11 ms·
A Saudi Arabia Telecom's Surveillance Pitch
- tptacek 13y agoThis stuff happens more than anyone in infosec wants to admit; it's (ironically) what got me into professional software security to begin with, after being upset by what a commercial network monitoring tool would have allowed us to do to our customers at an ISP I helped run. It's especially funny to see a government sponsored telecom reaching out to Moxie Marlinspike. Also: this isn't like that time a random Microsoft recruiter accidentally hit ESR and he wrote the "Your Worst Nightmare" post about it. Like Moxie says, money buys technology, and they will eventually find someone to rig up a workable solution for what they're trying to do. Moxie: one thing that would be hugely helpful is a quick list of the things you did that make you confident in Twitter's TLS code (which: thanks for doing).
- moxie 13y agoIn this case I was mostly referring to the inclusion of certificate pinning (ex: https://github.com/moxie0/AndroidPinning https://github.com/moxie0/AndroidPinning) in the mobile apps, which would theoretically prevent them from using a UAE or Saudi controlled CA to do the interception. In addition to iOS and Android, we also refused to compromise with low-end platforms like MediaTek, and made sure those clients were also all-TLS and that they employed certificate pinning. We also did common sense stuff like including assertions in all the platforms that would prevent accidental HTTP leakage. More generally, a lot of common sense effort was put into the general TLS posture of the website. From certificate pinning baked into the browsers, to HSTS headers, to making sure the links in search results are https. There was a bunch of generally nice TLS stuff in the pipe as well, but I'm not sure if it shipped yet.
- ComputerGuru 13y agoIf you really want the world to be a more secure place, can I please ask that you relicense the AndroidPinning code as BSD or something less viral than GPLv3? I don't see Instagram, Facebook, etc. using that code to secure their apps, they won't license their Android clients as GPLv3 just to use the Android pinning library. While it is easy enough to re-create your code (though I have not looked at it), given that we're talking encryption libs, it's always nicest to have secure, vetted libs that just work. (As a matter of fact, I'm sure you had to relicense it for Twitter to use it in their app.)
- tedks 13y agoFrom the README: >Please contact me if this license doesn't work for you. I see no reason why Moxie should give Facebook and Instagram this valuable feature for free. When did open-source hackers become the unpaid laborers for silicon valley? If they want it, they can either release the source code for their applications and liberate their users, or they can pay (hopefully) through the nose for it. Maybe that'll buy a few more months of TextSecure development, or whatever other cool things Moxie is doing now.
- ianlevesque 13y agoFacebook or Instagram will just reimplement it themselves if they care. Smaller developers will just remain insecure. GPLv3 harms adoption of something like this.
- tptacek 13y agoIf you think that, go implement a MIT-licensed variant.
- tomjen3 13y agoNot that simple, you have often stated that normal programmers shouldn't be near security and now you are stating that they should go implement something that is specifically to enhance the security of the web. The gp isn't asking for a change of license because he hate the GPL, he is (properly correctly) predicting what will happen if that license isn't changed: specifically, the thing that Moxie is trying to prevent won't be.
- tptacek 13y agoI don't say normal developers shouldn't be near "security"; I say they shouldn't be implementing cryptographic primitives.
- 13y ago
- minimax 13y agoLike Moxie says, money buys technology, and they will eventually find someone to rig up a workable solution for what they're trying to do. Governments are in a unique position here. They can always just move up the stack. Can't break the crypto? That's fine. They can just require the mobile phone companies to sell phones with spyware already included.
- tptacek 13y agoThat problem is, I think, a showstopper for "anti-circumvention" tools like whatever- the- next- generation- of - Tor will be. Dictatorships have little to lose by backdooring or rootkitting devices; they'll laugh off any outrage stirred up by the discovery of these methods. But the economics flip around in Europe, Japan, the US, &c: governments there do have something to lose by surreptitiously backdooring huge numbers of devices, and the odds are good that any efforts to do so will be detected (the state of the art for reverse engineering now includes decapsulation and imaging of electronics packages).
- minimax 13y agoThe US government is a special case again. Since most of the companies mentioned here are headquartered in the US, the US government can resort to the no-tech solution of just asking for the data and presenting a subpoena (or so was my experience working for a large US telecom carrier).
- tptacek 13y agoThe difference is that a subpoena doesn't decrypt an EDH TLS session.
- superuser2 13y agoBut it does decrypt the data at rest.
- cinquemb 13y agoThat problem is, I think, a showstopper for "anti-circumvention" tools like whatever- the- next- generation- of - Tor will be. Dictatorships have little to lose by backdooring or rootkitting devices; they'll laugh off any outrage stirred up by the discovery of these methods. Well until something like the DIY Cellphone gets more traction to deal with backdooring/rootkitting: https://webcache.googleusercontent.com/search?q=cache:http://hlt.media.mit.edu/%3Fp%3D2182&strip=1 https://webcache.googleusercontent.com/search?q=cache:http:/... (MIT Media Lab)
- spindritf 13y ago> money buys technology I don't think it matters. He quickly noticed that the problem is cultural, that >> I’d much rather think about the question of exploit sales in terms of who we welcome to our conferences, who we choose to associate with, and who we choose to exclude, than in terms of legal regulations. I think the contextual shift we’ve seen over the past few years requires that we think critically about what’s still cool and what’s not. But the problem with/in Saudi Arabia is also cultural, or social, not technological. It doesn't really matter that they can buy exploits or intercept communications. What matters is that those in power can stay in power while doing all that. Mao and Stalin built some of the most repressive regimes the world has seen with 1930s technology, and even then they were behind the times. Do you think those would have been rocked by secure Twitter? On the other hand, Greeks ran fairly decent democracies when the closest thing to mass communications was shouting in a place with good acoustics. I'm not saying the west should just provide scum of the world with access to modern technology. Let's not kid ourselves though. Whether we do or not, it won't change much.
- tptacek 13y agoIt is possible to believe both things at the same time: that dictatorships will inevitably acquire exploits, backdoors, and monitoring tools, and that it's unconscionable for companies to sell these things to dictatorships. The story is perhaps clearer on exploit markets. The alternative to markets is publication, which burns the vulnerability by hastening its patch deployment. Dictatorships will inevitably acquire more exploits, but they are in a race against everyone in else discovering vulnerabilities.
- spindritf 13y ago> dictatorships will inevitably acquire exploits That's not what I mean. Even if you somehow stop them from acquiring exploits, they will remain in power because it's not derived from subtle technological advantages.
- droopyEyelids 13y agoIf the technological advantages do not help them stay in power, why do you think they would pursue them? And what 'advantage' would they be?
- peterwwillis 13y agoThere needs to be an RFC for Postcard Key Encryption - send each other public keys on hand-written postcards to single-use P.O. boxes to avoid mitm of the initial key exchange. I don't understand why anyone trusts CAs any more.
- tptacek 13y agoNobody trusts CAs. There is a lot of work being done on layering more trustworthy authentication features on top of the TLS CA system, one good one being TACK: http://tack.io/draft.html http://tack.io/draft.html The problem with simply abandoning CAs is that it creates a situation in which it's even easier for government sponsored agencies to mass-intercept traffic, at least for a window of time (probably several years), and all that window buys us is the ability for sites that don't really care about security to save $10-$100 dollars on cert costs.
- runjake 13y ago> Nobody trusts CAs. No. The problem is that pretty much everyone trusts them, at this point in time. That was Peter's point. Sure, there are researchers and engineers who rightfully don't trust CAs. But we don't really matter. The users, the consumers, the parents, the grandparents, the activists do.
- EthanHeilman 13y agoThe users, the consumers, the parents, the grandparents, the activists, ... don't even know what CAs are. To the degree that people trust computers at all they trust what their browser tells them is safer. Generally almost everyone has experience with malware, bugs and broken software. No one who has used a computer for more than 10 minutes absolutely trusts computers in any capacity including security.
- tptacek 13y agoI am not sure what the point of this comment is. What conclusion do you come to as a result of this "everyone trusts CA" belief that is different from mine?
- OGinparadise 13y agoThe reality is that they will eventually find a company or five that will do exactly what they asked. Thanks to their checkbook. Moxie: Do not go to Saudi Arabia, you are probably persona non-grata by now.
- ihsw 13y agoThe persona non-grata status isn't limited to the .sa region -- he will likely feel retaliatory measures implemented against him from within the safety of the West.
- aw3c2 13y ago> TextSecure and RedPhone could serve as appropriate secure replacements sadly those are only available for Android.
- sneak 13y ago...and, under these sorts of regimes, will likely get blocked should they gain any sort of real traction anyway. (Moxie's post is clear that they want to intercept, and block what they can't.) Without jailbreaking or a dev cert, you can't ensure that an app you install from the App Store on iOS isn't backdoored anyway. I'm an iOS devotee but even I'm going to buy a second phone specifically to support sideloading of crypto software for secure communications. My phone's primary function is to communicate (despite all the smartphone value-adds) and secure and private communications are a pipe-dream on iOS. iMessage is great (and end-to-end encrypted) but if I can't control the list of keys to which it encrypts, it's only as secure as Apple (and presumably the DoJ by extension) allows it to be.
- gbrindisi 13y agoYou can safely assume that mobile software has been already backdoored. If not by the vendors directly, it is by the companies that are selling "lawful interception" tools based on 0days and what not.
- tomjen3 13y agoWith Android all you have to do is tick a checkbox to install apps that are not from the market, you don't need to root it and you don't need a special certificate. Oh and if you want a dev user, it is a one time fee of 20 usd (or was, when I got mine).
- deleted 13y ago[deleted]
- moxie 13y agoiOS versions are in the works!
- 13y ago
- creationary 13y agoUnfortunately, this is the world we live in now. Its only going to get worse, and sooner or later will self-destruct. Bliss.
- knowaveragejoe 13y agoAs long as so many people are still willfully ignorant of such things, maybe.
- luser001 13y agoI'm very curious what aspect of Twitter's TLS code makes hard to intercept whereas other websites can be easily intercepted? I'm also very curious about how they intercepted Whatsapp. Does it do something stupid like eval'ing code received over regular HTTP? Quoting the paragraph, in case my paraphrasing is inaccurate: "What’s depressing is that I could have easily helped them intercept basically all of the traffic they were interested in (except for Twitter – I helped write that TLS code, and I think we did it well). They later told me they’d already gotten a WhatsApp interception prototype working, and were surprised by how easy it was. The bar for most of these apps is pretty low."
- moxie 13y agoWhatsApp doesn't use TLS, and their protocol has a fairly long history of criticism.
- josh2600 13y agohttp://www.neowin.net/forum/topic/1148702-realized-that-whatsapp-has-a-huge-security-flaw/ http://www.neowin.net/forum/topic/1148702-realized-that-what... I seem to remember their authentication was a combination of your phone number and the IMEI of your handset, which is woeful security through obscurity at best.
- spyder 13y agoand it seems somebody got so angry about they security that he made this site: http://www.whatsappsucks.com http://www.whatsappsucks.com
- tptacek 13y agoThey pin the TLS certificate: to successfully create a connection to Twitter, their mobile apps will check not only the validity of the certificate the server presents, but also a hardcoded digest of the correct certificate, so that a "valid" certificate for Twitter from a CA Twitter has no relationship with will be rejected.
- 13y ago
- ck2 13y agoI suddenly had a realization why someday in the future everyone is going to want their own personal satellite. Government interception/manipulation (or any other party) would become rather difficult.
- mahyarm 13y agoUntil hunter-seeker satellites intercept other people's micro satellites and destroy them, or worse 'wiretap' into their internal computers without their knowledge.
- josh2600 13y agoTo be fair, is there anyone that doesn't want their own personal satellite? C'mon, that's pretty cool, right? And I don't think owning a satellite makes your communications secure simply by virtue of owning a satellite. I'd argue that you'd need to own the methods of communication to and from the satellite, which probably isn't realistic.
- deleted 13y ago[deleted]
- DanielBMarkham 13y ago"... insecurity predominately tended to be leveraged by a class of people that I generally liked against a class of people that I generally disliked..." This, this, a thousand times this. We cannot look the other way because the "good guys" are benefiting. Not any more. The person that reads an article about the USA implementing some automated service to monitor foreign communication must realize that other governments are now doing the exact same thing. We no longer have the luxury of pretending that as long as the outcome is good the means do not matter.
- mtgx 13y agoHow do the people at Viber, Line and WhatsApp plan to respond to this? Should they implement OTR?
- junto 13y agoSA are just trying to catch up with the technology that countries in the west, such as the USA and UK, and other technology adept countries such as China have had for a considerable amount of time.
- dguido 13y agoHm, I'm surprised more people aren't angry at the lack of adoption of cert pinning in mobile apps. It seems like no one cares to prepare for attacks like this, despite widespread knowledge that they occur?
- pmcmahon 13y agoDear Y Hackers, Please know that there are dumb, non-technical, readers that sit on the sidelines of this site and stare in awe of your courage and abilities. The fact that this article is atop the leaderboard speaks volumes about the community's character. Moxie Marlinspike you are a hero. You are a wonderful writer, and your adventurous spirit is incredibly inspirational. Thank you for sharing your stories. To me this site is a beacon of hope, a daily reminder that remarkably talented people are out there fighting for good.
- guelo 13y agoWe all supposedly know how totalitarian Saudi Arabia is compared to the free United States, so giving Saudi Arabia eaves dropping and decryption tools is something we all obviously dislike. But we are all bathing in American propaganda, so many people, like those "patriotic hackers", support the Feds having the same power that Saudi Arabia is seeking. In fact, the US government is doing much more sophisticated eavesdropping of all our communications and storing it for later perusal. And they use the same "terrorism" justification as the dictators. And what is a terrorist? Whoever they say is a terrorist. Which can include anyone advancing any political ideology that is frowned upon by the bipartisan "washington consensus" of what is acceptable debate. From libertarians to environmentalists to any kind of anti-authoritarian that doesn't serve the interests of the establishment.
- michael_h 13y ago...so many people, like those "patriotic hackers", support the Feds having the same power that Saudi Arabia is seeking They do? I'm not sure I can name a single hacker that wants the US, or any other govt, to have the same power.
- GHFigs 13y agoFrom libertarians to environmentalists to any kind of anti-authoritarian that doesn't serve the interests of the establishment. Who do you mean? Who is being called a terrorist?
- 13y ago
- wfunction 13y agoThere's no reason to believe Saudi Arabia is alone in surveillance like this. Meet the United States: http://www.guardian.co.uk/commentisfree/2013/may/04/telephone-calls-recorded-fbi-boston http://www.guardian.co.uk/commentisfree/2013/may/04/telephon...
- adamt 13y agoFurthermore - the US has a big advantage. Many of the companies that handle digital communication services (Facebook, Twitter, Google etc) are US based and have to by law co-operate with the US law enforcement agencies. So if the FBI (or other three-letter agency) wants access to your Facebook or gmail, they can get it via those companies. In countries like Saudi Arabia they don't have the same level of power/control so they have to look at intercepting & blocking the traffic.
- orokusaki 13y agoAt the risk of sounding paranoid, if I were Moxie, I'd be on the lookout for sure :/ when you get into this sort of thing, not to mention the money involved, you're running serious risk of being "cancered" to death.
- RRRA 13y agoSo according to a comment in that article, Taher ElGamal would be working in KSA doing interception... Anyone has a source? We need to modify wikipedia, this is shameful if true.
- icambron 13y agoI'm a total outsider to the security community. Of course I understand that are plenty of hackers selling exploits to shady government actors, but I'm to understand from this article that the practice is generally not considered abhorrent and immoral? Like, there's a real debate to be had here?