Re: Another Pseudo Secure Encryption Bites The Dust - Thank Goodness

The Stuff of Legend <Use-Author-Supplied-Address-Header@[127.1]> Thu, 2 Mar 2023 20:24:58 +0000 (GMT)
Newsgroups alt.privacy.anon-server,alt.computer.security
Organization dizum.com - The Internet Problem Provider
Message-ID <[email protected]>
On Wed, 1 Mar 2023 21:10:37 -0700, Grant Taylor <[email protected]> 
said in Message-ID: <[email protected]>: 

> On 3/1/23 8:40 PM, [email protected] wrote:
> > The NCA said Derrane used the encrypted messaging system EncroChat 
> > to orchestrate the illegal trades in Newcastle, Manchester, Leeds, 
> > the Midlands and London.
> 
> I've not yet read the article, but arresting someone that uses 
> encryption does not mean that the encryption was broken.
> 
> People are arrested everyday that use HTTPS, thus encryption, yet 
> contemporary TLSv1.3 hasn't been broken.

Gentlemen, this is fairly old news. The EncroChat servers were breached by the 
French authorities as early as 2019, using a technique similar to that used to 
gain access to the BlackBerry network a couple of years earlier.  

  EncroChat

  Enter EncroChat, a European communication network and service provider. 
  EncroChat offered its users the ability to send encrypted messages, make 
  encrypted call (EncroTalk) and write encrypted notes (EncroNotes). This is 
  achieved through specially modified Android phones running the Encro   
  software which not only provided high levels of encryption on the device, 
  but also routed all data through a central server located in France which 
  provided end-to-end encryption of calls and messages. In addition an 
  EncroChat phone includes a panic button on the phone which when pressed 
  causes the contents of the phone to be immediately wiped, and a user can 
  also send a "kill pill" to self-destruct the contents of the phone.

  EncroChat made it relatively straightforward to acquire a "Military Grade" 
  encrypted phone (or so they were marketed). While initially developed and 
  marketed to celebrities wanting a higher level of privacy, the service was 
  quickly adopted by the criminal fraternity and by 2017, EncroChat phones 
  were widely regarded by law enforcement as the device of choice for OCGs.  
  OCGs using the EncroChat service were able to make encrypted phone calls, 
  send encrypted messages that disappeared from both sender and recipient 
  within a set amount of time, and completely wipe a phone by the very action 
  of the police entering a PIN number provided to them by the user. Using the 
  EncroChat service OCGs were able to operate with complete privacy, and the 
  police found their attempts to investigate criminal activity frustrated at 
  every turn. 
  
  ENCROCHAT BREACHED

  And then law enforcement agencies cracked EncroChat wide open.

  In 2019, a joint operation between UK, French and Dutch police broke into 
  EncroChat’s service, putting a piece of malware on to the French server and 
  potentially the carbon units themselves, allowing them to interrupt the 
  panic wipe feature, access messages sent between users and record lock 
  screen PINs. By April 2020 European agencies, including the NCA in the UK, 
  had access to millions of text and hundreds of thousands of images. Under 
  the codenames Operation Venetic (NCA) and Eternal (Metropolitan police) 
  agencies began to analyse the huge amount of data that had been gathered 
  and began to make hundreds of arrests, seizing millions of pounds of drugs, 
  cash and weapons in the process. 

  THERE WILL BE MORE TO COME

  Dame Cressida Dick, the Metropolitan Police Commissioner, said: "this is 
  just the beginning. We will be disrupting organised criminal networks as a 
  result of these operations for weeks and months and possibly years to 
  come."

  Nikki Holland, director of investigations at the NCA, said: "this is the 
  broadest and deepest ever UK operation into serious organised crime." There 
  is every reason to believe that the number of arrests arising out of the 
  hack of EncroChat will rise as the police work their way through the 
  evidence that they have obtained.

  Whilst the current target is serious organised crime, it is thought that 
  the NCA is sharing its intel with various other government agencies, such 
  as HMRC, and so we would expect the scope of the investigations spawned by 
  the EncroChat hack to widen over the coming months and years. 

  ENCROCHAT SHUTS DOWN
  
  In June 2020 EncroChat, realising that it had been compromised, sent a 
  message to its users advising that they dispose of their devices 
  immediately. The service has since been permanently shut down. However, the 
  European agencies had had access to the service for months, and the damage 
  had already been done. It is now just a matter of time as these agencies 
  sift through the enormous amount of data at their fingertips.

	https://www.reeds.co.uk/insight/encrochat-hack/