Slashdot Mirror


NSA Publishes Blueprint For Top Secret Android Phone

mask.of.sanity writes "The National Security Agency has designed a super-secure Android phone from commercial parts, and released the blueprints(Pdf) to the public. The doubly-encrypted phone, dubbed Fishbowl, was designed to be secure enough to handle top secret phone calls yet be as easy to use and cheap to build as commercial handsets. One hundred US government staff are using the phones under a pilot which is part of a wider project to redesign communication platforms used in classified conversations."

35 of 172 comments (clear)

  1. I want one. by roc97007 · · Score: 3, Interesting

    That'd be the coolest geeky thing to have. Although I suspect it doesn't do you a lot of good unless both sides of the conversation is using them.

    --
    Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
    1. Re:I want one. by Dunbal · · Score: 5, Funny

      Surely you mean all three sides of the conversation...

      --
      Seven puppies were harmed during the making of this post.
    2. Re:I want one. by roc97007 · · Score: 4, Interesting

      If you're implying a back door, the overriding problem as far as I can see is that if you have a secret double encrypted phone with an option, no matter how secret, for someone else to listen in, as a secret organization you wouldn't dare use the phone. Because somehow, by hook or by crook, by bribery, blackmail or corruption from the richest countries and individuals of the world, that back door *will* be made available to foreign powers. It's inevitable.

      And so, the NSA will have created a phone that the NSA itself could not use.

      If it had been intended as a honey pot, then bravo. Otherwise, no.

      --
      Oliver's law of assumed responsibility: If you're seen fixing it, you will be blamed for breaking it.
    3. Re:I want one. by cavreader · · Score: 2

      Well they probably didn't really care since the Polish and England scientists already figured it out. And the "folks" making the statement you mentioned were most likely utterred by an one or two individuals not the organization as a whole. The US was more interested in moving nuclear physics from the white board to real world applications such as building nuclear weapons. Wasting resources on something already accomplished by others would have been a waste. And by the way England had a large head start with the information 2 Polish scientists were able to get out of the country before the Germans took control. The early versions of the enigma machine were targeted at business uses and had been around a while before it was applied to military uses. The Poles got their hands on one of these earlier machines before the war even started and security protocols were not as stringent as they were during the war. People make the mistake of judging US capabilities displayed in the past with the capabilities it now possesses.

    4. Re:I want one. by Dunbal · · Score: 3, Insightful

      And so, the NSA will have created a phone that the NSA itself could not use.

      And this surprises you how, exactly?

      Most security boils down to "security by obscurity" when you get past all the smoke and mirrors. Someone at the top above all the compartmentalization made the decision that he simply won't tell anyone about the back door. Except for Dan in Dept A where such a backdoor would be very VERY useful, you know, to keep tabs on the operatives, etc; and Roger in Dept B whose job it is to keep tabs on Dept A. Both Dan and Roger are trustworthy and sworn to secrecy, so there's no way that this back-door will be abused or leaked. Ever. Except...

      --
      Seven puppies were harmed during the making of this post.
  2. Double Encryption??? by msgmonkey · · Score: 5, Funny

    Wow sounds very secure, hopefully they did n't decide to go with ROT-13 twice.

    1. Re:Double Encryption??? by Dunbal · · Score: 5, Funny

      Watches the contrails of the age-old ROT-13 twice joke go streaming by far, far above AC's head.

      --
      Seven puppies were harmed during the making of this post.
    2. Re:Double Encryption??? by alostpacket · · Score: 4, Funny

      Not only double secure, but if you're caught doing something nefarious, they put you on double secret probation. They have also contacted Double Mint Gum about possible trademark licensing.

      --
      PocketPermissions Android Permission Guide
    3. Re:Double Encryption??? by icebike · · Score: 3, Interesting

      Actually, I remember reading somewhere that consecutive encryption of a file (or a data stream) provides no additional protection against brute force attacks. The brute force needed to decrypt the end result is virtually the same, whether you encrypt once or twice. Something about a "meet in the middle" attack.

      Not sure if this is true in all cases because TripleDES is a common encryption technique.
      I (obviously) don't understand all that I read about this stuff.

      --
      Sig Battery depleted. Reverting to safe mode.
    4. Re:Double Encryption??? by Anonymous Coward · · Score: 2, Insightful

      Most of the time, yeah, it makes little to no difference. It may change the problem (though double encrypting with the same encryption may not even do that, depending on the cipher), but not make it any more difficult.

      However, that's assuming that the ciphers you're using aren't flawed. Using multiple ciphers means that if a flaw is discovered for one, it (hopefully) won't apply to the combination of the two.

    5. Re:Double Encryption??? by Hentes · · Score: 2

      No, they went with XOR twice.

    6. Re:Double Encryption??? by Dunbal · · Score: 2

      The Roman empire lasted for almost 1000 years. I'm sure they had a few technological innovations during that time. That doesn't detract from the fact that ROT-13 was invented by the Romans, nor does it exclude the possibility of them inventing more advanced encryption and also being able to call that more advanced thechnology "Roman encryption technology"...

      --
      Seven puppies were harmed during the making of this post.
  3. Will it fit... by ackthpt · · Score: 5, Funny

    In a shoe?

    --

    A feeling of having made the same mistake before: Deja Foobar
    1. Re:Will it fit... by Maintenance+Goof · · Score: 5, Funny

      Since this is not a secure channel, I think we should use the cone of silence!

  4. transparent case and dip switches... by jdogalt · · Score: 5, Interesting

    All I've really wanted for christmas for the last 10 years is a phone easily disassemblable, with a transparent case, and user facing dip switches for the mic, the antennas, the battery, and these days, the power line going to the camera. Or alternately for the camera, a physical piece of plastic that slides to expose/cover the camera. Also the dip switches should be placed in such a way that it is reasonably convincing to technical users that they are in fact breaking the relevant physical traces/wires.

    Maybe in 10 more years...

  5. Microsoft about to sue government? by JonahsDad · · Score: 5, Funny

    Just wondering when Microsoft sues the NSA for patent infringement for using Android.

  6. Gotta love /. headlines... by RareButSeriousSideEf · · Score: 3, Funny

    Sensationalistic, inaccurate, or self-contradictory, pick any two.

    1. Re:Gotta love /. headlines... by kat_skan · · Score: 3, Funny

      It is but there's a trick to it. You just have to pick two different ones when they post the dupe.

  7. Hmmmm... by olsmeister · · Score: 3, Insightful

    (dons tin foil hat) Do they really want phones like these to become inexpensive and easy to produce? Would we have been able to locate bin Laden if the courier and the whole group had these? Is there a back door hidden in the design that allows the NSA access? (removes tin foil hat)

  8. Research In Motion by Mabbo · · Score: 3, Insightful

    Well, that should be the final nail in the coffin for the Blackberry. I've been saying for the last 2 years: All RIM has going is the fact that they have a secure phone. All someone needs to do is offer an Android-based phone with the same level of security, and they will have lost the only real selling point remaining that they had.

  9. fishbowl !=blowfish by optimism · · Score: 5, Interesting

    re: "The doubly-encrypted phone, dubbed Fishbowl"

    A strange combination of clever and ironic.
    Fishbowl is an anagram of Blowfish, though I dunno if they use that cipher.
    However to most folks, a fishbowl is something in clear view, under close observation.
    Quirky.

    1. Re:fishbowl !=blowfish by Anonymous Coward · · Score: 2

      It's doubly-encrypted, so they use Twofish.

  10. Re:Security Violation by oodaloop · · Score: 4, Informative

    Um, maybe being able to use it inside the secured faciltiy? I worked at DIA for a while, and if someone wasn't at their desk, aside from leaving a sticky note for them, the only thing you could do is walk around and look for them or wait. Outside of work, I could call, text, email, facebook, IM, etc. But at work, there was email to their desk, call their desk, or nothing. A secured cell phone to take with you when you walk around would make things so much easier.

    --
    Tic-Tac-Toe, Global Thermonuclear War, and relationships all have the same winning move.
  11. Rogue Apps by losttoy · · Score: 2

    Remember, double encrypting rogue apps in AES does not make them good. The traditional approach towards security doesn't work very well in the mobile world especially Android. You have to not only do the regular things like encrypt but have a strict login such that they cannot run any app other than authorized. Not even the HTML5 stuff because it doesn't matter how locked down the phone is - once you allow an app on the phone that can access the data, it is game over.

  12. Re:Where was it made? by OzPeter · · Score: 2

    The NSA has its own fab. They can make their own chips if they so choose. Depending on the level of security needed I'm sure they will.

    They may have their own fab .. but from TFA ..

    “The plan was to buy commercial components, layer them together and get a secure solution,”

    You have to be able to trust the entire supply chain. In addition, they are talking about 3rd parties building these (who won't access to NSA systems) .. so why should I trust a 3rd party any more than I trust any other telecoms supplier?

    --
    I am Slashdot. Are you Slashdot as well?
  13. Re:uh by Skapare · · Score: 2

    The article references conversations as secret, not the phone. Titles do get morphed on Slashdot. That's just the way of things.

    --
    now we need to go OSS in diesel cars
  14. Not a good article by Anonymous Coward · · Score: 5, Informative

    I was at the talk yesterday (at the RSA Conference) where NSA IAD director Margaret Salter presented this information. While the linked article is mostly factually correct, it glosses over or misses quite a few things. In no particular order:

    * NSA's goal was to produce a spec for how to use commercial devices and commercial carriers yet still meet the requirements for SECRET or higher classified comms *without* forcing every user to be a COMSEC custodian. IMO, this represents a *huge* change in NSA's outlook on COMSEC and security in general. In the past, their focus has always been "security first, regardless of the impact on usability." Fishbowl's goals are an intriguing departure from this mindset.
    * The selection of Android was not a starting point, but the outcome of a selection process that included requirements like "we have to be able to get the OS tweaked to meet our needs." The relative openness of Android played well against this requirement.
    * Fishbowl currently only works on one handset. Salter declined to say which one, but it was clearly a Motorola product. Again, this was related to technical requirements around customization, boot loaders, etc
    * The article gets it right about IPSEC vs SSLVPN but falls short of detailing the laundry list of things NSA wanted but was ultimately unable to obtain. It's clear that as the landscape evolves, NSA will update the fishbowl spec. For example, if someone made available an Android that supported Suite B, I think that would appear on the spec immediately.
    * Salter did address the issue of rogue apps directly. She said that Fishbowl basically required policy support for locking out unapproved app installs, and that only NSA approved apps from the NSA enterprise app store would be allowed. "we don't want to be in the business of accrediting Angry Birds" is as close a quote as I can manage from memory.
    * The best question from the audience was when someone asked if, by publishing a spec on how to do encrypted secure comms on an Android, her division hadn't made the job of the SIGINT spooks impossibly more difficult. She somewhat artfully dodged/refused to answer, and simply said that her job was to protect the data and communications of the US Government. My take: draw your own conclusions about NSA's ability to break IPSEC.

    The talk was interesting, well presented, and completely sold out. I got one of the last 5 or 6 seats before they stopped letting people in the room.

  15. They are smarter than that by Sycraft-fu · · Score: 5, Interesting

    MS knows that the government controls patents and that national security is a grounds that the government can take a patent away and make it public domain.

    Interestingly enough the NSA has special status when it comes to patents. They can file secret patents that remain classified until someone tries to patent the same thing. At such time their patent is revealed and is valid from that date of revelation.

  16. I kinda doubt it by Sycraft-fu · · Score: 3, Insightful

    So let's have a look and see what classified information has ever been leaked by Wikileaks. Looks like just the diplomatic cables and video that came from Bradley Manning. Well guess what? That wasn't a hack, that was a person with access, that misused their access to give the information to an unauthorized party. That kind of thing has been going on as long as there have been spys and it is something the intelligence community works on (preventing or exploiting depending on) all the time.

    Past that? Nothing. I see nothing from Anonymous getting on to JWICS and grabbing and releasing tons of documents. They've DDoS'd webservers (and failed to DDoS others, Amazon proved to be too big a target) and gotten in to people who have security holes, but they don't seem to be able to get at the classified networks.

    Maybe, just maybe, the NSA is a little better at signals security than you give them credit for.

  17. You could RTFA by Sycraft-fu · · Score: 2, Insightful

    Where you'd find out the encryption isn't about apps, but about the calls. The NSA requires it so that in the event there is a failure in the implementation of one of the encryption layers, that isn't an automatic compromise.

    In terms of app control yes, it only gets apps from a DoD run app store. The phones can only get apps that the NSA has decided are ok. The control actually goes further than that, in that to place a call you connect to signals and they then route your call to the requested party. So you can't even just call whomever you'd like, you have to go through a central point (which means they can track who called who).

    You have to remember the NSA is not new to this game. They are pretty much the best the world has ever seen at signals intelligence, and they were doing encryption back in the days when nobody had heard of such a thing. They are pretty good at it. Well their mission isn't only signals intelligence (as in capturing and decoding information from non-US entities) but also information assurance, meaning protecting US government communications.

    Further, they have a mission to help protect US civilian interests like helping keep electronic banking secure. This is why you see things like this phone, or SELinux, released to the public.

    1. Re:You could RTFA by MartinSchou · · Score: 3, Insightful

      You have to remember the NSA is not new to this game. They are pretty much the best the world has ever seen at signals intelligence, and they were doing encryption back in the days when nobody had heard of such a thing.

      Are you suggesting they also invented time travel and ventured back in time to before AD?

      Encryption is a VERY old discipline, and was being used for more than a thousand years by the time Leonardo da Vinci was even born.

  18. Re:Flip side of that coin? by tqk · · Score: 2

    The average person is innocent and therefore has nothing to hide thus rendering encryption unnecessary.

    Yo, identity theft? The TLAs aren't the only people after all your seeeecret stuff. If I drop my phone and don't notice it, I like to know it's locked and nobody's going to get any use of it, or any of the data that's stored on it. I'd really hate it if losing it hurt someone who's info was stored on it.

    On the other hand, would I trust the NSA to not enable a back door? Probably not (and I don't even particularly dislike them).

    --
    "Tongue tied and twisted, just an Earth bound misfit ..." -- Pink Floyd.
  19. Re:Flip side of that coin? by mlts · · Score: 2

    One can do mental gymnastics, but this is how I look at it:

    If the NSA has a backdoor, eventually someone will find it and then glean knowledge of how they work. This may weaken them in the end. Plus, even if the NSA did, they can't really use it unless it would be an extremely high value target, or else their hand gets tipped.

    A similar argument can be mounted against SELinux and PGP, where if the NSA did have backdoors, they would have to be extremely clever, as well as not used unless the target is extremely high value.

  20. NSA can seize patents for their own and gag the in by bd580slashdot · · Score: 4, Interesting

    One day I was reading James Bamford's book "The Puzzle Palace" which was all about the NSA and crypto stuff. I was sitting on the back porch of The Last Exit on Brooklyn street coffeehouse reading when I got to a chapter about a guy who had made an encrypting phone out of cheap off the shelf components. He called it the phasorphone. When he applied for a patent the NSA seized it and gagged him (that means he was threatened and coerced to not talk about it). I pointed at the name in the book and held it up to the guy across the table from me and said "Carl, is this you?". He told me a bit about it and said the NSA kept track of him all the time after that. Department of Defense DIRECTIVE NUMBER 5535.02 March 24, 2010 USD(P) SUBJECT: DoD Patent Security Review Process You know, national security and all that. Because the light of democracy is so weak that it can only succeed if veiled by the cloak of secrecy, right?

  21. No not at all by Sycraft-fu · · Score: 4, Insightful

    However cryptography wasn't widely used or known to the public back in the day. Also while the codes used were technically cryptography by the pure meaning of the word, they really weren't by modern thinking. They were, well, codes, secret language and the like. As an example the highly successful Navajo Code Talkers in WWII weren't using mathematical encryption, book cyphers, or the like, they were just speaking a language that nobody in Germany understood, and using special terminology.

    The public really didn't have much of a study of cryptography in the modern sense back in the day. Heck, read up on the DES process. The NBS asked for submissions and nobody presented anything useful so they went to IBM and asked them to try (IBM being the biggest civilian employer of mathematicians at the time) and they developed DES, with some consultation with the NSA (who asked them to keep a lid on things like differential cryptanalysis).

    When DES came out, it lead to a real jump start of civilian study of cryptography. People were curious about this new thing and started looking at it.

    If you want to equate coded speech with mathematical crypto, ok fine then I guess, but it really isn't. Mathematical cryptography changed the game. With codes it was all about working to understand and guess the enemy's coding scheme, and such things were done all the time. With mathematical crypto, you can design a system that is unbreakable except through brute force (which you can make infeasible) or via some sort of new discovery in cryptology.

    This is something the NSA was one of the very fist involved in, and indeed they came about due to the importance of code breaking in WWII. They were the largest employer of mathematicians in the world for a time (not sure if that is still true).

    That's what I mean by "nobody had heard of it." I don't mean they invented it, I mean the concept was pretty much unknown to the public. The idea of a mathematical system that you could use to secure information was just not something people had heard of on any large scale. The NSA was writing crypto systems back when the geeks who now use crypto all the time were doing everything in plain text.