[HN Gopher] Anom Encrypted App Analysis
       ___________________________________________________________________
        
       Anom Encrypted App Analysis
        
       Author : CPAhem
       Score  : 82 points
       Date   : 2021-06-08 10:17 UTC (12 hours ago)
        
 (HTM) web link (webcache.googleusercontent.com)
 (TXT) w3m dump (webcache.googleusercontent.com)
        
       | skissane wrote:
       | Archived versions: https://archive.is/jtJvK
       | 
       | https://web.archive.org/web/20210608102417/https://webcache....
       | 
       | (Since, as we all know, Google's webcache won't last)
        
       | yawaworht1978 wrote:
       | Wow, is this really all true? How could he find out the hosting
       | was on AWS? How did none of the criminals get to see this blog?
       | Did the police intervene and had him remove the blog?
        
         | hn_throwaway_99 wrote:
         | > How did none of the criminals get to see this blog? Did the
         | police intervene and had him remove the blog?
         | 
         | I mean, it's pretty clear to me that (a) criminals are highly
         | unlikely to see this blog and (b) if they did, so what, they
         | wouldn't have understood it/believed it anyway. Half the
         | comments _on HN_ don 't give it any credence because it's
         | written by someone whose first language is obviously not
         | English and who likes hyperbolic ALL CAPS, despite the fact
         | that the underlying analysis is valid.
        
       | hkyigkfnrj wrote:
       | 4D chess theory:
       | 
       | This analysis was written by law enforcement in advance of the
       | takedown to promote the next backdoored app.
        
       | layoutIfNeeded wrote:
       | "Encrypted Military Grade Encryption" - LOL
        
         | emptyparadise wrote:
         | Must be the same military that puts nuclear secrets on
         | flashcard websites
        
       | GekkePrutser wrote:
       | This 'analysis' seems to be more PR speak by another similar
       | network? I wouldn't put much trust in people using terms such as
       | 'ENTERPRISE MILITARY GRADE', of course in all caps to emphasize
       | the effect. Has snake oil written all over it.
       | 
       | I thought this article would be a genuine analysis by a security
       | researcher as a tie-in to the news today:)
        
         | hn_throwaway_99 wrote:
         | I think you don't understand what is going on here. ANOM was
         | just admitted by the Australian Police and FBI to have been
         | specifically built to infiltrate organized crime. The whole app
         | was a plot to get access to the messages of these purported
         | criminals.
         | 
         | This analysis came out a couple months ago, and was exactly
         | correct. Also, you are blaming the style of the writing but
         | ignoring the substance, which is that the app is most
         | definitely making encrypted connections where it has no need to
         | do so.
        
           | GekkePrutser wrote:
           | I didn't know that when I wrote that, no. I thought it was
           | the same story as EncroChat at the time (where an existing
           | network was taken over by the police). I saw it in more
           | detailed news reports since.
           | 
           | The points might have been valid but the language is not
           | instilling any kind of confidence: "This is an ENTERPRISE
           | MILITARY GRADE Encrypted setup." doesn't exactly make it seem
           | like a security researcher who knows what they're talking
           | about. And add many other words capitalised for maximum shock
           | effect: "imagine you were meeting up with someone like an EX-
           | LOVER your partner may not approve of"
           | 
           | It all sounds very much FUD and biased. If you do a good
           | analysis, this is not how you present it.
           | 
           | The main points he really makes are poor endpoint security
           | (not uncommon in this market, as many such networks have been
           | breached) and noticed some suspicious traffic which is indeed
           | a telltale that something more is going on.
           | 
           | But it sounds way too much like someone with 'skin in the
           | game' was trying to spin it and turned out to be right.
        
             | 9wzYQbTYsAIc wrote:
             | Technically, ANOM did start as a "legitimate" criminal
             | application, but was handed over to the FBI early in
             | development as part of a plea deal.
        
           | thieving_magpie wrote:
           | Not to speak for them but I experienced the same feeling of
           | interest in who the author was. For me it sounded like
           | someone associated with CIPHR or another messaging
           | application that did this analysis (still factual analysis)
           | on a rival application. There was some marketing-type
           | language in there that made me think that.
        
       | thieving_magpie wrote:
       | I've never considered JIRA would be used by the FBI or
       | intelligence agencies. The user stories would be fun to read.
       | 
       | I wonder why this blog was deleted by the author. Get a phone
       | call from the FBI?
        
       | Yeri wrote:
       | Guess this person was right :)
        
         | 542458 wrote:
         | Yes, but also no. Right in that AN0M wasn't secure. Wrong in
         | that it wasn't insecure because it didn't disable Google
         | services, or use secure updates or whatever - it was insecure
         | because it just deliberately sent everything to the Feds.
        
           | hn_throwaway_99 wrote:
           | Well, this analysis specifically points out that the app is
           | making connections to suspicious places where it shouldn't
           | need to.
        
           | yawaworht1978 wrote:
           | It also phones home to a logging service. Why would an app
           | like that keep logs.
        
       | jeltz wrote:
       | Is there any reason to believe that CIPHR is not just yet another
       | police honeypot? This could just be two police agencies shitting
       | on each other's honeypots.
        
         | zenexer wrote:
         | If I were such an agency, I'd definitely have multiple
         | honeypots competing with each other.
        
       | bcraven wrote:
       | "STAY AWAY FROM ANOM IF YOU VALUE YOUR PRIVACY & SAFEY, THEY ARE
       | COMPROMISED, LIARS AND YOUR DATA IS RUNNING VIA USA - Passed onto
       | LAW ENFORCEMENT and other Entities"
        
       | vmception wrote:
       | > STAY AWAY FROM ANOM IF YOU VALUE YOUR PRIVACY & SAFEY, THEY ARE
       | COMPROMISED, LIARS AND YOUR DATA IS RUNNING VIA USA - Passed onto
       | LAW ENFORCEMENT and other Entities
        
       | na85 wrote:
       | >This is an ENTERPRISE MILITARY GRADE Encrypted setup.
       | 
       | I'll take "Signs someone doesn't know what they are talking about
       | for 200, Alex"
        
       | ______- wrote:
       | Maybe I'm missing something vital here, but why trust these `drug
       | dealer` phones? What's wrong with using Signal on an encrypted
       | Android device?
       | 
       | Since the Encrochat scare I would imagine no dealer in their
       | right mind would ever use a crimephone again.
        
         | Cyril_HN wrote:
         | Exactly my thought. Surely, if you're a criminal and you're
         | actually successful, then you want to use open source privacy.
         | Heck, if only to hide your usage with everyone else's right?
         | It's not unusual to have Signal on your phone. It's pretty
         | weird to have Anom or whatever else exists
        
         | 9wzYQbTYsAIc wrote:
         | Apparently there's criminals that only trust other criminals
         | (also apparently, those same criminals are highly likely to
         | betray each other) and those trusted criminals are saying "use
         | this phone, it's secure".
         | 
         | Plus, managing DIY security is more complicated than just
         | running Signal on an encrypted phone. Same concerns regarding
         | supply chain interdiction, remote code execution, and other
         | security vulnerabilities on the operating system running
         | Signal.
        
           | md_ wrote:
           | > Plus, managing DIY security is more complicated than just
           | running Signal on an encrypted phone. Same concerns regarding
           | supply chain interdiction, remote code execution, and other
           | security vulnerabilities on the operating system running
           | Signal.
           | 
           | Yes, but specifically to supply chain security, as this
           | attack shows, the most affordable option to secure your
           | supply chain is to ensure your devices and downloads cannot
           | be uniquely targeted.
           | 
           | Buying a stock iPhone in cash and downloading Signal from the
           | App Store is a far better approach than buying a "drug dealer
           | phone."
           | 
           | I do think this attack, as you imply, simply highlights how
           | hard it is for even _motivated_ consumers in the market to
           | make _actually_ secure choices, which in turn is why the
           | market underemphasizes real security improvements.
        
             | 9wzYQbTYsAIc wrote:
             | Well put, and I agree that right now the most effective
             | thing would probably be to buy a stock iPhone, from a
             | random source, in cash, etc.
             | 
             | That said, one huge caveat: any stock, internet-connected
             | phone is always one law away from being rendered completely
             | transparent to law enforcement with legal jurisdiction over
             | the place of sale.
             | 
             | In the US, for example, Congress could write a law that
             | forces a back door.
             | 
             | The back door doesn't even have to be to the encryption
             | keys or algorithm, but could be a simple screen capture
             | interface that can be remotely triggered with a warrant.
        
               | mianos wrote:
               | This exact law exists in Australia, the "Assistance &
               | Access Act". That these laws exist in Australia is also a
               | reason why there is a lot of co-operation between US and
               | Australian law enforcement. I am not sure how but it
               | gives the US an ability to do things they can't do on
               | their own shore. The US often works on other countries,
               | like Bucharest in the An0m case to work around their own
               | laws.
        
         | notatoad wrote:
         | the missing context is that anom has been revealed to be an FBI
         | sting operation. no dealer in their right might should have
         | trusted it, but many did.
         | 
         | https://www.bbc.com/news/world-57394831
        
           | vmception wrote:
           | The real question is how long will they keep Wickr running?
        
             | jtbayly wrote:
             | Are you implying that Wickr is a sting operation also?
             | 
             | Anything you can point me to read about that?
        
               | vmception wrote:
               | It is set up like an obvious honey pot just like Anom was
               | set up like an obvious honey pot and should be avoided
               | purely for those reasons alone, just like Anom should
               | have been avoided purely for those reasons alone
               | 
               | There is no way to know whether either of those services
               | were compromised simply due to their express purpose of
               | forwarding everything to government agent's computers
               | 
               | They're just simply not capable of providing users any of
               | the assurances they claim in a way the user can ever have
               | the assurance of
        
               | jtbayly wrote:
               | Thanks. As-in there is no way to evaluate whether Wickr's
               | claims of encryption are true?
        
               | vmception wrote:
               | No way to evaluate whether your messages are readable by
               | law enforcement at any given point in time, with a
               | greater red flag being the advertising claims of Wickr
               | misleading users to the contrary. Wickr, a US based
               | company.
               | 
               | There may be _some_ level of encryption, it _acts_ like a
               | company set up by the government or made to be tapped
               | into.
               | 
               | This wasnt conspiracy theory fiction even before Anom, as
               | there are other examples of governments especially the US
               | government doing this already. Just let Anom be another
               | more clear cut reminder that it doesn't matter who you
               | trust that uses a software, if it doesn't pass some key
               | criteria then don't use it. There is no "I'm sure this
               | large group of people thought of that" just assume they
               | are stupid, negligent, thought the same as you did and
               | nobody attempted any scrutiny, or are all informants
               | themselves.
        
       | nix23 wrote:
       | >Stock Android Operating system with special Enterprise level
       | Encryption
       | 
       | OHOOO Enterprise level encryption...FIPS :)
       | 
       | Stay away from both.
        
       | sarnowski wrote:
       | I guess it's related to
       | https://www.europol.europa.eu/newsroom/news/800-criminals-ar...
        
         | worldsayshi wrote:
         | Main (I think) hacker news thread regarding this event:
         | https://news.ycombinator.com/item?id=27430508
        
       | tomcooks wrote:
       | > "in ROMANIA which is a third world country"
       | 
       | Classic.
       | 
       | No matter how powerful the infrastructure or skilled the local
       | personnel, some countries are doomed to be put always in the same
       | bucket by certain people from certain other countries.
        
         | pacman2 wrote:
         | Romania is a very interesting place. An Bucharest, "The Paris
         | of the East" must not be afraid compared to Prague or Budapest.
         | 
         | Estonia, is a third world country. Total breakdown of any
         | governmental admiistration, corrupt etc. (dont ask how I know)
        
           | mads wrote:
           | How do you know?
        
         | vodkapump wrote:
         | Can't even use the "Clearly they were using the cold war era
         | definition" excuse, as Romania would be a second world country
         | by that definition.
        
         | buran77 wrote:
         | > a third world country that may state they take privacy
         | seriously but as the old saying goes "shit walks, money talks"
         | 
         | You didn't even have to read that much into the article to spot
         | the ignorance. Whether by gun, "law", or money, there's no
         | place where your data untouchable. But you could have stopped
         | right here:
         | 
         | > This is an ENTERPRISE MILITARY GRADE Encrypted setup.
         | 
         | The famed "military encryption".
        
       | captainmuon wrote:
       | Maybe it is not normal, but when I read about these
       | gangsterphones I think, hmm I want to make my own (legit) secure
       | phone :-)
       | 
       | It seems they use off-the-shelf phones and put a custom ROM on
       | them. Can anybody recommend a state of the art phone that has
       | good custom ROM support (close to mainline Linux if possible;
       | custom images have full hardware support)?
       | 
       | I imagine to use it for "citizen journalism", i.e. safely taking
       | pictures and posting them anonymously to social media. For that
       | reason the PinePhone would be out - it doesn't have a very good
       | camera and doesn't run social media apps.
        
         | merlinscholz wrote:
         | Usually Google Pixel phones have the best OS support and the
         | most hardware security features. Most security focused Android
         | distros are only available for them:
         | 
         | https://grapheneos.org/faq#device-support
        
         | nuker wrote:
         | > Can anybody recommend a state of the art phone that has good
         | custom ROM support
         | 
         | I'd try this: https://wiki.lineageos.org/devices/
        
         | willis936 wrote:
         | Practically speaking, an iPhone is your best bet in terms of
         | least likely to be backdoored and best security practices.
         | Everything spooky like location services, tracking, phoning
         | home, etc. is well explained in the settings and can be turned
         | off. If you just want a secure hardware platform there is no
         | reason to attempt to reinvent the wheel and increase your
         | surface area.
         | 
         | VPNs work fine on them. You can set up your own tor nodes to
         | VPN in behind from another VPN, etc. A tinfoil hat can have
         | many layers.
         | 
         | It just won't be a cheap secondary burner toy phone because
         | they're so expensive.
        
           | GekkePrutser wrote:
           | These gangsterphones are far from cheap. I remember the
           | earlier network of them that was taken down in the
           | Netherlands. I forget the name but the phones apparently cost
           | around EUR2000 which is more than the most expensive iPhone
           | you can buy.
           | 
           | I guess gangsters only trust other shady types to sell them
           | stuff. In this case the trust was misplaced because they
           | stored all the keys centrally and the cops were listening in
           | for months before they shut it down.
        
             | willis936 wrote:
             | Sounds like they're suckers. Higher prices should be
             | setting off "con" alerts in their head. I wouldn't trust
             | someone who can't do proper risk assessment to sell me
             | drugs.
        
               | mytailorisrich wrote:
               | It (encrochat) worked well and the network was brought
               | down when the police go access the the servers (physical
               | access, I believe).
               | 
               | On a side note, conning international criminals carries a
               | level of risk to one's health...
        
               | willis936 wrote:
               | >conning international criminal carries a level of risk
               | to one's health
               | 
               | True, but so does cooperating with authorities to be a
               | honeypot. Branding yourself as a legitimate business for
               | criminals is a Bad Idea for the very reason encrochat
               | learned. The criminals should be thinking the same way.
        
               | mytailorisrich wrote:
               | > _True, but so does cooperating with authorities to be a
               | honeypot_
               | 
               | I'm not aware that Encrochat did anything of the sort.
        
               | hkyigkfnrj wrote:
               | Or maybe they are thinking that if they pay a lot, they
               | "are not the product".
               | 
               | A bit like buying Apple, which is also very expensive.
        
           | joemazerino wrote:
           | Are you sure that an iPhone can be completely cut off from
           | Apple?
        
             | willis936 wrote:
             | Yes, by simple means of IP filtering *apple.com from a
             | network you VPN to if you don't trust the device to honor
             | the settings. The device will still work.
             | 
             | You'll be hardpressed to find a more secure hardware
             | platform on android.
             | 
             | https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/ap
             | p...
        
               | sloshnmosh wrote:
               | You'll also want something that can also catch CNAME's
               | (such as Pihole) because Apple uses content delivery
               | servers such as Akamai for a lot of their data transfers.
        
               | willis936 wrote:
               | True. If it were me who really cared about phoning home,
               | I would buy a fresh iPhone, put it on its own WLAN from
               | first boot, then record all packets from it for a month
               | (plus some prodding of opening apps and changing
               | settings). That should build a relatively comprehensive
               | list of addresses to consider filtering.
               | 
               | Short of living in a shack in the woods, we will all have
               | to trust someone at some point. I'm content to trust
               | Apple to not lie on their documents, so the more
               | important security and privacy checkboxes are ticked.
        
         | user-the-name wrote:
         | > when I read about these gangsterphones I think, hmm I want to
         | make my own (legit) secure phone
         | 
         | Why? They are used by gangsters. These are not nice people.
         | They are not people with innocent secrets they need to keep
         | from those who would oppress them. They are people who murder,
         | who ruin lives, and who undermine peaceful society.
         | 
         | You would objectively be making the world a worse place by
         | helping them. Why would you want to do that?
        
           | emptyparadise wrote:
           | No encryption scheme can tell the difference between a
           | protest organizer and a drug dealer.
        
             | AJ007 wrote:
             | More than that, consider what percentage of the worlds
             | population can be imprisoned or executed for things we in
             | the West would consider mundane activity.
             | 
             | The greatest moral failure of Silicon Valley and American
             | tech was enabling human rights abuses on a massive scale by
             | selling hardware and software to oppressive and ultimately
             | illegitimate governments during the early days of the
             | internet. The ship has sailed on that one now, perhaps,
             | with the early assistance in building the Great Firewall of
             | China for example.
             | 
             | There remains a moral obligation for American companies to
             | build secure communication platforms for the internet.
             | Instead they drift further, yielding to demands from
             | governments to host data (which often never should have
             | been stored) locally.
             | 
             | The most disturbing trend I have seen over the last decade
             | on hacker news is the shift from support of an open and
             | free internet to an internet of control and censorship. I
             | can only conclude that all is lost if the core engineers
             | and hackers who build and design these systems can no
             | longer explain why this is important but rather argue why
             | the internet shouldn't be secure.
             | 
             | There are many unintended implications to this, one being
             | American intelligence agents can no longer operate safely
             | abroad. Others include the withering of development in the
             | protocols and standards from which the internet was born, a
             | redirection of talent and resources to private companies
             | and private networks which are constructed in a way to
             | build monopolies and then extract rent from its users.
             | Facebook could be built on the web, but nothing lasting
             | could be built on Facebook.
             | 
             | That's my rant.
        
         | [deleted]
        
         | lvass wrote:
         | Running social media apps is the furthest from secure I would
         | imagine. You could just use a web browser if you really wanted
         | to.
        
       ___________________________________________________________________
       (page generated 2021-06-08 23:03 UTC)