I’ve been quietly keeping up to date on the recent IPT trial on Operation Venetic . To find not only has some of the footage been posted to Twitter
https://archive.ph/wip/kC7Ir Archived Tweet
I was also interested to find that this interesting note appeared.
Matthew Ryder KC told the court that the NCA had decided that it wanted a Targeted Equipment Interference (TEI) warrant - the only warrant that would allow messages and images intercepted from EncroChat to be used as evidence in court.
and even more curiouser.
An analysis of the Investigatory Powers Act showed that the correct warrant for the EncroChat operation, would have been a Targeted Intercept (TI) warrant, Ryder told the court, which would not allow messages harvested from EncroChat to be used as evidence.
However, the most interesting news seems to be the first publicly known method of exploitation that was actually used.
Csoka said that one known vulnerability with EncroChat, which used the Signal protocol, was that the random number generator, used for encryption, could be replaced by an attacker.
This doesn’t seem entirely accurate and may be used in layman’s terms for the reader, i do recall a well known audit was performed before the takedown occurred and i believe included a TLS downgrade attack was feasible given the TLS version that the Encrochat network used at the time, however i cannot find this, please link me to it if you remember it and can secure the actual research. This may well be what Csoka is referring to as interpreted by the reporter.
The implications would indeed be quite big if found in the favour of those currently seeking to challenge.
