region with a highly advanced signals intelligence program and spent 40+ years defined by communism/socialism as public enemy number one.
A year delay in lighting at all suggests to me very strongly that they had direct evidence or strong indicators that their cable had been split/bent or their DWDM repeaters / inline terminals or other equipment came into question - most of it is made by companies pretty cozy with large state actors.
After traffic snooping your second big intelligence concern these days is data exfiltration. The classic radio bug is way more trouble and effort than malware mics & cams, keyloggers and mobile phones. Even more popular is just files - grab it all and see whats good. Mostly that's very hard to catch leaving the country because there are so many paths and the data volume is so large.
But if you've previously built a monitoring system for your only route out, and it's slow enough you can do a credible job of traffic analysis then you're probably loathe to give up on it. In comparison, the kind of gear needed to do DPI, anomaly detection, key weakening etc. at a 100G+ is very pricey and probably covered by export bans anyway.
Asymmetric internet works pretty well anyway. Most commercial service is tuned that way because thats what the use looks like, way more in than out. Sat latency ain't a ball of joy but for bulk data and web pages it's probably pretty decent service especially when compared to what it's replacing.
- jrockway 14y agoWouldn't this scale to multiple links? Bug one, then blow the others up. "Oops, that cruise ship had a C4-infused anchor and it hit your cable, sorry." I'm surprised this doesn't happen more often, actually.
- Element_ 14y ago"Passive undersea fiber monitoring is well within the means of more than a few intelligence operations" What kind of equipment/engineering would be required for that? Has there been any documented cases of a government doing that in the past?
- rurounijones 14y agoThere have been documented cases of undersea cables being tapped: http://en.wikipedia.org/wiki/Operation_Ivy_Bells http://en.wikipedia.org/wiki/Operation_Ivy_Bells Regarding Fibre I am not sure of documented cases but: http://www.zdnet.com/news/spy-agency-taps-into-undersea-cable/115877 http://www.zdnet.com/news/spy-agency-taps-into-undersea-cabl...
- trotsky 14y agoVery roughly, you strip the casing and then bend the fiber until a small amount of light begins escaping through the small gaps created by the bending. Most of the light continues to travel through the cable unharmed aside from a tiny decrease in intensity. Here is a page with some pictures of something along those lines: http://www.techrepublic.com/blog/security/protect-your-network-against-fiber-hacks/222 http://www.techrepublic.com/blog/security/protect-your-netwo... Here is an article about a US sub equipped for this kind of job: http://defensetech.org/2005/02/21/jimmy-carter-super-spy/ http://defensetech.org/2005/02/21/jimmy-carter-super-spy/
- mikeash 14y agoI assume there must be something preventing the two ends of the cable from just generating a secure 256-bit AES key and using it on all of the traffic going over the link, thus preventing snooping, but I can't think of what it would be. Is the data rate just too high for that to be practical, or is there something else there?
- trotsky 14y agoAnachronistically, The US still enforces a broad based embargo on trade with Cuba, leaving it with the dubious honor of the tightest controlled destination, beating out even Iran and North Korea. We also have it on the list of states that sponsor terrorism which is recognized by many 3rd party nations. Top tier crypto gear including anything suitable for trunk class traffic is one of the most controlled export goods - canada is literally the only country on earth that doesn't require an export license. Realistically it's mostly a formality if the destination is on the list of favored nations, mostly western democracies. There are 3 more tiers: mostly ambivalent, our shit list and lastly those we label rogue/terrorist. Mass communications gear and business grade crypto get a lot of scrutiny, really only topped by spaceflight and the tools of war. Theoretically you'd probably be able to get export licenses for high speed aes to send to Venezuela, but practically it would be subject to a ton of discretionary terms that would make it a non-starter. A smattering of possible terms the US would impose: all source code including 100% of the ASIC designs, use of a US ASIC fab with production under the supervision of the government, require lawful intercept functions to be enabled, key escrow storage in us territory only, no customer access to source code, software upgrades performed only by us personel on site, mandatory random on site checks by us government officials to ensure it hasn't been transferred, is used in a licensed manner, hasn't been tampered with, software is approved version, etc. It's not like they'd demand a huge obvious list like that, but pretty much any one of those restrictions means the customer is pretty much at the mercy of the US government. Most of those practices are designed to find or insert flaws that enable total plaintext recovery. Understandably most states that are subject to intense US intelligence activity generally don't even consider it. There is plenty of diversion that goes on through cutouts, but there are plenty of published stories where US intelligence knew all about it and owned the gear before it shipped. Practically your other choice is chinese gear, which is what most of that class of country buys. But the chinese gear is almost certainly subject to similar intentional weaknesses in addition to stuff placed by multiple competing domestic security services so they can spy on each other. It's a pretty safe bet that a number of western intelligence agencies can exploit these as well - so you're back to square one again. General purpose software is an option of course, but i think itd take a lot of kludges to handle such a fat pipe with consumer cpus/gpus. And then of course they are a bunch of computers on a network with static encryption keys sitting in memory run by poorly paid government workers, probably not something that would resist a motivated attacker.