News: 1623646990

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

The AN0M fake secure chat app may have been too clever for its own good

(2021/06/14)


Comment In April 1943, Japanese admiral Isoroku Yamamoto was killed when the US Air Force shot down the plane carrying him to Balalae Airfield in the Solomon Islands.

The attack was made possible by the USA cracking Japanese codes and decrypting a message that revealed Yamamoto’s flight plan would just take him within range of America's scarce long-range aircraft.

The chances of those aircraft happening upon Yamamoto were very small so US strategists worried Japanese analysts might conclude an attack was only possible because their codes been broken.

[1]

The US chose to kill Yamamoto, because he was felt to be so important to the war effort that losing access to decrypted intelligence was worth the risk. But on other occasions in World War II, troops were sent into harm’s way to effectively protect intelligence sources.

[2]

[3]

Which brings me to last week’s news that Australian and US law enforcement agencies seeded a backdoored encrypted chat app named [4]AN0M into the criminal underworld, then [5]intercepted word of a great many crimes and swooped to arrest those responsible.

Late last week, FBI International Operations Division legal attaché for Australia Anthony Russo added another important piece of information: [6]speaking to Australian newspapers he said one reason for discontinuing use of AN0M was that it produced too much intelligence.

[7]

“The volume [of content] was increasing at a scale and our ability to resource it and monitoring it really wasn’t scalable commensurate to the growth,” he reportedly said.

Russo said authorities therefore decided enough was enough, so revealed AN0M’s existence. We also noted that, in March, someone poking around in the software's code spotted what looked like a backdoor and [8]raised the alarm in a later-deleted blog post.

I'd been thinking about the Yamamoto story since news of AN0M’s existence was revealed. Russo's reported remarks again got me thinking about when and if it is appropriate to reveal hidden strengths to your enemies.

[9]

At the press conference that revealed the existence of AN0M, Australian Federal Police commissioner Reece Kershaw said his agency, and others like it around the world, understand that criminals can choose from many end-to-end encrypted communications services. Kershaw tried to send a signal that while AN0M has been de-activated, authorities will always seek similar capabilities and have the smarts to do so.

“Criminals should be on notice that law enforcement are resolute to continue to evolve our capabilities,” Kershaw said.

Which sounded like a clear message that criminals should not assume AN0M is the end of a story.

[10]UK terror law reviewer calls for expanded police powers to imprison people who refuse to hand over passwords

[11]Revealed: The military radar system swiped from aerospace biz, leaked online by Clop ransomware gang

[12]FBI confirms Zodiac Killer's 340 cipher solved by trio of amateur math and software codebreakers

[13]'Facebook simply would not exist today if not for Bletchley Park,' says social network – but don't hold that against it

So while the most easily-learned and obvious lesson from AN0M was that criminals ought not to trust anyone selling “secure” comms apps, another lesson was that even if an app is cracked it's possible to mess up the cops by changing the signal-to-noise ratio.

The lesson for the rest of us law-abiding Reg readers is that law enforcement authorities around the world are well and truly committed to finding ways through and around encryption, wherever it is used by criminals.

Strategists at those agencies will also be aware of the Yamamoto decision and that the Allies went to great lengths to create cover stories that made a decryption conclusion less plausible.

We may never know if any of what we were told about AN0M this week was one of those useful diversions. And we can only hope that when law enforcement agencies make their very difficult choices about what to reveal, their decisions don’t have the unintended consequence of diluting privacy for the innocent. ®

Get our [14]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YMcowkQNtORAtxRBaCzPZgAAAEA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YMcowkQNtORAtxRBaCzPZgAAAEA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YMcowkQNtORAtxRBaCzPZgAAAEA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://www.theregister.com/2021/06/08/operation_ironside_anom/

[5] https://www.theregister.com/2021/06/08/fbi_trojan_shield/

[6] https://www.smh.com.au/national/global-an0m-operation-was-terminated-as-app-s-popularity-stretched-police-resources-20210610-p57ztk.html

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YMcowkQNtORAtxRBaCzPZgAAAEA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://twitter.com/MichaelM_ACT/status/1402086472543465472

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YMcowkQNtORAtxRBaCzPZgAAAEA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2021/03/29/terror_cops_password_law_change_call/

[11] https://www.theregister.com/2021/02/24/seaspray_radar_ransomware/

[12] https://www.theregister.com/2020/12/12/zodiac_killers_cipher_solved/

[13] https://www.theregister.com/2020/10/14/facebook_bletchley_park/

[14] https://whitepapers.theregister.com/

One Time Pads.

Anonymous Coward

What do you want to bet that anyone _really_ intent on secure communications will go back to using OTP's to ensure "The Man" can't decrypt their comms chatter? And what if they start using OTP's to encrypt noncritical chatter so that The Man has to decrypt exponentially more traffic only to find themselves the proud holder of someone's shopping list? I think I'll start using OTP's to encrypt everything too - perhaps a copy of "War and Peace" to give them something to read afterwards!

Re: One Time Pads.

Neil Barnes

Time to write a one time pad generator... with perhaps just a touch of non-random about it?

Re: One Time Pads.

Anonymous Coward

Anyway, my secret messages are encoded in every 14th and 29th letter in my FB posts, in ROT13 and the sequence determined by the alphabetical order of the 49th letter (as sorted alphabetically by their names in German). Every third word in Nynorsk; the rest equally divided between Swahili and English.

There also may or may not also be some quite intentional compression artifacts in my influencer style Instagram posts. These could, for example and if they existed, be decoded into numbers that refer to pages and word counts in one particular edition of . Of course, only the posts that include a word from the known list and show is to be used.

If you are willing to accept low bandwidth steganography can be quite hard to detect and decrypt. Heck, I can send morse code by alternating with foot I first step out of my front door with (using our agreed upon version the old Q-codes to speed things up a bit).

As long as no one has the decrypts written down in a notebook in their back pocket...

Re: One Time Pads.

Inkey

Crime and punishment ...shirly ?

Re: One Time Pads.

thames

Or just use public key cryptography. It's well known and widely available.

The problem with one time pads is that the key is as long as the message and you have to have a secure means of distributing the OTPs. If you can solve the OTP problem then they're great, but their use is limited by the inherent difficulty of this in most cases.

They key exchange problem and the defeating traffic analysis problems are the big issues with any sort of Internet chat.

Even public key cryptography has a pair of problem. One is doing the initial public key exchange. If someone can man in the middle all the conversations, he can substitute his own sets of keys during the initial exchange and man in the middle all the subsequent conversations. To really be sure, you would need to exchange keys in person with someone you can trust present who can vouch for the identity of each party.

The other problem is the traffic analysis one. It is sometimes more useful to know who is talking to whom than it is to know what they are talking about. Find out who is talking to whom and you can find out what the organizational structure is, which can give you clues as to where to infiltrate it. When the secret police excuse their tapping everyone's conversations on the grounds that "we're only collecting metadata", then they're being disingenuous because the connections between people are what they really want to know anyway, rather than just someone saying "I'll have the thing we talked about to you a day later than the time we agreed".

The whole idea of a special secure chat network dedicated to criminal activity is a bit dubious, and I don't mean from a moral or legal standpoint. I mean as in it is such a massive target for the police to infiltrate, and it is an evidence and criminal intelligence collection machine par excellence, that I can't see how anyone could think they could trust it. I certainly wouldn't.

Re: One Time Pads.

cantankerous swineherd

first distribute your key material...

Re: One Time Pads.

John Robson

Just encrypt it with a OTP....

Re: One Time Pads.

DrXym

Going back to the WW2 analogues, Churchill and Roosevelt conversed over a system called SIGSALY. It compressed their speech, combined it with random noise stored on a special record, and sent it to the other end and where a duplicate record would remove the noise and play out the voice.

The distribution of the OTPs and the equipment needed to operate calls must have been a huge pain in the arse, justified only by being the most secret of conversations. The rest of the time they would have used more conventional crypto

The issue with distribution is the same today - crims would need to meet face to face in order to exchange OTPs, or they'd have to have a secure means to transfer it, e.g. a courier who can be trusted. Maybe it would work for the kingpins but I doubt it would lower down the hierarchy.

Criminality

Anonymous Coward

A constant battle between greed, arrogance, stupidity and violence.

My monies with the Plods.

Re: Criminality

katrinab

You have to remember that you only read about the ones that get caught. Despite all the massive drugs busts you read about, it doesn't really seem to impact the supply lines at all, people can still get them.

Re: Criminality

Neil Barnes

The ones that don't get caught get knighthoods and MBEs... er, allegedly.

Re: Criminality

Anonymous Coward

Oxford University has the very nice Sackler Library, funded by drug dealing and untold resulting human misery. They really need to deal with that before worrying about Cecil Rhodes, whose victims are long dead.

Re: Criminality

Anonymous Coward

Every time you build a better mousetrap, the mice get smarter & learn to avoid it. Sure you catch a few, but all that does is provide warnings to the smart ones to avoid said traps.

"The moment you make something idiot proof, Mother Nature builds a better idiot to prove you wrong."

Re: Criminality

Chris G

To a cop, everybody is a potential criminal, it'just that they haven't found what your crime is yet.

That is why they are so fond of having backdoors into any secure communications.

Add to that the fact that govermments generally trust the people that voted them in far less than the voters trust them.

That's why the likes of NSA and GCHQ has history of mass evesdropping on their own populations.

If the fuzz have 'come out' on AN0M, it is because they think the crims have sussed them and the cops think they now have something better.

Whether you are a crim or a normal member of the public don't assume that selecting 'do not track' means you won't be tracked.

Re: Criminality

Velv

" don't assume that selecting 'do not track' means you won't be tracked "

First rule of spying on the population is specifically track anyone who has given any indication they would prefer not to be tracked

Re: A constant battle between greed, arrogance, stupidity and violence. My monies with the Plods.

Anonymous Coward

I dunno, some of the criminals are also greedy, arrogant, stupid and violent.

Sounds like a PsyOp

Draco

Law enforcement is always hammering on about how hard encryption makes their lives and the way to help them is to provide them with a master key to all encryption.

But ... now they have AN0N - and it is so freakin' AMAZING that they have TOO MUCH data to deal with rather than too little, so the "obvious" thing to do is shut down the program and shout it from the rooftops.

------

There are lots of things we don't know that could make any of the following true (there might be more possibilities, but I'm limiting myself to these two):

1) AN0N is compromised, but its focus was so narrow that the recent bust clearly exposed AN0N as compromised.

2) AN0N is not compromised, was known to be used in this case, but the bust was made by other means and this is a disinformation campaign against AN0N (and, probably, other similar types of apps).

Re: Sounds like a PsyOp

DJV

I like the way you encypted AN0M to AN0N throughout your entire post - made it very hard to decrypt and read!

So, a backdoored encrypted chat, eh ?

Pascal Monett

" law enforcement authorities around the world are well and truly committed to finding ways through and around encryption, wherever it is used by criminals "

And I have no problem with that.

What I have a problem with is those same authorities arguing that my Sync encryption should be backdoored, or that my PGP mail should be backdoored, or that my communications over Internet with my bank should be backdoored.

No, they should not. It is what keeps criminals out of my affairs. If it so happens that it also keeps authorities out of my affairs, there is one big difference : criminals do not have warrants at their disposal.

Re: So, a backdoored encrypted chat, eh ?

brotherelf

> criminals do not have warrants at their disposal.

Well, unless…

(judicial oversight doesn't scale either, btw)

Crims now know what not to trust, and how to stymie future infiltrations

Anonymous Coward

it was only going to work once anyway (like the suicide belt demonstration, or Snowden leak). That said, give it some time, the idea could be forked into something that only becomes blindingly obvious once it's pulled off.

How long ?

Andy The Hat

The writer asked how long you should keep the ability to evesdrop secret.

In the case of an encryption methodology - until it's compromised.

In the case of a military type dictatorship - as long as possible as it aids your grip on power.

In the case of the foremost democracy in the world - about 25 years whilst making money selling that encryption as secure communications technology to your allies so you could (theorectically) snoop on them. Yes that is the way Great Britain works ...

Anonymous South African Coward

I would've kept this thing tight under wraps, and never mentioned it.

Now the cops will have to find another way of getting into the ne'er-do-well's lines of communications, and this time the ne'er-do-wells may turn the tables by sending cops on useless chases all over the country/world/galaxy.

Warm Braw

I would in principle agree with you, but this [1]isn't the first time that crims have put too much faith in a supposedly secure communications system.

The reality is that all those wires and data centres are under someone's legal jurisdiction and are potentially under the control of law enforcement whether post hoc or ante hoc.

Always a risky strategy trusting your liberty to "honour amongst thieves"...

[1] https://en.wikipedia.org/wiki/EncroChat

Budget

vektorweg

I think, the reveal of the app rather had funding in mind. It looked pretty impressive what they did. Sure they gained favor and leverage for a budget boost.

Under every stone lurks a politician.
-- Aristophanes