[HN Gopher] Anom Encrypted App Analysis
___________________________________________________________________
Anom Encrypted App Analysis
Author : CPAhem
Score : 82 points
Date : 2021-06-08 10:17 UTC (12 hours ago)
(HTM) web link (webcache.googleusercontent.com)
(TXT) w3m dump (webcache.googleusercontent.com)
| skissane wrote:
| Archived versions: https://archive.is/jtJvK
|
| https://web.archive.org/web/20210608102417/https://webcache....
|
| (Since, as we all know, Google's webcache won't last)
| yawaworht1978 wrote:
| Wow, is this really all true? How could he find out the hosting
| was on AWS? How did none of the criminals get to see this blog?
| Did the police intervene and had him remove the blog?
| hn_throwaway_99 wrote:
| > How did none of the criminals get to see this blog? Did the
| police intervene and had him remove the blog?
|
| I mean, it's pretty clear to me that (a) criminals are highly
| unlikely to see this blog and (b) if they did, so what, they
| wouldn't have understood it/believed it anyway. Half the
| comments _on HN_ don 't give it any credence because it's
| written by someone whose first language is obviously not
| English and who likes hyperbolic ALL CAPS, despite the fact
| that the underlying analysis is valid.
| hkyigkfnrj wrote:
| 4D chess theory:
|
| This analysis was written by law enforcement in advance of the
| takedown to promote the next backdoored app.
| layoutIfNeeded wrote:
| "Encrypted Military Grade Encryption" - LOL
| emptyparadise wrote:
| Must be the same military that puts nuclear secrets on
| flashcard websites
| GekkePrutser wrote:
| This 'analysis' seems to be more PR speak by another similar
| network? I wouldn't put much trust in people using terms such as
| 'ENTERPRISE MILITARY GRADE', of course in all caps to emphasize
| the effect. Has snake oil written all over it.
|
| I thought this article would be a genuine analysis by a security
| researcher as a tie-in to the news today:)
| hn_throwaway_99 wrote:
| I think you don't understand what is going on here. ANOM was
| just admitted by the Australian Police and FBI to have been
| specifically built to infiltrate organized crime. The whole app
| was a plot to get access to the messages of these purported
| criminals.
|
| This analysis came out a couple months ago, and was exactly
| correct. Also, you are blaming the style of the writing but
| ignoring the substance, which is that the app is most
| definitely making encrypted connections where it has no need to
| do so.
| GekkePrutser wrote:
| I didn't know that when I wrote that, no. I thought it was
| the same story as EncroChat at the time (where an existing
| network was taken over by the police). I saw it in more
| detailed news reports since.
|
| The points might have been valid but the language is not
| instilling any kind of confidence: "This is an ENTERPRISE
| MILITARY GRADE Encrypted setup." doesn't exactly make it seem
| like a security researcher who knows what they're talking
| about. And add many other words capitalised for maximum shock
| effect: "imagine you were meeting up with someone like an EX-
| LOVER your partner may not approve of"
|
| It all sounds very much FUD and biased. If you do a good
| analysis, this is not how you present it.
|
| The main points he really makes are poor endpoint security
| (not uncommon in this market, as many such networks have been
| breached) and noticed some suspicious traffic which is indeed
| a telltale that something more is going on.
|
| But it sounds way too much like someone with 'skin in the
| game' was trying to spin it and turned out to be right.
| 9wzYQbTYsAIc wrote:
| Technically, ANOM did start as a "legitimate" criminal
| application, but was handed over to the FBI early in
| development as part of a plea deal.
| thieving_magpie wrote:
| Not to speak for them but I experienced the same feeling of
| interest in who the author was. For me it sounded like
| someone associated with CIPHR or another messaging
| application that did this analysis (still factual analysis)
| on a rival application. There was some marketing-type
| language in there that made me think that.
| thieving_magpie wrote:
| I've never considered JIRA would be used by the FBI or
| intelligence agencies. The user stories would be fun to read.
|
| I wonder why this blog was deleted by the author. Get a phone
| call from the FBI?
| Yeri wrote:
| Guess this person was right :)
| 542458 wrote:
| Yes, but also no. Right in that AN0M wasn't secure. Wrong in
| that it wasn't insecure because it didn't disable Google
| services, or use secure updates or whatever - it was insecure
| because it just deliberately sent everything to the Feds.
| hn_throwaway_99 wrote:
| Well, this analysis specifically points out that the app is
| making connections to suspicious places where it shouldn't
| need to.
| yawaworht1978 wrote:
| It also phones home to a logging service. Why would an app
| like that keep logs.
| jeltz wrote:
| Is there any reason to believe that CIPHR is not just yet another
| police honeypot? This could just be two police agencies shitting
| on each other's honeypots.
| zenexer wrote:
| If I were such an agency, I'd definitely have multiple
| honeypots competing with each other.
| bcraven wrote:
| "STAY AWAY FROM ANOM IF YOU VALUE YOUR PRIVACY & SAFEY, THEY ARE
| COMPROMISED, LIARS AND YOUR DATA IS RUNNING VIA USA - Passed onto
| LAW ENFORCEMENT and other Entities"
| vmception wrote:
| > STAY AWAY FROM ANOM IF YOU VALUE YOUR PRIVACY & SAFEY, THEY ARE
| COMPROMISED, LIARS AND YOUR DATA IS RUNNING VIA USA - Passed onto
| LAW ENFORCEMENT and other Entities
| na85 wrote:
| >This is an ENTERPRISE MILITARY GRADE Encrypted setup.
|
| I'll take "Signs someone doesn't know what they are talking about
| for 200, Alex"
| ______- wrote:
| Maybe I'm missing something vital here, but why trust these `drug
| dealer` phones? What's wrong with using Signal on an encrypted
| Android device?
|
| Since the Encrochat scare I would imagine no dealer in their
| right mind would ever use a crimephone again.
| Cyril_HN wrote:
| Exactly my thought. Surely, if you're a criminal and you're
| actually successful, then you want to use open source privacy.
| Heck, if only to hide your usage with everyone else's right?
| It's not unusual to have Signal on your phone. It's pretty
| weird to have Anom or whatever else exists
| 9wzYQbTYsAIc wrote:
| Apparently there's criminals that only trust other criminals
| (also apparently, those same criminals are highly likely to
| betray each other) and those trusted criminals are saying "use
| this phone, it's secure".
|
| Plus, managing DIY security is more complicated than just
| running Signal on an encrypted phone. Same concerns regarding
| supply chain interdiction, remote code execution, and other
| security vulnerabilities on the operating system running
| Signal.
| md_ wrote:
| > Plus, managing DIY security is more complicated than just
| running Signal on an encrypted phone. Same concerns regarding
| supply chain interdiction, remote code execution, and other
| security vulnerabilities on the operating system running
| Signal.
|
| Yes, but specifically to supply chain security, as this
| attack shows, the most affordable option to secure your
| supply chain is to ensure your devices and downloads cannot
| be uniquely targeted.
|
| Buying a stock iPhone in cash and downloading Signal from the
| App Store is a far better approach than buying a "drug dealer
| phone."
|
| I do think this attack, as you imply, simply highlights how
| hard it is for even _motivated_ consumers in the market to
| make _actually_ secure choices, which in turn is why the
| market underemphasizes real security improvements.
| 9wzYQbTYsAIc wrote:
| Well put, and I agree that right now the most effective
| thing would probably be to buy a stock iPhone, from a
| random source, in cash, etc.
|
| That said, one huge caveat: any stock, internet-connected
| phone is always one law away from being rendered completely
| transparent to law enforcement with legal jurisdiction over
| the place of sale.
|
| In the US, for example, Congress could write a law that
| forces a back door.
|
| The back door doesn't even have to be to the encryption
| keys or algorithm, but could be a simple screen capture
| interface that can be remotely triggered with a warrant.
| mianos wrote:
| This exact law exists in Australia, the "Assistance &
| Access Act". That these laws exist in Australia is also a
| reason why there is a lot of co-operation between US and
| Australian law enforcement. I am not sure how but it
| gives the US an ability to do things they can't do on
| their own shore. The US often works on other countries,
| like Bucharest in the An0m case to work around their own
| laws.
| notatoad wrote:
| the missing context is that anom has been revealed to be an FBI
| sting operation. no dealer in their right might should have
| trusted it, but many did.
|
| https://www.bbc.com/news/world-57394831
| vmception wrote:
| The real question is how long will they keep Wickr running?
| jtbayly wrote:
| Are you implying that Wickr is a sting operation also?
|
| Anything you can point me to read about that?
| vmception wrote:
| It is set up like an obvious honey pot just like Anom was
| set up like an obvious honey pot and should be avoided
| purely for those reasons alone, just like Anom should
| have been avoided purely for those reasons alone
|
| There is no way to know whether either of those services
| were compromised simply due to their express purpose of
| forwarding everything to government agent's computers
|
| They're just simply not capable of providing users any of
| the assurances they claim in a way the user can ever have
| the assurance of
| jtbayly wrote:
| Thanks. As-in there is no way to evaluate whether Wickr's
| claims of encryption are true?
| vmception wrote:
| No way to evaluate whether your messages are readable by
| law enforcement at any given point in time, with a
| greater red flag being the advertising claims of Wickr
| misleading users to the contrary. Wickr, a US based
| company.
|
| There may be _some_ level of encryption, it _acts_ like a
| company set up by the government or made to be tapped
| into.
|
| This wasnt conspiracy theory fiction even before Anom, as
| there are other examples of governments especially the US
| government doing this already. Just let Anom be another
| more clear cut reminder that it doesn't matter who you
| trust that uses a software, if it doesn't pass some key
| criteria then don't use it. There is no "I'm sure this
| large group of people thought of that" just assume they
| are stupid, negligent, thought the same as you did and
| nobody attempted any scrutiny, or are all informants
| themselves.
| nix23 wrote:
| >Stock Android Operating system with special Enterprise level
| Encryption
|
| OHOOO Enterprise level encryption...FIPS :)
|
| Stay away from both.
| sarnowski wrote:
| I guess it's related to
| https://www.europol.europa.eu/newsroom/news/800-criminals-ar...
| worldsayshi wrote:
| Main (I think) hacker news thread regarding this event:
| https://news.ycombinator.com/item?id=27430508
| tomcooks wrote:
| > "in ROMANIA which is a third world country"
|
| Classic.
|
| No matter how powerful the infrastructure or skilled the local
| personnel, some countries are doomed to be put always in the same
| bucket by certain people from certain other countries.
| pacman2 wrote:
| Romania is a very interesting place. An Bucharest, "The Paris
| of the East" must not be afraid compared to Prague or Budapest.
|
| Estonia, is a third world country. Total breakdown of any
| governmental admiistration, corrupt etc. (dont ask how I know)
| mads wrote:
| How do you know?
| vodkapump wrote:
| Can't even use the "Clearly they were using the cold war era
| definition" excuse, as Romania would be a second world country
| by that definition.
| buran77 wrote:
| > a third world country that may state they take privacy
| seriously but as the old saying goes "shit walks, money talks"
|
| You didn't even have to read that much into the article to spot
| the ignorance. Whether by gun, "law", or money, there's no
| place where your data untouchable. But you could have stopped
| right here:
|
| > This is an ENTERPRISE MILITARY GRADE Encrypted setup.
|
| The famed "military encryption".
| captainmuon wrote:
| Maybe it is not normal, but when I read about these
| gangsterphones I think, hmm I want to make my own (legit) secure
| phone :-)
|
| It seems they use off-the-shelf phones and put a custom ROM on
| them. Can anybody recommend a state of the art phone that has
| good custom ROM support (close to mainline Linux if possible;
| custom images have full hardware support)?
|
| I imagine to use it for "citizen journalism", i.e. safely taking
| pictures and posting them anonymously to social media. For that
| reason the PinePhone would be out - it doesn't have a very good
| camera and doesn't run social media apps.
| merlinscholz wrote:
| Usually Google Pixel phones have the best OS support and the
| most hardware security features. Most security focused Android
| distros are only available for them:
|
| https://grapheneos.org/faq#device-support
| nuker wrote:
| > Can anybody recommend a state of the art phone that has good
| custom ROM support
|
| I'd try this: https://wiki.lineageos.org/devices/
| willis936 wrote:
| Practically speaking, an iPhone is your best bet in terms of
| least likely to be backdoored and best security practices.
| Everything spooky like location services, tracking, phoning
| home, etc. is well explained in the settings and can be turned
| off. If you just want a secure hardware platform there is no
| reason to attempt to reinvent the wheel and increase your
| surface area.
|
| VPNs work fine on them. You can set up your own tor nodes to
| VPN in behind from another VPN, etc. A tinfoil hat can have
| many layers.
|
| It just won't be a cheap secondary burner toy phone because
| they're so expensive.
| GekkePrutser wrote:
| These gangsterphones are far from cheap. I remember the
| earlier network of them that was taken down in the
| Netherlands. I forget the name but the phones apparently cost
| around EUR2000 which is more than the most expensive iPhone
| you can buy.
|
| I guess gangsters only trust other shady types to sell them
| stuff. In this case the trust was misplaced because they
| stored all the keys centrally and the cops were listening in
| for months before they shut it down.
| willis936 wrote:
| Sounds like they're suckers. Higher prices should be
| setting off "con" alerts in their head. I wouldn't trust
| someone who can't do proper risk assessment to sell me
| drugs.
| mytailorisrich wrote:
| It (encrochat) worked well and the network was brought
| down when the police go access the the servers (physical
| access, I believe).
|
| On a side note, conning international criminals carries a
| level of risk to one's health...
| willis936 wrote:
| >conning international criminal carries a level of risk
| to one's health
|
| True, but so does cooperating with authorities to be a
| honeypot. Branding yourself as a legitimate business for
| criminals is a Bad Idea for the very reason encrochat
| learned. The criminals should be thinking the same way.
| mytailorisrich wrote:
| > _True, but so does cooperating with authorities to be a
| honeypot_
|
| I'm not aware that Encrochat did anything of the sort.
| hkyigkfnrj wrote:
| Or maybe they are thinking that if they pay a lot, they
| "are not the product".
|
| A bit like buying Apple, which is also very expensive.
| joemazerino wrote:
| Are you sure that an iPhone can be completely cut off from
| Apple?
| willis936 wrote:
| Yes, by simple means of IP filtering *apple.com from a
| network you VPN to if you don't trust the device to honor
| the settings. The device will still work.
|
| You'll be hardpressed to find a more secure hardware
| platform on android.
|
| https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/ap
| p...
| sloshnmosh wrote:
| You'll also want something that can also catch CNAME's
| (such as Pihole) because Apple uses content delivery
| servers such as Akamai for a lot of their data transfers.
| willis936 wrote:
| True. If it were me who really cared about phoning home,
| I would buy a fresh iPhone, put it on its own WLAN from
| first boot, then record all packets from it for a month
| (plus some prodding of opening apps and changing
| settings). That should build a relatively comprehensive
| list of addresses to consider filtering.
|
| Short of living in a shack in the woods, we will all have
| to trust someone at some point. I'm content to trust
| Apple to not lie on their documents, so the more
| important security and privacy checkboxes are ticked.
| user-the-name wrote:
| > when I read about these gangsterphones I think, hmm I want to
| make my own (legit) secure phone
|
| Why? They are used by gangsters. These are not nice people.
| They are not people with innocent secrets they need to keep
| from those who would oppress them. They are people who murder,
| who ruin lives, and who undermine peaceful society.
|
| You would objectively be making the world a worse place by
| helping them. Why would you want to do that?
| emptyparadise wrote:
| No encryption scheme can tell the difference between a
| protest organizer and a drug dealer.
| AJ007 wrote:
| More than that, consider what percentage of the worlds
| population can be imprisoned or executed for things we in
| the West would consider mundane activity.
|
| The greatest moral failure of Silicon Valley and American
| tech was enabling human rights abuses on a massive scale by
| selling hardware and software to oppressive and ultimately
| illegitimate governments during the early days of the
| internet. The ship has sailed on that one now, perhaps,
| with the early assistance in building the Great Firewall of
| China for example.
|
| There remains a moral obligation for American companies to
| build secure communication platforms for the internet.
| Instead they drift further, yielding to demands from
| governments to host data (which often never should have
| been stored) locally.
|
| The most disturbing trend I have seen over the last decade
| on hacker news is the shift from support of an open and
| free internet to an internet of control and censorship. I
| can only conclude that all is lost if the core engineers
| and hackers who build and design these systems can no
| longer explain why this is important but rather argue why
| the internet shouldn't be secure.
|
| There are many unintended implications to this, one being
| American intelligence agents can no longer operate safely
| abroad. Others include the withering of development in the
| protocols and standards from which the internet was born, a
| redirection of talent and resources to private companies
| and private networks which are constructed in a way to
| build monopolies and then extract rent from its users.
| Facebook could be built on the web, but nothing lasting
| could be built on Facebook.
|
| That's my rant.
| [deleted]
| lvass wrote:
| Running social media apps is the furthest from secure I would
| imagine. You could just use a web browser if you really wanted
| to.
___________________________________________________________________
(page generated 2021-06-08 23:03 UTC)