TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

The Crime Messenger

99 点作者 SirLJ6 个月前

14 条评论

Zak6 个月前
&gt; <i>The Serbian criminals shared photos of their victims on Sky without realizing police had installed a probe on the Sky ECC servers in France, which allowed authorities to intercept and read every user’s messages.</i><p>I&#x27;m surprised criminals keep picking these niche messaging services, which keep turning out not to use proper end to end encryption, rather than Signal.
评论 #42246194 未加载
评论 #42247173 未加载
评论 #42246293 未加载
评论 #42248418 未加载
评论 #42248498 未加载
评论 #42246874 未加载
评论 #42246618 未加载
评论 #42247492 未加载
评论 #42246198 未加载
评论 #42246388 未加载
jpalawaga6 个月前
I have thoughts and feelings about a lot of this, but the part that stands out to me is LE folks intentionally working with agents out of their jurisdiction to circumvent the laws in their own jurisdiction.<p>You want to talk about unethical behaviour? That sounds borderline like a poison tree to me.
评论 #42246903 未加载
评论 #42246948 未加载
worldvoyageur6 个月前
&quot;His father designed the data encryption algorithm.<p>“My dad&#x27;s a genius,” said Eap. “It had the highest level of encryption available.”<p>Not only did Sky ECC provide end-to-end encryption, like Whatsapp or Signal, but unlike those free apps, it also redirected the data on its own secure network. &quot;<p>This was the basis for users to think the system was secure? Seriously!?!<p>I&#x27;m reminded of the saying &#x27;don&#x27;t roll your own crypto&#x27;. Obviously the authorities were able to crack the crypto, probably at multiple points.
评论 #42251226 未加载
paxys6 个月前
Pretty ironic that they got caught after going out of their way to buy secure phones and use secure messaging services when an off-the-shelf iPhone and Whatsapp&#x2F;Signal&#x2F;Telegram would have made them 100% untraceable.
评论 #42246624 未加载
评论 #42246460 未加载
评论 #42246658 未加载
评论 #42246882 未加载
评论 #42246774 未加载
ipython6 个月前
If you enjoy this story, read the book Dark Wire which focuses on the FBI’s infiltration of Anom, another encrypted message service. It also covers sky briefly. Fascinating story<p><a href="https:&#x2F;&#x2F;www.hachettebookgroup.com&#x2F;titles&#x2F;joseph-cox&#x2F;dark-wire&#x2F;9781541702691&#x2F;?lens=publicaffairs" rel="nofollow">https:&#x2F;&#x2F;www.hachettebookgroup.com&#x2F;titles&#x2F;joseph-cox&#x2F;dark-wir...</a>
评论 #42248170 未加载
darknavi6 个月前
A good defcon talk that referenced Sky but focused on another platform called Anon:<p><a href="https:&#x2F;&#x2F;youtu.be&#x2F;uFyk5UOyNqI?si=i-GtpeCR1QEj69cz" rel="nofollow">https:&#x2F;&#x2F;youtu.be&#x2F;uFyk5UOyNqI?si=i-GtpeCR1QEj69cz</a>
lyu072826 个月前
&gt; In 2011, Eap started developing an encrypted messaging system with the help of his father, who holds a master’s degree in computer science from Simon Fraser University in Burnaby, B.C. The app was initially designed for BlackBerry phones and later made available for iPhones.<p>&gt; His father designed the data encryption algorithm.<p>&gt; “My dad&#x27;s a genius,” said Eap. “It had the highest level of encryption available.”<p>It&#x27;s hard to imagine that this level of ignorance wasn&#x27;t intentional from the beginning.
评论 #42247194 未加载
评论 #42246829 未加载
评论 #42246892 未加载
avodonosov6 个月前
&gt; Not only did Sky ECC provide end-to-end encryption, like Whatsapp or Signal, but unlike those free apps, it also redirected the data on its own secure network.<p>So how the messages were intercepted if e2e encryption is used?
评论 #42246898 未加载
评论 #42246879 未加载
auscad6 个月前
What makes this different from a typical attack on encryption is that this company (probably) knowingly distributed to and worked with criminal enterprises.<p>But this article is written in a way that suggests that encryption is dangerous - an angle that the CBC has taken before - which makes sense considering that it is a government-owned news outlet in a Five Eyes member state.
评论 #42246271 未加载
评论 #42246761 未加载
评论 #42246511 未加载
评论 #42246430 未加载
评论 #42246571 未加载
评论 #42246374 未加载
barbazoo6 个月前
Reminds me of a recent episode of &quot;Search Engine&quot; about the &quot;AN0M&quot; phone: <a href="https:&#x2F;&#x2F;www.searchengine.show&#x2F;listen&#x2F;search-engine-1&#x2F;what-s-the-best-phone-to-do-crimes-on" rel="nofollow">https:&#x2F;&#x2F;www.searchengine.show&#x2F;listen&#x2F;search-engine-1&#x2F;what-s-...</a>
janmo6 个月前
The key aspect here is that both Sky ECC and Encrochat got F. over by the modern day equivalent of Crypto AG which is the french hosting provider OVH.<p>While intelligence agencies were pumping in real-time all the data from Encrochat&#x27;s and Sky ECC;s dedicated OVH servers, the OVH co-founder Octave Klaba and their ex-CEO Michel Paulin were selling the company with statements like:<p>- We don&#x27;t dig in our customer&#x27;s data unlike the the &quot;others&quot;.<p>- US secret services have no access to our data.<p>However there are many interesting anecdotes:<p>1) For many years OVH was hiding a &quot;maintenance&quot; backdoor in &quot;&#x2F;etc&#x2F;ssh&#x2F;authorized_keys2&quot;, authorized_keys2 was used for ssh protocol 2 which was depreciated in 2001 yet OVH was using it to store a maintenance key until around 2018. This was very poorly documented and a user warned of the backdoor on HN back in 2012. <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=4839414">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=4839414</a><p>2) In 2013 the TOR hidden service hosting provider &quot;Freedom hosting&quot; was taken down, &quot;they&quot; had rented 400 servers at OVH and in June 2013 &quot;they&quot; let all but one expire, likely moving to another provider, this is when through an unknown way the FBI obtained the IP address of the only remaining server at OVH. The server was imaged but it contained an encrypted &quot;container&quot;. The FBI claims that they were able to break the encryption within a week using &quot;cryptanalysis&quot; and to recover the &quot;root&quot; password used to encrypt these &quot;containers&quot;. This is total BS, they must just have used the ssh maintenance key or added &quot;something&quot; to the server when they did the imaging.<p>Source criminal complaint Eric Eoin Marques: <a href="https:&#x2F;&#x2F;www.justice.gov&#x2F;d9&#x2F;press-releases&#x2F;attachments&#x2F;2019&#x2F;03&#x2F;25&#x2F;marques_amended_criminal_complaint_-_redacted_0.pdf" rel="nofollow">https:&#x2F;&#x2F;www.justice.gov&#x2F;d9&#x2F;press-releases&#x2F;attachments&#x2F;2019&#x2F;0...</a><p>3) Later that same year Silk Road was taken down. It is undisputed that law enforcement lied about key parts in their investigation.<p>According to law enforcement Ross Ulbricht was ssh&#x27;ing into the Silk Road server using a &quot;VPN server&quot;. When they got to the &quot;VPN server&quot; it had been wiped out BUT, the hosting provider had kept &quot;VPN&quot; &quot;logs&quot;??? which led them to the IP address of a cafe where Ross Ulbricht had been. Ross Ulbricht kept a list with all the servers he was and had been operating. There is no mention of a VPN server, however in the &quot;retired&quot; server section there is a &quot;VNC Desktop&quot; server with the note &quot;SR related&quot;. This appears to be a server running a virtual desktop that Ross Ulbricht was using to connect to the Silk Road. It was a VPS hosted at ... OVH and rented through an intermediary called momentovps. But it gets even worse, just bellow he listed another VPS at OVH and it has the remark &quot;Will &#x2F; personal backup &#x2F; deadman switch&quot;...<p>Source: Silk Road Exhibit GX-264<p>4) The creation story is quite strange. OVH was offering very low prices while not having any funding. The secret was that for years Xavier Niel who is one of Octave Klaba&#x27;s competitors and has been outed as being a former agent for the french government was hosting the OVH servers in his datacenter for FREE. Obviously if you do not pay for the electricity, internet and rent life is easy. The question is what did Xavier Niel get in return? According to him (Interview on BFMTV) he did it out of generosity. Of course...<p>Now we pretty much know that Pavel Durov founder of Telegram got his french passport because he agreed to work with the french intelligence agencies but failed to deliver. Guess who was the first person he called when he got arrested, and then the person he met once he was released? Xavier Niel!
评论 #42247699 未加载
Hizonner6 个月前
&gt; They communicated with each other on highly secure phones<p>You keep using that word...
dghlsakjg6 个月前
&gt; “Privacy is really, really important and we all have the right to our privacy,” said Catherine De Bolle, executive director of Europol, the law enforcement agency of the European Union. “But when we see now that encrypted communication is really an enabler for crime, then we have to do something.”<p>Can she hear herself when she talks? Apparently we don’t have a right to our privacy. Interpol intercepting every message going across a server just because some of the messages might be criminal is explicitly acting in a way that does not imply any right to privacy.
评论 #42246852 未加载
评论 #42246397 未加载
评论 #42260453 未加载
评论 #42246248 未加载
评论 #42246355 未加载
评论 #42246364 未加载
kubb6 个月前
Feels like criminals will eventually get encrypted communication right and there won’t be anything left for police to do.
评论 #42246140 未加载
评论 #42246283 未加载
评论 #42246467 未加载
评论 #42246910 未加载
评论 #42247465 未加载
评论 #42246146 未加载
评论 #42246391 未加载