Re: Another Pseudo Secure Encryption Bites The Dust - Thank Goodness
The Stuff of Legend <Use-Author-Supplied-Address-Header@[127.1]> Thu, 2 Mar 2023 20:24:58 +0000 (GMT)
| Newsgroups | alt.privacy.anon-server,alt.computer.security |
|---|---|
| Organization | dizum.com - The Internet Problem Provider |
| Message-ID | <[email protected]> |
On Wed, 1 Mar 2023 21:10:37 -0700, Grant Taylor <[email protected]> said in Message-ID: <[email protected]>: > On 3/1/23 8:40 PM, [email protected] wrote: > > The NCA said Derrane used the encrypted messaging system EncroChat > > to orchestrate the illegal trades in Newcastle, Manchester, Leeds, > > the Midlands and London. > > I've not yet read the article, but arresting someone that uses > encryption does not mean that the encryption was broken. > > People are arrested everyday that use HTTPS, thus encryption, yet > contemporary TLSv1.3 hasn't been broken. Gentlemen, this is fairly old news. The EncroChat servers were breached by the French authorities as early as 2019, using a technique similar to that used to gain access to the BlackBerry network a couple of years earlier. EncroChat Enter EncroChat, a European communication network and service provider. EncroChat offered its users the ability to send encrypted messages, make encrypted call (EncroTalk) and write encrypted notes (EncroNotes). This is achieved through specially modified Android phones running the Encro software which not only provided high levels of encryption on the device, but also routed all data through a central server located in France which provided end-to-end encryption of calls and messages. In addition an EncroChat phone includes a panic button on the phone which when pressed causes the contents of the phone to be immediately wiped, and a user can also send a "kill pill" to self-destruct the contents of the phone. EncroChat made it relatively straightforward to acquire a "Military Grade" encrypted phone (or so they were marketed). While initially developed and marketed to celebrities wanting a higher level of privacy, the service was quickly adopted by the criminal fraternity and by 2017, EncroChat phones were widely regarded by law enforcement as the device of choice for OCGs. OCGs using the EncroChat service were able to make encrypted phone calls, send encrypted messages that disappeared from both sender and recipient within a set amount of time, and completely wipe a phone by the very action of the police entering a PIN number provided to them by the user. Using the EncroChat service OCGs were able to operate with complete privacy, and the police found their attempts to investigate criminal activity frustrated at every turn. ENCROCHAT BREACHED And then law enforcement agencies cracked EncroChat wide open. In 2019, a joint operation between UK, French and Dutch police broke into EncroChat’s service, putting a piece of malware on to the French server and potentially the carbon units themselves, allowing them to interrupt the panic wipe feature, access messages sent between users and record lock screen PINs. By April 2020 European agencies, including the NCA in the UK, had access to millions of text and hundreds of thousands of images. Under the codenames Operation Venetic (NCA) and Eternal (Metropolitan police) agencies began to analyse the huge amount of data that had been gathered and began to make hundreds of arrests, seizing millions of pounds of drugs, cash and weapons in the process. THERE WILL BE MORE TO COME Dame Cressida Dick, the Metropolitan Police Commissioner, said: "this is just the beginning. We will be disrupting organised criminal networks as a result of these operations for weeks and months and possibly years to come." Nikki Holland, director of investigations at the NCA, said: "this is the broadest and deepest ever UK operation into serious organised crime." There is every reason to believe that the number of arrests arising out of the hack of EncroChat will rise as the police work their way through the evidence that they have obtained. Whilst the current target is serious organised crime, it is thought that the NCA is sharing its intel with various other government agencies, such as HMRC, and so we would expect the scope of the investigations spawned by the EncroChat hack to widen over the coming months and years. ENCROCHAT SHUTS DOWN In June 2020 EncroChat, realising that it had been compromised, sent a message to its users advising that they dispose of their devices immediately. The service has since been permanently shut down. However, the European agencies had had access to the service for months, and the damage had already been done. It is now just a matter of time as these agencies sift through the enormous amount of data at their fingertips. https://www.reeds.co.uk/insight/encrochat-hack/