Euro police forces infiltrated encrypted phone biz – and now 'criminal' EncroChat users are being rounded up
- Reference: 1593723368
- News link: https://www.theregister.co.uk/2020/07/02/encrochat_op_venetic_encrypted_phone_arrests/
- Source link:
The encrypted chat platform is alleged by British, French and Dutch law enforcement agencies to have been used by around 60,000 people in total – many of whom, it is alleged, were members of organised crime gangs using the network to plan their crimes.
"Since 2017, the French gendarmerie and judicial authorities have been investigating phones that used the secured communication tool EncroChat, after discovering that the phones were regularly found in operations against organised crime groups and that the company was operating from servers in France," said EU law enforcement coordination body Eurojust in a statement.
[1]
This is what £1.4m looks like... as hauled in by the East Midlands Special Operations Unit. Pic credit: National Crime Agency
In May, police in France, assisted by the Netherlands' cops, infiltrated EncroChat's core network – and in mid-June the operator pulled the plug, having realised the game was up. Users were urged to throw away their handsets.
EncroChat was a reseller of encrypted phones as well as a mobile network operator – potentially an MVNO, if Motherboard's [2]description of its operations is accurate. Its handsets, said to be BQ Aquaris X2 Android units running two OSes side by side – one innocent, one with privacy features enabled – had a custom messaging app which routed messages through a central server.
The phones also had a panic button feature, where entering a certain PIN to the unlock screen would wipe the device. Handsets were said to cost around £1,500 for a six-month contract.
The takedown of the network has been a poorly disguised secret, with Northern Irish suspects [3]reportedly being arrested last week after data from EncroChat's servers was shared around European police forces. Various media reported a fortnight ago that EncroChat's operators pulled the plug after realising the entire product had been compromised by police agencies.
"The data was in first instance shared with the Netherlands. Eurojust facilitated the creation of a joint investigation team (JIT) between the two countries and with the participation of Europol, the European Union Agency for Law Enforcement Cooperation, in April 2020," said Eurojust, which tantalisingly mentioned that Dutch police had access to an "encrypted data stream".
This latter phrase could be read as suggesting that EncroChat's encryption had been broken, though official sources have, perhaps understandably, been very coy about what exactly was done to compromise EncroChat's systems. More should emerge during criminal trials in the coming weeks and months.
After French and Dutch police broke into EncroChat, British police were permitted to use their findings, meaning UK police forces were then able to kick down doors and make arrests. The National Crime Agency (NCA) claims a total of 746 arrests and the seizure of two tonnes of drugs, 77 assorted firearms and £54m in cash – so far – as a result of the EncroChat intelligence.
"The NCA created the technology and specialist data exploitation capabilities required to process the EncroChat data, and help identify and locate offenders by analysing millions of messages and hundreds of thousands of images," said the UK agency in a statement about its Operation Venetic.
There is no evidence in the public domain so far to support British police claims that all 10,000 of EncroChat's UK users were criminals. Such devices are of interest to legitimate users (journalists, lawyers, academics, domestic and foreign political campaigners – to name just a few) as well as criminals, though the UK state is notably hostile to the idea of [4]encrypted comms that its agents can't read whenever they feel like it. ®
Get our [5]Tech Resources
[1] https://regmedia.co.uk/2020/07/02/emsou_money.jpg
[2] https://www.vice.com/en_us/article/3aza95/how-police-took-over-encrochat-hacked
[3] http://www.irishnews.com/news/northernirelandnews/2020/06/25/news/further-searches-following-encrochat-breach-1984920/
[4] https://www.theregister.com/2019/12/20/uk_conservatives_brexit_from_whatsapp_to_signal/
[5] https://whitepapers.theregister.com/
Re: So...
No legaly mandated backdoors, no. Just the ones EncrChat made available to their own employees. All the cops had to do was get someone employed by EncroChat, and Bob's their Auntie.
I wouldn't call it good police work, I'd call it bad security practices at EncroChat.
How's that Zoom and/or Skype (etc. etc.) workin' for all y'all? Are your corporate lawyers happy with Microsoft storing all the stuff your employees use Office363 for?
But private ciphers also exist...even if end-to-end encryption is broken.......
Quote: "..UK state is notably hostile to the idea of encrypted comms that its agents can't read whenever they feel like it.*
*
Well...........the quote actually means "can't read the plain text".....because of course "the agents" can read the cipher text. But I wonder how often people use private ciphers BEFORE THE MESSAGE ENTERS A (SUSPECT) ENCRYPTED CHANNEL.
*
170G0f1M04$w05G40H660www0rjf0vux0Zxp0DsF
0Kgl1Lxu10tY0z9q07lL0PlT09RR1VmT0YfC0EW9
1Cod009h0bhS15Sz0tby1bLr1lUx0Xjv0BfA0xuL
0R2H1HD21Gw717DU18f20L3C0KEQ1ckO0L3a1bS0
1JLq0$Uv15jh0eQf0y0u0=pv0NxG0F=g04gg0SMo
0jC$0wsX1cfR00GG1jBd1OqP0A5n0sH30=FP0$3H
0hoL1CVn0J1l1c5M0$hh0JqB0qTL16ij0Sdp0DcZ
1jdt0XYO1cKu0jXy0K7=0G1k18GW0MQL0XVL07do
1gG30Yxp0=av02wB0Z6i16tl10wc1Imv0$xS0n64
1PDV1iX01kBB19TK1K3104st0AVe0DO61ZI51IVx
1Rnj1jdz0VNM0fAY05Ph08St141O1IvP1DM30Pne
0STY125Q0=Js1deS0JsY0oG10Ho00dbp0hig1IDy
1RA=0Kdr0=Vs0XoU12960fl00h3Q0tqI1jko1X7B
0n0r0kv=0V=i0kl=1brL0VD10d6V1DwO1PmC1h=c
11b70rN419Zp0y5y0X5z0jmT0MIR1SH01Sjx1gUL
16iD0ONn0DWc1HS50fJN0FfD0Hyz1LSC0i030cN1
02Wb0FdV10jl0hBx0eSy1NuV09oP06BV1bXt1OIf
1H7a0zoF1ZkG02td1fMt0axf0kxh0noc09450Cxf
1XkW0A7Y122N1Jzh0s4D1Ckf0kGI0gaK
*
Re: But private ciphers also exist...even if end-to-end encryption is broken.......
Can I have double fries and a banana fritter with that?
Re: But private ciphers also exist...even if end-to-end encryption is broken.......
The cock crows at midnight. Don't tell Madeline.
So having 'broken' an encrypted message service and shown it be a hive of scum and villainy, presumably they can point to all end-to-end encrypted messaging systems and say "Well, that one was full of wrong 'uns, so those probably are too - if only we had a way of intercepting the messages there, see what great work we can do in cleaning it up'.
The NCA, Mrs May's folly, may well think along those lines. Other agencies, e.g. the real expertise at GCHQ and its like, know better.
Matters arising
I may be wrong but my understanding is of encryption when using this device depending upon a dedicated chip. If so, the question arises whether relying upon a pre-configured chip is inherently less secure than when using software running on a generic processor. Among possibilities for insecurity are inclusion of a planned back-door or exploitation of an accidental vulnerability. Either way, an entire batch of devices becomes suspect. Vulnerabilities in solely open source, solely software, implementation of a reliable encryption algorithm can be identified and fixed without need of changing a physical component.
It would appear that both honest and criminal users of this device placed too much faith in the high cost of the service guaranteeing fitness for purpose.
The criminal element might have done better by using throwaway phones for each transaction. By not using potentially dodgy encryption they wouldn't draw attention to themselves. Moreover, open communication using, when feasible, agreed code words/phrases (perhaps decided in advance under encrypted email communication) can be made very secure for many purposes.
Perhaps, law enforcement agencies should offer expensive master-classes for criminals? There again, perhaps not.
Re: Matters arising
It's actually simpler than that.
The cops infiltrated EncroChat (the company itself) and snooped on supposedly encrypted data directly off the EncroChat servers. This is a very good example of why using code that has to go through a central server not under the control of the users should never be considered secure.
If you want security, peer to peer is the way to go. And sometimes not even then, at least in the hands of typical members of the GreatUnwashed.
We now return you to the usual unfounded bickering and speculation.
"When three sit down to talk revolution, two are fools and the third is a police spy."
Surveillance via small print. Human rights to privacy are gone.
for as long as 'authorities' have the power to read encrypted or otherwise data transmissions, launch secret satellites for interception reason, issue nsa letters compelling service providers to obey and reveal etc... thats if they obey the law. truth is, if they want badly enough, one worker can be expendable.. just re-employed elsewhere//
ask yourself, why does any company require so much information when registering for a service? Surely that would put customers off?
The answer is to consider that you're actually registering onto a spy program.
If youtube can store and serve so, so very much video hi res content, easily. how much storage space and speed capaility do you think text based data would require?
Re: Surveillance via small print. Human rights to privacy are gone.
"how much storage space and speed capaility do you think text based data would require?"
Speaking as a guy who has speced, built and run several Usenet news farms, the answer to that is "probably more than you think".
So...
So I presume no legally mandated "backdoors" we're mandated for this to happen?
No thought not.
Just good Police work.