After Cracking Another 'Secure' Messaging App, European Police Arrest 42 (barrons.com) 38
Slashdot reader lexios shares this report from the French international news agency Agence France-Press:
European police arrested 42 suspects and seized guns, drugs and millions in cash, after cracking another encrypted online messaging service used by criminals, Dutch law enforcement said Friday. Police launched raids on 79 premises in Belgium, Germany and the Netherlands following an investigation that started back in September 2020 and led to the shutting down of the covert Exclu Messenger service.
After police and prosecutors got into the Exclu secret communications system, they were able to read the messages passed between criminals for five months before the raids, said Dutch police. Those arrested include users of the app, as well as its owners and controllers. Police in France, Italy and Sweden, as well as Europol and Eurojust, its justice agency twin, also took part in the investigation. The police raids uncovered at least two drugs labs, one cocaine-processing facility, several kilograms of drugs, four million euros in cash, luxury goods and guns, Dutch police said.
The "secure" messaging app was used by around 3 000 people who paid 800 euros (roughly $866 USD) for a six-month subscription.
After police and prosecutors got into the Exclu secret communications system, they were able to read the messages passed between criminals for five months before the raids, said Dutch police. Those arrested include users of the app, as well as its owners and controllers. Police in France, Italy and Sweden, as well as Europol and Eurojust, its justice agency twin, also took part in the investigation. The police raids uncovered at least two drugs labs, one cocaine-processing facility, several kilograms of drugs, four million euros in cash, luxury goods and guns, Dutch police said.
The "secure" messaging app was used by around 3 000 people who paid 800 euros (roughly $866 USD) for a six-month subscription.
Douglas Adams? (Score:2)
But can they hack Truconf? (Score:5, Interesting)
Apparently the Ukrainian security service "hacked" into a Trueconf call [twitter.com] between Russian terrorists and quislings in Ukraine. Those on the Ukrainian side were told they were both fired and charged with treason. Then everybody was made to listen to the Ukrainian national anthem.
Trueconf [trueconf.com] touts itself as a "secure video conferencing solution that meets European cybersecurity and data protection standards."
So much for being secure.
Re: But can they hack Truconf? (Score:4, Insightful)
yeah? (Score:2)
Who says it was "secure"? Doesn't sound secure to me.
I read the article/link, but still had all these questions.
Re: (Score:2)
Who says it was "secure"? Doesn't sound secure to me.
Obviously, it's the guys behind the app said it is secure (it's proprietary code so not worth of trust anyway). Here is their ad line "Exclu Messenger is an unique world class product, featuring one of the most secure encryption used for communications." -- from exclumessenger.com exclu.chat exclu.network excluchat.cc exclu.app exclusivepgp.org I don't know why you would register so many similar domains other than some scam. I did not open any of these links, I only used the text quoted by the search engin
Re: (Score:2)
They "cracked" it. How? What? What did they crack? Maybe they just read the metadata that wasn't encrypted? Who says it was "secure"? Doesn't sound secure to me. I read the article/link, but still had all these questions.
If you really want to know, then my advice would be to apply for a job in Homeland security. You will obviously have to sign an NDA to never reveal such information.
Re: (Score:2)
As someone above mentioned, it's often social engineering used to gain access to something that then allows access to the encrypted
Did users review the source code of Exclu? (Score:3)
Re: Did users review the source code of Exclu? (Score:4, Insightful)
Re: (Score:2)
This seems to be another example of "dumb criminals".
They were sold on a "secure" app (at a high price) which turned out not to be so secure.
Re: (Score:2)
This is the inherent nature of criminality. People who think it's OK to lie, cheat, and steal, are prime candidates as targets of others who think it's OK to lie, cheat, and steal.
Re: (Score:3)
I'm willing to bet that while you may be right about dumb criminals, but I'm also willing to bet it wasn't because the app itself isn't secure. Most of these criminal cases law enforcement like to crow about how through highly advanced 'techniques' their team of 'highly skilled' hackers 'broke' encrypted communications by 'evil' doers. When really no such thing happened.
All they really did was exploit poor security habits of the users or some common real world weakness. If you read the official press
Re: (Score:2)
Or it was a honey trap like the "ANOM" "secure" phone that was used in a spate of stings in 2021: https://www.bbc.com/news/world... [bbc.com]
Re: (Score:2)
Oh let me guess, nobody reviewed the source code because it was not even published...
I'm willing to bet you've never done this either and simply taken the word of others on face value that someone somewhere at some point has reviewed it.
And we've learned nothing from Heartbleed.
Re: (Score:2)
> Oh let me guess, nobody reviewed the source code because it was not even published... so they paid for believing in some obscurity, which is not security.
Dude, it's called an Intelligence Operation.
Many criminals are kinda dumb.
Fish in a barrel (Score:4, Insightful)
If criminals were smart they'd hide their activities in a sea of mundanity - using apps where the majority of activity was banal, legal, and not likely to convince a judge to sign off on mass surveillance. The cops would have to focus on specific individuals and present probable cause which would limit their searches and who they eventually arrest.
But criminals are fuckwits who gravitate towards apps & devices custom advertised to serve their nefarious purposes. It's kind of amusing in a way that people desperate to avoid attention end up concentrating their criminality in a way that cannot escape attention. Oh well, enjoy prison.
Re: (Score:3)
They do. This gets the lazy ones, as the low value of seizures attests.
Re: (Score:2)
Even in a sea of mundanity, criminal patterns can be found and traced. The reality is, criminals want to be able to do things that society does not want people to do, such as steal from others. This type of activity will always stand in contrast to other activity that conforms to societal norms. There isn't a sea big enough to hide in.
Re: (Score:2)
Not a problem for me, just these geniuses.
Comment removed (Score:5, Informative)
Re: (Score:3)
Re: (Score:3)
The ONLY unbreakable encryption is the One Time Pad.
When someone uses that and becomes a person of interest, then the homeland security simply bundles some keyboard logger into their next android/os update.
Re: (Score:2)
Fake news (Score:3)
European countries have some very strict gun laws. So criminals wouldn't have guns.
Re: (Score:3)
Re: (Score:3)
They won't threaten to shoot an autistic child with a toy truck, and they won't shoot the nearby unarmed black man simply because.
Re: (Score:2)
https://worldpopulationreview.... [worldpopul...review.com]
Gun Deaths per 10k in
USA = 10.89
Belgium = 1.95
Germany = 1.22
Netherlands = 0.48
Re: (Score:2)
Re: (Score:2)
European countries have some very strict gun laws. So criminals wouldn't have guns.
Logic error. European countries have some very strict gun laws. So only criminals have guns.
It's why we don't go around shooting each other over arguments, or suiciding, or having our kids accidentally shoot themselves. It's why the Netherlands has 1/20th of the gun deaths per capita than 'MURIKA.
Re: Fake news (Score:1)
The US is much larger than Europe. If you divide up the US into chunks the size of European countries, comparison starts to become a lot easier to show crime stats in a meaningful way.
Not sure I want answers (Score:4, Interesting)
These and others weren't just suspects harassed by police but have been proven cases further investigated and found guilty based on overwhelming evidence, I find myself no longer the complete absolutist I used to be. Which is why I don't know if I want to know what they used for "encryption". Not so much as