Remix.run Logo
janmo 6 hours ago

The key aspect here is that both Sky ECC and Encrochat got F. over by the modern day equivalent of Crypto AG which is the french hosting provider OVH.

While intelligence agencies were pumping in real-time all the data from Encrochat's and Sky ECC;s dedicated OVH servers, the OVH co-founder Octave Klaba and their ex-CEO Michel Paulin were selling the company with statements like:

- We don't dig in our customer's data unlike the the "others".

- US secret services have no access to our data.

However there are many interesting anecdotes:

1) For many years OVH was hiding a "maintenance" backdoor in "/etc/ssh/authorized_keys2", authorized_keys2 was used for ssh protocol 2 which was depreciated in 2001 yet OVH was using it to store a maintenance key until around 2018. This was very poorly documented and a user warned of the backdoor on HN back in 2012. https://news.ycombinator.com/item?id=4839414

2) In 2013 the TOR hidden service hosting provider "Freedom hosting" was taken down, "they" had rented 400 servers at OVH and in June 2013 "they" let all but one expire, likely moving to another provider, this is when through an unknown way the FBI obtained the IP address of the only remaining server at OVH. The server was imaged but it contained an encrypted "container". The FBI claims that they were able to break the encryption within a week using "cryptanalysis" and to recover the "root" password used to encrypt these "containers". This is total BS, they must just have used the ssh maintenance key or added "something" to the server when they did the imaging.

Source criminal complaint Eric Eoin Marques: https://www.justice.gov/d9/press-releases/attachments/2019/0...

3) Later that same year Silk Road was taken down. It is undisputed that law enforcement lied about key parts in their investigation.

According to law enforcement Ross Ulbricht was ssh'ing into the Silk Road server using a "VPN server". When they got to the "VPN server" it had been wiped out BUT, the hosting provider had kept "VPN" "logs"??? which led them to the IP address of a cafe where Ross Ulbricht had been. Ross Ulbricht kept a list with all the servers he was and had been operating. There is no mention of a VPN server, however in the "retired" server section there is a "VNC Desktop" server with the note "SR related". This appears to be a server running a virtual desktop that Ross Ulbricht was using to connect to the Silk Road. It was a VPS hosted at ... OVH and rented through an intermediary called momentovps. But it gets even worse, just bellow he listed another VPS at OVH and it has the remark "Will / personal backup / deadman switch"...

Source: Silk Road Exhibit GX-264

4) The creation story is quite strange. OVH was offering very low prices while not having any funding. The secret was that for years Xavier Niel who is one of Octave Klaba's competitors and has been outed as being a former agent for the french government was hosting the OVH servers in his datacenter for FREE. Obviously if you do not pay for the electricity, internet and rent life is easy. The question is what did Xavier Niel get in return? According to him (Interview on BFMTV) he did it out of generosity. Of course...

Now we pretty much know that Pavel Durov founder of Telegram got his french passport because he agreed to work with the french intelligence agencies but failed to deliver. Guess who was the first person he called when he got arrested, and then the person he met once he was released? Xavier Niel!

Etheryte 5 hours ago | parent [-]

You can add What.CD, the de facto Music Library of Alexandria at the time, to this list, along with a number of other private torrent trackers. When What.CD's servers got raided by the French authorities, a number of other trackers that were hosted at OVH also got raided "by accident". The authorities went in with a warrant for one site, but oh so luckily just happened to also stumble on a number of other private trackers hosted by OVH at the time, never mind that they're spread across separate servers in separate racks etc. You can smell the foul play from half a continent away.

What.CD is dead, long live What.CD (and Oink's Pink Palace).

janmo 5 hours ago | parent [-]

They don't need a warrant if OVH just hands it out to them which they do.

But what really matters is that intelligence agencies are sniffing in your data at OVH and that the company wants you to think otherwise.